Home Blog Page 387

Post hack, Equifax yet to release 3rd quarterly results report

Equifax Settles Indiana Lawsuit Over Data Breach for $19.5 Mn

Equifax Inc. which is still recuperating after an enormous data breach that affected 145.5 million of its customers, is yet to schedule its first quarterly results report.

Equifax generally schedules its report by mid of every month but this time, it hasn’t announced a date to report its third-quarter earnings and management’s first conference call with Wall Street analysts.

As per a report published in Reuters, Equifax has to release its results by November 9 otherwise it will have to seek an extension from the U.S. Securities and Exchange Commission. SEC gives large companies 40 days after the close of a quarter to report their financials to investors.

Equifax’s shares crashed about 24 percent from September 7, the day it disclosed the massive breach to consumers and investors.

According to Thomson Reuters data, “the average analyst price target on the stock is now $124.62, down from $153.25 before the breach. Still, 11 of the 15 analysts who cover the company have a ‘buy’ or ‘strong buy’ recommendation on the stock”.

The cyber attack that took place between May and July of this year compromised personal data including customers’ names, social security numbers, addresses, credit card numbers, and other financial details that could be used by criminals to steal identities for financial gain.

Shortly after the hack, San Francisco Superior Court sued the credit reporting firm for failing to protect the personal data of 15 million Californian residents. The investigation into one of the worst cyber attack in history is underway. The hack took a major toll on Equifax as had to lose a fraud prevention contract worth $7.25 million with the Internal Revenue Service that it had been awarded on September 29.

Mobile messaging apps new hideout of Dark Web activities: Study

Messaging

After shutdown of illicit dark websites such as Alphabay and Hansa in July this year, criminals are trying messaging apps to evade crackdown, a report by security researchers on October 25, 2017, revealed.

Over the past 12 months, there has been a 30-fold increase in dark web activities using smartphone –based messaging applications such as Facebook, WhatsApp, Telegram and Microsoft, and Skype, Israeli threat intelligence software firm IntSights said in the study.

IntSights uncovered San Francisco-based ‘Discord’, a lesser-known, 2-year-old messaging app that has reportedly emerged as a hub of dark web discussions, with several links of criminal forums. The firm identified 9,046 dark web invite links sent via ‘Discord’ by criminal groups run from Brazil and one in Turkey. Criminal groups use ‘Discord’ 20 times more than WhatsApp in India, Brazil and Nigeria while 30 times more than Skype in Brazil.

Meanwhile, ‘Discord’ spokeswoman said the company had not seen the report but would consider responding once it had.

“Today’s black market is accessible more than ever, with the tap of a finger over a portable pocket-held device. This could prove to cause a proliferation of low-level cyber crime, that is conducted by less qualified perpetrators”, the study said.

During an interview at the Reuters Cyber Summit in Tel Aviv, IntSights co-founder and chief product officer said “cyber crime is a commodity today. Anyone can do it.”

The findings of the study were based on data scraped from black markets, document dump sites, hacker forums, chat channels, messaging apps, and social media pages over the 12 months ending in July 2017. It used the number of invitation links into dark web discussions as a proxy for how active criminals were across different messaging platforms, Reuters reported.

In July 2017, the attorney general of the United States, Jeff Sessions, announced the shutdown of two dark web marketplaces, AlphaBay and Hansa. Alexandre Cazes, the founder of AlphaBay, who was arrested in Thailand, apparently committed suicide within a week of being taken into custody.

Servers for Hansa were seized in Lithuania, the Netherlands, and Germany under the coordination of the Dutch National Police.

Israel sees cyber threat from Iran ahead of elections, says senior official

Israel

Israel is taking measures to prevent any incident of cyber attack during next general elections. On October 24, 2017, a senior cybersecurity official said that Iran poses the greatest risk to the country’s cybersecurity.

Yigal Unna, head of technology at the Israeli prime minister’s cyber directorate at Reuters Cyber Security Summit in Tel Aviv said “we are on the way to identifying and assisting from a distance everywhere we find or identify as a vulnerability … and make it tougher for the bad guys to hack.”

Unna, who earlier headed cyber defense at the Israel Security Agency, also known as Shin Bet revealed “we see a growing threat coming from Iranian cyber. They are a threat not just to Israel but to Saudi Arabia, Egypt and others” while also pointing suspicion needle towards North Korea.

“If there is an independent group that launches attacks against national assets then I automatically suspect it’s not really an independent or private group. It’s no secret we see Iranian efforts through all measures you can imagine to attack, to engage, to cause trouble in Israel.”

Unna further said that Israel also faces cyber threats from Lebanon-based Shia Islamist militant group Hezbollah.

Noting that Israel does not wait for hackers to strike, Unna said his country deploys active defense and uses hacking to counter potential attacks. Notably, since 2002, Israel hasn’t suffered from any cyber attack.

“We are trying to make the hackers’ nightmares come true”, Unna concluded.

Israel’s general elections are slated to be held in 2019. With less than 6 million voters, Israel still uses paper ballots and that’s why it is less concerned about hacking attempts on polling stations. Rather, the country is more worried about dissemination of fake news and smear campaigns.

Microsoft drops lawsuit against the US government after amendments in ‘gag orders’

Brand Phishing Attacks

Tech giant Microsoft recently announced that it will drop a lawsuit against the U.S. government after the Department of Justice (DOJ) changed data request rules on alerting Internet users about agencies accessing their information. The lawsuit filed in April 2016 alleged that the government was violating the constitution by preventing the company from informing its customers about government requests for their emails and other documents.

In a blog, Microsoft Chief Legal Officer Brad Smith wrote that the new policy limits the use of secrecy orders and calls for such orders to be issued for defined periods.

“In response to concerns that Microsoft raised in a lawsuit we brought against the U.S. government in April 2016, and after months advocating for the United States Department of Justice to change its practices, the Department of Justice established a new policy to address these issues. This new policy limits the overused practice of requiring providers to stay silent when the government accesses personal data stored in the cloud. It helps ensure that secrecy orders are used only when necessary and for defined periods of time. This is an important step for both privacy and free expression. It is an unequivocal win for our customers, and we’re pleased the DOJ has taken these steps to protect the constitutional rights of all Americans.”

“Until now, the government routinely sought and obtained orders requiring email providers to not tell our customers when the government takes their personal email or records. Sometimes these orders don’t include a fixed end date, effectively prohibiting us forever from telling our customers that the government has obtained their data.”

The lawsuit was filed in a federal court in Seattle came after the U.S. congressional panel voted unanimously to advance a package of reforms to the Electronic Communications Privacy Act (ECPA).

 

 

‘BadRabbit’ malware hits Ukraine, Russia, and other nations: Reports

BADRABBIT

On October 24, 2017, Ukraine, Russia, Japan, and Bulgaria were hit by a wave of cyber attacks. Reuters reported that Ukraine’s Odessa airport and metro system in Kiev were targeted by a malware called “BadRabbit” and prompted state-run Computer Emergency Response Team (CERT) to ask transport networks to be on alert. However, country’s banking services remained unaffected.

Ukraine government, that suffered a major cyber attack early this year, was reportedly warned of this strike on October 13.

In a statement, CERT-Ukraine said “We ask the owners of telecommunication systems, other information resources, transport infrastructure first of all, as well as ordinary internet users, to comply with stricter cyber security requirements.”

Kiev metro system reported that its payment system was attacked while Odessa airport said it had to delay some flights, as it beefed up its security arrangements.

“We report that the IT system of Odessa international airport has been hit by a hacker attack. All services of the airport are working in a stricter mode,” the airport said in a statement.

Ukraine suspects that its neighbor Russia is behind these cyber attacks and is planning to draft a national strategy to overcome such attacks and to keep major institutions and companies safe.

Russia’s one of the largest news agency, Interfax was affected, as its services were unavailable to subscribers. Two more media outlets of Russia were targeted but their names were not disclosed.

The country’s cybersecurity firm Kaspersky Lab said it was investigating to see whether ‘BadRabbit’ was related to NotPetya virus, that previously targeted Ukrainian government agencies.

According to cyber firm ESET, Russia, Ukraine, Bulgaria, Turkey and Japan were targeted in the latest cyber attack. Meanwhile, the U.S. Department of Homeland Security issued a warning on ‘BadRabbit’ malware advising citizens to report any infections to the Federal Bureau of Investigation through the government’s Internet Crime Complaint Center.

New norms likely for India’s power grid to avoid cyber attacks: Report

India

To address cyber crimes, the Indian government is trying to protect imported power equipment. To avert cyber attacks on electricity grids, tough measures such as multiple checkpoints will be deployed to ensure that equipment imported for the domestic power distribution sector is not vulnerable to cyber attacks.

A senior government official was quoted saying as to Economic Times “government will lay down product-wise technical specifications and regulations to ensure that only audited and tested equipment are connected to the electricity grid. The country neutral regulations will help local industry.”

“The Central Electricity Authority will lay down testing standards and procedures for cybersecurity compliance and it will also amend the regulations so that only authentic equipment is installed in the grid.”

The government also plans to develop a testing facility for cybersecurity where sourced equipment can be tested for malware before installation and periodically after commissioning.

The domestic electrical equipment industry has earlier raised concerns over contracts given to Chinese companies for installation of supervisory control and data acquisition systems (SCADA) for power distribution, as they can tamper with the system.

In the past, foreign power equipment companies have bagged contracts for implementation of SCADA in states such as Rajasthan, Madhya Pradesh, Tamil Nadu, and Puducherry. Once implemented, these new norms would give limited access to foreign players.

According to media reports, Central Electricity Authority has been planning to draft a roadmap for securing India’s power stations and smart grid systems against cyber attacks.

I cannot change my origin: Eugene Kaspersky

Eugene Kaspersky

The row between the U.S. government and Kaspersky Lab seem to have reached a culmination. Eugene Kaspersky, the founder of Kaspersky Lab, has chosen to stick to his roots and origin and doesn’t plan to move the Moscow-based firm out of Russia. “I cannot change my origin or my company’s foundation,” he told The Hill in an email interaction. “If we moved we would probably still be referred to as ‘the Russian cybersecurity company,’ even though more than 85 percent of our sales and operations are outside of Russia.”

“I get it — it’s not popular to be Russian right now in some countries,” Kaspersky in the interview.

He also cited concerns of finding the apt talent outside Russia. “Skilled computer engineers are challenging to find and Russia has very experienced computer engineers — this is our natural competitive advantage over other cybersecurity vendors.”

According to the statement, the only condition in which he would move out Russia was if he was forced to take part in offensive hacking operation. “It’s clear the steady stream of leaks to media was intentionally designed to damage our reputation without providing us with any real opportunity to address any concerns,” he said. “We want to make sure that our customers have the best cybersecurity protection available, so we ask — if anyone has any real proof or information that my company’s systems may have been exploited, please provide us with this information,” he said.

This comes after the U.S. Senate proposing a federal ban against Kaspersky Lab products citing concerns the company may be linked to Kremlin and Russian spy agencies. “The department is concerned about the ties between certain Kaspersky officials and Russian intelligence and other government agencies,” the directive said. “The risk that the Russian government — whether acting on its own or in collaboration with Kaspersky — could capitalize on access provided by Kaspersky products (in order) to compromise federal information and information systems directly implicates US national security.”

Senator Jeanne Shaheen in a statement had stated that. “Americans were outraged by Russia’s interference in our presidential election, but a wider threat is Russia’s doctrine of hybrid warfare, which includes cybersabotage of critical American infrastructure from nuclear plants to electrical grids. Kaspersky Lab, with an active presence in millions of computer systems in the United States, is capable of playing a powerful role in such an assault. It’s time to put a stop to this threat to our national security.”

Following which Eugene Kaspersky offered to testify before the U.S. Department of Defense with the source code of the company. “I do understand why we look strange. Because for Russia it’s very unusual, a Russian IT that’s very successful everywhere around the world. But it’s true,” he had stated in an earlier interview.

“I am an engineer trying to save the world from cyber threats. That is my only concern and priority,” he concluded.

Ghana to establish a national cybersecurity center

Ghana

The government of Ghana is mulling on establishing a national cybersecurity center to safeguard the nation against cybercrime. According to the President Nana Akufo-Addo, the nation is making leaps in terms of digital addressing system, e-payments, digital financial services and several other e-governance initiatives. Lack of a cybersecurity wing may mean that the infrastructure may completely come to a halt post a cyber incident.

“Ghana cannot fully reap the digital dividends, associated with her adoption of ICT as a means of our socio-economic transformation if the country fails to mitigate both existing and emerging cybersecurity threats,” stated the president while talking at the inauguration of National Cyber-Security Week and National Cyber-Security Inter-Ministerial Advisory Council, at the Accra International Conference Centre.

The government preparing compliance policies and are undertaking several measures including capacity building, judicial enforcement of cybercrime legislation, and implementation of technical standards. The president, earlier this year, had also instructed Ursula Owusu-Ekuful, the minister for communications to oversee the very same project. “This has led to our adoption of a multi-stakeholder approach, as a foundation for the effective implementation of the various cybersecurity activities and programs. The National Cyber Security Technical Working Group (NCSTWG) and the National Cyber Security Inter-Ministerial Advisory Council (NCSIAC) would be the critical drivers of our effort,” he said.

The government has partnered with United States government and the European Union to take the mission forward. “We will also engage with international institutions and technology partners, such as International Telecommunication Union (ITU), the Commonwealth Telecommunications Organisation (CTO), Google, Facebook, and Microsoft, to ensure cyber safety for our citizens, especially children,” he said.

“We also intend to improve the forensic capabilities of the Criminal Investigation Department (CID) and other law enforcement agencies, including the Economic & Organized Crimes Office (EOCO), to enable officers to investigate and prosecute cyber-facilitated crimes,” the President said. “To improve our cybersecurity emergency response readiness, government, through the Ministry of Communications, is currently working on the establishment of a dedicated Computer Emergency Response Team (CERT), to protect critical national information infrastructures, and sectorial CERTs for the various sectors of the economy, based on international standards and benchmarks.”

He assured that before the year-end, the government will get cabinet approval for the establishment of the center.

‘Absent’ Trump’s cybersecurity official invites subpoena threat from Senator McCain

zero-trust, Counter-Ransomware Meeting , Biden Administration and Tech Giants

Senior Senator from Arizona John McCain on October 19 suggested that Senate Armed Services Committee chaired by him may consider issuing a subpoena to make a White House’s top cybersecurity official testify. McCain’s warning was a result of the non-availability of Rob Joyce, the White House cybersecurity coordinator. Joyce failed to appear before the committee hearing to discuss cyber threats facing the US, that led to exasperation among lawmakers in both the parties.

Republican McCain countered that the absence was a “misinterpretation” of the president’s executive authority to have private counsel. Other Senators also indicated that more coordinated efforts are required to combat growing cyber threats.

McCain, the committee’s chairman said “Joyce’s absence here, whose job it is to do all this, is an example of the disarray in which this whole issue rests.” While accusing the Defense Department of deflecting responsibility for certain cyber-related threats, McCain said “It’s the Department of Defense’s job to defend this nation; that’s why it’s called the Department of Defense.”

Chris Krebs, who joined the Department of Honeland Security (DHS) 8 weeks back, was present at the hearing told McCain “I share your frustration and I think we have a lot of work to do.”

Angered McCain further said “well, when the coordinator doesn’t show up for a hearing, that’s not an encouraging sign.”

Democrat Senator Bill Nelson from Florida urged McCain to consider a subpoena to compel Joyce to appear, Reuters reported.

In a statement, a White House spokesman said it has been “longstanding practice” of presidents of both parties to not make White House advisers available for congressional testimony.

“This practice is rooted in the separation of powers and in the confidentiality interests of the executive branch. Officials from relevant departments and agencies are available to accommodate the committee’s legitimate oversight needs without violating the confidentiality interests that attach to White House staff”, the spokesman added.

Organized cyber crime originates from Eastern Europe, says NCSC CEO

GCHQ

Britain’s cybersecurity agency National Cyber Security Centre (NCSC) CEO Ciaran Martin on October 21, 2017 revealed that Northern Ireland infrastructure has been hit by “significant” online attacks from hostile nations.

43-year-old Omagh-born Martin made the revelation on a two-day visit to Belfast, during which he briefed the permanent secretaries of Stormont departments and delivered a speech at Queen’s University.

In an exclusive interview with Belfast Telegraph, Martin, who was serving as Government Communications Headquarters’ director general for cybersecurity said “Attacks on critical infrastructure are going to happen – what’s important is that they can’t do as much harm as they might otherwise do.”

He said “The risk is there, I don’t want to over-hype the risk, but in a digital economy like Northern Ireland, there are critical systems – the National Health Service (NHS), there will be power grids and so forth – so part of our job is to help the owners of those networks and make sure that if there is a large-scale very serious attack that it can only do a certain amount of damage and it can’t paralyze the system. Part of the NCSC’s job is, over time, to build in that resilience into the system so that large-scale damage is less likely.

“So a very serious attack is possible. I wouldn’t say it’s statistically more probable or less probable that it would happen in Northern Ireland than England or the Republic or somewhere else. What I would say with high confidence is that there is an everyday risk to the economy here from that sort of low sophistication, but highly prolific, set of attacks. There is always the potential for a very serious attack, and certainly at a UK-wide level I think we expect a ‘significant scale attack’ in the next few years.”

Martin also said that such organized cyber crime network originates from Eastern Europe, particularly Russia.