Home Blog Page 383

Clothing brand Forever 21 reports possible credit card breach

Forever 21

Popular clothing retailer Forever 21 may have become the latest victim of credit card breaches. In an official statement released recently, the company notified its customers that they recently received a report from a third party suggesting unauthorized access to data from payment cards used at certain Forever 21 stores.

“We immediately began an investigation of our payment card systems and engaged a leading security and forensics firm to assist us”, the statement said. “Because of the encryption and tokenization solutions that Forever 21 implemented in 2015, it appears that only certain point of sale devices in some Forever 21 stores were affected when the encryption on those devices was not in operation. Our investigation is focused on card transactions in Forever 21 stores from March 2017 – October 2017. Because our investigation is continuing, complete findings are not available, and it is too early to provide further details on the investigation. We expect to provide an additional notice as we get further clarity on the specific stores and timeframes that may have been involved.”

As a precaution, the US clothing retailer said, “it is always advisable for customers to closely monitor their payment card statements. If customers see an unauthorized charge, they should immediately notify the bank that issued the card. Payment card network rules generally state that cardholders are not responsible for such charges.”

“We regret that this incident occurred and apologize for any inconvenience. We will continue to work to address this matter”, the statement concluded.

California-based Forever 21 has 815 outlets in 57 countries, but it has not been disclosed which locations were compromised. The retailer is not the first to suffer a credit card breach in the last couple of months. The U.S. fast food chain Sonic Drive and supermarket chain Whole Food Market suffered similar fate in the months of September and October.

Russia meddled with UK’s telecom systems, confirms NCSC chief

United Kingdom

The United Kingdom’s National Cyber Security Center (NCSC) chief Ciaran Martin confirmed that Russian hackers targeted the country’s telecommunications systems, media, and energy networks in the past one year.

Martin’s remarks came amid heightened scrutiny of Russia’s influence in last year’s Brexit referendum. Addressing the Times Tech Summit in London on November 15, 2017, Martin said “I can’t get into precise details of intelligence matters, but I can confirm that Russian interference, seen by the National Cyber Security Centre over the past one year, has included attacks on the UK media, telecommunication and energy sectors.”

A part of Martin’s speech summary was released on November 14, 2017. Martin said, “the Prime Minister sent Russia a clear message in her speech to the Lord Mayor’s Banquet on Monday night. Russia is seeking to undermine the international system. That much is clear. The PM made the point on Monday night — international order as we know it is in danger of being eroded.”

On November 13, 2017, Britain’s Prime Minister Theresa May had said that Russia was “weaponizing information” and meddling in elections to undermine the international order.

Sending a stark warning to Russia, May said “We know what you are doing. And you will not succeed. Because you underestimate the resilience of our democracies, the enduring attraction of free and open societies, and the commitment of Western nations to the alliances that bind us.”

Last month, 43-year-old Martin also said that organized cyber crime network originates from Eastern Europe, particularly Russia. UK media reported that at least 45,000 messages were posted by over 400 Twitter accounts that were running from Russia about Britain’s departure from the European Union.

Meanwhile, Russian foreign ministry has rejected scathing criticism by Britain.

Beyond 11 percent: Need for women role models in cybersecurity

Women in cybersecurity

The debates on the skill gap and gender gap in cybersecurity have off late become few of the most redundant topics. But both continue to escalate even after significant efforts by several organizations. A study by The Global Information Security Workforce Study from (ISC)² and its Centre for Cyber Safety and Education had revealed that the women only make up to 11 percent of the global cybersecurity workforce. And even here, the 11 percent has been a stagnant figure since 2013, as the same agency has been conducting the survey every year, and has not spotted an earth-shattering trend. This is a dangerous trend considering the fact that the same survey had projected that the gap between cybersecurity professionals and unfilled positions will expand to 1.8 million globally by 2022.

To dive deeper into this subject, Kaspersky Labs and Arlington Research conducted an online survey, titled ‘Beyond 11%’, of 4,001 youngsters aged between 16 and 21 from countries like the UK, U.S., France, Germany, Italy, Spain, Israel, and Netherlands.

The study pointed out that nearly 72 percent of respondents had decided on their future career paths, where female respondents dominated their male counterparts by a slight margin of three percent. “The average age at which young women have decided on their future career is fifteen years and ten months, and those that haven’t decided by this time expect to have made a decision by the age of twenty-one and nine months, making it very difficult for cybersecurity firms to influence their choices after this point,” the report pointed out. “This gives the industry a challenge as businesses only have a small window in which to attract young people, especially women, to a career in cybersecurity. Positioning it as a practical and worthwhile career choice across all channels of influence is clearly more important than ever. This suggests a need for young girls to have access to advice and information about the industry at a younger age so that they don’t rule it out in favour of more traditional professions such as lawyers, medics or teachers that have long-established career paths.”

One of the reasons cited by the study was the general lack of understanding of the subject. Most young women did not know what the employers are looking for, and if they had the right attributes. “The issue here is one of awareness, as companies today aren’t just looking for coders. Skills such as critical thinking and problem-solving are just as crucial to a career in cybersecurity, but the perception of the industry from the outside tends to focus primarily on the technical side,” the study pointed.

But arguably, the biggest reason was the lack of a role model. The problem here is the fact that men make up for a majority of key commenters and high-profile influencers. “Trade shows and industry events are also usually dominated by men, which might be another key turn-off point in the career path choice for young women. Most young people (69 percent) haven’t met anyone who works in cybersecurity at all and even fewer (11 percent) have met a woman working in cybersecurity. But when they have, their opinion of the role skyrockets, with 63 percent of women thinking more positively about cybersecurity after meeting someone who works in the sector. This clearly shows the power of role models in promoting the industry as a whole and how inspirational female personalities can be utilized to make cybersecurity a more attractive proposition for women and help to reduce today’s skills shortage.” Without someone to look up to, it is difficult for young women to roll into the alien territory of cybersecurity.

“The topic of women in cybersecurity has received more press in the past few years than ever before, and I think it’s possible for readers to assume that women working in this field are something new – it’s not,” Caroline Wong, Vice President of Security Strategy at app security company Cobalt, told Help Net Security in a recent interview. “Recent press coverage on the topic has a tendency to focus on the negative – underrepresentation, unfair pay, and challenges in the workplace. These aspects are true, however, I know there’s a story that’s just as true, and that’s how many women in the field are thriving. I personally know so many women – and now I have the data to back it up – that love their jobs, feel deeply satisfied with the work they’re doing, and are tremendously successful.”

Culprits behind massive Malaysian leak identified

Cyberattacks on Downtrend in Malaysia in Q4 2019: Kaspersky

The culprits behind the recent online breach in Malaysia which compromised data of nearly 46 million mobile phone subscribers have been identified. The details were revealed by the Inspector-General of Police (IGP) Tan Sri Mohamad Fuzi Harun at a press briefing recently.

The initial investigation has revealed that the leak could have happened during a data transfer with the involvement of a few insiders in an organization. According to Fuzi Harun, the firm where the miscreants worked has no part in the crime. “We have some leads pertaining to the case and we have identified those involved. Further action will be taken (against the alleged culprits).” He said. “I cannot confirm the source of the leak, but we have leads on how it happened. (It was) not (the work of a) syndicate.”

The sleuths are currently working with telephone operators to locate the source of the leak, but the motive behind the attack is yet to be established.

In late October, mobile phone numbers, identification card numbers, home addresses and SIM card data of 46.2 million customers of at least 12 Malaysian mobile phone operators were leaked on the grey market. The leak has been dubbed as the biggest breach the country has ever witnessed and may have involved the details of its entire population. But, considering the fact that Malaysian population is around 32 million, several listed mobile numbers may have been inactive or temporary phone numbers that may have been bought by foreigners who were visiting the nation.

It was also reported that the breached data also contained medical records of 81,309 persons that were stored in the databases of Malaysian Medical Council, the Malaysian Medical Association, and the Malaysian Dental Association.

The hack was first reported by Malaysian news site Lowyat.net. The site’s founder Vijandren Ramadass in an interaction with The Star stated that all the information was handed over to the Malaysian Communications and Multimedia Commission (MCMC). According to him, “Telcos need to admit that this breach actually happened and should inform all their customers what should be done.”

The initial investigation had revealed that the staff managing the date might have been negligent. Another startling revelation was that most victims found their MyKad numbers (a unique national registration identity card number) linked to unknown mobile phones. They found it on a verification website called sayakenahack.com. According to reports, nearly 50,000 Malaysians checked to see if their information was leaked during the breach.

75 percent UK law firms unprepared for GDPR

United Kingdom GDPR

According to a study constituted by CenturyLink Emea, nearly 75 percent of law firms in the United Kingdom are not ready for General Data Protection Regulation (GDPR). With just six months to go before the compliance deadline of 25 May 2018, a majority of the law firms are not ready to be fully compliant with the legislation. Here, the fine for non-compliance and failings to protect data under the GDPR is up to €20 million or four percent of annual global turnover.

The report indicates that one in five firms have suffered a cyber incident in last month, a rise of 44 percent over the last year. The report mentions Joanne Frears, Consulting Solicitor at Blandy & Blandy, challenging the finding that 34% of the companies claim they have never been the victim of an attempted cyberattack.

“The average length of time it takes to discover a cybersecurity breach is 196 days and so although it is easy to believe that almost half of all firms have suffered attempted cyberattacks, it is alarming to think that the 34% who claim to never to have been targeted, could simply be unaware that malware has been planted on their system or that perhaps one of their accounts staff is currently being spear-phished! This lack of awareness and preparedness is one of the biggest risks the profession faces,” Frears argues.

The study highlighted that only 31 percent of IT directors believed their firm was compliant with all cybersecurity legislation. Frears urges companies to fall in the line while there is still time. “With the advent of GDPR next May bringing greater record keeping and privacy by design obligations as well as the potential of fines for breach of €20million or 4 percent of annual turnover, those 75 percent of firms that admit they are not prepared [or don’t know if they are prepared] for these changes have a chance to get ready, but time is running out!” She also warns that Brexit will not provide a panacea for GDPR worries: “Perhaps most firms think Brexit is a cure for GDPR, without realising that unless the UK has robust data protection compliance equivalent to GDPR, it will not be able to provide or accept any personal information from EU businesses or EU citizens and most of the UK service and technology industries would fold as a result!,” she adds.

1,44,496 cyber attacks in India in the last three years

Thales

India has fallen victim to a staggering 1,44,496 cyber attacks in last three years. The data was tabulated by the Indian Parliament. According to the CERT division of India, as many as 44,679 cyberattacks were reported in 2014. By 2015, the number reached 49,455, and by 2016, the numbers crossed the 50,000 mark.

Citing concerns over the upward trend, Home Minister Rajnath Singh reviewed several measures and steps taken by the government to avert any cyber incident. He also extended his support to strengthen surveillance and legal framework of the country as well as explored methods to deal with financial frauds. This comes at a time when the country is moving toward making the nation a cashless economy.

One of the steps by the government plans to adopt is deploying big data analysis developed by Indian Institute of Technology Delhi for identifying the attackers. The move aims to prevent duplication of e-wallets, and keep the customers updated through SMS and email alerts.

The alert mechanism will include names of the beneficiaries “of any financial transaction wherever necessary for better traceability and cross-checking on the part of the victim, publishing online statistics depicting the specific incidents, frauds against of e-wallet companies and banks along with details including investigation to enable customers to make an informed choice before subscribing to e-wallet services are other initiatives being planned,” reads a PTI report.

To keep a tab on phone frauds, the government had recently constituted the Inter-Ministerial Committee on Phone Frauds (IMCPF). The home minister directed the department to analyze and study relevant regional case studies and also examine the issues in consultations with key stakeholders.

Nearly half of companies have suffered a data breach in the past year: Survey

DEO data breach

Radware, a provider of cybersecurity and application delivery solutions, released a new study today titled, ‘Radware Research: Web Application Security in a Digitally Connected World’. The report takes an in-depth look into how organizations protect their web applications, and identifies clear gaps in security among common DevOps practices, highlights top attack types and vectors, as well as identifies key areas of risk and concern.

The research, which focused on such highly targeted industries as retail, healthcare and financial services, exposes the proliferation of bot-driven Web traffic and its impact on organizations’ application security. In fact, bots conduct more than half (52 percent) of all Internet traffic flow. For some organizations, bots represent more than 75 percent of their total traffic. This is a significant finding considering one-in-three (33 percent) organizations cannot distinguish between ‘good’ bots and ‘bad’ ones.

The report also found that nearly half (45 percent) of respondents had experienced a data breach in the last year, and 68 percent are not confident they can keep corporate information safe. What’s more, companies often leave sensitive data under-protected. In fact, 52 percent do not inspect the traffic that they transfer to-and-from APIs, and 56 percent do not have the ability to track data once it leaves the company.

Any organization that collects information on European citizens will soon be required to meet the strict data privacy laws imposed by General Data Protection Regulations (GDPR).  These regulations take effect in May 2018. However, with less than a year until the due date, 68 percent of organizations are not confident they will be ready to meet these requirements in time.

“It’s alarming that executives at organizations with sensitive data from millions of consumers collectively don’t feel confident in their security,” said Carl Herberger, Vice President of Security Solutions at Radware. “They know the risks, but blind spots continue to pose a threat. Until companies get a handle on where their vulnerabilities are and take steps to protect them, major attacks and data breaches will continue to make headlines.”

According to Dr. Larry Ponemon, “This report clearly shows that pressure to continuously deliver application services limits DevOps’ ability to ensure web application security at various stages in the SDLC.”

Key Survey Findings Include:

Application security is an afterthought. Everyone wants the full automation and agility that the continuous delivery model of app development provides. Half (49 percent) of the respondents currently use the continuous delivery of application services and another 21 percent plan to adopt it within the next 12-24 months. However, continuous delivery can compound the security challenges of app development: 62 percent reckon it increases the attack surface and approximately half say that they do not integrate security into their continuous delivery process.

Bots are taking over. Bots are the backbone of online retail today. Retailers use bots for price aggregation sites, electronic couponing, chatbots, and more. In fact, 41 percent of retailers reported that more than 75 percent of their traffic comes from bots, yet 40 percent still cannot distinguish between “good” and “bad” bots. Malicious bots are a real risk. Web scraping attacks plague retailers by stealing intellectual property, undercutting prices, holding mass inventory in limbo, and buying out inventory to resell goods through unauthorized channels at markup. But bots are not the exclusive problem of retailers. In healthcare, where 42 percent of traffic is from bots, only 20 percent of IT security execs were certain they could identify the “bad” ones.

API security is often overlooked. Some 60 percent of organizations both share and consume data via APIs, including personally identifiable information, usernames/passwords, payment details, medical records, etc. Yet 52 percent don’t inspect the data that is being transferred back and forth via their APIs, and 51 percent don’t perform any security audits or analyze API vulnerabilities prior to integration.

Holidays are high risk for retailers. Retailers face two distinct but highly damaging threats during the holidays: outages and data breaches. Web outages during the holiday season, when retailers make most of their profits, could have disastrous financial consequences. Yet more than half (53 percent) are not confident in their ability to provide 100 percent uptime of their application services. High-demand periods like Black Friday and Cyber Monday also spell trouble for customer data: 30 percent of retailers suggest they lack the ability to secure sensitive data during these periods.

Patient healthcare data is at risk. Just 27 percent of healthcare respondents have confidence they could safeguard patients’ medical records, even though nearly 80 percent are required to comply with government regulations. Patching systems is critical to an organization’s security and its ability to mitigate today’s leading threats, but some 62 percent of healthcare respondents have little or no confidence in their organization’s ability to rapidly adopt security patches and updates without compromising operations. More than half (55 percent) of healthcare organizations said they had no way to track data shared with a third party after it left the corporate network. Healthcare organizations are particularly unlikely to monitor the Darknet for stolen data, with 37 percent saying they did so, compared to 56 percent in financial services, and 48 percent in retail.

Multiple touchpoints equal higher risk. The rise of new financial technology (like mobile payments) has increased the access and volume of engagement with consumers, which, in turn, increases the number of access points with vulnerabilities and expands the risk security executives face. While 72 percent of financial services organizations share usernames and passwords and 58 percent share payment details via APIs, 51 percent do not encrypt that traffic, potentially exposing valuable customer data in transit.

The survey, conducted by Ponemon Research on behalf of Radware, included responses from more than 600 chief information security officers and other security leaders across retail, healthcare, and financial services in six continents.

Optiv Security acquires Conexsys to expand presence in Canada

Google’s Project Nightingale

BUSINESS WIRE: Optiv Security, a provider of end-to-end cyber security solutions, announced that it is continuing to accelerate its growth strategy by acquiring Conexsys, a Toronto-based security and networking solutions provider. This acquisition increases Optiv’s ability to serve Canadian, U.S. and global clients with expanded skills, knowledge and presence. Additionally, Optiv enhances its vertical presence in government markets, with the strong business relationships Conexsys brings with the Canadian government. The transaction allows Optiv to serve private and public entities in Canada with more local resources and immediate access to Optiv’s comprehensive service offerings that help remove complexity, align the right technology and process to business needs, and optimize security investments to minimize cost and maximize protection. The terms of the transaction are not being disclosed.

“Many Canadian organizations have magnified their investment and focus on cyber security but are finding it increasingly challenging to protect against the sophisticated threat landscape,” said Cheryl McGrath, Optiv’s country general manager for Canada. “Canadian companies need the right expertise from a partner that can bring clarity to the cyber security landscape, which can sometimes feel chaotic and complex. Together, Optiv and Conexsys provide expansive local coverage in Canada to help organizations navigate a myriad of products and technologies, and evaluate their infrastructures and operations to develop safer, saner and more strategic paths forward.”

“Conexsys has been committed to serving the Canadian government and large Canadian companies with exceptional technical expertise and high-quality services for more than 30 years,” said Michael Yassin, president of Conexsys. “By joining Optiv, we are gaining access to a number of holistic service offerings that enable us to perform comprehensive security optimization—from strategy and planning straight through to implementation and management. We are very excited about this transaction and what it allows us to bring to the Canadian market.”

WeirFoulds LLP and Holland & Hart LLP served as legal advisors to Optiv on the transaction.

IS’s “unhackable” news site hacked by Muslim hactivists

IS

Hours after the terrorist Islamic State (IS) claimed it was unhackable, Muslim hacking collective called Di5s3nSi0N hacked into the network and published a list of almost 2,000 subscribers’ email addresses. This has come as one of the latest blows to the online caliphate. For the hacker collective, it was just another ‘Challenge accepted’ scenario.

Within three hours after the terrorist wing claimed that its news site Amaq had spruced up its security, the subscribers received a mail which read, “We have hacked the full ‘secure’ email list for Amaq,”. Adding “Daesh…shall we call you dogs for your crimes or snakes for your cowardice? We are the bugs in your system.”

Di5s3nSi0N activists took to Twitter and wrote “Challenge complete – too easy! 2,000 email subscribers hacked from Amaq…what is next?”  The email contained a list of 1,784 subscribers’ email addresses, which were partly verified by The Independent.

Di5s3nSi0N is one among several hacktivist groups that have responded to hacking attacks by pro-Islamic State groups using hashtags #silencetheswords, #OpIsis, and #OpIceIsis.

Robert Hannigan, former GCHQ head while speaking at the FT Cyber Security Summit Europe, had warned that “We know individuals in groups like Islamic State, mostly because they are young men, love the idea of destructive [cyber] attacks, but are a long way from having the capability. But, as always with terrorism, intent and capability will meet at some point, so businesses, particularly CNI [critical national infrastructure providers], have got to ensure they are protected against this kind of attack before then.”

Cybersecurity experts hack Apple’s face ID

apple face id

The much-touted facial recognition feature from Apple is now drawing, even more, flak than it did around the launch date. A cybersecurity firm has claimed that it has tricked the Face ID into unlocking the device using a specially developed mask which imitated the face of a real person. Thus, testifying that the feature is not as secure as Apple had claimed it to be.

The Vietnam-based security firm Bkav also released a video showing how the $150 mask can bypass the security feature. Ngo Tuan Anh, Bkav’s Vice President of Cyber Security, stated in a statement, “The mask is crafted by combining 3D printing with makeup and 2D images, besides some special processing on the cheeks and around the face, where there are large skin areas, to fool AI of Face ID”.

When asked, how similar experiments from publications like WIRED failed where Bkav succeeded, he said, “We are the leading cyber security firm 😉 It is quite hard to make the “correct” mask without certain knowledge of security. We were able to trick Apple’s AI, as mentioned in the writing, because we understood how their AI worked and how to bypass it. As in 2008, we were the first to show that face recognition was not an effective security measure for laptops.”

Commenting on the dimensions of a person’s face, and how would those be obtained without a target sitting for them, he elaborated, “The first point is, everything went much more easily than you expect. You can try it out with your own iPhone X, the phone shall recognize you even when you cover a half of your face. It means the recognition mechanism is not as strict as you think, Apple seems to rely too much on Face ID’s AI. We just need a half face to create the mask. It was even simpler than we ourselves had thought. Apple has done this not so well. I remember reading an article on Mashable, in which Apple told that iPhone X had been planned to be rolled out in 2018, but the company then decided to release it one year earlier. This shows that they haven’t carried out scientific and serious estimation before deciding to replace Touch ID with Face ID.”

He continued, “The second point is, in cyber security, we call it Proof of Concept, which is useful for both sides, the hackers and the users. The hackers, they can find out a simpler way to exploit users’ device based on such PoC. While with users, if they know about such possibility, they will not use the feature to keep themselves safe. Just like the KRACK attack, it is not easy to be successfully exploited but users are urged to update the patch ASAP, because the threats are real. With Face ID’s being beaten by our mask, FBI, CIA, country leaders, leaders of major corporations, ect. are the ones that need to know about the issue, because their devices are worth illegal unlock attempts. Exploitation is difficult for normal users, but simple for professional ones.”

Earlier, the United States Senator Al Franken had written to Apple CEO Tim Cook citing concerns on privacy and security of the users. Franken, a ranking member of the Senate Judiciary Subcommittee on Privacy, Technology and the Law, in a wordy letter addressed to Tim Cook pointed out, “While details on the device and its reliance on facial recognition technology are still emerging, I am encouraged by the steps that Apple states it has taken to implement the system responsibly.” He continues, “However, substantial questions remain about how Face ID will impact iPhone users’ privacy and security, and whether the technology will perform equally well on different groups of people. To offer clarity to the millions of Americans who use your products, I ask that you provide more information on how the company has processed these issues internally, as well as any additional steps that it intends to take to protect its users.”