Home Blog Page 361

They made $30 million because hackers showed them the future

Data breach

Contributed by SecureWorld

When I was a cub reporter at KHQ-TV, those of us in the business truly were the first to know: breaking news was coming in across the AP wire, and video was coming in from live trucks around the country.

We saw things, everyday, before the rest of the world did.

Those times are long gone. Now newsrooms learn about things from live streams, tweets, and posts that bounce around the world in seconds.

One of the key exceptions: earnings releases and other material facts about companies. These are still tightly controlled and timed to guard against insider trading.

Criminal hackers see opportunity

And that’s where former hedge fund manager Vitaly Korchevsky and securities trader Vladislav Khalupsky saw opportunity.

They worked with a gang of criminal hackers who allowed them to see the future, and that, it turns out, is highly profitable.

The criminal group made $30,000,000 over five years.

A jury convicted both men on July 6, 2018, of crimes that could put them in jail for two decades.

Hacking the future: how the scheme worked

According to the U.S. Attorney’s office in New York, computer hackers based in the Ukraine gained unauthorized access into the computer networks of Marketwired, PR Newswire, and Business Wire, through a series of sophisticated cyber attacks.

“At one point, one of the hackers sent an online chat message in Russian to another individual stating, ‘hacking prnewswire.com.’  The hackers moved through the computer networks and stole press releases about upcoming announcements by public companies concerning earnings, revenues and other material non-public information.”

Over the course of the scheme, the hackers stole more than 100,000 press releases. They were the first to know what businesses would announce in a few hours or the next day.

And they shared this information via overseas computer servers controlled by the hackers or through secure email accounts.

Korchevsky and Khalupsky would then go to work with these secrets, trading stocks on the stolen information before the rest of the world knew what that information would be.

In other words, the men placed their bets because they already knew who was going to win. They were.

Were your company’s earnings accessed?

The U.S. Attorney’s office says stolen press releases contained material nonpublic information about hundreds of publicly traded companies (maybe yours), and it named a few of the most recognizable:

Align Technology Inc. (makers of invisalign)

CA Technologies

Caterpillar Inc.

Hewlett-Packard

Home Depot

Panera Bread Co.

Verisign Inc.

Criminal network tries to cover its tracks

According to the the U.S. Attorney’s Office, the criminal hacking and trading gang tried to hide and destroy evidence while it was making millions.

“The conspirators used separate phones, computers and hotspots to conduct their illegal trading activity, and routinely deleted emails and/or destroyed hardware that contained evidence of their crimes.”

Where did the profits go? They were carefully transferred to offshore shell accounts.

But five years and $30 million in profits later, a collaborating group of U.S. law enforcement agencies arrested Korchevsky and Khalupsky.

Now that a jury has found them guilty, they are awaiting sentencing.

“This case represents the core of the U.S. Secret Service’s commitment and strategy to aggressively pursue cyber-enabled financial criminal enterprises through our proven task force model of global partnerships,” says United States Secret Service Deputy Assistant Director Michael Breslin.

Prosecuting crimes like these is also why the UK just announced the establishment of a flagship cyber court.

Knowing things before anyone else

As I flash back to my days in the TV newsroom, I know why we were excited to have inside information on breaking news. Because as journalists, we would get to share it with the world.

Now it’s Vitaly Korchevsky and Vladislav Khalupsky who may get to share something.

Not the secrets they stole, but instead, time together in prison.

This article was originally published here

Disclaimer: The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

CyberGym sets up its first U.S. cybersecurity training center

cybersecurity training

CyberGym recently opened its first U.S. cybersecurity training and technology arena in New York to aid US firms to cope with cyberthreats. The new facility provides human-centered training programs using real-time scenarios designed for specific industries like energy, manufacturing, infrastructure, banking, finance, and insurance, which are under constant threat of data breaches.

Founded in 2013 by the Israel Electric Corporation with Israeli cybersecurity company Cyber Control, CyberGym offers training and qualification programs for government and private organizations across Israel, Europe, Asia and Australia.

“CyberGym NYC is bringing sophisticated cybersecurity training and technologies with the benefit of a remote arena so more organizations can safely train against real-world cyber-attack scenarios,” said Ofir Hason, CEO at CyberGym. “Our proprietary technologies allow us to bring cyberattacks to life, so an organization can have a critical understanding of their cyber defense capabilities.”

Each training arena is designed to duplicate the company’s Information and Operational technologies that show real-world scenarios without exposing the original network systems. The organizations can defend against cyberthreats with CyberGym’s multiple training programs under international cybersecurity professionals.

Speaking on the new facility, the Chairman, and CEO of CyberGym NYC, Norihiko Ishihara said, “As cyberattacks grow increasingly sophisticated, along with the potential damages and costs to defend against a breach, training people to defend the network is as important as any investment in technology. As we’ve seen time and again, the human factor is the weakest link in both prevention and mitigation, so our core focus is training people.”

Few minutes with Rakesh Viswanathan

Rakesh Viswanathan

Rakesh Viswanathan is the Regional Director for India & SAARC at Cyberbit, a provider of IT/OT security solutions, and cybersecurity simulation. Cyberbit is a subsidiary of defense technology leader Elbit Systems.

Rakesh heads strategy and business for Cyberbit in India, and is dedicated to providing next-generation cybersecurity to BFSI, government and enterprises. In an exclusive interview with CISO MAG, Rakesh talks about IoT security, patch management, ways to build an information security team, and much more.

What are your views on the IoT ecosystem in India? Which sectors or industries do you think will widely adopt IoT in the recent future?

The IoT ecosystem in India is maturing right now, and IT and OT convergence is beginning to take place, but there are still a lot of gaps between the two. On the one hand, IT has developed very profoundly in India and the industry here has adapted many new technologies and developed a very advanced work force of highly skilled professionals that are very aware of security concerns and best practices.

By the end of next year (2019), India is set to become the world’s 3rd largest manufacturing nation (PWC). Critical industries like manufacturing, oil & gas and energy will be the frontrunners in IT/OT convergence and the leaders in adapting the best security tools and practices.

Attacks on converged OT networks almost always begin in the IT network, but those skilled IT teams are always focused on layers 1-7. As IT/OT networks converge, the security approach and tools must adapt. The entire OT industry in India is responding because everyone understands the how costly a cyberattack could be.

Most OT and IT networks in India today are segregated only by a firewall. The OT networks are mostly isolated and have not interconnectivity, no internet access.

This means also security operations are segregated. OT security alerts aren’t sent to IT and vice versa. The departments are not connected and there is a very real lack of both cooperation and skill set needed to run a security-focused OT organization. This is a very real pain for OT networks and a strong driver for convergence. These organizations understand the value of implementing one platform that can orchestrate investigation and response to alerts from both the OT and IT networks together in a unified platform.

One of the hurdles in IoT security is authorizing and authenticating devices. How do you think this can be handled?

Authorizing and authenticating devices is a known problem that can be handled by following industry standards such as ISA/IEC 62443, ISO/IEC 27001, NERC CIP,  NIST. The standards address particular sectors and industries. By carefully implementing the relevant standards, organizations can be confident that devices are been authenticated and authorized and security is being upheld.

A recent survey by Ivanti suggested that 80% of the organizations have a patch management policy in place. How scary is this stat and what can companies do to address such problem?

Indeed, most OT organizations do not have a patching policy in place, and this means they are more exposed to cyber threats and vulnerabilities. The first step to address this problem is to improve detection, monitoring and management of assets. I recommend beginning by mapping assets and traffic and using this to create baseline policies for all assets, protocols and communication in the OT environment. The baseline makes it much easier to detect known vulnerabilities and unpatched devices.

What are the essentials of building an efficient cybersecurity team?

People. Metrics. Training. Tools

People: The first essential element is people. Everything starts with people. Recruiting, training and retaining skilled, motivated security professionals is the most important foundation for any cybersecurity team. CISOs and SOC manager need to be creative about how to achieve this. One very basic element that is lacking in the hiring process is a reliable, relevant way to assess the skills of candidates. Some of our global customers are using our Cyber Range simulator to test the capabilities of candidates in a very realistic environment.

Metrics: “You can’t improve what you don’t measure”. The old adage is especially true in the modern SOC. The speed and accuracy of detection and response can mean the difference between just another alert handled by the SOC or a devastating breach that costs the organization dearly in terms of time, money and damage to reputation. Every SOC manager needs to set key performance metrics, constantly monitor the performance of the SOC as a whole and each individual analyst. This is the best way to identify bottlenecks and failure points and implement solutions.

Training: 68% of SOC analysts have never seen a live attack. This means when an attack hits, it will be the first time many of your team members have every confronted the situation. That fact should make everyone uneasy. Just as you wouldn’t send an inexperienced young soldier into battle, young SOC analysts deserve ample hands-on training so that they are ready to face the worst. The most effective way to give them the experience and training they need is to perform realistic drills in a cyber range simulator.

Tools: Obviously, having the best cybersecurity tools in place is important, but I mention tools last because just deploying them isn’t enough. Tools will only ever be as good as the people using them. So don’t just purchase the best tools, make sure your team is well trained on how to use them. Tools should empower your people and make each analyst smarter, faster and more effective.

Any advice to a budding information security professional?

Firstly, I would congratulate him or her on choosing a challenging, important career. Cybersecurity is one of the fastest growing highly skilled technology fields and the demand is only going to continue to grow. My advice would be to constantly continue learning, through reading, online course, managers and senior team members, conference and industry events. Whenever you have an opportunity to learn or practice, grab on to that opportunity with both hands. Also, make sure your learning is practical and includes lots of hand-on experience. This will make you a highly valuable and sought after professional.

FS-ISAC joins hands with Cyber Security Agency of Singapore

Singapore cybersecurity

The Financial Services Information Sharing and Analysis Center (FS-ISAC) recently inked a partnership with Cyber Security Agency of Singapore (CSA) to jointly develop cybersecurity measures to combat cybercrimes. The three-year extensive deal allows enhanced communications between the two companies on cyberthreats intelligence sharing.

“Asia-Pacific is increasingly a top target for cybercriminals and the region is seeing a growing need to bolster cyber intelligence cooperation to enable cyber-readiness,” the officials said in a statement on Wednesday.

FS-ISAC is a non-profit organization responsible for cyber and physical threat intelligence analysis and sharing for the financial and banking institutions. The partnership will help FS-ISAC get greater visibility of cyberthreats and challenges that Singapore face.

Speaking on the new initiative, FS-ISAC President and CEO Bill Nelson said, “Cybersecurity is a global concern. One of the best ways to defend the financial services sector against cyberattacks is through information sharing and readiness exercises,”

“Cybercriminals are collaborating to break down defenses, which is why it’s now more important than ever for us to work together on the global, regional, and country levels both in terms of information sharing and conducting joint exercises to stay ahead of cybercrime,” Nelson added.

On February 6, 2018, the Singapore Parliament passed the Cybersecurity Bill under which the owners of key bodies like national security, defense, foreign relations, economy, public health, public safety or public order, called as critical information infrastructure (CII), will have to comply to the standards and regulations mandated by the bill. The bill also mandates CIIs to conduct cybersecurity audits and risk assessments, and routinely participate in cybersecurity exercises.

 

OMB names Grant Schneider as Federal Chief Information Security Officer

CISO appointment

The Office of Management and Budget (OMB) recently announced the appointment of Grant Schneider as the permanent Federal Chief Information Security Officer. Schneider, who has served as interim Federal CISO since January 2017, will now serve as the chairman of CISO Council and continue his role as a senior director for cybersecurity at the National Security Council, according to a media statement.

In a statement announcing the move, Margaret Weichert, the chief management official at OMB, said, “Schneider brings extensive cybersecurity experience well aligned to lead efforts in securing government systems from cyberattacks,”

Schneider is the second official to hold Federal CISO position after Gregory Touhill, who stepped down as the first Federal CISO in January 2017. Touhill is currently working as President of the Federal Group at Cyxtera Technologies. He is among a number of professionals who walked through regency corridors and are now assisting enterprises in constructing their cybersecurity retreats.

“Grant was my deputy when I served in the position and has a firm grasp on the threats, vulnerabilities and current cyber issues. We need the Federal CISO as leadership is needed to implement best practices to protect the people’s information,” Touhil said in a statement.

CyberMDx raises $10 million to strengthen cybersecurity for hospitals

Startup Funding

In a recent Series A round of funding, CyberMDx, a New York-based healthcare cybersecurity startup, raised $10 million to expand medical cybersecurity to hospitals globally. The funding round was led by Pitango Venture Capital, with the participation of equity crowdfunding company OurCrowd Qure.

Founded by Amir Magner in 2016, CyberMDx offers cybersecurity preventive measures for medical devices and other Internet of Medical Things (IoMT). The company has deployed cybersecurity professionals from Israeli Intelligence’s elite cyber units and Artificial Intelligence (AI) academic leaders specialized in the healthcare industry.

“The expedited growth of connected medical devices poses exceptional challenges for hospital network security. Connected devices have become an integral part of hospitals’ IT networks, yet they are not monitored and remain unprotected. Recent massive cyber-attacks such as OrangeWorm, NotPetya, and WannaCry illustrate the challenges and high-risk exposure for hospitals,” said Amir Magner, CEO at CyberMDX. “We passionately believe in the significance of our work, addressing the arising threat for healthcare provider networks. Cybersecurity for medical devices is an absolute necessity in order to enable hospitals to focus on their main and most important mission – treating and saving human lives.”

Speaking on the new investment move, Rami Kalish, Managing General Partner and Co-Founder at Pitango, said, “CyberMDX’s solution is well timed with the rapidly increasing threats hospitals face today. Existing security and IoT solutions are not enough to protect the dynamic healthcare cyber threat landscape. We believe the market will continue to see a shift towards specialized cybersecurity solutions that address hospitals’ unique needs. CyberMDX delivers a powerful solution for the industry, and we are excited to collaborate with and support them as they continue to grow the company.”

UK cybersecurity organizations unite to strengthen cybersecurity structure

Banks in United Kingdom

In response to the UK’s National Cyber Security Strategy (NCSS), a cross-sector association has been formed incorporating 15 leading UK organizations. The alliance aims to shape the government’s commitment to advance the cybersecurity standards in cyber education and to further develop cybersecurity profession in the country.

The association brings together several cross-sector cybersecurity experts from established councils, professional certification bodies, academics and industry representative groups, as per a media report. The announcement of the alliance comes on the same day after a Joint Committee on the National Security Strategy released a report criticizing the government for the shortage of cybersecurity experts in the country.

The Chairperson of the Joint Committee, Margaret Beckett MP, said, “Our Report reveals there is a real problem with the availability of people skilled in cyber security but a worrying lack of focus from the Government to address it. We’re not just talking about the ‘acute scarcity’ of technical experts which was reported to us; but also, the much larger number of posts which require moderately specialist skills. We found little to reassure us that Government has fully grasped the problem and is planning appropriately.

We acknowledge that the cybersecurity profession is relatively new and still evolving and that the pace of change in technology may well outstrip the development of academic qualifications. However, we are calling on Government to work closely with industry and education to consider short-term demand as well as long-term planning. As a very first response, Government must work in close partnership with the CNI sector and providers to create a cybersecurity skills strategy to give clarity and direction. It is a pressing matter of national security to do so.”

 

Israeli-American cybersecurity company ObserveIT raises $33 million

NCSC for Startups Initiative

In its Series B round of funding, ObserveIT, an Israeli-American cybersecurity company, recently raised $33 million. The new funds will be used for technological advancements and expanding business globally. Some of the investors are NightDragon Security, FireEye, Spring Lake Equity Partners, and Bain Capital Ventures. The latest round has brought ObserveIT’s total funding to $55 million.

Founded by Gabriel Friedlander and Avi Amos in 2007, ObserveIT designs a cyber defense system to prevent insider breaches within an organization. The company moved its control center to Boston after it was acquired by Bain Capital in 2013.

ObserveIT CEO and Director Michael McKee told they’re making major efforts to expand the company’s global reach. “In the coming years, we will take the company to a point at which it will achieve $100 million in revenue. When we get there, we may hold another financing round that will enable us to grow and become a $500 million company. That’s our challenge – to build the company as a global company.”

Speaking on the company’s origin, McKee, said, “We proudly tell customers that the company was founded in Israel, and that automatically gets us respect for our technology, but what the customers really want is a global service and global access, because most of them are global companies.”

US Lawmakers advise Google, Facebook to resist Vietnam’s new cybersecurity law

Facebook

A group of 17 U.S. lawmakers advised the CEOs of Google and Facebook to push back on Vietnam’s new cybersecurity law approved by Vietnamese legislators last month. The new regulation comes into effect on January 1, 2019, and requires global technology giants like Facebook, Google to store user data on local servers and open offices in Vietnam.

“If the Vietnamese government is coercing your companies to aid and abet censorship, this is an issue of concern that needs to be raised diplomatically and at the highest levels,” the Congressional Vietnam Caucus said in a letter, according to Reuters. The letter issued on July 12 also stated, “We urge you to live up to your stated missions to promote openness and connectivity,”

The Law focuses on social media usage, data localization, cybersecurity audit of information systems of agencies and organizations, handling illegal content, and protection of children.

The social media users will have to abide by the Constitution and legal regulations while voicing their opinion and discontent on the platform. According to the law’s Article 15, “information on cyberspace classified as illegal includes anti-state information; information that excites violent disturbance, undermines security and deranges public order; information that causes defamation and slander; information that violates economic management order; and false information that causes public panics, damages socio-economic activities, hampers state agencies’ activities and on-duty persons, and violates the rights and benefits of other organizations and individuals.”

Only 65% of firms have cybersecurity experts: Gartner

Top Cybersecurity Jobs in 2021

Gartner, a market research firm, recently came out with a survey stating that only 65 percent of companies globally have a cybersecurity expert. The Gartner’s 2018 CIO Agenda Survey suggested that over 95 percent of Chief Information Officers (CIOs) anticipate that cyber attacks might increase in the next three years due to the shortage of cybersecurity experts, eventually causing potential threats to the organization’s security.

“In a twisted way, many cybercriminals are digital pioneers, finding ways to leverage big data and web-scale techniques to stage attacks and steal data,” Rob McMillan, Research Director at Gartner, said in a statement.

“CIOs can’t protect their organizations from everything, so they need to create a sustainable set of controls that balance their need to protect their business with their need to run it. The bad news is that cybersecurity threats will affect more enterprises in more diverse ways that are difficult to anticipate,” McMillan added.

As per the survey results, most CIOs consider market evolution as the highest priority for 2018. The findings collected from 3,160 CIO respondents in 98 countries from different industries indicated that 35% of them have already deployed cybersecurity experts in their organization, while 36% are still planning.

Last year, a survey conducted by a software industrial company indicated that a number of industrial companies are not taking cybersecurity seriously enough. The “Putting Industrial Cyber Security at the Top of the CEO Agenda” survey, that was conducted by Honeywell in collaboration with LNS Research, included responses from 130 strategic decision makers from industrial companies across North America, Europe, and other parts of the globe.

Forty-five percent of the respondents agreed to the fact that their organization lacks a reliable enterprise leader for cybersecurity. Forty percent have a chief of cybersecurity while 15% plan to get a cybersecurity incharge within the next year. When it comes to the companies’ manufacturing plant, only 35% of the organizations have an established role for cybersecurity.