Home Blog Page 360

SIAS discovers security breach after five years

Singapore

The Securities Investors Association of Singapore (SIAS) recently revealed that hackers may have compromised the personal data of 70,000 members in 2013. The incident was uncovered recently when the Cyber Security Agency of Singapore (CSA) notified SIAS about the breach on Wednesday, July 25, 2018, after receiving a clue from an anonymous source.

The company stated that the names, IC numbers, home addresses, email addresses, mobile and landline numbers of Sias’ members were compromised.

“This is not related to the SingHealth incident. As SIAS is neither a public-sector agency nor Critical Information Infrastructure, Singcert reached out to them to inform them and asked them to verify the situation.” Ms. Goh Yan Kim, the Deputy Director of the Singapore Computer Emergency Response Team (Singcert), stated in a media briefing.

“We don’t know who did it. We have contacted our IT management company, who are external specialists working with our in-house IT team and will take their advice on what to do. We are very sorry to members, especially the older members. Most of them don’t have emails, so it took a little longer to inform them,” said David Gerald, the president and CEO of Sias.

To prevent any further loss, the organization has taken down its current website and is working on a new website. “We are working on how to make our processes more robust. We had a firewall and other precautions in place, but we were told that there is no 100 percent, when it comes to cybersecurity. Hackers are getting smarter and smarter.” Gerald said.

The news comes after the recent cyber attack on SingHealth which affected more than 1.5 million patients. According to a statement from the Ministry of Health and Ministry of Communications and Information, the hackers compromised more than 1.5 million SingHealth patients’ personal information. Singapore’s Prime Minister Lee Hsien Loong’s personal particulars and outpatient medication data were also exposed.

The security officials detected the attack on July 4 and stopped the unusual activity that lasted from June 27 to July 4. A four-member Committee of Inquiry (COI) has been set up to investigate the incident.

Prisoners hack tablets to steal $225,000 worth of credits

Prison Tablet

Prison officials in Boise, Idaho, stated that 364 inmates hacked their JPay tablets and transferred $225,000 worth of credits into JPay account balances. The tablets are made available to inmates in prisons across the country through a contract with CenturyLink and JPay. Prisoners use these tablets to communicate with their families and friends, and purchase music and games.

“This conduct was intentional, not accidental. It required a knowledge of the JPay system and multiple actions by every inmate who exploited the system’s vulnerability to improperly credit their account,” Idaho Department of Correction spokesman Jeff Ray said in a statement. He added that no taxpayer money has been compromised.

According to the statement, around $225,000 was credited in 364 inmates’ accounts; 50 inmates received more than $1,000. The largest amount credited by a single inmate was under $10,000.

“JPay is proud to provide services that allow incarcerated individuals to communicate with friends and family, access educational programming, and enjoy positive entertainment options that help prevent behavioral issues,” JPay spokesperson Jade Trombetta stated. “While the vast majority of individuals use our secure technology appropriately, we are continually working to improve our products to prevent any attempts at misuse.”

The corrections-related service provider stated it has recovered more than $65,000 worth of credits so far and suspended the music and games facilities to the prisoners until they compensate for the losses.

Facebook pledges tough security efforts ahead of midterm elections

Facebook copyright complaint

Facebook pledged to use a variety of security measures, including artificial intelligence, to counter Russian intelligence officers or other online intruders who use misleading strategies and false information to meddle in the upcoming U.S. midterm elections, the Facebook officials stated in a media briefing.

The social media giant drew fire for not handling misinformation and election manipulation on the platform too well. To counter the same, the company recently introduced a tool that shows all political promotions circulated in the network.

Facebook recently stated that it will not remove postings simply because they are wrong. Mark Zuckerberg cited the Holocaust denial row as an example of false announcements that would not be taken down if they were sincerely stated.

Last year, Facebook claimed that a Russian group posted more than 80,000 times on its service between January 2015 to August 2017. Nearly 29 million Facebook users directly received its posts in their news feeds. The Facebook officials disclosed these numbers to the Senate Judiciary Committee on October 31, 2017.

John McAfee announces $100K bounty for hacking Bitfi wallet

McAfee Acquires Browser Isolation Firm Light Point Security

John McAfee recently announced a reward of $100,000 for anyone who can hack his Bitfi wallet. The founder of McAfee antivirus software stated that Bitfi wallet is the world’s first unhackable device and the  bounty goes to anyone who can hack it.

McAfee partnered with hardware wallet company Bitfi last month to launch what John McAfee claims to be the first unhackable and open source crypto wallet. The Bitfi wallet is a physical device created for storing cryptocurrencies and other digital assets.

The company specified the rules to hack the Bitfi wallet in an official statement. According to the statement, the participant needs to buy a Bitfi wallet (worth $120) preloaded with cryptocurrencies worth $50 to try and steal. The charge is to make sure that only serious participants are involved.

Bitfi considers a hack successful when the user extracts all the coins from the wallet. The successful hackers will get to keep the coins and will receive a reward of $100K. The participants are asked to share their hacking progress, so that the other cryptocurrency community members will not have to try the same process. Bitfi also stated that the bounty program is not intended to identify the security vulnerabilities.

 

Japan introduces cybersecurity strategy for 2020 Tokyo Olympics

Tokyo Olympics 2020

With the Olympic and Paralympic Games starting in two years, the Japanese government introduced a new cybersecurity strategy Wednesday in a meeting held at the government’s Cyber Security Strategy Headquarters. The meeting was headed by Chief Cabinet Secretary Yoshihide Suga. The new strategy is pending for approval from the Cabinet.

“The likelihood of cyber attacks resulting in major economic losses is growing,” Yoshihide Suga said at the meeting.

As a part of the strategy, the government plans to create a new body to ensure effective coordination among government agencies, the Olympic organizing committee, municipalities, and business operators to respond to cyber threats.

The government also decided to introduce a five-level scale to classify the severity of cyber attacks. The severity index categorizes the cyber attacks into five levels: the lowest level 0 indicates ‘No Impact’ while the highest level 4 indicates ‘Extremely Grave Impact’. The index would be helpful for people, government, and business entities in understanding the magnitude of threats and taking necessary actions.

 

Singapore disconnects healthcare computers from the Internet

Only 44% of Health Care Providers Meet National Standards on Cybersecurity, OpenEMR vulnerabilities

In the wake of the recent cyberattack on SingHealth, which affected more than 1.5 million patients, the Singapore government has disconnected computers from the internet at public healthcare centers.

The health ministry stated that the disconnection will cause “some inconvenience for patients and healthcare staff, as a result of the unavailability of some IT system connections that require the internet.”

“We could, and should, have implemented internet surfing separation on public healthcare systems, just as we have done on our public-sector systems,” said Teo Chee Hean, the Deputy Prime of Singapore in a statement.

“This would have disrupted the cyber kill-chain for the hacker and reduced the surface area exposed to attack. This has now been done,” he added.

According to a statement from the Ministry of Health and Ministry of Communications and Information, the hackers compromised more than 1.5 million SingHealth patients’ personal information. Singapore’s Prime Minister Lee Hsien Loong’s personal particulars and outpatient medication data was also exposed.

The security officials detected the attack on July 4 and stopped the unusual activity that lasted from June 27 to July 4. A four-member Committee of Inquiry (COI) has been set up to investigate the incident.

Blockchain cybersecurity startup Xage Security raises $12 million

Startup funding

Xage Security, a blockchain security startup, recently raised $12 million in a Series A funding round led by March Capital Partners. The other participants included GE Ventures, City Light Capital, and NexStar Partners. The new funds will be used to develop the company’s security infrastructure and capabilities of offering services for energy, telecom, utilities, building management, and manufacturing industries.

“For IIoT technologies to successfully take hold, we need to deepen and broaden the integration of comprehensive cybersecurity within industrial systems,” said Duncan Greatwood, CEO of Xage Security. “We believe that every industry can be made more efficient and more secure. With this support, we will continue developing and implementing a foundational security solution that enables industrial innovation.”

Founded in December 2017, Xage Security claims to be the only blockchain-protected security fabric for the Industrial Internet of Things (IIoT). The company offers a secured communication medium between machines, people, and data using Xage Security Suite.

“The Xage Security Suite is a pioneering technology that transforms the way we protect and innovate with the new generation of smart, connected infrastructure,” said Sumant Mandal, Managing Director at March Capital Partners, in a press release. “March Capital is proud to partner with Xage as they expand their reach and lay the foundation for Industry 4.0.”

Speaking on the funding, Abhishek Shukla, the managing director of GE Ventures, stated, “For industries to benefit from the IoT revolution, organizations need to fully connect and protect their operations. Xage is enabling the adoption of these cutting-edge technologies across energy, transportation, telecom, and other global industries. We are excited to support Xage’s innovative approach,”.

Three Key Principles for Securely Migrating to the Cloud

Cloud Forensics

Contributed by Jethro Beekman, Fortanix

As more organizations continue to migrate to the cloud, concerns remain about security of the infrastructure backing the cloud and privacy of their data. For decades, businesses have been trying to run software with hardened, more secure architectures. Such architectures modified for today’s cloud are generally known as shielded compute, confidential compute, enclave-based cloud, and protected module architectures (PMA). Various security technologies offering these approaches are currently available from companies such as Intel (SGX), AMD (SKINIT, SME and SEV), ARM (TrustZone) and Microsoft (VBS). When deciding which approach is best for your organization, consider these key principals for securely migrating data and systems to the cloud.

#1: Lower your TCB (Trusted Computing Base)

Whichever approach you choose, organizations should look for an architecture that implements complete mediation, enables least privilege, and can significantly reduce the trusted computing base (TCB). Complete mediation ensures that all access paths are checked. For example, a bank can have a state-of-the art biometric security system at the front door, but that’s not going to stop anyone from climbing through the basement window. Least privilege is about compartmentalization: Making sure that once a user is inside, he or she is allowed to only see or do certain things in accordance to identity and access policies, such as interact with the bank teller, but the user cannot gain access to the bank’s vault.

Reducing the TCB means less opportunities to do things wrong. Keeping with the bank analogy, it’s easier to secure a small fortified building than it is to secure an entire campus. As it turns out, most of the commercially available security technologies simply don’t meet the three properties of complete mediation, least privilege, and reduced TCB.

 #2: Confidentiality is hard, but integrity is much harder

The security properties of complete mediation, least privilege, and reduced TCB can be partially attained using cryptography. However, an organization can’t build a secure system relying only on confidentiality (encryption). They have to also use integrity protection. This is a well-known principle in cryptographic engineering. Not using integrity protection can be considered a failure in complete mediation. That is because without it not only can someone tamper with data outside the security boundary, but the tampered data is allowed right back in during decryption. This often leads to unfortunate results. For example, it’s the lack of integrity protection that has left AMD SME/SEV vulnerable to attack, as described in two papers from Cornell University last month and 2016.

#3: Protect workloads from privileged threats

Current-day computer systems generally have a strictly hierarchical privilege model, which can’t properly enable least-privileged designs. ARM TrustZone, for example, introduces a special secure mode on the processor, but for the most part it is just a more privileged mode of the processor. This means that all software running in secure mode has blanket access to all other software and data running in both secure and non-secure mode. The best scenario is to have separate programs responsible for their own data.

Modern computing infrastructure is extremely complex. For example, consider the boot process of a typical computer. To get to a running state, you need to go through the BIOS, the bootloader, possibly the hypervisor, the kernel, and the graphical shell. And that’s just for the CPU. There might be other components that also have privileged access to system components, such as an embedded processor (Intel ME or AMD PSP), or a baseboard management controller (BMC). Technologies that require security of a large chunk of the platform and boot chain such as Intel TXT, AMD SKINIT, and Microsoft VBS can’t practically be used in a secure way because the TCB is so large. This is especially true if organizations don’t want to trust the platform owner, such as in the cloud.

The best solution is one that offers complete mediation by implementing integrity-protected encryption and isolation directly at the processor level. This also reduces the TCB to just the processor and the application. And it’s that same isolation that allows an organization to split up its application achieving least privilege.

 Getting to the secure cloud

Organizations looking to secure sensitive workloads in the cloud need an end-to-end approach that provides security from the hardware to the cloud. Solutions that enable security controls to be embedded in the application are desirable, but the controls need to be rooted in hardware-based security. The solution must provide complete isolation of the application from other applications on the same system, and even from the operating system or hypervisor, protecting the application against root users and physical attacks. The application’s memory and data in use must be protected using encryption to thwart unauthorized access. The technology should enable applications to extend the runtime encryption easily to support end-to-end encryption for persistent data and data in transit. In addition to confidentiality, the solution must also deliver integrity protection. The solution should enable proof of secure execution by being able to attest that the application is running securely.

The use of hardware-based security controls that run within an application has the potential to deliver deterministic security that automatically scales as the application scales in the cloud. Finally, any solution selected must balance security and ease of use. The solution must be easy for application developers and security architects to adopt without a significant learning curve, and ideally be compatible with millions of existing cloud and data center applications. All this combined is the best way to securely migrate to the cloud.

Disclaimer: The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

New Gmail feature could open users to phishing risks: Homeland Security officials

Gmail, apt28

Google Mail users have been warned about a new Google Mail feature which could be leveraged by hackers to carry out a phishing scam.

According to the intelligence report issued by DHS, obtained by ABC News, The Department of Homeland Security (DHS) warned Gmail users about the potential threats with the new Gmail feature – Confidential Email.

In April, the company unveiled its updated Gmail design that provides a new user interface, the ability to snooze a message, auto-generated smart replies, and Confidential Email option.

The Confidential Email feature allows users to access the content via a link, prevent the content from forwarding, copying, downloading or printing, and set an expiration date for confidential emails. But according to the DHS, the feature “presents an opportunity for malicious cyber actors to mimic the e-mail message and phish unwary users,”.

“We have reached out to Google to inform them of intelligence relevant to their services and to partner to improve our mutual interests in cybersecurity,” Lesley Fulop, a Department of Homeland Security spokeswoman, told ABC News.

“The tech giant is committed to protecting the security of users’ personal information and hence, had created “machine learning” algorithms to detect potential phishing scams that cyber criminals carry out,” stated by Google spokesman Brooks Hocog.

Nigeria and Israel to join hands to fight cyber crime

Nigeria and Israel

Nigeria and Israel are considering areas of partnership to implement measures for tackling cybercrimes. According to a media report, a team of three representatives from the Israeli Embassy visited   Professor U. G Danbatta, the Executive Vice Chairman and CEO of Nigerian Communications Commission (NCC) in Abuja. The delegation comprising Barnea Hassid, Director Africa Department II, West and Central Africa, Nadav D. Goren, Deputy Chief of Mission, and Florence Osuji, Senior Economic Officer discussed the areas of collaboration with U.G Danbatta.

While addressing the event, Professor Danbatta stated that the Commission will welcome any kind of alliance to mitigate cybercrime, security and privacy issues in the telecom ecosystem and online media database. Barnea Hassid, who led the delegation, announced that he’s going to provide training to the NCC staff in the collaborative areas.

In January 2018, the Israeli government made a similar partnership with India when Israeli Prime Minister Benjamin Netanyahu visited the country. He and his Indian counterpart Narendra Modi shook hands on cybersecurity collaboration, which would include training, B2B assistance, and enablement of industrial summits to enhance skill development in the country.