Home Blog Page 349

ObamaCare portal suffers data breach

Obamacare

The United States government’s health insurance system HealthCare.gov recently suffered a data breach that resulted in the theft of thousands of patients’ records.

According to the official statement, unknown attackers breached the government portal’s sign-up system named Federally Facilitated Exchanges (FFE) and compromised around 75,000 patients’ personal data. Managed by the Centers for Medicare & Medicaid Services (CMS), the HealthCare.gov is a platform for insurance agents and brokers to enroll users in Obamacare insurance plans.

The CMS stated they discovered the suspicious activity on October 13, 2018, and notified the Federal law enforcement for an immediate investigation. On October 19, the CMS officials declared that the portal was compromised between October 13 and 16, and it is unclear what information was exposed in the unauthorized activity.

“We are working to address the issue, implement additional security measures, and restore the Direct Enrollment pathway for agents and brokers within the next 7 days,” the statement said.

The accounts connected to the data breach were deactivated and the enrolment platform was temporarily disabled. The government is enhancing the security measures of the portal and investigating to find the culprits behind the breach.

“Our number one priority is the safety and security of the Americans we serve. We will continue to work around the clock to help those potentially impacted and ensure the protection of consumer information,” said CMS Administrator Seema Verma. “I want to make clear to the public that HealthCare.gov and the Marketplace Call Center are still available, and open enrollment will not be negatively impacted. We are working to identify the individuals potentially impacted as quickly as possible so that we can notify them and provide resources such as credit protection.”

FDA releases new recommendations on medical device cybersecurity

Medical device cybersecurity

The Food and Drug Administration (FDA) of the United States of America recently released the updated draft of premarket guidance for medical device cybersecurity. The draft comprises new recommendations for internet-connected medical device manufacturers on how to assess cybersecurity in the review of the medical devices to ensure protection against cyber threats. FDA also notified manufacturers to provide its customers with a list of software and hardware components that could be vulnerable to exploitation.

“The need for effective cybersecurity to ensure medical device functionality and safety has become more important with the increasing use of wireless, Internet- and network-connected devices, portable media (e.g. USB or CD), and the frequent electronic exchange of medical device-related health information. In addition, cybersecurity threats to the healthcare sector have become more frequent, more severe, and more clinically impactful. Cybersecurity incidents have rendered medical devices and hospital networks inoperable, disrupting the delivery of patient care across healthcare facilities in the US and globally. Such cyberattacks, and exploits can delay diagnoses and/or treatment and may lead to patient harm,” the guidance reads.

According to the FDA, the new recommendations enable device manufacturers in the premarket review process to ensure that medical devices are designed to tackle cyber-attacks.

“Cybersecurity threats and vulnerabilities in today’s modern medical devices are evolving to become more apparent and more sophisticated, posing new potential risks to patients and clinical operations,” FDA Commissioner Scott Gottlieb, M.D., said in a statement. “The FDA has been working to stay a step ahead of these changing cybersecurity vulnerabilities, including engaging with external stakeholders. In this way, we can help ensure the healthcare sector is well positioned to proactively respond when cyber vulnerabilities are identified in products that we regulate.”

As a part of the ongoing efforts to strengthen cybersecurity in the healthcare department, the FDA and the U.S. Department of Homeland Security (DHS) recently joined hands to address cybersecurity issues in medical devices.

“Our strengthened partnership with DHS will help our two agencies share information and better collaborate to stay a step ahead of constantly evolving medical device cybersecurity vulnerabilities and assist the health care sector in being well positioned to proactively respond when cyber vulnerabilities are identified. This agreement demonstrates our commitment to confronting cybersecurity risks and the unscrupulous cybercriminals who may seek to put patient lives at risk,” Gottlieb said in a statement about the partnership,” Scott Gottlieb stated.

 

Former Equifax manager sentenced, fined for insider trading

Equifax

Sudhakar Reddy Bonthu, a former software product development manager at Equifax, was sentenced to serve eight months home imprisonment over insider trading charges related to Equifax’s data breach last year.

According to the U.S. Justice Department, Sudhakar was penalized by the U.S. District Court Judge Amy Totenberg in Atlanta federal court for selling Equifax stock options in the wake of the company’s data breach announcement. He was fined for $50,000 and also ordered to pay $75,979 in restitution.

“Bonthu intentionally took advantage of information entrusted to him in order to make a quick profit,” said U.S. Attorney Byung J. “BJay” Pak. “The integrity of the stock markets and the confidence of investors are impaired by those who use non-public information for personal gain.”

According to the prosecutors, Sudhakar knew the breach announcement date was September 6, 2017. And on September 1, 2017, he used his wife’s brokerage account to buy 86 “put” options. He went on to make a profit of $75,000 after the share value plunged following the disclosure of the data breach on September 7, 2017.

“If we don’t hold company insiders to the same rules that govern regular investors, the public’s confidence in the stock market erodes,” said Chris Hacker, Special Agent in Charge of FBI Atlanta. “The FBI will do everything in its power to hold accountable those who choose to take advantage of their inside knowledge.”

On September 7, 2017, Equifax, the Atlanta-based consumer credit reporting agency, disclosed that its databases had been breached between May and June 2017, that hackers had gained access to Company data that potentially compromised sensitive information for 143 million American consumers, including Social Security numbers, credit card numbers and driver’s license numbers.  Equifax discovered the breach on July 29, 2017, but had waited until after the close of trading nearly six weeks later to disclose the breach to consumers and Equifax’s investors, after hackers exfiltrated data for 76 days.

The Atlanta-based consumer credit reporting agency was charged with a fine of £500,000 ($660,000) by the Information Commissioner Office (ICO) for failing to protect the personal and financial data of customers. The Information Commissioner’s Office, which carried out the investigation, stated that Equifax had been warned about vulnerabilities in its systems by the US Department of Homeland Security in March 2017. However, Equifax failed to take proper steps to fix the vulnerabilities.

 

Cybersecurity firm Garrison secures $30 million investment

Startup funding

Cybersecurity software developer Garrison recently raised £22.9m ($30m) investment in a funding round led by the London-based technology investor Dawn Capital along with the existing investors IP Group, BGF, and NM Capital. Garrison stated the new funding will be used to expand the company’s sales and marketing activities as well as development of its national security grade technology for commercial use.

Speaking on the investment round, Dawn Capital partner Norman Fiore said, “Garrison is taking a radically different approach to security by moving beyond the previous threat-detection paradigm. We see a significant opportunity for Garrison to bring its military-grade technology to major commercial institutions and fundamentally reduce the threat posed by their employees’ everyday web browsing. We’re delighted to support the business in the next phase of its growth.”

Founded by cybersecurity veterans David Garfield and Henry Harrison in 2014, Garrison offers ultra-secure Web browsing technology that detects and eliminates malware before it reaches the end-point. The company’s secure web software enables organizations and individual users to access any content on the internet without the risk of cyber threats.

“Organizations today recognize the ever-growing threat to their most sensitive data and systems posed simply by allowing employees to browse the web, but until now they’ve faced an unhappy choice: restrict web access and allow productivity to suffer, or run the risk of exposure to hackers,” said Garrison CEO David Garfield. “We’ve designed the world’s first truly secure web browser to solve this problem, applying national-security-grade levels of protection to the commercial environment – at an accessible price point – in a way that doesn’t destroy the user experience as employees go about their work.”

“The security industry has long suffered from overblown claims and over-inflated prices, without ever ensuring organizations remain truly protected from even some of the most basic threats – this is particularly true of web browsing security. From day one our mission has been developing practical security tools that actually do what they’re supposed to. This funding round marks a key milestone for our business and will help us to transform the day-to-day security of many thousands more organizations worldwide,” Garfield concluded.

US voter list for sale on dark web hacking forum

US Voters

The content of voter databases of around 35 million US citizens are being peddled on a hacking forum, according to a report from threat intelligence firms Anomali and Intel 471. The researchers revealed that cybercriminals have obtained unauthorized access to the U.S. voter registration databases and put them for sale in dark web forums.

The database holds personal information like names, phone numbers, address details, and voting history, according to the researchers. They also said the data is priced between $150 and $12,500. The report stated the disclosure affects 19 states, including Georgia, Idaho, Iowa, Kansas, Kentucky, Louisiana, Minnesota, Mississippi, Montana, New Mexico, Oregon, South Carolina, South Dakota, Tennessee, Texas, Utah, West Virginia, Wisconsin, and Wyoming.

According to the researchers, the sellers receive updated voter registration data across the states via their close contacts within the state governments. It was specified that voters’ information disclosure is not a technical breach but a targeted operation by threat actors to perform malicious activities.

“To our knowledge, this represents the first reference on the criminal underground of actors selling or distributing lists of 2018 voter registration data, including US voters’ personally identifiable information and voting history,” Anomali stated in an official post. “With the November 2018 midterm elections only four weeks away, the availability and currency of the voter records, if combined with other breached data, could be used by malicious actors to disrupt the electoral process or pursue large-scale identity theft.”

In related news, the Microsoft Corporation recently stated that hackers linked to Russian military intelligence tried to hack the websites of two conservative think-tanks in the United States ahead of November midterm elections. The tech giant revealed it has detected and seized websites that were created by hackers to mimic the pages of the International Republican Institute and the Hudson Institute.  These sites are designed to redirect the users to fake web pages where they were asked to enter usernames, passwords, and other credentials.

Pentagon reveals data breach in Defense Department

DEO data breach

Pentagon recently announced that Defense Department has suffered a data breach that exposed the personal and credit card information of some U.S. military and civilian personnel.

According to the official statement, attackers allegedly gained unauthorized access to the sensitive information through a system that stores travel records. The system was maintained by a third-party contractor. “The department is continuing to assess the risk of harm and will ensure notifications are made to affected personnel,” said the statement.

The Associated Press quoted an official who stated that the incident might affect at least 30,000 individuals and the number may increase in the future. The data breach, which is believed to have happened some months ago, was disclosed on October 4, the report stated.

Lt. Col. Joseph Buccino, a Pentagon spokesman, stated the details of the third-party vendor were not disclosed due to security reasons. “It’s important to understand that this was a breach of a single commercial vendor that provided service to a very small percentage of the total population,” he added.

The disclosure of the data breach comes on the heels of the latest report by that highlighted the cyber vulnerabilities in the DOD weapons systems. According to the report, DOD testers frequently found “mission-critical cyber vulnerabilities” in almost every weapon system they were developed between 2012 and 2017. “Testers were able to take control of these systems and largely operate undetected. In some cases, system operators were unable to effectively respond to the hacks,” the report added. “Furthermore, DOD does not know the full scale of its weapon system vulnerabilities because, for a number of reasons, tests were limited in scope and sophistication.”

In the report, GAO was also critical of DOD’s attitude toward cybersecurity. GOA stated that it and others have warned DOD “of cyber risks for decades, until recently, DOD did not prioritize weapon systems cybersecurity. Finally, DOD is still determining how best to address weapon systems cybersecurity.”

Bug Bounty Programs are working: Patches for nearly 200 vulnerabilities released

cyberthreats, bug

Contributed by SecureWorld

It’s taken us a couple of days to do the math.

But PDF-related reader programs have had some major vulnerability updates in the last few days. Which ones do employees use in your organization?

Adobe PDF and Acrobat security update

On Monday October 1, 2018, Adobe released 86 vulnerability fixes for its Adobe Acrobat and Adobe PDF reader in an update. You can see details here: Adobe Acrobat and Adobe PDF security update.

Many of the vulnerabilities are listed as critical, and they impact everything from arbitrary code execution to privilege escalation.

Foxit reader and Foxit Phantom PDF security update

Adobe’s announcement comes just three days after Foxit updated more than 100 vulnerabilities in its Foxit reader and Foxit Phantom PDF programs.

Vulnerabilities range from remote code execution to remote admin authentication bypass vulnerability, which could be exploited by attackers to disclose information. See the Foxit security update here.

Security patches and updates: a sign bug bounty programs are working

It’s more common than ever now for companies to give credit to the white hat hackers who submit the security vulnerability—and the bug bounty programs those hackers are working through.

And in both of these cases, over and over again, you’ll see Trend Micro’s Zero Day Initiative listed as the source of the vulnerability research.

I recently spoke with Brian Gorenc, who is the Director of Vulnerability Research with Trend Micro and leads the Zero Day Initiative (ZDI) bug bounty program.

He was recently presenting at SecureWorld St. Louis.

And this is proof, he says, that bug bounty programs are working:

“The impact is significant, if you think about it. Every patch that is coming out, especially when it comes to enterprise software and operating systems, it is being fed by bug bounty programs,” Gorenc says. “The community is coming together to make sure the vendors are actually releasing patches for these bugs, and as a result the attack surface shifts and changes. We see that in the way people are using exploits in the wild because they have to go after different things because the old vulnerabilities are no longer there for them to take advantage of.”

And because of these two PDF reader updates, there will soon be nearly 200 vulnerabilities that are no longer available for hackers to exploit. Bug bounty programs, and the researchers who participate in them, are clearly making a difference in cybersecurity.

This article was originally posted here and is published on cisomag.com with SecureWorld’s permission.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Optus Cyber Security to acquire Hivint Strategic

Acquisition

Cybersecurity firm Optus is acquiring Hivint Strategic in a bid to boost the latter’s security services across Optus Business. The announcement was made by Singtel, Optus’s parent company. “This acquisition will strengthen Optus Business’ cybersecurity capabilities as Trustwave, the global cybersecurity arm of Singtel and Optus, integrates Hivint’s advisory services into Trustwave’s security offerings across Australia and the Asia Pacific,” Singtel said.

Over the last couple of years, Optus has been strengthening its cybersecurity infrastructure. Last November, Optus and Singtel has invested AU$3.5 million into the Cyber Security Cooperative Research Centre. It had also opened its Advanced Security Operations Centre (ASOC) alongside Trustwave, a year prior to that. It also co-invested AU$8 million along with La Trobe University in Melbourne to form cybersecurity degree as well as to digitize the university and its Sports Park. Apart from that it also co-invested AU$10 million to establish a cybersecurity hub in the region. With the acquisition of Hivint Strategic, Optus will become one of Australia’s leading cybersecurity service providers for both enterprise and government, claimed John Paitaridis, MD, Optus Business. “This acquisition is timely as an overwhelming 85% of over 200 Australian enterprises we surveyed cited cyber and information security as having the highest disruptive impact on their industries in the next three years,” he said.

“Protecting businesses from data breaches, disruption of operations, and loss of IP and economic assets has become a key objective for C-suite and board-level executives,” Trustwave CEO and Singtel Global Cyber Security CEO Arthur Wong said. “Additionally, Australia’s business leaders already leveraging Hivint as a preferred security advisor now have direct access to the complete Trustwave portfolio of security solutions, managed security services, and advanced education programs.”

Few minutes with Paul Hadjy

Paul Hadjy

Paul Hadjy is one of the reputed names in information security. As the CEO of Horangi, a company that offers cybersecurity solutions, Paul is tirelessly working to make cyberspace safer. Prior to Horangi, Paul worked at Palantir Technologies, where he was instrumental in expanding Palantir’s footprint in Asia Pacific. He has built over a decade of experience and expertise in Anti-Money Laundering, Insider Threat, Cybersecurity, Government and Commercial Banking.

In a conversation with CISO MAG, Paul discusses his journey with Horangi, the menace of insider threats, and much more.

You have been at the helm of Horangi for almost three years now. How has the journey been so far?

It has been an exciting experience growing a cybersecurity company with the rapid evolution of the industry landscape, regulations, and greater understanding of end users. There is certainly a lot of room to grow in terms of cybersecurity maturity, and we will continue to be at the forefront of this effort. Horangi has grown tremendously, and I am proud of what we have managed to achieve in just three years.

During its relatively short journey so far, Horangi has helped a number of SMEs in thwarting cybersecurity threats. According to you, which factors make it difficult for SMEs to deploy right cybersecurity practices?

The most important factor limiting SMEs in deploying the right cybersecurity practices is simply resources. The primary objective of most SMEs is to establish and drive their own business, and security is not necessarily a priority concern. This is where we have had tremendous success with SMEs because we understand these constraints and have built our solutions to help organizations to close the widening gap of resources and manpower required to better secure themselves. It is difficult for most SMEs to identify the right solution that holistically addresses both their business and technical requirements, especially since they rarely have deep cybersecurity expertise on their team.

Secondly, cybersecurity is a human problem. It is not enough to put in the technical solutions to secure an organization, the right security practices also involves changing behavior of employees which is a complex problem on its own. This is why we built our cybersecurity training product which allows organizations to educate their employees on the latest cybersecurity threats and track their security posture with employees in a cost-efficient and effective way.

Insider threat is a persistent problem in a number of organizations. As a cybersecurity solution provider, what kind of training is provided to your employees with regards to insider threats?

To answer this we must be clear ​why Insider Threat might occur, and it usually boils down to financial or personal motivations. At Horangi, we instill a cohesive family culture where our employees, or ‘Tigers’ as we call ourselves, support each other in and out of the office. Building a strong culture where everyone are more than just colleagues in a room, is the foundation towards mitigating Insider Threat.

Additionally, we clearly outline the roles and responsibilities of individual Tigers whilst promoting a strong internal culture of interdepartmental support, cohesion and cross training. The sharing of knowledge and opinions allows individuals to gain respect from their fellow Tigers, so they know their value to the Horangi culture and family. This is how we ‘train’ our employees at Horangi with regards to insider threat.

Having created that culture of mutual trust and common purpose, we also verify by defining access control for each role at the company and monitoring logs and systems carefully.

What are the biggest challenges you face in the recent future?

One of the biggest challenges that we and the industry at large face, is scaling up, while not compromising on the high standards we hold ourselves to. We have to constantly educate our customers, the general public and improve ourselves, at the same time constantly improve the quality of deliverables and interactions while threats and the need for cybersecurity continue to grow rapidly.

What is the advice you would like to give to a budding information security professional?

Horangi was founded to solve 2 things:

  • The lack of cybersecurity professionals, industry maturity and general awareness
  • The gap in alignment of cybersecurity with business objectives and priorities

There are a lot of opportunities for growth in this field today but you should focus on ​learning to explain your findings in simple way.​ Try explaining things to your mother, father or a friend that isn’t in cybersecurity. Each one of us will play an important role in educating others about the importance of cybersecurity, and ensuring the safety of technology users everywhere so make sure you’re ready when it’s your time.

F-Secure partners with NetAssist to provide solutions to Malaysian SMEs

F-Secure, a cybersecurity company, recently inked a partnership deal with security services provider NetAssist to jointly provide cybersecurity solutions to small and medium enterprises (SMEs) in Malaysia. The alliance combines F-Secure’s threat detection and privacy prowess with NetAssist’s security and training expertise.

According to F-Secure, the SMEs in the Asia-Pacific region are lacking cybersecurity skills and are, hence, facing obstacles while defending against security threats. The company claims that the new partnership will address the cyber protection issues facing by SMEs across the cloud, hybrid, and on-premise environments.

Speaking on the new agreement F-Secure’s Southeast Asia regional manager Yong Meng Hong said, “We are excited by our partnership with Netassist and are confident of the great value our combined efforts can bring to end-users. As a global corporation, F-Secure strongly believes that such partnerships are vital in helping connect the dots of the cybersecurity supply chain.”

Established in 1999, NetAssist is an end-to-end cybersecurity services provider. Best known for its training platforms, the company offers various cyber protection and consultancy services to help organizations protect their operations in a secure manner.

“Aside from helping our clients secure their systems, we strongly believe that it is in everybody’s best interest to do so in as holistic a manner as possible. As such, we ensure that we include the necessary training for our clients so that they will be able to realize the maximum potential of any security solutions they take on from us,” said NetAssist’s CEO Fun Ping Hon in a news statement. “Our carefully assembled team has cutting-edge skills in multiple niche areas of cybersecurity. This allows them to offer a powerful yet unified solution that is both practical and in-depth. Our unique capability to draw from external experts is a bonus, so no detail in cyber protection is beyond our capabilities.”

In related news, F-Secure signed an agreement earlier this year to acquire all the outstanding shares of MWR InfoSecurity, a privately held cybersecurity company operating globally from its main offices in the UK, the US, South Africa, and Singapore.