Home Blog Page 350

Zaif reveals compensation plan post $60 mn hack

Zaif

Japanese cryptocurrency exchange, Zaif, has released its official plan to compensate customers impacted by the recent breach the exchange suffered which had resulted in losses worth 6.7 billion yen (around $59.7 million).

Tech Bureau, the parent company of Zaif, in a notification stated that it will sell its entire stake to Fisco Digital Asset Group, a publicly listed Japanese firm operating digital assets. With the move, Tech Bureau will transfer the entire responsibility of compensation to Fisco.

“In the official contract between the Fiscal virtual currency exchange corporation and our company, the contract specifies the former as the successor. Therefore, the contractual relationship between us and the customer will be transferred from our company to the Fiscal Virtual Currency Exchange Co., Ltd,” reads the statement. “Under the Official Agreement, Fisco Cryptocurrency Exchange shall assume customers’ rights with Tech Bureau in regard to seeking a return of deposited cryptocurrency and the remaining cryptocurrency that was not lost: Compensation for some Monacoin will be made in Japanese yen; Agreements with customers that do not agree with the business succession will remain with Tech Bureau Corp.”

The new announcement differs from the initial announcement that was made, as both the parties were primarily focused on the business transfer method, avoiding any future risks for Fisco. On the changes, Tech Bureau stated that “On September 20, 2018, Tech Bureau reported that it had reached a basic agreement involving consideration to provide “financial support of ¥5 billion yen, enter a capital alliance enabling acquisition of a majority of the Company’s shares and allow for a majority of directors and the dispatch of an auditor.” However, the ultimate agreement was to pursue the business transfer method from the viewpoint of avoiding risk for those supporting and due to the requirement to implement a decision rapidly to protect customers.”

Evolving from Human- to Machine-scale in Cybersecurity

Edureka data breach

Contributed by Ashley Fidler, Vice President of Product, Versive

The cloud. Big data. BYOD. In this era where human-scale has given way to machine-scale, today’s cybersecurity challenges require a substantial change in the way incidents are identified and resolved. These new technologies, such as cloud computing, the Internet of Things, and artificial intelligence, are delivering digital transformation on a previously-unknown scale for both attackers and defenders.

Even though defending the cybersecurity landscape now exceeds human capacity, the question should not be how to replace humans. Instead, efforts should focus on how to compensate for human error and resource limitations within security strategies and how to augment human defenders. In other words, how can chief information security officers (CISOs) leverage new, advanced technologies to successfully grapple with the scale and complexity of today’s evolving threat landscape?

The machine-scale of cyber threats

Today’s increasingly vulnerable and expanding attack surface is attracting all types of malicious actors, regardless of whether they are motivated by pride, money or ideology. Recent major attacks such as the Mirai botnet Distributed Denial of Service (DDoS) and WannaCry ransomware are a clear demonstration of the scope and breadth of cyber threat actors. Furthermore, 2.6 billion records were compromised worldwide in 2017, an 87 percent increase over 2016, which translates to 7.1 million records that are stolen or lost per day.

One of the most important aspects of this evolution of cyber threats is the combination

of cheaper, easier access to technology with the democratization of the tools and knowledge required to execute these sorts of operations. You no longer have to be a stereotypical kid in a basement or a nation-state to be a hacker. Malware-as-a service, in all of its guises, is readily available on the Dark Web and sold on a commission basis. Anyone who wants to make a fast buck and knows how to get on the Dark Web can become a hacker. The goal posts have changed forever.

Human-scale limitations

But malicious actors aren’t the only cause of machine-scale threats. Whether an innocent mistake, sheer carelessness, or malintent, the complexity and scale of today’s digitized platforms poses a serious challenge to traditional models of security that still heavily rely on human analysts. In many instances, it’s outstripping them completely.

There are a number of factors contributing to this increased complexity of enterprise cybersecurity and why securing it now exceeds human cognition:

  • Humans struggle to spot patterns across the scale of big data. How big? By 2025, there will be a projected 163 zettabytes of digital data in existence.
  • The attack surface is greatly magnified given the interconnectedness and cloud-hosting of many services. Most people assume their organizations use up to 40 cloud apps when, in reality, the number is generally closer to 1,000.
  • The newness of the technologies means security teams are unclear on best practices. In June 2017, the names, addresses and account details of some 14 million Verizon customers were found in an unsecured data repository on a cloud server. This was not a result of a malicious attack; the repository was simply exposed to the internet because of an incorrect configuration.
  • There is an outsourcing of security to well-known cloud infrastructure technology companies, under the assumption that those companies have better security practices. This is true in terms of the security of the infrastructure, but the company (cloud customer) is still responsible for utilizing the available security settings and securing their own data.

Integrating machine-scale with human touch to fight back

So, what is the path forward – blockchain, deep learning, artificial intelligence, machine learning, neural nets? Buzzword bingo is a game that we are all tired of playing. If we cut through the noise, we can all agree that these machine-scale problems require machine-scale solutions, like machine learning. But the conversation needs to be about how to apply these technologies in the right way, to augment the analyst, not replace them. The use of integrated machine learning can have a pertinent and powerful impact on its application in cybersecurity.

To use ML, or more broadly, AI effectively, the cybersecurity paradigm needs to shift from finding low-level patterns in siloed data and then aggregating the output, to aggregating data from across the network and then looking for the patterns in that cross-network data that really matter. Using these tools within an integrated approach will optimize the use of these new technologies, ensuring that the data used to determine cybersecurity incident trends and patterns are relevant, informative and accurate. The promise of AI is to help organizations to automate the time-consuming process of analyzing the data to understand a threat and to augment their human analysts, who then must add context and determine how to respond.

It is important to have an understanding of the three stages of change management in evolving from human-scale to machine-scale in cybersecurity defense. These are:

  • Human Control: Many AI-based cybersecurity platforms work to reduce cyber threat mitigation by monitoring network traffic. The results of the algorithm will usually initiate an alert being sent to a dashboard viewed by a human operator, who will then take action.
  • Automation: Automating this process is the next phase change, to move away from the floods of alerts being generated by most tools today.
  • Holistic control: The phase change that takes AI platforms in cybersecurity to new levels is the use of integrated ML that is applied holistically across an entire enterprise. These systems use automation to complete complex human tasks by using data from an entire system, not just a single focus point.

What Cybersecurity Requires Now

The challenge of mitigation of cybersecurity threats is real and advancing, but the tools at our disposal, such as artificial intelligence and machine learning, are also advancing. To successfully leverage new, advanced technologies to combat today’s ever-evolving threat landscape, human-machine interaction is what we need to work towards. Building integrated AI platforms that empower human cybersecurity analysts is the new wave of change that the industry needs to make it effective against a formidable and ever-changing foe.

 

GAO’s test reveals vulnerabilities in DOD weapons systems

The U.S. Government Accountability Office (GAO) recently conducted a study to evaluate the state of Department of Defense (DOD) weapon systems cybersecurity and the results were not very promising. The legislative branch government agency stated that most of the new weapons designed by DOD are vulnerable to cyber-attacks. Moreover, GAO pointed out that DOD does not even know the full extent of the problems that existed in their weapons.

According to the report, DOD testers frequently found “mission-critical cyber vulnerabilities” in almost every weapon system they were developing between 2012 and 2017. “Testers were able to take control of these systems and largely operate undetected. In some cases, system operators were unable to effectively respond to the hacks,” the report added. “Furthermore, DOD does not know the full scale of its weapon system vulnerabilities because, for a number of reasons, tests were limited in scope and sophistication.”

One of the major reasons that GOA quoted behind weapon systems’ vulnerability are their connectivity to other devices that facilitate “information exchanges that benefit weapon systems and their operators in many ways.” However, if attackers breach the security layers and gain access to systems, it may be easier for them to “reach any of the others through the connecting networks”.

In the report, GAO was also critical of DOD’s attitude toward cybersecurity. GOA stated that it and others have warned DOD “of cyber risks for decades, until recently, DOD did not prioritize weapon systems cybersecurity. Finally, DOD is still determining how best to address weapon systems cybersecurity.”

“DOD has recently taken several steps to improve weapon systems cybersecurity, including issuing and revising policies and guidance to better incorporate cybersecurity considerations. DOD, as directed by Congress, has also begun initiatives to better understand and address cyber vulnerabilities,” the report further stated.

WhatsApp video call can make you easy prey to cybercriminals: Research

Whatsapp

A recent survey has discovered that answering a WhatsApp video call can compromise your smartphone. According to Natalie Silvanovich, a digital forensics expert at Google Project Zero, a security bug in the WhatsApp messenger application allows attackers to take control of the smartphone by placing a WhatsApp video call.

Describing the issue as a “memory corruption bug in WhatsApp’s non-WebRTC video conferencing implementation,” the security researcher stated that a memory heap overflow issue causes when an attacker places a specially created malformed RTP (Real-time Transport Protocol) via WhatsApp video call request, resulting in the break-in to the mobile memory.

“Heap corruption can occur when the WhatsApp mobile application receives a malformed RTP packet,” Silvanovich said in a bug report. “This issue can occur when a WhatsApp user accepts a call from a malicious peer.”

The security flaw discovered in August 2018 affected the WhatsApp application on Android and iOS devices, but not on WhatsApp Web, the research report stated. The Facebook-owned messaging app fixed the flaw on September 28 for Android platform and October 3 for the iPhone platform after Silvanovich reported the issue to the WhatsApp team.

“WhatsApp cares deeply about the security of our users. We routinely engage with security researchers from around the world to ensure WhatsApp remains safe and reliable. We promptly issued a fix to the latest version of WhatsApp to resolve this issue,” WhatsApp said in a news statement.

A few months ago, the Indian Army issued a warning to users of WhatsApp application, alleging that Chinese hackers are targeting them to extract personal data. The Army took to the microblogging site, Twitter to urge users to use WhatsApp with caution. Indian Army’s official handle, the Additional Directorate General of Public Interface (ADGPI) also posted a video that said, “Stay cautious, stay alert, stay safe! The Chinese were penetrating the digital world.”

Interview: Is Neurodiversity an answer to cybersecurity skill gap?

Mike Spain

It is common these days to hear cybersecurity leaders talking about skill gap in the domain. According to a study by PricewaterhouseCoopers, the cybersecurity workforce gap will widen to 1.5 million job openings by 2019.

While companies shuttle between different education institutions to find the right cybersecurity talent, the answer may lie somewhere else. It is believed that more than 70 percent of cognitively able autistic adults have the aptitude and the skills for a career in cybersecurity. The Cyber Neurodiversity Group is working tirelessly in this direction to promote an accessible, inclusive, and diverse cyber ecosystem for neurodiverse candidates to prosper.

CISO MAG’s Augustin Kurian got in touch with Mike Spain, founder of the Cyber Neurodiversity Group and the Director for Cyber Exchange UK, and discussed this noble cause.

Tell us a bit about you and the idea behind founding the Cyber Neurodiversity Group? Can you shed some light on the term “neurodiversity?”

I’m a security consultant by trade and have been in or around the sector for over 10 years. My passion is innovation and growth. I’ve had the privilege of working across government, industry and academia on a number of growth initiatives that provide pathways for good ideas to commercialize. I’ve been introduced to wonderfully creative thinkers and entrepreneurs.

Many have very specific talents and personally identify with the term “Neurodiverse”. The term is brilliantly diverse and inclusive itself – it includes Autism Spectrum Condition (ASC), Dyslexia, Dyspraxia, Dysnomia, ADHD, and more.

I founded the Cyber Neurodiversity Group shortly after my own son, now almost 4, was diagnosed with Autism. This prompted me to look toward what his opportunities might be through education and into employment. I was shocked by my findings: only 16% of autistic adults are in full time employment, a figure not improved in over 10 years. Autistic kids also form a significant proportion of exclusions from school and subjects for police involvement for “hacking” offences.

Read More

Binance Labs invests in cybersecurity startup CertiK

Investment

Cybersecurity startup CertiK recently announced that it has received investment from Binance Labs, a venture arm of Binance cryptocurrency exchange. According to the official statement, the two companies have joined hands to bring enhanced security standards to smart contracts and blockchain technology platforms. While the exact amount is unknown, CertiK stated it has received multiple millions of dollars in funding from Binance.

“We’re really excited to be supported by one of the world’s top exchanges,” said Daryl Hok, COO of CertiK. “With published research that begun in academia, we believe that Binance Labs is the perfect partner to accelerate the impact of our unique technology into the broader blockchain space.”

The CertiK is a blockchain and smart contract verification startup founded last year by veterans from Yale and Columbia University, alongside former software professionals from Google and Facebook. Best known for its certified operating system ‘CertiKOS’, Cerkit claims that its solution ensures the safety of blockchain and smart contracts platforms. The company stated its testing methods include a layer-based decomposition approach, pluggable proof engine, machine-checkable proof objects, certified dApp libraries, and smart labeling.

The CEO of Binance Labs Ella Zhang stated that they ensure a secure blockchain ecosystem through CertiK’s background and expertise. “CertiK mathematically validates the security of smart contracts, which is a critical pain point we are facing in the blockchain ecosystem, bypassing the limitations of manual detection,” he said.

ICO fines Heathrow Airport Limited over USB drive data breach

Heathrow Airport breach

Information Commissioner Office recently fined Heathrow Airport Limited (HAL) with £120,000 ($1,56,548) for failing to secure the sensitive information about the airport staff. The penalty comes after a Heathrow Airport employee lost his USB stick that contained confidential information, but was not password protected. The stick was later found by an outsider who viewed the content at a local library.

According to the ICO’s statement, a member of the public found the USB device on October 16, 2017. The device contained over 76 folders and 1,000 files. The sensitive data included a training video that had details like names, dates of birth, and passport numbers of HAL employees. ICO claimed that the stick was given to a newspaper authority before giving it back to HAL authorities.

“Data Protection should have been high on Heathrow’s agenda. But our investigation found a catalog of shortcomings in corporate standards, training, and vision that indicated otherwise,” said ICO Director of Investigations, Steve Eckersley. “Data protection is a boardroom issue and it is imperative that businesses have the policies, procedures, and training in place to minimize any vulnerabilities of the personal information that has been entrusted to them.”

According to the ICO investigation report, only two percent of the 6,500 HAL workforce had been trained in data protection awareness. It also noted that the airlines violated its own norms by using removable media and failed to prevent personal data from being downloaded onto unauthorized sources.

Speaking on the charges, a spokeswoman from HAL said, “We accept the fine that the ICO have deemed appropriate and spoken to all individuals involved. We recognize that this should never have happened and would like to reassure everyone that necessary changes have been implemented, including the start of an extensive information security training programme which is being rolled out company-wide.”

 

Google+ suffers data breach, to shut down

Google Cybersecurity Action Team Google, EU warns Google

Google announced that it is going to shut down its social media network Google+ for consumers in the next 10 months. The declaration comes after the disclosure of a vulnerability that exposed around 500,000 users’ personal information to third-party developers. The services of Google+ for enterprise customers will remain active.

According to a report from the Wall Street Journal, the security flaw exposed the private Google+ profile data in 2015. Google resolved the flaw in March 2018, but did not reveal it to the public due to regulatory issues.

The tech giant admitted that the flaw in Google’s APIs did expose users’ data, including usernames, email addresses, occupation, date of birth, profile photos, and gender-related information. The bug allowed around 438 third-party developers to access the users’ data, but Google clarified the users that there is no evidence of misuse of the data by any of the developers.

“We found no evidence that any developer was aware of this bug or abusing the API, and we found no evidence that any profile data was misused,” said Ben Smith, the vice-president of engineering.

Defending the company’s decision, Smith said, “Whenever user data may have been affected, we go beyond our legal requirements and apply several criteria focused on our users in determining whether to provide notice.” Smith added that they are providing ways to the consumers to download or migrate their data from Google+ till August 2019.

Rebound Orthopedics & Neurosurgery reports data breach

Data breach

The officials at Rebound Orthopedics & Neurosurgery stated that they’ve fallen victim to a major data theft that exposed its customers’ personal data, including Social Security numbers and limited health information. The Vancouver-based diagnosis and treatment services company stated around 2,800 of its patients and employees may have been affected by the incident.

As per the official statement, on May 22, 2018, an unknown perpetrator allegedly obtained unauthorized admission to an employee’s email account. The suspicious activity was immediately discovered and halted after Rebound alerted its security department. On Aug. 8, 2018, Rebound’s computer forensic investigation declared that patients’ name, date of birth, Social Security number, driver’s license number, financial account information, and limited health information may have been compromised in the incident.

“Although at this time there is no evidence of any attempted or actual misuse of anyone’s information as a result of this incident, Rebound has sent notification letters to the potentially impacted individuals to notify them of this incident and to provide resources to assist them,” the company said in a statement.

Rebound Executive Director John Bauman said the company believes the attack occurred due to a phishing email with attachment received by one of its employees. The employee downloaded the email attachment that released a malware and resulted in a data breach, Bauman said.

The company is notifying the affected individuals via emails on how to monitor and protect their personal data and has also established a call center to address the issues about the incident. Rebound stated that it’s offering free identity theft protection and credit monitoring services through cybersecurity company Kroll.

“The privacy and protection of personal information is a top priority for Rebound, which sincerely regrets any concern or inconvenience that this matter may cause,” Rebound said.

Gold Coast Health Plan suffers massive data breach

Unprotected Server Exposes Facebook Scraped Data of 12 Mn Users in Vietnam

Gold Coast Health Plan (GCHP) recently announced that it has suffered a phishing email attack that compromised about 37,000 clients’ health information.

In an official statement, GCHP stated that the attackers compromised one of its employee’s email account and obtained unauthorized access to the emails sent to that account between June 18, 2018 and Aug. 1, 2018. The compromised information included members’ names, health plan identification numbers, medical service dates, dates of birth details, and medical procedure codes. The company clarified that the social security numbers or financial information were not misused.

Based out in California, Gold Coast Health Plan is a publicly funded enterprise that offers health insurance to the residents of Ventura County. GCHP said they’ve discovered and halted the suspicious activity on Aug. 8, 2018, and also notified the law enforcement authorities for further investigation.

The compromised email account has been disabled to prevent further loss, GCHP stated in a statement. The law enforcement authorities stated the criminals were trying to fraudulently move GCHP funds to their account. GCHP officials notified the victims via emails asking them to look for any suspicious medical bills in their credit reports. The company provided contact details on its official website for the clients who want to know whether they were affected by the incident.

To prevent future attacks, the Gold Coast Health Plan is going to offer identity theft protection services to its clients through a data breach and recovery services provider ID Experts. It also providing identity protection services offered by MyIDCare to the victims.