Home Blog Page 359

Dixons Carphone says 10 million customer records compromised in 2017

Dixons Carphone

The British Electricals and mobile phone retailer Dixons Carphone recently announced that around 10 million records containing personal data of customers may have been compromised by a cyber attack in 2017.

According to an official statement, the company declared that approximately 10 million records containing personal information may have been breached in 2017 and some of the data may have left the company’s systems. It also notified the stolen records don’t contain payment card or bank account details and there is no sign of any fraud activity.

Dixons Carphone Chief Executive Alex Baldock said, “Since our data security review uncovered last year’s breach, we’ve been working around the clock to put it right. That’s included closing off the unauthorized access, adding new security measures and launching an immediate investigation, which has allowed us to build a fuller understanding of the incident that we’re updating on today. As a precaution, we’re now also contacting all our customers to apologize and advise on the steps they can take to protect themselves. Again, we’re disappointed in having fallen short here and very sorry for any distress we’ve caused our customers. I want to assure them that we remain fully committed to making their personal data safe with us.”

The company is implementing enhanced controls, monitoring, and testing applications to strengthen its security structure as a part of precautionary measures. It also apologized to its customers and advised them to take protective steps to mitigate the risk of fraud.

Cisco acquires cybersecurity firm Duo Security for $2.35 billion

CISCO

Cisco Systems recently announced that it would acquire cybersecurity firm Duo Security for $2.35 billion to accelerate its operations in cloud computing. The latest deal is the biggest acquisition for Cisco since its $3.7 billion deal with application management company AppDynamics last year.

The acquisition integrates Cisco’s network, device, and cloud security platforms with Duo Security’s zero-trust authentication and access products, allowing Cisco clients to connect their users easily and securely.

“In today’s multi-cloud world, the modern workforce is connecting to critical business applications both on- and off-premise,” said David Goeckeler, executive vice president and general manager of Cisco’s networking and security business. “IT teams are responsible for protecting hundreds of different perimeters that span anywhere a user makes an access decision. Duo’s zero-trust authentication and access products integrated with our network, device and cloud security platforms will enable our customers to address the complexity and challenges that stem from multi-and hybrid-cloud environments.”

Founded by Dug Song, the Duo Security delivers unified access security and multi-factor authentication to organizations through a cloud-based platform. Its security applications verify the identity of users and the health of their devices before accessing the accounts, helping prevent information breaches.

“Our partnership is the product of the rapid evolution of the IT landscape alongside a modernizing workforce, which has completely changed how organizations must think about security,” said Dug Song, Duo Security’s co-founder and chief executive officer. “Cisco created the modern IT infrastructure, and together we will rapidly accelerate our mission of securing access for all users, with any device, connecting to any application, on any network. By joining forces with the world’s largest networking and enterprise security company, we have a unique opportunity to drive change at a massive scale and reshape the industry.”

Cybersecurity startup ZecOps raises $3.5 million

Startup funding

Cybersecurity startup ZecOps recently announced that it has raised $3.5 million in a funding round led by KPN Ventures. The other investors in the round included Evolution Equity Partners, Plug and Play Silicon Valley, WISE Ventures, Array Ventures, and individual investors. The new investment allows the startup to launch its products that aid organizations find attackers’ mistakes effectively.

“We were surprised with the overwhelming demand for our products. It can be exceedingly difficult to innovate in a crowded market like the cybersecurity space – but we were able to do it effectively. Consequently, the reactions from CISOs around the globe made our efforts worthwhile,” said Mr. Avraham. “In the last year, we detected multiple APTs for a variety of businesses, a rare achievement especially for a one-year-old company.”

Founded in 2017 by Zuk Avraham, the stealth mode startup, ZecOps specialize in automated threat analyses and has experience in working with law enforcement agencies, banks, critical infrastructure, tech, payment solutions, and telcos to solve critical issues in cybersecurity. Avraham also serves as the Chairman of the Board at Zimperium, a mobile threat defense solution provider.

“Through KPN’s cooperation with Zimperium, we have got to know Zuk as a clear thought leader in cybersecurity” said Herman Kienhuis, EVP and Managing Director at KPN Ventures “With ZecOps, he is taking on a new challenge: automating security breach analysis; we see great potential in enabling more companies to learn from attacks, generate new threat intelligence and substantially improve their security.”

UnityPoint Health suffers breach; 1.4 million patient records compromised

Lowa-based health system UnityPoint Health has fallen victim to a recent data heist that compromised 1.4 million patient records. According to an official statement from the company, the issue began when UnityPoint Health received a series of phishing emails that trapped some employees to provide their sign-in credentials. This gave the hackers unauthorized access to the company’s business email accounts. The organization discovered the incident on May 31, 2018, and notified the victims about the data theft.

Around 1.4 million people are being informed about the unauthorized access to protected personal and health information by compromising the company’s business email system. The health system stated that the fraudulent emails were designed to appear to have come from a trusted executive within the organization. The compromised data included patients’ names, addresses, dates of birth, medical record numbers, treatment and surgical information, diagnoses, lab results, medications, dates of service, and insurance information.

The health system stated that they’ve informed law enforcement authorities about the data heist and launched an investigation with a computer forensics firm. To prevent further loss, the health system implemented a multi-factor authentication to verify the users before accessing their accounts and educated employees to identify and avoid phishing emails or attachments.

Pentagon creating a list of “Do Not Buy” software

Russian hackers, Senate Homeland Security Report, Electronic Warfare Associates

According to Ellen Lord, the Under Secretary of U.S. Defense for Acquisition and Sustainment, the Pentagon is currently working on a “Do Not Buy” list of software from vendors whose code originate from Russia and China.

Lord informed that the Pentagon had been working on the “Do Not Buy” list for the last six months, which is meant to assist the Department of Defense’s acquisitions staff and partners to avoid buying problematic codes from unreliable sources.

“What we are doing is making sure that we do not buy software that has Russian or Chinese provenance, for instance, and quite often that’s difficult to tell at first glance because of holding companies,” according to a Reuters report, while adding “we have identified certain companies that do not operate in a way consistent with what we have for defence standards”.

“It’s a huge education process,” Lord said.

According to Defense One, official have been working with intelligence community to identify “certain companies that do not operate in a way consistent with what we have for defense standard,” while adding that the department is focusing on one particular system and not around programs and weapons compromised by foreign software.

“If a U.S.-based company wants to go into China and facilitate and enlarge their business from a global perspective, they have to hand over source code and when they get online, they’re working with not only that company in China, but what — the PLA and the MSS, right?,” said William Evanina, who directs the National Counterintelligence and Security Center to Defense One. “So it’s an unfair playing advantage, and the metaphor I would use is: could you imagine if a company coming to do business in the U.S. had to deal with not only our government, but CIA, NSA, the Department of Commerce, Treasury, as well as maybe some U.S.-based oligarchs, right?  It’s just foreign to us, but that’s part of the understanding that we need to have, the understanding that when they globalize their goods and services, that we’re at an unfair advantage in those countries,” Evanina said.

Symantec unveils its largest Security Operations Center in India

Symantec

Cybersecurity firm Symantec Corporation has expanded its Security Operations Center (SOC) with a state-of-the-art facility in Chennai, India. The center will provide security intelligence insights, and faster detection and response through greater regional coverage and visibility of the threat landscape for customers in India and overseas.  In addition to being the largest Symantec SOC in Asia Pacific and Japan to support regional customers, this facility will also support customers and other Symantec SOCs across the globe. Powered by the company’s Global Intelligence Network, and more than 100 cyber security professionals, the SOC is designed to bolster cyber defenses and respond to new threats as they emerge 24X7.

“Symantec continues to heavily invest in our global SOC locations,” said Greg Clark, Symantec CEO. “Our strategic expansion in Chennai and other SOC territories highlights our commitment to providing the most evolved cyber security to customers around the world. Symantec’s SOCs are powered by the world’s largest civilian threat intelligence network, harnessing the power of artificial intelligence (AI) and machine learning (ML), to comb through trillions of telemetry elements. This unique capability provides protection against advanced cyber threats in an increasingly connected world.”

“The cyber attacks that companies, governments and people face today are multi-faceted, requiring the combination of Symantec intelligence, technology and expertise to bolster defenses to stop advanced threats,” said Samir Kapuria, Executive Vice President and General Manager, Cyber Security Services at Symantec. “With the expanded Chennai SOC, Symantec CSS continues to sharpen its competitive advantage for our customers as well as our growing network of cyber warriors.  Symantec is focused on staying ahead of the evolving threat landscape by integrating advanced technologies and developing innovative tools designed to track unusual behaviors and identify attacks to protect our customers from both internal and external attacks.”

The expanded SOC will offer the full suite of Symantec Cyber Security Services (CSS) capabilities, helping customers reduce operational costs while extending the capabilities of their security teams to expedite response to attacks across on-premises and cloud environments – before, during and after an attack.

 

European Commission issues warnings to 17 EU countries over cybersecurity

European Commission

The European Commission has issued warnings to seventeen European Union countries for missing the deadline to adopt an EU Directive that is designed to ensure the security of digital networks and information systems across the EU. The missed deadline for adoption of the directive was May 9.

The Commission sent warnings to EU member states on July 19 as the first step in the proceedings that will end up in the EU Court of Justice. It also announced another deadline of November 9, 2018, for the EU countries.

According to the NIS Directive, the authorities in EU countries must take the necessary steps to ensure the protection of economic activities against cyber attacks. The operators in essential sectors, including energy, utilities, banking, transportation, and healthcare, are required to take cybersecurity precautions and notify the authorities of any suspicious activities. The directive also included search engines, cloud computing services, and online marketplaces, that hold the data of a large number of users.

The EU countries warned by the European Commission are Austria, Bulgaria, Belgium, Croatia, Denmark, France, Greece, Hungary, Ireland, Latvia, Lithuania, Luxembourg, the Netherlands, Poland, Portugal, Romania, and Spain.

The European Commission laid down several proposals last year to boost cybersecurity in the EU member states. Some of the measures include increasing investment in technology, setting more stringent consumer safeguards, and improving diplomacy. The EU also stressed the importance of greater national and law enforcement cooperation to counter cyberattacks as well as increasing technical capabilities for cyberattack investigation.

Blockpass makes investment in Holdex, offers premium compliant ICO platform

Partnership

ACN Newswire: Digital identity verification platform Blockpass has announced an investment in partner Holdex and the offering of a production ready premium compliant ICO platform. The fully integrated, cloud-based platform will aid ICOs, Token Resellers and Token Distributors in ensuring seamless compliant interactions with investors.

Blockpass offers shared regulatory compliance services for humans, companies, objects and devices. As an identity system that supports verification of humans (KYC), objects (KYO) and connected devices (KYD), Blockpass will enable the development of new applications that rely on a trusted connection between multiple entities.

Holdex develops tools to support crypto crowdfunding campaigns. In doing so, Holdex ensures that campaigns will be the most secure and compliant by providing ICOs with top KYC and AML checks and reports.

By integrating Blockpass’ seamless KYC verification process into the Holdex platform, the partnership allows for a premium, painless investor registration and due-diligence process. Blockpass will work with Holdex exclusively to launch the new cloud-based platform.

“This really is the next generation of ICO services,” said Adam Vaziri, Blockpass CEO. “Partnering with Holdex to create this premium platform means that we can offer seamless and compliant onboarding, while ensuring that our partners have the best possible experience in setting up their token events.”

“We just couldn’t miss this strategic investment opportunity, as Holdex and Blockpass’ visions correlate,” said Vadim Zolotokrylin, Holdex CEO, CTO and Co-Founder. “For Holdex, having Blockpass as not just a provider, but as a deeply integrated partner on both a technology and corporate level means creating a superpower when we are talking about compliance. I am confident that this strategic deal will be the start of a new exciting chapter for Holdex platform and its customers.”

Blockpass also recently launched its own Initial Token Distribution event, which will run from 31 May to 30 November, with 250 million PASS Tokens available. PASS Tokens act as discount vouchers for Blockpass’ service offering, while growing the Blockpass customer base as the first “KYC Token” available on the market. The Blockpass Airdrop will be open for registration through partner Infinito Wallet until 12 August 2018, with 2 million PASS Tokens available.

Blockpass has announced a number of key collaborations recently, most notably with Edinburgh Napier University for the creation of the pioneering new blockchain research laboratory, the Blockpass Identity Lab. With five fully funded Studentships and led by Professor Bill Buchanan, the Blockpass Identity Lab will focus on the creation of world-leading knowledge and innovation around citizen-focused systems which enshrine the right to privacy.

Rising hacker threats to ERP applications: Homeland Security

SAP Oracle

In an alert named ‘Malicious cyber activity targeting ERP applications’, the Department of Homeland Security stated that a number of government and private organizations have been exposed to cyber attacks due to security flaws in some of the business systems manufactured by Oracle or SAP.

The alarm was raised in the wake of the recent survey by two cybersecurity firms Onapsis and Digital Shadows that highlighted ERP (Enterprise Resource Planning) software applications as one of the primary targets for the breach. According to the survey report, unpatched business systems at two government agencies and other firms in the media, energy, and finance sectors are vulnerable to cyber attacks, as they failed to take necessary security measures advised by Oracle or SAP.

“These attackers are ready to exploit years-old risks that give them full access to SAP and Oracle systems without being detected,” said Onapsis Chief Executive Mariano Nunez. “The urgency level among chief security officers and CEOs should be far higher.”

According to Reuters, the study identified that around 17,000 SAP and Oracle software installations are exposed to the Internet at more than 3,000 private companies, government agencies, and universities. And more than 4,000 known bugs in SAP and 5,000 in Oracle software pose security threats, especially in older business systems. It also warned that at least 10,000 servers are running incorrectly configured software that could allow cybercriminals to exploit the vulnerabilities in SAP or Oracle applications to obtain access to sensitive information. An SAP spokesman recommended all customers to implement SAP security patches as soon as they are available to protect the SAP infrastructure from attacks.

Cybersecurity solutions provider Imperva to acquire Prevoty

U.S. and Australia to Jointly Develop Cyber Training Platform

Cybersecurity solutions provider Imperva recently signed an agreement to acquire network management startup Prevoty for $140 million to provide security solutions for application services residing on-premises and in the cloud. The California-headquartered firm develops and sells information security software for databases and web applications, on-premises, in the cloud, and across hybrid environments.

The agreement, which is expected to close in the third quarter of the fiscal year 2018, allows both companies to expand their customers’ security capabilities and their visibility into how applications are accessed, and how applications and users interact with data. This gives deeper insights to the customers to understand the security risks and the ability to protect their business from cybercriminals.

“The acquisition is expected to advance our hybrid security strategy and further our mission to deliver best-in-class cybersecurity solutions,” said Chris Hylen, president, and CEO of Imperva. “Prevoty complements current Imperva application and data security offerings. When combined with our on-premises and cloud products, it will help businesses better protect themselves from attacks, prevent breaches and monitor security across their digital business. Combined with Imperva insights offerings, Prevoty will further help to identify the true risks to customers’ application services.”

Founded in 2013 by Julien Bellanger and Kunal Anand, Prevoty claims to be a leading provider of autonomous application security solutions that enable enterprises to improve remediation of vulnerabilities.

“Our team is excited to join Imperva, a company with a long track record of cybersecurity leadership and innovation,” said Julien Bellanger, Co-founder, and CEO of Prevoty. “We believe that the combination of our solutions with Imperva’s portfolio of products will allow us to jointly create the gold standard in technology for application and data protection for organizations everywhere.”