Home Blog Page 386

Saudi Arabia sets up National Cyber Security Authority

Riyadh

In an effort to strengthen and enhance its cybersecurity infrastructure, Saudi Arabia on October 31, 2017 established a new authority to combat cyber threats. Country’s minister of state Dr Musaed al-Aiban has been appointed as the chairman of the board of directors, a royal decree announced by the Custodian of Two Holy Mosques King Salman said.

Members of the board of newly-set up National Cyber Security Authority (NCSA) will comprise of the head of state security, the head of general intelligence, the deputy interior minister and, assistant to the minister of defense, Saudi Press Agency reported.

“NCSA has been created to boost cyber security of the state, protect its vital interests, national security and sensitive infrastructure and it will be linked to the monarch”, it reported.

While thanking the King and Crown Prince Muhammad Bin Salman, Al-Aiban said that the authority will give top priority to attract and hire qualified national cadres, build partnerships with public and private entities, and stimulate innovation and investment in cybersecurity to contribute for achieving a technological renaissance that serves the future of the Kingdom’s national economy.

As Saudi Arabia has been a victim of frequent cyber attacks in the past, the NCSA will improve protection of networks, information technology systems, and data. In 2012, Saudi Aramco, the world’s largest oil company was targeted by the Shamoon virus, a disk-erasing malware. In 2016, Saudi Arabia witnessed a slew of cyber attacks that had a huge impact on its government agencies and private sector companies.

In September this year, Saudi Arabia, which is believed to be one of the most vulnerable nations to cyber attacks, featured in the list of “Top 10 target countries”, in a report led by an Israel-based multinational cybersecurity firm Check Point Software Technologies Ltd.

Germany-based Continental to acquire Israel’s Argus Cybersecurity: Reports

FireEye Acquires Respond Software

Germany’s Continental, the world’s second-biggest supplier to carmakers by sales is all set to acquire Israel-based Argus Cybersecurity, media reports claimed on October 30, 2017. However, neither Continental nor Argus has made any official announcement about acquisition deal.

According to Israeli media reports, Continental is in advanced stage of negotiations to acquire Argus between $300 million to $400 million. Earlier this month, Argus jointly launched a technology for delivering over-the-air vehicle software updates with the Continental subsidiary Elektrobit.

Meanwhile, contradictory to media reports, Argus spokeswoman was quoted saying as “this is not the first time such rumors have circulated and Argus does not comment on rumors or speculation.”

Hannover-based Continental hasn’t yet commented on these speculations.

Founded in 2013 by three veterans of Israeli Military Intelligence vaunted 8200 technology unit, Argus has raised $30 million. It is headquartered in Tel Aviv, with offices in Detroit, Silicon Valley, Stuttgart, and Tokyo.

Russian meddling in 2016 U.S. presidential election: Social media sites to testify

blockchain-based social media, Parental Consent for Minors, Iranian Facebook accounts

After being dismissive for almost a year, social media websites have finally acknowledged that Russia meddled in 2016 U.S. presidential elections. According to media reports, additional evidence of Russian activity on their services have been found during 2016 U.S. polls.

For instance, Facebook has claimed that a Russian group posted more than 80,000 times on its service between January 2015 to August 2017. Nearly 29 million Facebook users directly received its posts in their news feeds. The social networking company will disclose these numbers to the Senate Judiciary Committee on October 31, 2017.

Similarly, micro-blogging site Twitter plans to tell the committee that it has shut down 2,752 accounts linked to Russia’s Internet Research Agency, which is known for promoting pro-Moscow messages. Twitter also said that Russia-linked accounts posted 1.4 million election-related tweets from September 2016 to November 2016, nearly half of them automated.

Search engine giant Google is also set to testify at three hearings as part of congressional investigation of Russia’s meddling in the U.S. elections. Google mentioned in a blog that it found 18 YouTube channels hosting 1,108 videos with 43 hours of material, that got 309,000 views between June 2015 to November 2016.

After coming under constant pressure, all three firms have announced that they will verify identities of election-related ad buyers to ensure transparency.

North Korea hacked Daewoo Shipbuilding, took warship blueprints: South Korea lawmaker

South Korea

South Korea has alleged that North Korea hacked its Daewoo Shipbuilding & Marine Engineering Co Ltd and stole warship blueprints and unspecified submarines in April 2016. The investigative team hasn’t revealed whether the hacked data was sensitive and classified in nature.

On October 31, Kyung Dae-soo of the main opposition Liberty Korea Party told Reuters “we are almost 100 percent certain that North Korean hackers were behind the hacking and stole the company’s sensitive documents.”

South Korean newspaper Dong-A Ilbo reported “About 60 classified military documents were among the 40,000 hacked from the world’s biggest shipbuilder. The leaked documents contained information on construction technology, blueprints, weapons systems, and evaluations of the ships and submarines.”

A division under South Korea’s Ministry of Defense that monitors cybercrime-related activities uncovered the hacking incident after receiving a briefing about the investigation.

Meanwhile, Daewoo Shipbuilding is verifying the details of Kyung’s remarks. Recently, North Korean hackers carried out a cyber attack in Taiwan and targeted the global SWIFT messaging system.

Earlier this month, South Korean lawmaker Rhee Cheol Hee had alleged that North Korean hackers had broken into the South’s military network in September 2016, that contained a vast cache of highly classified military documents and sensitive data.

On Monday, North Korea reiterated that it had no role in the infamous ‘WannaCry’ ransomware that crippled computers worldwide including National Health Service (NHS) in England in May this year. It termed United Kingdom’s accusations as a “wicked attempt” to further tighten international sanctions against Pyongyang.

Loss of sales in U.S. would be less than 10 percent: Kaspersky

Eugene Kaspersky

Moscow-based multinational cybersecurity firm Kaspersky Labs CEO Eugene Kaspersky on October 27 said that recent hack claims would see a ‘single-digit’ drop in the U.S. sales this year. During an interview with Reuters, Kaspersky asserted saying “we’ve done nothing wrong.”

“We have zero, zero wrong connections, contacts or assistance to espionage agencies. Zero”, he said in an interview that was part of the Global Reuters Cyber Security Summit.

Kaspersky said he expected global revenue for his company to reach about $700 million in 2017, as compared to $644 million in global revenue in 2016.

“The loss of sales in the United States would be less than 10 percent. It’s because of this information war against our company, this is the main reason”, Kaspersky said. He also said that he has not visited the United States since 2015 because there are “more promising options in other nations.”

Anton Shingarev, Kaspersky Lab’s vice president of public affairs, told Reuters that “it is pretty much impossible to sell to the U.S. government these days, and we don’t have any plans to do that.”

He said the company was looking at switching its Washington-area subsidiary Kaspersky Government Security Solutions (KGSS) employees to different roles in the company, such as enterprise and intelligence service sales.

Kaspersky Lab repeatedly denied that it has any unethical ties to any government and said it would not help a government with cyber espionage or offensive cyber efforts. It also highlighted that more than 85% of its revenue comes from outside Russia. It maintains that it has no connection with Russian intelligence but it is registered with the Federal Security Service.

To restore people’s and government’s trust again, Kaspersky on October 23 allowed to have his company’s source code audited independently by internationally recognized independent authorities in the first quarter of 2018. As part of comprehensive transparency initiative, the firm plans to open three transparency centers across the U.S., Europe, and Asia by 2020.

North Korea behind ‘WannaCry’ NHS cyber attack: UK

The United Kingdom on October 27, 2017 claimed that it believes that North Korea was behind the devastating ‘WannaCry’ cyber attack in May this year. WannaCry malware that led to havoc across the world did grievous temporary damage to the network security of Britain’s National Health Service (NHS).

In a report on the attack, Britain’s National Audit Office said “NHS systems were the worst impacted as more than 20,000 appointments including cancer treatments were cancelled, roughly 600 general practitioners. and ambulances were forced to divert from hospitals. Around 81 hospital groups across England out of the total number of 236 were infected.

It said WannaCry attack could have been prevented by the NHS had it followed basic IT security best practice.

Security Minister Ben Wallace told BBC Radio “North Korea was the state that we believe was involved in this worldwide attack on our systems.”
“We can be as sure as possible – I can’t obviously go into the detailed intelligence but it is widely believed ‘quite strongly’ in the community and across a number of countries that North Korea had taken this role.”

“It’s a salient lesson for us all that all of us, from individuals to governments to large organizations, have a role to play in maintaining the security of our networks.”

In May, British National Cyber Security Centre (NCSC), a department of the Government Communications Headquarters (GCHQ) had said that APT Lazarus hacking group was behind the massive cyber attack.

Democratic People’s Republic of Korea (DPRK) has been denying the allegations that linked Pyongyang with the ransomware WannaCry cyber attack, calling it ‘ridiculous’.

Within a matter of days, WannaCry ransomware had infected more than 300,000 computers in 150 countries and demanded victims for ransoms starting at $300 to regain access to their machines.

23-year-old Marcus Hutchins, a British cybersecurity researcher, gained overnight fame with quick thinking in May when he helped curb the spread of the WannaCry ransomware attack that had crippled thousands of computers worldwide.

AIG to provide cyber insurance from Q1 2018

To ensure that customers are covered if they become victim of a security breach, the American International Group (AIG) on October 26 said it would include cyber coverage to its commercial casualty insurance during the first quarter of 2018.

On the sidelines of a cyber risk conference in New York, Tracie Grella, AIG’s Global Head of Cyber Risk Insurance said that “the change is part of AIG’s effort to shift from issuing policies that do not specify whether cyber losses are covered”.

“The insurance giant is in the process of reviewing all types of coverage it offers to gauge its exposure to cyber risk.”

“When you buy affirmative cyber coverage, you should be paying for it,” Grella said.

Amid mounting cyber risks, AIG unveiled a property policy in April that specifically includes cyber coverage.

McAfee halts government source code reviews: Report

U.S.-based cybersecurity McAfeee on October 26, 2017 said that it will no longer allow government source code to be reviewed. In an email to Reuters, McAfee spokeswoman said “the new McAfee has defined all its own new processes, reflecting business, competitive and threat landscapes unique to our space. This decision is a result of this transition effort.”

“McAfee ended the reviews earlier this year after spinning off from Intel in April as an independent company. The new policy would prohibit third-party entities, including Echelon, from doing reviews on behalf of governments.”

To ensure that no hidden “backdoors” exist in foreign-made software, reviews are required by Russian defense agencies and are conducted in secure facilities known as clean rooms.

In June this year, it was reported that McAfee was among several Western technology companies that had acceded in recent years to greater demands by Russia for access to source code.

Recently, Kaspersky Labs, that has been banned in the U.S., announced to allow its source code audited independently by internationally recognized independent authorities in the first quarter of 2018. As part of comprehensive transparency initiative, the firm plans to open three transparency centers across the U.S., Europe and Asia by 2020.

Same hackers may be behind BadRabbit and NotPetya malware: Security Researchers

BADRABBIT

Two days after it was reported that a malware called ‘BadRabbit’ targeted Ukraine, Russia, Japan, Turkey, and Bulgaria, security researchers at Cisco’s Talos unit on October 26 pointed out that NotPetya hackers are likely behind the same attack.

According to a report published in Reuters, Russia-based cyber firm Group-IB said the BadRabbit virus shared a key piece of code with the NotPetya malware that crippled businesses in Ukraine earlier this year. Technical indicators, who analyzed both attacks said there found similarities in the malware coding and hacking methods.

“BadRabbit bore some similarities with NotPetya as they were both based on the same malware, but large parts of code had been rewritten and the new virus distribution method was less sophisticated”, researchers said.

Researchers added that both BadRabbit and NotPetya employed same hacking tool called ‘Eternal Romance’, which is believed to have been developed by the U.S. National Security Agency before being stolen and leaked online in April. However, some experts have cautioned that this might be a trick to mislead investigators about their identity.

The Guardian reported that BadRabbit malware’s code has referred to the names of two dragons from Game of Thrones and the character Grey Worm.

In June 2017, Ukraine’s energy, telecommunications and financial sectors were targeted by a hacking group called ‘Black Energy’. It is suspected that Russia was behind carrying out NotPetya cyber attack, an allegation that it denies.

NSA hacking code lifted from a personal computer in U.S.: Kaspersky

Kaspersky

Moscow-based multinational cybersecurity firm Kaspersky Lab on October 25 said that it obtained suspected National Security Agency (NSA) hacking code from a personal computer in the U.S. During the review of file’s contents, a Kaspersky analyst discovered it contained the source code for a hacking tool later attributed to what it calls the Equation Group.

Kaspersky said it assumed the 2014 source code episode was connected to the NSA’s loss of files. The antivirus software-maker spokeswoman Sarah Kitsos was quoted saying as “we deleted the archive because we don’t need the source code to improve our protection technologies and because of concerns regarding the handling of classified materials”.

Another spokeswoman Yuliya Shlychkova told Reuters that removals of such uninfected material happen “extremely rarely.”

Meanwhile, Democratic Senator Jeanne Shaheen sent a letter to the Department of Homeland Security (DHS) acting Secretary Elaine Duke and Director of National Intelligence Dan Coats, urging the U.S. government to declassify information about Kaspersky products.

In October this year, the U.S. NSA contractor came under scanner, whose personal computer was equipped with Kaspersky anti-virus software and confidential details were shared with the Russian company. The unidentified NSA contractor had reportedly downloaded a cache of classified information from his workplace, even though he was aware of the consequences that moving such a classified and confidential data without approval is not only against NSA policy, but it also falls under criminal offence.

Kaspersky Lab repeatedly denied that it has any unethical ties to any government and said it would not help a government with cyber espionage or offensive cyber efforts. It also highlighted that more than 85% of its revenue comes from outside Russia. It maintains that it has no connection with Russian intelligence but it is registered with the Federal Security Service.

To restore people’s and government’s trust again, Kaspersky on October 23 allowed to have his company’s source code audited independently by internationally recognized independent authorities in the first quarter of 2018. As part of comprehensive transparency initiative, the firm plans to open three transparency centers across the U.S., Europe and Asia by 2020.

According to Wall Street Journal, it was reported earlier this month that hackers working for the Russian government appeared to have targeted an NSA worker by using Kaspersky software to identify classified files in 2015.

The New York Times reported on October 10 that Israeli officials reported the operation to the United States after they hacked into Kaspersky’s network.

Following allegations Russian hackers interfered in 2016 U.S. elections, the DHS had banned the Kaspersky Lab software in September 2017, citing concerns the company may be linked to the Kremlin and Russian spy agencies.