Home Blog Page 355

EMEA employees showing security fatigue: Survey

Cyber hygiene

A recent survey revealed that workers in Europe, the Middle East, and Africa (EMEA) are exposing signs of security fatigue towards cybersecurity.

The study conducted by Aruba, a Hewlett Packard Enterprise Company, on 2,650 employees across EMEA region found that most workers don’t have cybersecurity discipline and aren’t concerned about the consequences of a security breach.

“Employees in EMEA have been inundated with security messaging through their organizations, as well as the media. Clearly giving further warnings and adding procedures isn’t having the desired effect. If employees understand the risks but aren’t acting on it, the answer is not to provide yet more training, but to bring in enhanced technology that can provide the assistance and the protection workers need to do their jobs,” said Morten Illum, VP EMEA at Aruba.

The survey questioned over 7,000 workers across large and small organizations in public and private sector in the EMEA region as well as the US, Mexico and Brazil, India, China, Japan, Singapore, South Korea, and Australia. The survey revealed that the employees across EMEA and in the UAE have the worst cybersecurity discipline and don’t think cybersecurity is their responsibility, many thinking it’s the responsibility of the leadership and the IT team.

Many of the recent surveys revealed that the employees are often the biggest cyber risk. Finn Partners Research, the research arm of global marketing and communications firm Finn Partners, recently released findings from its Cybersecurity at Work study that examined the level of cyber risk that employees pose to their organizations. The in-depth study, which surveyed 500 full-time office employees across the U.S., found that nearly two in five workers admitted to clicking on a link or opening an attachment from a sender they did not recognize. This security slip-up is significant due to the installation of malware on their devices and the harvesting of sensitive corporate data.

Fourth person sentenced to prison for the 2014 celebrity iCloud hack

George Garofano Sentence

The fourth and the final person involved in the 2014 iCloud hack has been sentenced to eight months of prison. Connecticut resident George Garofano along with three others were involved in the one of the most notorious hacks involving intimate images of Hollywood A-listers of the likes of Jennifer Lawrence and several others.

Garofano had already pleaded guilty in April for sending out phishing emails to the victims while pretending to from Apple online security team in a bid to obtain log-in details. After obtaining the details, Garofano and his three accomplices, all of whom have already been sentenced to between nine and 18 months in prison, accessed photos and pieces of personal information of the nearly 240 victims which included several Hollywood celebrities.

While the prosecutors argued that Garofano should spend 16 months in prison, the judge noted that the sentence will be followed by three years of supervised release. The prosecution wrote: “Mr Garofano’s offense was a serious one. He illegally hacked into his victims’ online accounts, invaded their privacy, and stole their personal information, including private and intimate photos. Not only did Mr Garofano keep for himself the photographs he stole, he disseminated them to other individuals. He may have also sold them to others to earn ‘extra income’. In committing this offense, Mr Garofano acted in complete and utter disregard for the impact on his victims’ lives.”

Garofano stated that he had already suffered serious consequences for his actions and has cleaned up his act, which occurred while he was in college. Defense attorney Richard Lynch wrote, “He now stands before the court having matured, accepting responsibility for his actions and having not been in trouble with the law since. There is nothing to suggest that he would ever engage in this or any other criminal conduct in the future.”

Research shows Smart Light can lead to information leakage

Smart Light

Internet-enabled smart lighting products offer several novel functionalities over traditional lamps. But, a recent survey revealed these connected lights can be maliciously used to violate users’ privacy and security.

According to the researchers from the University of Texas, the hackers can make use of internet-connected light bulbs as a covert channel to exploit the user’s private data. The researchers have taken the LIFX and Phillips Hue smart light systems for the study.

The research stated that the hackers can launch an attack by manipulating the infrared light by creating a communication channel between the smart lights and a device that senses infrared light. And by installing a malicious agent on the phone the attackers can encode the private data and transfer them through the infrared covert channel.

The researchers also specified that the proposed threats can be mitigated by enforcing strong network systems and reducing the light transmittance and the brightness of the bulbs that stops the attacks to perform.

Many of the recent surveys are discovering the unknown vulnerabilities in the devices we use often. A new research from cybersecurity solutions provider Check Point revealed how organizations and individuals are vulnerable to hacking through their fax machines. The research experts at Check Point stated that fax machines have security vulnerabilities which could possibly allow a hacker to steal data through a company’s network using just a phone line and a fax number.

Describing the potential threat, the researchers said the attackers can send specially created malware coded image file via fax to the targeted networks. The vulnerabilities in the fax machine enable malware to decode and uploads to its memory, which can breach sensitive information or cause disruption across the connected networks.

Fiserv under the pump for security flaw

Fiserv

Fiserv, a financial services technology provider, was recently under the scanner for a potential vulnerability in its one-way messaging feature in a number of bank websites.

The details about the incident came to light when a security researcher Kristian Erik Hermansen informed Fiserv that he discovered an unusual activity while logged into his account at a local bank that uses Fiserv’s platform. He stated that a security flaw in Fiserv’s technology platform allowed any one to view customer’s email address, phone number, and full bank account number. This would allow cyber criminals to spy on the daily transaction activity of the customers and exploit the data for personal gain, according to Hermansen.

“I shouldn’t be able to see this data,” Hermansen said. “Anytime you spend money that should be a private transaction between you and your bank, not available for everyone else to see.”

Fiserv’s cybersecurity platform enables financial institutions to address specific issues from threat detection, response, and remediation to regulatory compliance and reporting. The company clarified to CISO MAG that they have not “received reports of any adverse consumer impact.”

“To provide context on the recent blog post, which related to a one-way messaging feature in a limited number of bank websites, our ongoing research and continued monitoring have not identified, and we have not received reports of, any adverse consumer impact,” said a spokesperson from Fiserv. “We promptly developed a patch to update the feature, deployed the patch to clients using the feature and completed testing to confirm the patch resolves the issue. Fiserv recognizes the importance of security and takes any security concern seriously.”

Fiserv recently joined hands with a cybersecurity firm BlueVoyant to develop a security platform that aids financial institutions to fight against cybercrimes. The strategic alliance between Fiserv and BlueVoyant develops an integrated combination of endpoint monitoring, extensive threat intelligence, and behavioral analytics to offer real-time response and automated remediation of any suspicious activity.

*This story was updated after Fiserv’s clairification. 

 

Data breach affects 261,000 customers of Atlas Quantum

Atlas Quantum

Cryptocurrency trading platform Atlas Quantum recently suffered a major data theft that compromised personal details of around 261,000 of its customers, the company stated on its official Facebook page.

The Brazil-based company allows its users to buy and sell Bitcoins on various other cryptocurrency trading platforms to make profits based on Bitcoin price fluctuations and exchange rates.

“We would like to point out that this is not a steal of bitcoins in custody or violation of our accounts in the exchanges. However, our customer base was exposed. At the time of the incident, we took immediate steps to protect the database and passwords and private keys remain encrypted,” the company’s translated post reads.

The company confirmed that the incident has not affected any of the funds from the users’ accounts, except the loss of personal data. It also stated that they’ve stopped some of its operations and monitoring the affected accounts to prevent further loss.

In a similar incident, cryptocurrency exchange platform Bancor fell victim to a cyber heist after hackers stole $23.5 million in three different cryptocurrencies. The company stated that the hackers breached its wallet that was used to upgrade the user contracts. It was then later used to steal $12.5 million of Ether Tokens, $1 million of Pundi X, and $10 million of Bancor Network Tokens.

The Switzerland-based startup offers a low-cost cryptocurrency exchange platform for users to convert tokens directly from their wallets. Post the breach, Bancor froze the BNT tokens and limited damage to its own coins. However, they declared that they can’t freeze or recover the theft of the Ether tokens. The security officials at Bancor stated that they will be able to reduce the losses to $13.5 million of Bancor Network Tokens after finding the compromised wallet.

Indegy raises $18 million, appoints key executives

Startup funding

Industrial cybersecurity startup Indegy recently closed an $18 million Series B round of financing led by Liberty Technology Venture Capital. The other investors in the round included Centrica PLC, O.G. Tech Ventures and existing investors Shlomo Kramer, Magma Venture Partners, Vertex Ventures, and Aspect Ventures. The company stated that the new funds will help to expand its marketing reach in the cybersecurity industry.

Indegy also announced the appointment of Joe Scotto from BAE Systems as Chief Marketing Officer and Todd Warwick from Imperva as Vice President of Sales to its management team.

“Recent reports by the DHS and FBI regarding attacks against critical infrastructures have created a greater sense of urgency among industrial organizations to shore up their defenses and produced a major spike in new business for Indegy,” said Barak Perelman, CEO of Indegy. “This capital infusion provides the financial resources required to scale up the company and capitalize on this market opportunity. On the management front, the addition of Joe Scotto as CMO and Todd Warwick as VP Sales, Americas, gives us the experienced leadership we need to escalate our growth and market expansion.”

Founded in 2014, the Tel Aviv-based startup develops Industrial Control System (ICS) networks, which help protect systems from cyber threats, malicious insiders and human error by providing visibility and control. The ICS suite combines cybersecurity expertise with hands-on industrial control knowledge, deployed by manufacturing, pharmaceutical, energy, water, and other industrial organizations to protect their systems from cyberattacks.

“With a growing customer portfolio that spans 35 countries, we’re working to bring businesses world-leading energy management solutions that will allow customers to take greater control of their energy,” said Christophe Defert, VP Ventures for Centrica Innovations. “In an increasingly connected world, we’re looking forward to working with Indegy as we explore ways to deploy distributed energy resources with the optimal security solution.”

Nicehash reimburses 60 percent of stolen bitcoins to its users

Bitcoin

Slovenia-based Crypto mining pool, Nicehash which suffered a major breach on December 2017 after hackers stole nearly 80,00 bitcoins core (BTC) has returned as much as 60 percent (4,700 BTC) of the stolen bitcoins to its pool member.

The platform was hacked on December 6, when the company notified its customers that “Our payment system was compromised, and the contents of the Nicehash bitcoin wallet have been stolen,” in a Reddit post. Around the time when bitcoins had reached its all-time high of almost $20,000. The missing cryptocurrency at that time was valued at approximately $65 million.

Post the incident, the company pledged to reimburse all the missing bitcoins to its customers for their losses. So far, the company has been reimbursing the pool members monthly.

Following the hack and several other incidents and regulatory hurdles, the value of bitcoin core (BTC) plunged to around $6,900 dollars, which is nearly 70 percent slump.

Recently, Cryptocurrency startup Taylor fell victim of a cyber heist after hackers stole nearly S$1.5 million cryptocurrencies along with nearly seven percent of the total supply of its own TAY tokens. The only tokens left with the startup were those belonging to the Founders’ and Advisors’ pool which were held in an inaccessible vesting contract. Following the incident, the company was forced to launch a “survival fund token sale.”

Another major incident occurred this year was the hack of South Korean exchange, Coinrail. In the aftermath of the hack, the value of bitcoin dipped had to an all-time low for that time. The currency exchange lost about 30 percent of the coins it traded. Its website had to temporarily suspended trading while the site reassured users that remainder of the coins were “safely stored.” Although the exchange was relatively a small firm, the news of the hack has tumbled the bitcoin value and several other virtual currencies to two-month lows. Apparently, the hack had jolted holders of digital assets fueling a $46 billion selloff.

Kaspersky Lab exposes malicious operation by Lazarus group

Kaspersky

Kaspersky Lab recently uncovered AppleJeus, a malicious operation by North Korea’s cyber-hacking outfit ‘Lazarus Group’ to intrude on cryptocurrency exchanges and applications.

According to an official report, Kaspersky Lab’s Global Research and Analysis Team (GReAT) discovered the unusual activity of attackers who penetrated into the network of an Asia-based cryptocurrency exchange using Trojanized trading software to steal cryptocurrencies.

Vitaly Kamlut, the head of GReAT, stated that the cryptocurrency exchange did not encounter any financial losses during the incident.

“We noticed a growing interest of the Lazarus group in cryptocurrency markets at the beginning of 2017 when Monero mining software was installed on one of their servers by a Lazarus operator. Since then, they have been spotted several times targeting cryptocurrency exchanges alongside regular financial organizations. The fact that they developed malware to infect macOS users in addition to Windows users and even created an entirely fake software company and software product in order to be able to deliver this malware undetected by security solutions, means that they see potentially big profits in the whole operation, and we should definitely expect more such cases in the near future. For macOS users, this case is a wakeup call, especially if they use their Macs to perform operations with cryptocurrencies.” Vitaly added.

The security team at Kaspersky stated that the incident occurred after an employee downloaded a cryptocurrency application from a look-a-like website of a company which is dedicated to crypto trading. The malicious update installs a Trojan known as Fallchill that provides the hackers unlimited access to the compromised computer network system, allowing them to steal sensitive information or to deploy other viruses for exploitation.

Through the years, the scandalous Lazarus Group was linked to a series of cyber-attacks. One of the most brazen attacks occurred in February 2016 when hackers tried to steal $101 million from a Bangladesh Central Bank account at the New York Federal Reserve and move it to Sri Lanka. Only a spelling error caused the banks to realize they were under attack.

Turkish hacktivists take over Twitter accounts of U.S. journalists

Twitter

Turkish hacker faction Ayyildiz Tim, which claims that it is supported by Erdogan’s security forces, took over the social media handles of several United States journalists in a bid to praise Turkish President Recep Tayyip Erdogan. The attackers targeted journalists from publication like Bloomberg, The New York Times, and Fox News. The incident was notified to CNBC by cybersecurity intelligence firm, Crowdstrike.

Adam Meyers, vice president of Crowdstrike told CNBC that the company found social media account takeovers by pro-Erdogan hacktivists.

“They also claim their activity goes back to 2002,” Meyers said. “They’ve made attacks on a number of entities that they believe are hostile towards Turkey or critical of Turkey. This is a particular group we have been tracking for quite some time.”

According to the report, hackers often take over media personalities’ social accounts to propagate their political stance and agenda before a larger crowd of audience.

The account took over belonged to reporters Elizabeth MacDonald from Fox, Tom Keene from Bloomberg and Vanessa Friedman from the New York Times.

Elizabeth and Tom had recently covered Turkey’s economic conditions, while it is not established why Vanessa Friedman account was taken over as she majorly covers fashion and trends and hasn’t written about Turkey.

Times confirmed the hack and the security team has locked down Friedman. According to Meyers, the group has also created several spoofed accounts of BBC and other media outlets.

This isn’t the first-time hacktivists have taken over a Twitter handle. Last year, Twitter accounts of celebrated football clubs FC Barcelona and Real Madrid were hacked, where the Ourmine hacking group breached the Twitter account of the Real Madrid Club de Futbol and sent out tweets in English and Spanish that announced the joining of major rival player Lionel Messi. The attackers posted a video footage from an earlier match which showed Messi scoring for Barcelona against Real Madrid.

Data breach at Cheddar’s restaurant exposes 567,000 payment cards

Cheddar’s Scratch Kitchen

Darden restaurants recently announced a cyber attack incident on one of its eateries, exposing payment data of around 567,000 cards.

The American multi-brand restaurant operator stated that the attack was carried out at Cheddar’s Scratch Kitchen restaurants in 23 states. The compromised data included card numbers of guests who visited Cheddar’s restaurants between November 3, 2017, and January 2, 2018. The company has approached a third-party forensic cybersecurity firm for investigation.

“The trust our guests place in us is something we take very seriously, and we regret that this incident occurred,” Darden said in a statement. “We deeply value our relationships with our guests, and our priority is to assist those who may have been impacted by this incident.”

Hackers targeted point-of-sale machines that had been a part of Cheddar’s Scratch Kitchen before Darden bought it in April 2017 and it was permanently disabled and replaced on April 10, 2018. Darden officials stated their current systems and networks were not impacted by the attack.

Darden offering free identity protection services to the customers who dined at any Cheddar’s restaurant located in Alabama, Arizona, Arkansas, Delaware, Florida, Illinois, Indiana, Iowa, Kansas, Louisiana, Maryland, Michigan, Missouri, Nebraska, New Mexico, North Carolina, Ohio, Oklahoma, Pennsylvania, South Carolina, Texas, Virginia, and Wisconsin between November 3, 2017 and January 2, 2018.