Home Blog Page 356

Australia shelves Ministry of Cyber Security

Remote Access Scams

As of August 26, 2018, Australia does not have a Ministry of Cyber Security, as the new cabinet appointed by Prime Minister Scott Morrison has not named a minister for cyber security in his first ministerial line-up. Morrison has rolled the cybersecurity wing into the Department of Home Affairs, and not appointed a replacement for Angus Taylor who resigned his post on August 23, along with 12 other ministers on the basis of their support for Peter Dutton’s leadership aspirations.

The cabinet was reshuffled after Peter Dutton and former foreign affairs minister Julie Bishop was beaten by Morrison in a spill, ousting Malcom Turnbull in the process.

“The Hon Peter Dutton MP will remain in the key role of minister for home affairs where he has served with distinction by continuing to protect our borders and keep Australians safe. Unfortunately there isn’t a place for everyone in Cabinet,” the PM announced on Sunday, while adding, “Minister Dutton, as the minister for home affairs, will be focusing on everything from cybersecurity through to law enforcement, border protection, security agencies, and he’ll have his focus more principally on these security tasks.”

“And the Hon Angus Taylor MP will join cabinet as minister for energy. Mr Taylor’s primary focus will be on continuing to get electricity prices down for Australian households and businesses,”.

Currently, the website for Department for Cyber Security is redirecting users to the page of Ministry of Home Affairs, stating that the information the former page has been transferred to the latter, with a message that reads, “The Department of the Home Affairs is the lead agency for cyber security policy across the Australian Government.”

The ministry of cybersecurity was started by former Prime Minister Malcom Turnbull in 2016 as part his national cybersecurity strategy. The ministry focused on threat mitigation and sharing of threat intelligence between several businesses and the government.

Zscaler acquires stealth security startup TrustPath

Acquisition

Information security company Zscaler recently announced that it has acquired stealth cybersecurity startup TrustPath. The acquisition accelerates Zscaler’s ability to build user behavioral profiles, compute enterprise risk posture, and detect sophisticated targeted attacks.

“Zscaler’s cloud security platform is helping leading global enterprises securely transform their infrastructure for the cloud and mobile world,” said Zscaler CEO Jay Chaudhry. “TrustPath’s technology complements the broad and deep security capabilities that Zscaler has already built and further enhances the platform that is protecting over 200 of the Forbes Global 2000 companies.”

TrustPath, a stealth-mode security startup, develops artificial intelligence-based algorithms through machine learning to identify cyber threats, providing enhanced efficiency and security incident response. Zscaler has obtained TrustPath’s development team, artificial intelligence (AI), and machine learning (ML).

With its flagship services, Zscaler Internet Access and Zscaler Private Access, Zscaler claims that it allows organizations to securely transform their network systems and applications for a mobile and cloud-first world. Its cloud-based security platform includes behavior analytics, machine learning, Cloud IPS, and zero-day detection. Innovative technologies like AI and ML from Trustpath help Zscaler deliver new sophisticated capabilities and protections for Zscaler customers.

Zscaler is also one among the cybersecurity startups that have reached the $1 billion valuation benchmark. The other startups include Cloudflare, Cylance, Crowdstrike, and Cybereason.

AT&T acquires AlienVault, appoints Barmak Meftah as CEO of new cybersecurity wing

AT&T Inc.

AT&T has completed the acquisition of open-source threat intelligence firm AlienVault. The new acquisition will help AT&T bolster its security portfolio and will also become a business division in itself. Barmak Meftah, CEO of AlienVault will be the in charge of the new cybersecurity division, who has been named the president of AT&T Cybersecurity Solutions. The Financial details of the acquisition have not been disclosed.

With the acquisition, Dallas-based AT&T will support and expand AlienVault’s investment in its multichannel sales ecosystem as well as make the company accessible to all the partner businesses including several Fortune 100 companies, as well as companies deep down to local mom-and-pop stores.

“Regardless of size or industry – need cyber threat detection and response technologies and services. With AlienVault, we are able to accelerate cybersecurity for businesses of all sizes. AlienVault’s expertise in threat intelligence improves our ability to help small and medium-size organizations detect and respond to cybersecurity attacks. AlienVault’s expertise in delivering threat detection and response to midmarket customers combined with our enterprise-grade cybersecurity portfolio enables us to provide scalable, intelligent, affordable security for business customers of all sizes,” said Barmak Meftah in a Q&A with Channel Partners Online.

“We will combine our phenomenal threat detection, incident response and compliance security platform with AT&T’s managed security capabilities, making near-real-time threat information actionable and achievable,” Meftah said in a statement.

AT&T had first unveiled its plan to acquire AlienVault in July with an aim to provide its enterprise security solutions to smaller businesses. “Whether big, small or somewhere in between, all organizations are now targets of the types of sophisticated cyberattacks that have bombarded large enterprises for years,” said Thaddeus Arroyo, CEO of AT&T Business. “AlienVault’s cybersecurity talent and threat intelligence capabilities, combined with our ability to deliver innovative threat detection and response solutions at scale, will help enable businesses of all sizes to better defend themselves.”

T-Mobile discovers data breach that compromised two million users’ information

T-Mobile data breach

The mobile telecommunication company T-Mobile US, Inc has revealed a data breach that compromised around two million users’ personal information. In an official announcement, the company informed its customers about the potential security breach that was discovered and stopped on August 20.

The compromised customer data included names, email addresses, account numbers, and other billing information. Fortunately, the people behind the breach did not access financial data like credit card numbers, social security numbers, and passwords, according to the company.

“Our cybersecurity team discovered and shut down an unauthorized access to certain information, including yours, and we promptly reported it to authorities. None of your financial data (including credit card information) or social security numbers were involved, and no passwords were compromised. However, you should know that some of your personal information may have been exposed, which may have included one or more of the following: name, billing zip code, phone number, email address, account number, and account type (prepaid or postpaid).” the company announced on its official website.

T-Mobile notified the affected people via a text message. It also stated if any of the users don’t receive a notification, then that means their account was not among those impacted by the incident.

Democrats say suspected cyber attack was actually a phishing test

Democratic National Committee

The Democratic National Committee (DNC) clarified that the suspected hacking attempt on its voter database was actually a simulated phishing test and not the work of cyber criminals. The party officials stated that the mishap was caused due to lack of communication between the DNC and one of its state branches.

“We have taken heightened steps to fortify our cybersecurity especially as the Trump Administration refuses to crack down on foreign interference in our elections. In an abundance of caution, our digital partners ran tests that followed extensive training. Despite our misstep and the alarms that were set off, it’s most important that all of the security systems in place worked,” Brandon Dillon, the chair of the Michigan Democratic Party, said in a statement.

On Wednesday, the DNC announced that they’ve stopped a cyber-attack on its party’s website VoteBuilder after cybersecurity firm Lookout and cloud service company DigitalOcean notified them about the incident. Briefing Democrats on the unsuccessful attack, the DNC’s chief security officer Bob Lord said, “These threats are serious and that’s why it’s critical that we all work together, but we can’t do this alone. We need the (Trump) administration to take more aggressive steps to protect our voting systems. It is their responsibility to protect our democracy from these types of attacks. This attempt is further proof that there are constant threats as we head into midterm elections and we must remain vigilant in order to prevent future attacks.”

However, now it became clear that the apparent hack was not what it seemed after the investigation.

“We have continued to investigate the phishing site reported to the DNC yesterday. We, along with the partners who reported the site, now believe it was built by a third party as part of a simulated phishing test on VoteBuilder. The test, which mimicked several attributes of actual attacks on the Democratic party’s voter file, was not authorized by the DNC, VoteBuilder nor any of our vendors.” Bob Lord said in a statement.

“There are constant attempts to hack the DNC and our Democratic infrastructure, and while we are extremely relieved that this wasn’t an attempted intrusion by a foreign adversary, this incident is further proof that we need to continue to be vigilant in light of potential attacks,” he added.

Kenyan Central Bank proposes new cybersecurity guidelines

Kenyan Central Bank

In order to fight against banking frauds and to get a better view of the new threats that payment service providers are facing, the Central Bank of Kenya (CBK) has proposed new guidelines for cybersecurity standards.

According to the newly proposed guidelines, banks and mobile payment operators are required to file cybersecurity reports with the industry regulator. The firms are asked to notify the Central Bank of Kenya within 24 hours of any suspicious activity and also need to submit a quarterly report with CBK on the incidents experienced and how they were resolved.

“CBK is well aware of the fact that cyber risk will keep morphing due to the evolution of cyberthreats in Kenya and across the globe. The Bank, therefore, requires all Payment Service Providers (PSPs) to periodically review their cybersecurity strategy, policy, and framework regularly based on each PSP’s threat and vulnerability assessment. All PSPs are required to submit their Cybersecurity Policy, Strategies and Frameworks to the Central Bank of Kenya by August 31, 2018.” CBK stated in the new guidelines. “The Payment Service Providers should notify the Central Bank of Kenya within 24 hours of any Cybersecurity incident(s) that could have a significant and adverse impact on the PSP’s ability to provide adequate services to its customers, its reputation or financial condition in the stipulated format.”

CBK stated that the banking industry and mobile money operators incurred huge losses due to cyberattacks, but most of them are unreported to the regulators. It also directed the firms to share the security strategies on how they are handling cyberattacks by August 31.

Cybersecurity startup Bandura Systems raises $4 million

Startup

Lake St. Louis-based cybersecurity startup Bandura Systems recently raised $4 million in a Series A financing round led by a group of investors that included Grotech Ventures, Gula Tech Adventures, Maryland Venture Fund, and Cultivation Capital. The new investment will support the company accelerate sales, channels for global expansion, and beef up its Threat Intelligence Gateway (TIG) platform marketplace.

Founded by St. Louisan Suzanne McGee, Bandura assists organizations finding gaps in their existing security controls. Bandura claims to be the pioneer of the Threat Intelligence Gateway (TIG) platform with the U.S. Department of Defense that monitors network systems against large volumes of threat intelligence indicators to mitigate the risk of breaches and information theft.

“Firewalls are getting crushed by the sheer volume of threats that hit organizations industry-wide every day,” said Chris Fedde, CEO of Bandura. “And, while external threat intelligence is available, most companies lack the staff and resources to effectively and efficiently operationalize it. The Bandura TIG complements the firewall, enabling companies of all sizes to use threat intelligence without limits in an easy and automated way. We are grateful for the support of our investors and believe it is a testament to our work redefining the industry’s use of threat intelligence from reactive detection and response to proactive prevention.”

Bandura claims that it delivers robust threat intelligence and control technology that filters both inbound and outbound network traffic to block known threats, including network probes and scans, malware, command and control, botnets, ransomware, and other threats.

“We partner with innovative cybersecurity technology companies who are bringing fresh ideas and unconventional approaches to tackle the large and growing cybersecurity challenge,” said Steve Fredrick, General Partner at Grotech Ventures. “Bandura offers such innovation by empowering organizations with the most comprehensive and advanced IP threat protection available.”

Russian hackers targeted websites of U.S. conservative think-tanks: Microsoft

Russia-based APT29 Targets COVID-19 Vaccine Research

Hackers linked to Russian military intelligence tried to hack the websites of two conservative think-tanks in the United States ahead of November’s midterm elections, according to Microsoft.

The Microsoft Corporation said that it has detected and seized websites that were created by hackers linked to the Russian unit to mimic the pages of The International Republican Institute and The Hudson Institute.  These sites are designed to redirect the users to fake web pages where they were asked to enter usernames, passwords, and other credentials.

“We’re concerned that these and other attempts pose security threats to a broadening array of groups connected with both American political parties in the run-up to the 2018 elections. To be clear, we currently have no evidence these domains were used in any successful attacks before the DCU transferred control of them, nor do we have evidence to indicate the identity of the ultimate targets of any planned attack involving these domains,” Microsoft said in a statement.

The Russian authorities denied the allegations made by Microsoft, describing it as a political game.

Microsoft’s report comes after the latest research that revealed the websites of the candidates running for the House of Representatives elections in November are vulnerable to hacking. A team of four researchers led by former National Institutes for Standards and Technology security expert Joshua Franklin highlighted that three of every 10 candidates running for the U.S. House of Representatives are vulnerable to cyberattacks. The team identified multiple threats, malicious web pages, and problems with digital certificates using automated scans and test programs.

Apple assures customers after Australian teenager breaches its network

Apple Notarization

A 16-year-old boy in Australia pleaded guilty to hacking Apple’s computer systems multiple times over the course of a year and steal secure data.

The unnamed teen from Melbourne told police that he loved Apple company and dreamed of working there. He obtained unauthorized access to customer accounts and downloaded around 90 gigabytes of secure files without revealing his identity.

He saved hacking instructions and stolen files in a folder dubbed “hacky hack hack” on his laptop and allegedly shared the stolen info with his friends on WhatsApp.

“Two Apple laptops were seized, and the serial numbers matched the serial numbers of the devices which accessed the internal systems,” a prosecutor said in a statement. “The purpose was to connect remotely to the company’s internal systems.”

Apple stated that no customer information was compromised in the incident. The U.S. Federal Bureau of Investigation (FBI) referred the matter to the Australian Federal Police (AFP) after Apple contacted FBI when it discovered the unauthorized activity.

An Apple spokesman stated that the company “discovered the unauthorized access, contained it, and reported the incident to law enforcement. We want to assure our customers that at no point during this incident was their personal data compromised.”

 

Animoto suffers data breach; users’ personal information compromised

70 Mn Records Exposed After AFL Fan Website Leaks Users’ Data

Video making service provider Animoto has revealed a data breach that occurred on July 10 which compromised users’ personal information like names, dates of birth, and email addresses.

According to the official statement, on July 10, 2018, Animoto discovered and halted the unusual activity on its systems and reported to the law enforcement authorities for further investigation. From August 16, 2018, Animoto began notifying its users about the incident, after confirming the activity was unauthorized.

Based out in New York, Animoto offers cloud-based video creation services that generate video from photos, video clips, and music into video slideshows for social media sites.

The company stated that the compromised users’ data may have included first name, last name, username, email addresses, hashed and salted passwords, geolocation, gender, and date of birth. The officials stated it wasn’t clear if the hackers obtained the private key, which could be used to expose the passwords. Animoto also specified that the complete payment data was stored in a separate system and was not accessed.

To prevent the further loss, Animoto suggested its employees and users reset their passwords and reduced employees’ access to critical systems. The company is also reviewing its policies and procedures and examining ways to enhance overall network cyber threat detection at Animoto to detect and prevent unauthorized access to user information.