Home Blog Page 347

Google announces enhanced security measures

Google

Google recently announced key security improvements to beef up the data protection measures of Google account users. According to Jonathan Skelker, product manager at Google, the search engine giant is enhancing the account security by introducing a new step-by-step checkup, notifications, and JavaScript requirement.

“It’s Halloween and the last day of Cybersecurity Awareness Month, so we’re celebrating these occasions with security improvements across your account journey: before you sign in, as soon as you’ve entered your account, when you share information with other apps and sites, and the rare event in which your account is compromised,” Jonathan said in a blog post. “We’re constantly protecting your information from attackers’ tricks, and with these new protections and tools, we hope you can spend your Halloween worrying about zombies, witches, and your candy loot—not the security of your account.”

Jonathan Skelker explained that the Google’s new step-by-step checkup activates automatically whenever it detects any unauthorized activity and diverts the users to a four-step process: verifying security settings, securing other accounts linked to Google account, checking financial activity to ensure no payment methods connected to the google account weren’t compromised, and reviewing whether any content and files on Gmail or Google drive was compromised.

With Google’s latest notifications set-up, users can use a Web dashboard to set-up two-factor authentication and can review unusual security events. JavaScript, which is enabled on the Google sign-in page, runs every time users enter their credentials and block suspicious sign-ins automatically.

“Online security can sometimes feel like walking through a haunted house—scary, and you aren’t quite sure what may pop up. We are constantly working to strengthen our automatic protections to stop attackers and keep you safe from the many tricks you may encounter. During Cybersecurity Month, and beyond, we’ve got your back,” Jonathan added.

Recently, Google announced that it is going to shut down its social media network Google+ for consumers in the next 10 months. The declaration comes after the disclosure of a vulnerability that exposed around 500,000 users’ personal information to third-party developers. The services of Google+ for enterprise customers will remain active.

Under the Spotlight: Mark Houpt

Mark Houpt

Mark Houpt is responsible for developing and maintaining DataBank’s security program roadmap and data center compliance programs. He has over 25 years of extensive information security and information technology experience in a wide range of industries. In an interview with Rahul Arora, Houpt talks about essentials of a sound cloud migration strategy, ways of reducing the attack surface of data center and cloud computing, and much more. 

What are the cybersecurity practices that DataBank follows?

DataBank uses the NIST SP800-53R4 methodology as our primary framework for cyber security. Under this framework, we specifically utilize the moderate control set for a majority of our implementation. In some cases, we raise it to the high and other cases we lower it to low requirements based upon a risk assessment of the product or item we are
securing.

DataBank utilizes the NIST methodology identified above to comply with HIPAA requirements. For PCI-DSS requirements, we utilize the NIST methodology and cap it with PCI requirements when they are higher. For example, NIST calls for a penetration test to be conducted annually and PCI for a twice per year event. For PCI environments, we follow the twice method.

What are the essentials of a sound cloud migration strategy?

The essentials of a sound cloud migration strategy are to conduct an internal risk assessment before communicating with a cloud provider.

Read More

Call of Duty players steal crypto worth $3.3 million

Call of Duty

It was recently disclosed that a group of Call of Duty (CoD) players have been a part of a cybercrime syndicate that remotely stole $3.3 million in cryptocurrency by hacking several crypto wallets.

A person from Bloomington, whose identity was kept under wraps, was intimidated by the hackers to aid them hack nearly 100 phones to access crypto wallets. He told the FBI that he met the members of the ring online while playing Call of Duty and was forced to participate in the cyber-attacks. He disclosed that the hackers intimidated him into participating by “SWATting” him, a terminology used for calling police by making a hoax call to the emergency services in an attempt to bring about the dispatch of a large number of armed police officers, in this case the SWAT team, to a particular address.

The FBI hasn’t pressed any charges against him, however. The incident came to light when San Francisco-based firm Augur, creators of the Reputation Token, reported to the FBI that employees and investors of their company have had their crypto currency stolen. It is suspected that the hackers stole $805,000 worth Reputation Tokens which were later moved to Ether and Bitcoin, and then into their own wallets.

The Bloomington man said in an online interview, “I have done nothing but cooperate with Augur and the FBI. I have never once profited from anyone [by] crypto-hacking, ever.”

This is one of the rare incidents where hackers emerged out of the gaming community. Earlier this year, a Second Life player was accused of abusing funds through the game.  Second Life allowed gamers to buy and sell items through Linden Dollars which could be withdrawn through PayPal. It was reported that the gamer laundered money through Second Life and then traded for Bitcoin gathering up to 10 Bitcoins. The money was later seized by the UK Law Enforcement.

Eurostar hacked; customers asked to reset passwords

Eurostar

After British Airways and Cathay Pacific, European rail service, Eurostar, has joined the legion of transportation companies that have become a victim of a cyber-attack.

The breach into its systems to access user accounts occurred between October 15 and 19, 2018, and was detected by the company. The company immediately notified the customers stating that it had identified multiple attempts to access eurostar.com accounts using users’ email addresses and passwords and instructed customers to immediately reset their login credentials and passwords.  

On the bright side, there are hardly any chances that credit card details and payment information of users were compromised as payment details are not stored online by the company. Even though the company is still uncertain about the magnitude of the attack surface or even the fact that if any data has been stolen. The company also reported the incident to the Information Commissioner’s Office (ICO) as required by law.

“We have taken this action as a precaution because we identified what we believe to be an unauthorised automated attempt to access eurostar.com accounts using your email address and password,” the company told customers. “We’ve since carried out an investigation which shows that your account was logged into between the 15 and 19 October. If you didn’t log in during this period, there’s a possibility your account was accessed by this unauthorised attempt.”

The company has still not revealed if they have found the origin of the attack. Earlier, when the company rolled out emails to customers to reset passwords, the company told the customers that it was due to “maintenance” to the firm’s website.

“This email was sent after we identified what we believe to be an unauthorised automated attempt to access customer accounts, so as a precaution, we asked all account holders to reset their password,” explained a Eurostar spokesperson. “We deliberately never store any payment details or bank card information, so there is no possibility of those being compromised”.

 

Kaspersky partners with SABRIC to strengthen cybersecurity resilience in South Africa

Kaspersky Lab

Kaspersky Lab recently announced the extension of its partnership with the South African Banking Risk Information Centre (SABRIC). The Moscow-based anti-virus provider renewed the memorandum of understanding (MOU) signed with the SABRIC in October 2017. According to the MOU, Kaspersky Lab offers specialized cybersecurity training to security professionals in South Africa’s major banks.

Formed by four major banks in South Africa, SABRIC is a non-profit organization that works to detect and prevent cybercrimes in the banking industry through public-private partnerships.

“The advent of digital technology has seen cybercrime increase at an alarming rate, as it is virtual in nature, enabling it to transcend time and physical proximity. In addition, the convenience and anonymity of the internet make it easy for criminals to perpetrate these crimes. Industry collaboration is, therefore, a critical component in the fight against organized cybercrime in the financial services space, and we therefore welcomed the opportunity to partner with Kaspersky Lab – given their immense expertise in global cybersecurity and deep threat intelligence,” said Kalyani Pillay, CEO at SABRIC.

“Today, no industry can operate optimally without technology.  Yet this dependence on IT means that cyber threats are a growing global problem and as such, expertise in IT security has become critically important. Kaspersky Lab understands the world’s cyber threat landscape and our experts possess immense knowledge and experience in the detection and protection against growing threats. Transferring these skills is critical in the fight against cybercrime. This MOU has helped us to achieve just this, and we hope to continue working with SABRIC in this regard,” said Ben Gaum, Enterprise Lead at Kaspersky Lab Africa.

In related news, Kaspersky Lab recently uncovered AppleJeus, a malicious operation by North Korea’s cyber-hacking outfit ‘Lazarus Group’ to intrude on cryptocurrency exchanges and applications. Kaspersky Lab’s Global Research and Analysis Team (GReAT) discovered the unusual activity of attackers who penetrated into the network of an Asia-based cryptocurrency exchange using Trojanized trading software to steal cryptocurrencies.

Chinese Intelligence officers charged in US for jet engine hack

Chinese indicted

The United States Department of Justice has indicted 10 Chinese intelligence officers who broke into computer systems of private companies and stole data on a turbo fan engine used in commercial jetliners from January 2010 through May 2015, according to a Reuters report. The Chinese officers allegedly conspired with hackers and company insiders to steal the information.

“For the third time since only September, the National Security Division, with its U.S. Attorney partners, has brought charges against Chinese intelligence officers from the JSSD and those working at their direction and control for stealing American intellectual property,” said John Demers, assistant attorney general for national security.

According to the sealed indictment, the charged Chinese Intelligence officers Zha Rong, Chai Meng, and other co-conspirators and accomplices reportedly worked for the Jiangsu province Ministry of State Security, a unit of the foreign intelligence arm of the Ministry of State Security. They allegedly conspired to steal sensitive data to help their Chinese counterparts build the same engine using stolen technology which would reduce the expenses of research and development.

The officers had apparently targeted more than a dozen companies, including French company Safran SA that has been co-developing a turbofan jet engine with the U.S. company, General Electric Co (GE).

Lu Kang, a spokesperson from Chinese Foreign Ministry called the charges groundless, stating that “the relevant accusations are pure fiction and totally fabricated,” though he did not provide any elaborations. Arrest warrants have been issued against the ten, however, it is believed that all defendants are in China.

“This action is yet another example of criminal efforts by the (Ministry of State Security) to facilitate the theft of private data for China’s commercial gain,” U.S. Attorney Adam Braverman said in a statement. “The concerted effort to steal, rather than simply purchase, commercially available products should offend every company that invests talent, energy, and shareholder money into the development of products.”

Tomorrowland ticketing system hacked; 64,000 visitors affected

Tomorrowland

According to a report from a Flemish daily newspaper, a data breach compromised personal information of around 64,000 attendees of Tomorrowland’s 2014 festival. Tomorrowland is an electronic dance music festival held in Belgium every year.

The De Standaard reported that attackers breached the ticketing system Paylogic and allegedly obtained users’ personal data like names, addresses, emails, ages, postcodes, and gender details. However, the officials of Tomorrowland clarified attackers were not able to access any payment details, bank information or any other financial data from the affected systems. Paylogic stated the attack affected the customers who’ve purchased the tickets via their ticketing system and not the customers who obtained tickets online.

Tomorrowland’s spokesperson Debby Wilmsen claimed that the suspicious activity was noticed in an outdated system of Paylogic. As a preventive measure, Wilmsen stated they took actions immediately and halted the affected server right away. The company also reported the incident to the privacy commission and notified the potentially affected users.

“The managers of the Paylogic ticketing system noticed some unusual activity on an older system,” Debby Wilmsen said in a media statement. “After careful analysis, it appeared that an old database from Tomorrowland 2014 was concerned. The server in question was immediately taken offline.”

“We ask to be vigilant when receiving e-mails about ticket sales, promotions or other addressees that do not come from official Paylogic or Tomorrowland communication channels. All communication from Tomorrowland is led by tomorrowland.com. Links to Tomorrowland ticket sales can only be found via my.tomorrowland.com or official travel partners,” Wilmsen added.

 

Cisco Chairman John Chambers invests in India-based cybersecurity startup

Startup funding

Lucideus, a cybersecurity startup based in Delhi, India, recently raised $5 million in a Series A round of funding led by Emeritus John Chambers, the chairman of networking hardware company Cisco Systems, through his investment firm JC2 Ventures. Of the $5 million investment, John Chambers pumped in $4 million and a group of angel investors infused the rest. The company stated the new investment will be used to accelerate its business expansion plans.

Founded in 2012 by Saket Modi along with his friends Rahul Tyagi and Vidit Baxi, the startup delivers information security platforms and services to enterprises and governments globally. Its cybersecurity and risk management platform offer consultancy, training, and solutions to its clients to help them monitor and respond to cyber threats in real time.

The company claims to have the National Payments Corporation of India (NPCI), ICICI Bank, Quikr, Goibibo, and Tatasky among its clients’ list.

“I think cybersecurity is absolutely in the top three. Many companies do not talk about it, however, because they don’t have a good answer. If you ask a CEO, how would they evaluate their status of risk exposure to cybersecurity and what are they doing as key elements, it’s piecemeal. The CEO would probably struggle. And that’s what Modi got, that others didn’t,” Chambers said in a news statement.

Recently, Cisco Systems acquired cybersecurity firm Duo Security for $2.35 billion to accelerate its operations in cloud computing. The latest deal is the biggest acquisition for Cisco since its $3.7 billion deal with application management company AppDynamics last year. The acquisition integrates Cisco’s network, device, and cloud security platforms with Duo Security’s zero-trust authentication and access products, allowing Cisco clients to connect their users easily and securely.

The great hack of 2018: Code red for Cathay Pacific

Cathay Pacific

With nearly 9.4 million accounts compromised, the recent breach of the Cathay Pacific is possibly one of the largest cyber-attacks of 2018. No major revelations have been made about the attackers. Fortunately, the affected IT systems were separate from its flight operations systems, and haven’t affected the flight safety.

The airline is now facing its first collective legal action in Hong Kong, “where nearly 200 customers have expressed their intentions to claim over the leak,” suggest a report. Even the local government has warned the airline to cooperate with the city’s privacy regulators else face repercussions. The incident has been dubbed as the largest data leak in Hong Kong. “The revelation came months after the breach was discovered in March and confirmed in early May,” suggests the report.

“If Cathay Pacific is not cooperative, the [privacy] commissioner is entitled to take legal action under the ordinance, which carries penalties,” Cheung, a spokesperson on behalf of Chief Executive Carrie Lam Cheng Yuet-ngor said. “[Cathay] has to obey the instructions and fully cooperate with our investigation.”

The leaked personal data includes names, birth dates, phone numbers, email addresses, physical addresses, passport numbers, identity card numbers, flyer program membership numbers, customer service remarks, and history of travel. Apart from these, 403 expired credit card numbers were accessed, and twenty-seven credit card numbers with no CVV were accessed.

“We are very sorry for any concern this data security event may cause our passengers. We acted immediately to contain the event, commence a thorough investigation with the assistance of a leading cybersecurity firm, and to further strengthen our IT security measures,” Cathay Pacific Chief Executive Officer Rupert Hogg said. “We are in the process of contacting affected passengers, using multiple communications channels, and providing them with information on steps they can take to protect themselves.  We have no evidence that any personal data has been misused. No-one’s travel or loyalty profile was accessed in full, and no passwords were compromised.”

Phishing the main cause behind Australian data breaches: Report

xss vulnerability in UPS, Phishing Attack, spear phishing, phishing mails

The Office of the Australian Information Commissioner (OAIC) stated that phishing attacks are the key source of data breaches in Australia. The OAIC recently released the quarterly statistics report on the Notifiable Data Breaches (NDB) occurred between July 1, 2018 and September 30, 2018. The latest report notified 245 data breaches that affected users’ personal information during the quarter.

Of the 245 reported breaches, the OAIC stated that 57 percent of incidents were caused by malicious attacks, 37 percent resulted from human error, and 6 percent were due to the system fault.

The report detailed the top five industries that suffered the most breaches are health service providers (45%), finance (35%) legal, accounting, management services (34%), private education providers (16%), and personal service providers (13%).

The OAIC publishes quarterly statistical information about data breach notifications received under the Notifiable Data Breaches scheme to help the community, businesses, and government understand the scheme and the causes of data breaches.

Speaking on the importance of workforce training on cybersecurity awareness, the Australian Information Commissioner and Privacy Commissioner Angelene Falk said, “Everyone who handles personal information in their work needs to understand how data breaches can occur, so we can work together to prevent them. Organizations and agencies need the right cyber security in place, but they also need to make sure work policies and processes support staff to protect personal information every day.”

“Our latest report shows 20 percent of data breaches over the quarter occurred when personal information was sent to the wrong recipient, by email, mail, fax or other means,” Ms. Falk added.