Home Blog Page 385

24% of UK employees maliciously misuse company emails: Research

Employees

A considerable number of Britain employees have maliciously and frequently leaked confidential information by misusing their workplace emails, an insider threat research has revealed. One in four employees has purposefully shared confidential business data outside their organization, a leading risk management and data privacy firm Egress Software Technologies said. The survey was conducted by OnePoll on behalf of Egress.

Around 2,000 employees were quizzed to ascertain email misuse within the organization. To cover up the blunder, 50 percent workers said they deleted emails from their sent folder if they forwarded information to any person they should not. 37 percent of them admitted that they sent wrongful mails even without checking or reading them.

One in ten out of those people who sent wrong information said they accidentally leaked sensitive attachments such as bank details or personal customer information, putting customers and organizations on risk. 40 percent of them even ended up insulting the recipient unknowingly by sending offensive jokes.

Research revealed that erroneous emails were also caused by human errors such as ‘haste’ and ‘liquor’. 68 percent of respondents admitted they sent wrong emails in hurry. Surprisingly, eight percent of employees have even sent wrong mails in the influence of alcohol. 42 percent of them blamed the auto select option for choosing wrong recipients.

Tony Pepper, the CEO and co-founder of Egress said “email is frequently misused by the UK workforce. While offending an accidental recipient may cause red faces, leaking confidential information can amount to a data breach. As we move towards the EU General Data Protection Regulation, it has never been more important to get a grip on any possible risk points within the organization and, as this research shows, email needs serious attention.”

To combat the email misuse menace, Egress has launched Switch Threat Protection that enable users from stopping emails being sent to the wrong people, correct misaddressed emails, and fix data breaches before they happen.

“Switch Threat Protection acts as an additional line of defense, helping employees and administrators spot and prevent potential breaches”, Pepper said.

iOS 11.1 hacked a day after release

iOS

Apple was left red-faced when its newly launched iOs 11.1 and Safari were reportedly hacked several times by security researchers at a hacking competition called Pwn2Own in Tokyo on November 1, 2017. The contest was conducted by Trend Micro and researchers from “Tencent Keen Security Lab” participated in it.

Dustin Childs of the Tipping Point-founded Zero Day Initiative said “they (white hat hackers) used a total of four bugs to gain code execution and escalate privileges to allow their rogue application to persist through a reboot.”

“It took them just a few seconds to successfully demonstrate their exploit, which needed only two bugs — one in the browser and one in a system service to allow their rogue app to persist through a reboot,” said Childs.

One of the fault that researchers managed to pick was related to newly discovered series called Key Reinstallation Attacks (KRACK) vulnerability in the Wi-Fi Protected Access II (WPA2) protocol.

Two critical vulnerabilities were found in Apple’s Safari web browser. The bugs earned the researchers $70,000 in awards.

Apple, that is fixing the patches, released iOS 11.1, the latest version of the iPhone and iPad operating system on October 31, 2017, with several new features, emojis, and security fixes including a patch for KRACK vulnerability.

Apple has been given 90 days to respond to the discoveries.

In September this year, a security researcher broke vulnerability for Apple’s new operating system, macOS High Sierra, on same day the software was released.

Kaspersky took inactive files in pursuit of hackers

Eugene Kaspersky

In an acknowledgement that could raise suspicion that Moscow-based multinational cybersecurity firm aids Russian spies, Kaspersky Labs CEO Eugene Kaspersky on November 3, 2017 admitted taking inactive files in pursuit of hackers.

In an interview conducted at Kaspersky Lab’s offices in Moscow, as part of Reuters Cyber Security Summit, Kaspersky said his company’s antivirus software has copied files that did not threaten the personal computers of those customers.

While claiming that “we did nothing wrong”, Kaspersky said “the files containing the National Security Agency (NSA) hacking tools were taken because they were part of a larger file that included suspicious software, a tool researchers dubbed GrayFish. Such actions occur only in very, very, very rare cases.”

Kaspersky explained that the NSA tools were copied because they were part of a larger file that had been automatically flagged as malicious and he had ordered the file to be deleted “within days” because it contained the U.S. government secrets.

“From time to time, yes, we have their code directly from their computers, from the developers’ computers. Sometimes we are able to catch cyber criminals, that’s why I am not so comfortable to speak about this to media. Many of them are very clever, they can learn from what I am saying” he said in the interview.

On October 25, 2017, it was reported that one of the Kaspersky analyst discovered it contained the source code for a hacking tool later attributed to what it calls the Equation Group.

To restore people’s and government’s trust again, Kaspersky on October 23 allowed to have his company’s source code audited independently by internationally recognized independent authorities in the first quarter of 2018. As part of comprehensive transparency initiative, the firm plans to open three transparency centers across the U.S., Europe and Asia by 2020.

Following allegations Russian hackers interfered in 2016 U.S. elections, the Department of Homeland Security (DHS) had banned the Kaspersky Lab software in September 2017.

Software security vendor Synopsys acquires Black Duck for $565 million

Acquisition

In a major deal, California-based Synopsys on November 2, 2017 acquired Massachusetts-based cybersecurity company Black Duck software for $565 million in cash. According to a press release, the deal is subjected to Hart Scott Rodino regulatory approval and other customary closing conditions, and is expected to be closed in December 2017.

Founded in 1986, Synopsys is the world’s 15th largest software company and it is renowned for selling electronic design automation (EDA) software that help customers design and test silicon chips. It claims to have generated more than $2.4 billion revenue in 2016 and with this deal, the firm is broadening its product offering and expanding its customer reach.

Since its inception in 2003, Black Duck, that underwent several transformations, has created a niche for itself by accumulating one of the most comprehensive databases of open-source code. Lou Shipley, who took over as Black Duck’s CEO and president in 2013, focused more on expanding cybersecurity domain by helping companies to find and fix vulnerabilities in the open-source components they use.

“It expected to generate around $75 million in annual revenue in 2017”, Shipley told Xconomy in August this year.  With no plans for layoffs, Shipley said that “vast majority of Black Duck’s roughly 400 employees, including him, will join Synopsys”.

Black Duck raised $74 million from investors including Intel Capital, Fidelity Ventures, SAP Ventures, General Catalyst Partners, next 47, and Red Hat.

Shipley further revealed that he will report to Andreas Kuehlmann, the senior vice president and general manager of Synopsys’s software integrity group. In a statement, Kuehlmann said “development processes continue to evolve and accelerate, and the addition of Black Duck will strengthen our ability to push security and quality testing throughout the software development lifecycle, reducing risk for our customers”.

British Telecom develops patent to protect Blockchain

BT

On October 31, 2017, the United Kingdom’s largest internet and telecoms provider British Telecom secured the patent for a proposed cybersecurity measure to protect Blockchain. The system enables users to process transactions via user-specific profiles that can be identified by the Blockchain’s underlying code.

The patent titled “Mitigating blockchain attack” reads “a computer implemented method for detecting malicious attacks presenting a threat to a blockchain associated with a blockchain data structure of a computing device comprising: defining by the computing device a transaction creation profile according to which transactions can be generated and submitted to the blockchain; submitting a transaction to the blockchain, the transaction causing the generation of a profiler data structure in the blockchain including executable code to generate profile transactions to be submitted to the blockchain according to the transaction creation profile; monitoring by the computing device the blockchain to identify profile transactions based on profile transactions submitted by the profile data structure generated in the blockchain; and comparing identified profile transactions with the transaction creation profile to detect a deviation from the transaction creation profile, such detection corresponding to a malicious attack occurring with respect to the blockchain.”

A part of the invention claims, “Despite the architecture of blockchain systems, malicious attacks present a threat to the security and reliability of blockchains. One such malicious attack involves a single entity (or entities under common control) procuring or appearing to procure sufficient computing resource to constitute more than half of all mining resource working with a blockchain.”

The patented system is said to be effective in protection of Blockchain against Distributed Denial-of-Service (DDoS) attack such as sending excessive data to a miner to overwhelm the miner such that it cannot process normal blockchain transactions. If user details and profiles of the pre-described accounts do not match, then Blockchain code will automatically dismiss the transactions being carried out.

Netherlands to hold referendum on controversial law in March 2018

Netherlands

Four months after the controversial referendum law was passed, the Netherlands is all set to hold a non-binding referendum in March 2018 over the legislation giving law enforcement authorities ‘mass-surveillance’ powers, the Dutch Voting Commission said on November 1, 2017.

As per a report published in Reuters, digital privacy advocates, activists, politicians, and media groups want to overturn the data-slurping “tapping law” which was passed by the Dutch Senate in July, after years of debate and allowed intelligence agencies to gather data en masse from large groups of people.

While emphasizing that the public referendum was ‘purely consultative’, the Dutch Electoral Council said that if more than 30 percent of the electorate vote in the favor and a majority oppose the law, the government would re-examine the proposal.

To hold the advisory referendum, the petition required at least 300,000 signatures to be submitted before the Voting Commission and the agency received more than 384,000 valid signatures. Now, the government is obliged to hold national referendum on March 21, 2018 along with the country’s municipal elections.

According to media reports, the controversial law may be repealed by the newly appointed government under Prime Minister Mark Rutte. The country’s opponents argued that the new law breaches civil liberties by granting authorities to tap into electronic communications of far more people.

This is not the first time when the Netherlands is forced to hold a referendum. In 2016, voters had rejected Dutch ratification of the European Union’s agreement with Ukraine.

Iran orchestrates thousands of cyber attacks daily on Israel military: Israeli General

Israel and Iran, Iran cyberattack, cyber war

Israel’s general incharge of network security said that his country’s military faces thousands of cyber attacks daily, mostly from Iran whose “hacking capabilities are improving”.

Speaking at the Reuters Cyber Security Summit in Tel Aviv on October 31, Major General Nadav Padan who heads the military’s command, control, computer, communications and intelligence (C4I) plus cyber division, said that Iran has mounted attacks on Israel with the help of proxies like Lebanese Shiite group Hezbollah.

“They are not the state of the art, they are not the strongest superpower in the cyber dimension, but they are getting better and better,” Padan told the news agency.

“As far as we know, nobody has been able to penetrate our operational systems”, Padan said while adding “sometimes when I see an Iranian tool, I can just observe it, control it and try to figure out its meaning. And other times I act very aggressively to block it.”

On October 24, 2017, Yigal Unna, the head of technology at Israeli prime minister’s cyber directorate said that Iran poses the greatest risk to the country’s cybersecurity. It was suspected that Israel and the U.S. had collaborated to create Stuxnet malware that crippled Iranian networks in 2010. Earlier this month, the U.S. President Donald Trump accused Iran of launching cyberattacks against the country’s “critical infrastructure, financial system, and military”.

Israeli hacking firm’s founders to launch ‘Orchestra’ in 2018

Candiru DevilsTongue

In an order to identify simpler ways of securing networks, Israeli hacking firm’s founders are reportedly moving to set up a new business to defend computer systems against cyber attacks. The new company will be known as Orchestra

Omri Lavie, a co-founder of cyber surveillance firm NSO Group, and investment partner Issac Zack, told the Reuters Cyber Summit that they would fund a new cybersecurity company that will look to derive simpler ways of defending a network.

In a joint interview to Reuters, Lavie and Zack said that the Founders Group has invested around $30 million over four to five years, using mostly the partners’ own money, in mostly seed or early-stage funding rounds for a mix of cyber security, Fintech and other start-ups.

“We are going to be developing ourselves a lot of the platform. We are also going to be merging a lot of technologies we currently own a part of or intend to own a part of,” Lavie said.

The chief executive of Orchestra will be Omri Lavie and the new firm will be launched in early 2018, subject to the closing of a new funding round. The firm will have offices including in Tel Aviv and in the eastern United States.

Orchestra will enter a market as Security Information and Event Management (SIEM) tools, which aggregate data from across computer networks to allow an organization’s security staff to keep tabs on their users, devices and systems.

Breach aftermath: Former Yahoo, Equifax CEOs to testify at Senate hearing

Yahoo data breach

After suffering from massive data breaches, the embattled Equifax and Yahoo former chief executive officers are all set to testify at the Senate hearing on November 8. According to reports, the former Yahoo CEO Marissa Mayer, and the Equifax interim CEO Paulino do Rego Barros Jr. and former Equifax CEO Richard Smith will appear before the Senate Commerce Committee about the massive data breaches at their firms.

Besides these three high-profile officials, Karen Zacharia, Verizon’s deputy general counsel and chief privacy officer will also appear for the hearing.

Frederick Hill, a spokesman for the Senate committee confirmed that Mayer, Barros and Smith would appear to testify.

On October 1, Republican Senator John Thune from South Dakota, who chairs the committee said “massive data breaches have touched the vast majority of American consumers. When such breaches occur, urgent action is necessary to protect sensitive personal information.”

A pair of influential US senators have sent a letter to then-Equifax CEO Rick Smith demanding details about the hack, including information about when authorities and board members were informed of the hack, CNET reported.

Equifax disclosed the enormous data breach on September 7 this year that affected 145.5 million of its customers. It is yet to schedule its first quarterly results report. The credit monitoring bureau has to release its results by November 9 otherwise it will have to seek an extension from the U.S. Securities and Exchange Commission.

Internet Service company Yahoo, that took three years to discover and disclose the breach, on October 3, 2017, revealed that all three billion of company’s accounts were compromised. Yahoo was hit by another enormous cybersecurity breach in late 2014 that impacted 500 million accounts and was disclosed in September 2016. Due to the severity of two cyber attacks, the U.S. telecom firm Verizon lowered its original offer to acquire Yahoo! by $350 million and finalized the deal at $4.48 billion in June 2017.

First time in India: Netizens to get insurance coverage against cyber crimes

cyber insurance

In an effort to provide a safe and secure experience for Internet and ecommerce users, the Bajaj Allianz General Insurance has come up with a cyber safe policy. It will be a first such initiative in India, as the policy enables netizens to buy insurance cover against cyber crimes including loss of funds to online fraud, identity theft, cyber stalking and extortion, phishing and malware attack, a news report said.

As per a report published in TOI, the policy can be purchased for a sum insured ranging from Rs 1 lakh ($1,548) to Rs 1 crore ($154,834). The firm has not revealed the premium schedule. The insurance will undertake transactions made using home devices or workplace devices except for those made at cyber cafes and suspected devices.

Apart from covering the financial losses, the insurance cover will also defend the policyholder by compensating the cost of legal defense, if a hacker posts controversial remarks on social media. Besides, it will also provide legal costs for proceeding against the perpetrator in cases such as stalking, phishing, and online frauds.

Tapan Singhel, MD & CEO of the company was quoted saying as “this cover is the first of its kind designed keeping in mind the changing risk profile of the consumer. A couple of decades ago the biggest risk was having your pocket picked. In this day and age covers against pickpockets do not help when the bigger risk is of cyber crime.”

“In today’s digital world, the amount of personal data being generated, transmitted, and stored on to various digital devices is growing. The critical nature of this data and the complexity of the systems that support its transmission and use have created a gamut of cyber risks.”

Currently, the Indian cyber insurance market is valued at Rs 30 crore ($4.65 million) and provides protection under the corporate and institution cover purchased by the bank and is not available to individuals.