Home Blog Page 353

F-Secure says modern laptops are vulnerable to cyber attacks

Laptop

Security researchers from cybersecurity provider F-Secure discovered vulnerabilities in modern computers that allow hackers to steal encryption keys and other sensitive data.

According to Olle Segerdahl, a cybersecurity consultant at F-Secure, a firmware weakness in modern computers and laptops exposes encryption keys that can be used by hackers to steal sensitive information. The researcher also stated that the present security measures are not sufficient to protect data on lost or stolen laptops.

“Typically, organizations aren’t prepared to protect themselves from an attacker that has physical possession of a company computer. And when you have a security issue found in devices from major PC vendors, like the weakness my team has learned to exploit, you need to assume that a lot of companies have a weak link in their security that they’re not fully aware of or prepared to deal with,” said Segerdahl.

Olle Segerdahl stated that an attacker needs physical access to exploit the vulnerabilities in the systems to perform a cold boot attack that involves rebooting a computer without following a proper shutdown process, then recovering data that remain briefly accessible in the RAM.

“It takes some extra steps compared to the classic cold boot attack, but it’s effective against all the modern laptops we’ve tested. And since this type of threat is primarily relevant in scenarios where devices are stolen or illicitly obtained, it’s the kind of thing an attacker will have plenty of time to execute,” explained Segerdahl. “Because this attack works against the kind of laptops used by companies, there’s no reliable way for organizations to know their data is safe if a computer goes missing. And since 99 percent of company laptops will contain things like access credentials for corporate networks, it gives attackers a consistent, reliable way to compromise corporate targets.”

Olle Segerdahl has shared his research findings with Intel, Microsoft, and Apple to help the PC industry improve the security measures of current and future products. He also recommended companies to prepare themselves to address the cyber issues. “There’s no easy fix for this issue either, so it’s a risk that companies are going to have to address on their own,” Segerdahl added.

Tata Communications opens new cybersecurity center in Dubai

Dubai

Tata Communications, a digital infrastructure provider, recently unveiled an advanced cybersecurity response center in Dubai. The new response center will provide round-the-clock cybersecurity services to help customers thwart cyber threats in the Middle East region.

Inaugurated by Omar bin Sultan Al Olama UAE Minister of State for Artificial Intelligence and Indian Ambassador to the UAE Navdeep Suri, the Dubai facility marks Tata Communications’ fourth dedicated security center. The rest of the three centers are located in Chennai, Pune, and Singapore.

“The launch of Tata Communications cybersecurity response center in Dubai is a strong indication of the growing market in digitization and data solutions in the UAE; it’s a reflection of the country’s vision in building an ecosystem that supports utilization of advanced technologies in favor of a safe and conducive business environment as well as providing a better experience for its residents. As data and operations become increasingly digitized in the UAE and the wider region, cybersecurity has become even more paramount now, and collaboration with global leaders in this area is one step forward to ensure a safe environment for everyone,” said Omar Sultan. “It’s great to see a global telecom player like Tata Communications share our vision by making the right investments and efforts to protect the interests of the government and businesses in the region.”

As a digital infrastructure provider, Tata Communications offers Managed Security Services to enterprises globally to ensure the organization’s network and infrastructure security. Through the new cybersecurity response center, the company aims to offer enterprises and Government bodies in the UAE and other GCC countries across the region with cyber-attack protection.

 

Agile project management and Big Data: A guide

Digital Transformation

Contributed by Mayank Kumar, Co-founder and MD, UpGrad

Big Data is the hottest trendsetter in the industry now. Today, organizations and institutions across the world are leveraging data to power their entire infrastructure, from enhancing business operations to boosting revenues and sales. As more and more companies are joining the Big Data bandwagon, the competition in the market is soaring high with every passing minute. Thanks to the Internet, and the surge of social media and IoT, consumers are now aware of the latest trends in the market, what services/products can optimize their utility, and where can they access them. When dealing with such smart consumers of a ‘connected world,’ companies can no longer afford uncertainty and indecision.

Organizations and companies need to identify their target audience and then strive to have a clear understanding of the pain points of their customers. To help achieve these two fundamental goals, companies are leveraging Big Data (both structured and unstructured) along with data science technologies. It is data science that makes it all happen – it allows companies to extract meaningful information from massive datasets and make sense of it so that businesses can use those insights to their advantage.

Data science has, thus, become the lifeline of Big Data. As a result, the demand for skilled and professional data science experts is increasing exponentially across all sectors of the industry. If you wish to begin a career in Big Data, there are plenty of online data science courses on the Internet today.

While tapping into Big Data can unravel secrets related to consumer and market trends, taste and preference patterns of consumers, and their interaction with your brand, you need to understand one thing – these patterns and behaviors are ever-changing. Thus, if you wish to stay relevant in the market, you need to possess ‘Agility,’ for it is now the official order of the day.

What does the ‘Agile Approach’ exactly mean?

IT companies deal with huge amounts of data on a daily basis. Everyday data scientists and analysts leverage various statistical and scientific methods to test the hypotheses around the information buried in the data to approve or reject them. Based on the outcomes of these validations, they come up with new hypotheses or new ways to utilize the insights gained. However, the uncertain nature of Big Data projects often makes them challenging. The key is to chalk out such a delivery method that is able to cope with the specific requirements of the changing trends of Big Data.

Enter Agility.

Project management pertains to the planning, delegation, monitoring, and control of every aspect of the project. It motivates the participants to perform better and achieve the objectives within the expected parameters set for time, cost, quality, benefits, and risks.

Essentially, software projects include piling up one assumption on the other and so on. Throughout the planning process, it is assumed that every aspect of the project will go as planned, including the padding. Further, it is assumed that all the implemented functionalities will provide the expected business value. The Agile manifesto focuses on validating the hypotheses or assumptions as early as possible in the product delivery lifecycle, thereby minimizing the risk exposure of the project as it progresses. The fundamental aim of the agile approach is to create software devoid of defects.

The Agile Approach is a synergistic, cohesive, and time-tested approach to software development and business process management that fosters collaboration between the various teams of an organization to develop innovative software applications. The method also focuses on continually testing the products by assessing the customer interactions and dynamically enhance and refining them to better suit the latest consumer and market trends.

How can agile project management be combined with big data?

Applying the Agile methodology to Big Data can be very advantageous as it will allow data scientists and analysts to extract valuable insights from vast datasets quickly. By encouraging the collaboration of cross-functional teams within a company, the Agile approach will allow the data and management professionals to implement those insights in ways that can enhance customer satisfaction, optimize business operations, boost sales and revenue, and most importantly enhance and streamline business decisions. As all hands on the deck come forward, a company can not only craft well-designed business strategies, but it can also transform the plan into reality in accordance with the dynamic business environment.

In the Agile methodology, it is assumed that each line of a code does not have any bugs. The code is developed and deployed in smaller increments so that the end result is a working and production ready software. So, every line of the code and its architecture and design are continually validated each time a new increment is added to it. Apart from the obvious benefit of early validation, Agile also enables data professionals to learn from consumer feedback and improve the product according to the feedback as and when necessary, without having to alter the process or start from scratch.

In a research study it was found that the transition to Agile methodology helped mitigate a number of business problems.

 

Source

Here are some other benefits of applying the agile approach to Big Data projects:

  • Declutters an organization’s information and management domains.
  • Allows IT companies to prioritize data transformation strategies
  • Rapidly generates data-driven insights that further creates the scope for fresh business opportunities.
  • Facilitates easy access to data from multiple databases and business units.
  • Promotes cohesion among cross-functional units of a company, thus, bringing in an increased visibility and transparency within the organization.

The unique ability of early validation and to change direction to incorporate the necessary changes into a product are what make Agile compatible with Big Data and data science technologies. It is all about keeping pace with the dynamic data and business landscape to deliver cutting-edge, quality products.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Russian accused of hacking JP Morgan extradited to U.S.

JP Morgan Data Breach

New York prosecutors announced that the country of Georgia handed over an alleged cyber criminal accused of breaking into JP Morgan in 2014 to the United States.

According to the indictment report, Russian citizen Andrei Tyurin was extradited to New York from the Republic of Georgia for his involvement in the JPMorgan’s data breach. Tyurin was also charged for computer hacking, securities fraud, identity theft, and wire fraud in various companies. The other targeted companies include Fidelity Investments, Dow Jones & Co., E-Trade Financial Corp. and, Scottrade Financial Services Inc.

“Andrei Tyurin, a Russian national, is alleged to have participated in a global hacking campaign that targeted major financial institutions, brokerage firms, news agencies, and other companies,” said Manhattan U.S. attorney Geoffrey Berman in remarks.

In 2014, the American multinational investment bank reported a massive data theft that exposed 76 million customer records. The company described that attackers compromised an employee’s personal computer and went on to gain unauthorized access to the company’s server.  The bank declared that names, email and postal addresses, and phone numbers of account holders were compromised. However, the account login credentials such as social security codes, PINs and passwords remained safe. The phishing attack was carried out in June, discovered in late July, and could not be stopped till the middle of August 2014.

Prosecutors said that Tyurin was allegedly worked for Gery Shalon, an Israeli who’s facing charges over the hack in Manhattan federal court along with two other Israelis, Joshua Samuel Aaron, and Ziv Orenstein.

“Today’s extradition marks a significant milestone for law enforcement in the fight against cyber intrusions targeting our critical financial institutions,” said Berman.

 

DFS approves two new cryptocurrencies

cryptocurrencies, Echelon Malware

The Department of Financial Services (DFS) has authorized two stablecoins (price-stable cryptocurrencies) pegged to the U.S. Dollar. According to a statement from Financial Services Superintendent Maria T. Vullo, the approval has been granted to the Gemini dollar belonging to the Gemini Trust Company LLC and Paxos standard token from the Paxos Trust Company LLC.

“As the financial technology marketplace continues to evolve, New York is committed to fostering innovation while ensuring responsible growth.  These approvals demonstrate that companies can create change and strong standards of compliance within a strong state regulatory framework that safeguards regulated entities and protects consumers,” Maria T. Vullo said.

Speaking on the sanction, Tyler Winklevoss, CEO at Gemini Trust Company, LCC said, “To date, there has been no trusted and regulated digital representation of the U.S. dollar on the blockchain. We are excited to bring the Gemini dollar to market, a stablecoin that combines the creditworthiness and price stability of the U.S. dollar with blockchain technology and the oversight of the NYDFS.”

DFS stated that the approvals granted for stablecoins are subjected to strict conditions. As part of the conditions, the companies are required to apply New York’s strong standards and regulations regarding anti-money laundering, anti-fraud, and consumer protection measures.

“This is a very exciting time and we thank the DFS and Superintendent Vullo,” said Charles Cascarilla, CEO and co-founder of Paxos. “With Paxos Standard, we hope to enable a truly frictionless, global economy by offering a token that is stable, fast, redeemable, audited, and most importantly, approved and regulated. This is a digital asset that can be trusted.”

In another cryptocurrency news, major cryptocurrency exchange Bittrex announced that it will delist the Bitcoin Gold (BTG) by mid-September, following the $18 million hack of the BTG network that began in May. Earlier this year, the hard fork cryptocurrency Bitcoin Gold suffered a double-spending hacking attack that managed to amass over $18 million worth of BTG coins taking control of more than 51 percent of the BTG hashrate in the process.

Building Regional PoPs to Improve SaaS App Performance? There’s a Better Way to Accelerate App Delivery

SaaS

Contributed by Pejman Roshan, VP Product, Teridion

The SaaS delivery model is now trusted by companies ranging from small startups to large global enterprises for their business-critical functions. By 2020, three out of four organizations will be running nearly all their applications on a SaaS platform, according to recent studies.

For purveyors of SaaS applications, great opportunity comes with great responsibility. As more customers prefer SaaS for their most important business functions, providers must ensure their applications meet users’ expectations for good performance—and that means optimizing the application and its delivery however possible.

One method for performance optimization is to locate the application as close to users as possible to reduce latency. Oftentimes, a SaaS provider with a global customer base will build out a series of private regional points of presence (PoPs) across the Internet and host its applications at those PoPs.

The reasoning behind this approach is quite sound. The fact is, the public Internet has inherent performance issues that are magnified as traffic needs to travel further across the Internet. The more “hops” the traffic needs to take as it gets routed from one packet-passing autonomous system on the Internet to another, the slower the performance of the SaaS app will be for end users.

So, for example, if the application is hosted in a datacenter in Seattle but a significant portion of users reside in Singapore, Moscow and Sao Paulo, those remote users are going to wait too long – perhaps multiple seconds – for page loads and data updates coming from and going to the application. Users grow impatient if response time regularly goes beyond a few seconds, and impatient users are unhappy users that aren’t likely to renew their service subscription. However, if the SaaS provider puts a PoP in (or close to) Singapore, Moscow and Sao Paulo and then hosts its application in each of those PoPs, the users should see a noticeable improvement in application performance.

That’s fine if only a few PoPs are needed, but what happens when the application is in high global demand and customers are located all over the world? While it’s possible to put a PoP in most major geographies, this is a very expensive, time-consuming approach. The DDoS protection company Imperva wrote a good blog post on what it takes to implement just one PoP. In their experience, it took many months to select an appropriate datacenter provider, negotiate a contract, provide and test the equipment, and get everything working to go live with their application. This process – which can take upwards of six months – is anathema to customer responsiveness and business agility.

In addition, once that series of private PoPs is fully deployed, it must be maintained. Someone has to make sure the devices are all in service and operating effectively. They must be monitored, secured and upgraded from time to time. DevOps resources can be severely stretched managing multiple PoPs, sometimes requiring third party maintenance which comes with additional costs and complexity.

Another requirement when using a series of private PoPs is the need to do application sharding. Sharding is the process of splitting an application into many instances which act as one. This is needed because if there are multiple PoPs, logically there must be multiple instances of the application. It’s a very big undertaking, just purely from an engineering cost and time perspective.

Traditionally, implementing private PoPs was the only way a SaaS provider could assure itself that its users in different geographies were going to get adequate performance. Content delivery networks, or CDNs, aren’t viable for SaaS providers because a CDN caches static content within its own network. This works well for, say, an eCommerce vendor that wants to assure prompt page display of a product catalog. It doesn’t work for bi-directional traffic in enterprise applications where users are uploading and downloading content, there’s dynamic or personalized content for each user, and collaboration is going on. CDN vendors are trying to make their caching smarter, but it’s still just caching, and it doesn’t work for most SaaS providers.

Ditch the expensive and complicated regional PoPs

SaaS providers don’t have to build their own PoPs to get improvement in throughput on the public Internet. In fact, it’s possible to get 10X (or more) in application performance improvement with little more effort than making a CNAME change.

For example, one prominent application acceleration solution deploys a global overlay network on top of some of the largest public cloud providers on the Internet—AWS, Google Cloud, Alibaba Cloud, etc. Sensors within these providers’ network fabrics collect data in real time about the performance of the various traffic routes that the providers have available to them. A cloud-based orchestrator can then make decisions about how to use this overlay to route traffic most efficiently between a particular SaaS provider and its customers, regardless of where those customers are located.

The orchestrator also controls virtualized routing engines that get deployed across the fabric of those public cloud providers. This routing infrastructure dynamically establishes the fastest path, at any given time, between an end user and a SaaS provider; for example, to enhance data upload performance for a cloud-based storage application. Route adjustments are made in real time if performance on a different route is better. The goal is to always get the best throughput, the lowest latency, and the tightest control over packet loss between user and provider.

This kind of solution has close to infinite scalability. When traffic goes up, more virtual cloud routers can spin up. And when traffic goes down, those containers are discarded until they are needed again. It’s an elegant way of handling capacity demands. Overall this kind of solution gives SaaS providers the kind of performance control they could never get from deploying their own PoPs on the public Internet.

And unlike a CDN, the SaaS traffic isn’t decrypted at the edge, preserving privacy and data security. The solution is single tenant by design so that every SaaS provider gets its own network, which further enhances security and provides protection against DDoS attacks.

SaaS customers expect to have a good experience. If they don’t, it’s easy enough to move to the next provider waiting in the wings. A vast improvement in application performance can go a long way to improve the user experience and reduce customer churn.

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Perth Mint’s customer data targeted

Panasonic network breach

The Western Australian Perth Mint recently caught up in a data hack that compromised its customers’ data. According to an official statement, people behind the breach possibly obtained information relating to 13 customers of the mint’s precious metals depository online trading platform from a third-party provider.

“We identified the potential breach on Wednesday this week and immediately began a comprehensive forensic investigation to verify the nature and extent of the breach,” Perth Mint Chief Executive Richard Hayes said in a statement. “We are working with the external third-party provider to understand how this breach occurred and have taken steps to remediate the identified threat.”

Hayes clarified that the ongoing investigation has confirmed all investments at The Perth Mint are secure.

“We are in the process of contacting each of the customers whose data has been accessed. We sincerely regret any distress caused by the misconduct of these unlawful individuals who are responsible for this breach. We have assured these customers that their investments remain safe and secure,” he added.

The Perth Mint is working with the Western Australian Police and Australian Federal Police for investigating on the incident and also notified the Office of the Australian Information Commissioner. Hayes stated that they are monitoring the situation and informing its depository online customer base for further protection.

“We are very disappointed this has occurred but can assure our customers that our systems remain secure and that there is no threat to their account holdings,” Hayes said.

On July 3, 2018, an inspection by the Australian National Audit Office (ANAO) exposed the failure of key Australian government agencies to implement cybersecurity requirements. The ANAO’s fourth report on the cyber resilience of government departments and agencies stated that except the Treasury Department, both the National Archives and Geoscience Australia failed to implement the top four mandatory cybersecurity strategies instructed by the Australian Signals Directorate (ASD). The top four mandatory strategies include application whitelisting, application patching, OS patching, and the control of administration rights.

Government Accountability Office releases investigation report on Equifax hack

Equifax

The U.S. Government recently released a detailed report on how the Equifax hack happened and the consequences of the incident. In its latest report, the Government Accountability Office (GAO) published a complete investigation details about the credit reporting company. The report comes almost a year after the breach that exposed the personal details of 145.5 million users, including Social Security numbers, credit card numbers and driver’s license numbers.

The GAO report stated that the incident occurred because Equifax failed to segment its databases into smaller networks, which allowed the attacker to get access to all of its customers’ data.

“After successfully extracting PII from Equifax databases, the attackers removed the data in small increments, using standard encrypted web protocols to disguise the exchanges as normal network traffic,” the GAO investigation report said.

On July 29, 2017, Equifax’s security team observed suspicious network traffic associated with its U.S. online dispute portal web application and blocked the suspicious traffic that was identified. But the company waited until after the close of trading nearly six weeks later to disclose the breach to consumers and Equifax’s investors. After discovering a vulnerability in the Apache Struts web application framework as the initial attack vector, Equifax patched the affected web application before bringing it back online.

The incident potentially affected personal information of 143 million U.S. consumers – primarily names, Social Security numbers, birth dates, addresses, and, in some instances, driver’s license numbers. Equifax also identified unauthorized access to limited personal information for certain U.K. and Canadian residents and is working with regulators in those countries. Equifax made a public disclosure of the incident on September 7, 2017, after hackers exfiltrated data for 76 days.

Equifax said that they were unable to detect the hackers’ moment for 76 days was because of malfunction of a device that’s meant to inspect network traffic for signs of malicious activity.

US Govt. charges North Korean hacker involved in WannaCry cyber-attacks

U.S. Government Offers $5 Mn Reward for Information on North Korean Threat Groups

The U.S. Department of Justice announced charges against a North Korean national who was accused of being behind the hack of Sony and the WannaCry ransomware attacks.

According to the official statement, Park Jin Hyok worked with a team of hackers, also known as the Lazarus Group, to conduct multiple destructive cyber-attacks around the world, resulting in damage to massive amounts of computer hardware, loss of data, money, and other resources.

Those malicious activities/attacks include the creation of a malware used in the 2017 WannaCry 2.0 global ransomware attack, theft of $81 million from Bangladesh Bank in 2016, attack on Sony Pictures Entertainment in 2014, and numerous other intrusions on the entertainment, financial services, defense, technology, virtual currency industries, academia, and electric utilities.

“Today’s announcement demonstrates the FBI’s unceasing commitment to unmasking and stopping the malicious actors and countries behind the worlds cyber-attacks,” said FBI Director Christopher Wray.  “We stand with our partners to name the North Korean government as the force behind this destructive global cyber campaign.  This group’s actions are particularly egregious as they targeted public and private industries worldwide – stealing millions of dollars, threatening to suppress free speech, and crippling hospital systems.  We’ll continue to identify and illuminate those responsible for malicious cyber-attacks and intrusions, no matter who or where they are.”

In addition to these, the U.S. Treasury Department has imposed sanctions against Park and Chosun Expo Joint Venture, the company he worked for.

“We will not allow North Korea to undermine global cybersecurity to advance its interests and generate illicit revenues in violation of our sanctions,” said Treasury Secretary Steven Mnuchin.  “The United States is committed to holding the regime accountable for its cyber-attacks and other crimes and destabilizing activities.”

Earlier, North Korea denied accusations of conducting the WannaCry attack. Even, the United Kingdom on October 27, 2017, claimed that it believes that North Korea was behind the devastating WannaCry cyber-attack. WannaCry malware that led to havoc across the world did grievous temporary damage to the network security of Britain’s National Health Service (NHS).

British Airways hacked, 380,000 payment-card details of customers compromised

British Airways

In the latest victims of a massive cyber attack is British Airways. The airlines in a statement notified its customers that “From 22:58 BST August 21 2018 until 21:45 BST September 5 2018 inclusive, the personal and financial details of customers making or changing bookings on our website and app were compromised.”

Around 380,000 payment-card details were stolen by hackers during the period. The airline has notified the police and investigations are underway. “The stolen data did not include travel or passport details.” The airline has requested users to reach out to their respective banks and reset their passwords as well as change their passwords for the British Airways website account. No details of the breach have been revealed. We believe, as the investigation proceeds, more details about the hack will unfold. Currently, the airline is working normally, and assured that future bookings will not be affected. “The breach has been resolved and our website is working normally. British Airways is communicating with affected customers and we advise any customers who believe they may have been affected by this incident to contact their banks or credit card providers and follow their recommended advice. We have notified the police and relevant authorities.”

The airlines also assured that it will compensate for all the losses (if any) to its customers. ‘Every customer affected will be fully reimbursed and we will pay for a credit checking service. We take the protection of our customers’ data seriously, and are very sorry for the concern that this criminal activity has caused. We will continue to keep our customers updated with the very latest information. We will be contacting customers and will manage any claims on an individual basis.”