Home Blog Page 358

Holiday camp firm Butlin’s data breached, 34,000 guest records affected

Butlin Data Breach

Hackers may have accessed nearly 34,000 guest records from the server of Britain’s holiday camp firm Butlin’s.  The leaked data includes names, home addresses, email addresses, phone numbers as well as the trip itinerary.

The firm assured that payment details of the customers were unaffected. The firm notified Information Commissioner’s Office (ICO) and has been informing affected customers to tell them what they should do. The company is also undergoing its own investigations and hasn’t found any fraudulent activity related to the breach.

“Butlin’s take the security of our guest data very seriously and have improved a number of our security processes. I would like to apologise for any upset or inconvenience this incident might cause. A dedicated team has been set up to contact all guests who may be affected directly. I would like to personally reassure guests that no financial data has been compromised,” Butlin’s managing director, Dermot King said.

“A dedicated team has been set up to contact all guests who may be affected directly. I would like to personally reassure guests that no financial data has been compromised,” he added.

Several companies of Britain have been the recent victims of cyber attacks.

Recently, ticketing website, Ticketmaster, became the most recent victim of a data breach, after hackers stole data from the website including payment information of several customers.

The website issued an alert after noticing a malicious software on a customer support product hosted by its third-party, Inbenta Technologies which ran several Ticketmaster international websites like Ticketmaster International, Ticketmaster UK, GETMEIN! and TicketWeb. Affected customers may include UK citizens who purchased or attempted to purchase tickets between February and June 23 2018, as well as international customers who purchased, or attempted to purchase tickets between September 2017 and June 23, 2018.

Candidates for U.S. House of Representatives vulnerable to security threats: Researchers

House of Representatives

Researchers stated that the websites of the candidates running for the House of Representatives elections in November are vulnerable to hacking.

A team of four researchers led by former National Institutes for Standards and Technology security expert Joshua Franklin highlighted that three of every 10 candidates running for the U.S. House of Representatives are vulnerable to cyber attacks. The team identified multiple threats, malicious webpages, and problems with digital certificates using automated scans and test programs.

Joshua Franklin stated that they’re going to inform all the candidates to help fix the vulnerabilities. “We’re trying to figure out a way to contact all the candidates,” Franklin said in a media report. He also specified that hackers use typo-squatting method to develop mimic sites, which are used for phishing campaigns or to steal sensitive information.

The warnings about the midterm elections come after Democrats have spent more than a year working to strengthen cyber defenses of the party’s campaign operations.

In November 2017, Democrats and Republicans joined hands with Harvard to prevent hacking in 2018 midterm elections. The Harvard University released 27-page guidelines on how the U.S. can prevent hacking attacks during elections. The Belfer Center for Science and International Affairs, based at the Harvard Kennedy School of Government, charted out the guidelines in collaboration with top politicians and security experts. The recommendations reportedly suggest campaign leaders focus on enhancing security and to implement measures such as two-factor authentication process for email access and end-to-end encryption messaging via Signal and Wickr services.

The contents of the playbook include topics such as Vulnerable Campaign Environment, Threats Campaigns Face, Managing Cyber Risks, and Steps to Securing Your Campaign, among other pressing issues. The handbook is a result of Belfer’s four-month-old effort called “Defending Digital Democracy” (DDD) program.

PGA golf championship targeted by ransomware attack

PGA

PGA of America, which runs the PGA Championship golf tournament, has become the latest victim of a ransomware attack after hacker group Shadowy bandits hijacked its computer servers locking the staff out of crucial files containing marketing materials for the competition as well as the Ryder Cup in France.

After the staff of PGA realized that their systems were compromised and attempted to work on the files, they were greeted with a message that read, “Your network has been penetrated. All files on each host in the network have been encrypted with a strong algorythm [sic].”

The hackers also warned that break the encryption would cause loss of all the data, which may “lead to the impossibility of recovery of certain files”

According to GolfWeek, the locked files “include extensive promotional banners and logos used in digital and print communications, and on digital signage around the grounds at Bellerive. The stolen files also include development work on logos for future PGA Championships. Some of the work began more than a year ago and cannot be easily replicated.”

“We exclusively have decryption software for your situation. No decryption software is available in the public,” they wrote.

The hackers also sent an encrypted email address which PGA could use to send hackers two files which they would decrypt to testify their honest intentions.

The hackers provided a bitcoin address but haven’t specified the desired amount. The bitcoin wallets were not linked to a particular person or entity and due to the very same reason couldn’t be used to track the attackers.

Reports suggest that PGA of America is unwilling to pay up the ransom and has deployed its IT team to fix the issue and identify the hackers. PGA has not commented on the issue yet as it is an “ongoing situation”.

On the bright side, the hacking incident did not impact the PGA Championship, and the tourney went on without any disruptions. Cyber-security expert Matthew Hickey at Hacker House told BBC that it’s likely the hackers were trying to maximise the effect of their attack, as the incident occurred right at the onset of the championship. “They would have picked a date to cause as much disruption as possible,” he said.

 

Singapore seeks ASEAN cooperation to strengthen cybersecurity standards

ASEAN

The Singapore government is trying to establish cybersecurity standards with the Association of Southeast Asian Nations (ASEAN) to strengthen the protection of critical information infrastructure. Several government officials highlighted the urgent need for stronger safeguards against cyber attacks and called on the ASEAN to cooperate in the cross-border protection of internet-based systems.

“We should find ways to find some common reference points and learn from each other. It’s a partnership thing, whether we can work with each other, support each other in capability-building,” Singapore Minister for Communications and Information S. Iswaran said in a media report.

Iswaran stated that a similar discussion was going on with the Asia-Pacific Economic Cooperation to develop cybersecurity standards globally.

“And ASEAN should be working together to see what other ways we can harmonize our standards. You’re only as strong as the weakest link in these matters. So, the more we work together – that’s why I talked about common standards and so on- if we are able to raise our capability and bring it to a certain level, then the interconnectivity becomes one that we are more confident of. It cuts both ways,” he added.

The comments came in the wake of the unprecedented cyberattack on SingHealth database, which affected around 1.5 million people. The hackers allegedly compromised more than 1.5 million patients’ personal information. Singapore’s Prime Minister Lee Hsien Loong’s personal particulars and outpatient medication data were also exposed in the breach. On July 4, 2018, the security officials at SingHealth detected and stopped the unusual activity that lasted from June 27 to July 4. The Singapore government disconnected computers from the internet at public healthcare centers and set up a four-member Committee of Inquiry (COI) to investigate the incident.

RiskSense raises $12 million to prioritize cybersecurity risks

Startup funding

Cyber risk management company RiskSense recently raised $12 million in a Series B round of funding co-led by Spring Mountain Capital and NightDragon Security. The other investors in the round included UL Ventures, Paladin Capital Group, Sun Mountain Capital, EPIC Ventures, and Jump Capital. The new funds will support the company accelerate growth through sales, marketing, research & development investments, and help customers prioritize cybersecurity risks.

Formerly known as CAaNES, RiskSense was founded in 2006 by Srinivas Mukkamala. The company aids private and government organizations to reveal cyber risks and provides clear remediation guidance to fix them. The RiskSense’s technical team joined forces with the U.S. Department of Defense and U.S. Intelligence Community on applying artificial intelligence to cybersecurity threats as a part of the CACTUS (Computational Analysis of Cyber Terrorism against the U.S.) project.

“This new investment will allow us to take advantage of the enormous market opportunity for helping customers prioritize their risks. The funding will provide the resources we need to accelerate our business momentum and strengthen our technology advantage,” said Srinivas Mukkamala, CEO of RiskSense. “We are pleased to welcome Spring Mountain Capital to our board. Both ​Raymond Wong and Dave DeWalt will be invaluable advisors to our management team. ​”

“Spring Mountain Capital invests in companies that are developing breakthrough technology innovations in high growth markets. RiskSense stands out in the cyber risk management sector because of its ability to identify and prioritize security blind spots, so companies can fix what matters most,” said ​Raymond Wong, ​Managing Director and Head of Growth Equity at Spring Mountain Capital. “We love the fact that RiskSense makes the security tools that companies already have more effective.”

Meltdown vulnerability could leave Samsung Galaxy 7 open to hacking: Researchers

A team of researchers from Graz Technical University in Austria recently said that they’ve found a way to exploit the Meltdown vulnerability to attack the Galaxy S7 and other smartphones made by Samsung Electronics Co Ltd.

The Samsung’s Galaxy S7 smartphones contain a Meltdown microchip security flaw, uncovered earlier this year, that allows a hacker to exploit the vulnerability and steal information from the memory of running apps like password managers, browsers, emails, and documents, according to the findings of the research.

“There are potentially even more phones affected that we don’t know about yet. There are potentially hundreds of millions of phones out there that are affected by Meltdown and may not be patched because the vendors themselves do not know,” a researcher Michael Schwarz said in a statement.

The revelation came after Samsung rolled out security patches to protect Galaxy S7 handsets from Meltdown in January and further boosted the security through a software update in July this year. “Samsung takes security very seriously and our products and services are designed with security as a priority,” the company quoted in a statement.

The Graz team carries out research on various topics that look into Meltdown’s impact on other smartphones and they are expected to reveal more vulnerable devices in the future.

CyberVista adds EC-Council’s certification training to its cadre of training programs

U.S. and Australia to Jointly Develop Cyber Training Platform

Cybersecurity training and workforce development company CyberVista recently announced a series of new launches and partnerships to strengthen its place in cybersecurity training platform.

Addressing at Black Hat USA 2018 information security event, the CEO of CyberVista Amjed Saffarini stated, “As an organization committed to help address the skills gap, we are proud to share news about adding EC-Council as a partner, adding a partnership with Skills Fund to provide greater affordability and access to cybersecurity training, and announcing a partner relationship with the FAIR Institute. We are also launching our Advance initiative, which defines and delivers skills-based and role-based training. There is no other training company more focused on finding new solutions to the skills gap plaguing our industry.”

The International Council of Electronic Commerce Consultants (EC-Council) is an information security certification body well-known for its flagship training program Certified Ethical Hacker (CEH). Founded by Jay Bavisi, EC-Council has developed industry-leading programs to their portfolio to cover all aspects of information security, including EC-Council Certified Security Analyst (ECSA), Computer Hacking Forensics Investigator (CHFI), Certified Chief Information Security Officer (CCISO), and Licensed Penetration Tester (LPT) programs.

“We’re proud to add CyberVista to our partnership ranks,” said Jay Bavisi, Founder of EC-Council. “CyberVista’s mission to help solve the cybersecurity skills gap aligns with our mission to validate information security professionals who are equipped with the necessary skills and knowledge required in a specialized information security domain that will help avert a cyber conflict.”

AI startup Hazy announces $1.8 million in latest seed raise

Artificial Intelligence startup Hazy announced $1.8 million in a latest seed funding round led by the UCL Technology Fund. The other investors in the round included Nationwide Building Society, Pentland, Amadeus Capital Partners, and AI Seed. The funds will support the London-based startup build a new range of products and expand its workforce. This brings Hazy’s total seed investment to $2.8 million following a $1 million funding from M12 and Notion in May, this year.

Established in 2017 by Harry Keen, Hazy offers cloud-based artificial intelligence solutions and has worked with several startups, international banks, and the UK government. The company claims that its artificial intelligence platform allows organizations to share data responsibly and securely through a workflow tool that automatically anonymizes the data.

Speaking on the new investment, Harry Keen, CEO of Hazy, said, “In recent months we have seen a seismic cultural shift around data. Consumers are acutely aware of the importance of data security and GDPR legislation means that businesses rightly now consider safe data-handling as mission-critical. Our technology ensures that huge, unwieldy data sets are GDPR-compliant. Recognising that most companies don’t have data experts, Hazy has been built to require zero technical integration or any technical expertise. We are proud to be working with organizations ranging from major banks and building societies, to small businesses and UK central government and we are excited to continue developing our solution as we launch our product more widely.”

David Grimm, Investment Director at Albion Capital, who manages the UCL Technology Fund stated, “Big data analytics offers unparalleled opportunities for start-ups and corporate giants alike, but also puts data security at the top of the agenda for the world’s regulators. Hazy’s solution is a game changer, enabling businesses to automatically anonymize complex datasets without the need for a lengthy technical integration with internal systems. We are excited to support the team through the next phase of growth.”

Hackers infiltrate UK airwoman’s Tinder profile to steal F-35 fighter jets’ secrets

CISO MAG Desk

Hackers have succeeded in honey trapping United Kingdom’s Royal Air Force (RAF) personnel by hijacking an RAF airwoman’s Tinder profile and reaching out to another RAF serviceman to get details of the F-35 stealth fighter out of him. The source of the hack remains largely unknown but comes in the midst of concerns of China and Russia staging state-sponsored attacks.

According to the Britain RAF, hackers have been able to gain “some information” about its fleet of stealth fighter jets. “Within the last week, a serving member of the RAF had their online dating profile hacked. It subsequently transpired that the perpetrator then attempted to befriend another serving member of the RAF to apparently elicit comment and detail on F-35,” according to an internal RAF memo viewed by the UK’s Daily Mail. “‘Fortunately, little information was disclosed and the individual whose account had been hacked reported this matter expediently enabling prompt follow-up action and investigation.”

The honeytrap attack had raised the concerns among RAF officials, prompting the commanders to warn the RAF personnel to be wary of similar attacks in future. ‘Nevertheless, this incident serves to highlight the risk of social engineering (SE) and online reconnaissance against social media profiles that disclose links to HM Forces,’ the memo stated.

The F-35 Joint Strike Fighter project is currently the world’s most expensive weapon at over $1.3 trillion wherein the UK will manufacture 15 percent of every one of over 3,000 jets ordered. The attack has occurred weeks after RAF received its first batch of F-35s from American weapons maker Lockheed Martin. “It should be noted that UK military posture, policy and capabilities continue to be significant targets of interest for hostile state and non-state actors,” the memo read.

This isn’t the newest incident this year where dating apps were used to infiltrate smartphones used by military personnel. In July this year, Palestinian Sunni-Islamist fundamentalist organization Hamas was accused by the Israel army’s intelligence directorate for building fake dating and FIFA World Cup 2018 applications to entice soldiers into downloading malware on to their mobile phones with the intention to gather sensitive information about the military activities around Gaza strip. According to reports, “Hamas also created bogus profiles with the stolen identities of young women, asking to chat on WhatsApp and interact with soldiers and later requesting them to download their Trojan Horse apps on Google Play Store.”

Cybersecurity startup HYAS raises $6.2 million

Startup funding

Canadian cybersecurity startup HYAS recently raised $6.2 million in a Series A funding round led by Microsoft’s Venture Fund M12. The other investors in the round included Startup Capital Ventures, 205 Capital, Wesley Clover, and cybersecurity professionals Tim Eades and Tom Noonan.

Hyas was founded in 2015 by Chris Davis, one of the only three civilians to receive the Federal Bureau of Investigation’s (FBI) Director Award of Excellence. The venture-backed startup supports organizations, researchers, and law enforcement personnel identify the perpetrators behind cyber attacks with its online threat detection, analysis, and investigation tools.

“Every industry professional today is facing unrelenting adversaries. At HYAS we have dedicated ourselves to helping them finally put their attackers on the back foot,” said the Founder and Chief Executive Officer Chris Davis of HYAS. “Our Comox platform allows enterprises to see the unseeable – it’s like X-ray vision for cybersecurity professionals. With the release of our next generation of products, these capabilities will grow significantly.”

“HYAS is going beyond threat detection and providing the attribution tools required to actually identify and prosecute cybercriminals,” said Matthew Goldstein, a partner at M12. “Their approach is wholly unique, as are the results, and customers are already responding aggressively. Widespread adoption of Comox and subsequent products will help take bad actors off the internet, and lead to an overall decrease in cybercrime globally.”