Home Blog Page 390

Australian state Victoria appoints its first CISO

Victoria CISO

The Andrews Labor Government in Victoria on October 9, 2017 appointed John O’Driscoll as its first Chief Information Security Officer (CISO).

While making the announcement, Special Minister of State Gavin Jennings said, “John O’Driscoll’s extensive experience working across information technology and cyber security make him ideally suited to be Victoria’s first Chief Information Security Officer, as we seek to secure government services.”

“As organized crime and others become more sophisticated in hacking and disrupting digital services, it’s crucial government steps up to better protect our public services and information – John will help us do just that”, he said.

Having 20 years of experience, Driscoll is a former senior manager of information and technology risk at Australia and New Zealand Banking Group, where he worked till 2011. Prior to that, he held senior security positions at AMP and Commonwealth Bank of Australia.

In an attempt to protect government and public services from cyber threats, the Victorian government released a 23-point Cyber Security Strategy with five priority areas in August 2017. The strategy was first announced by the former Liberal government in November 2013, but it fell off the radar.

The Atlantic suffers phishing scam; at least 50 job seekers targeted

Atlantic magazine phishing

The Atlantic magazine recently became a victim of a massive phishing scam, in which job seekers and freelance journalists were targeted. The magazine staffers came to know about the scam on October 5, 2017.

In an email, Atlantic Media General Counsel Aretae Wyler wrote “Across the last few months, individuals posing as our editors and senior leaders have sent fraudulent job offers to unwitting freelancers or jobseekers looking to work with The Atlantic. The impostors have created numerous misleading email accounts, including gmail addresses in the names of editors, gmail addresses that include the Atlantic’s name (e.g., [email protected]), and addresses employing fake domains (e.g., @atlanticmediagroup.net).  The aim of the scam is to obtain personal information such as social security numbers, addresses, and bank account information from the intended victims.”

“The perpetrators have gone so far as to conduct job interviews by phone and gchat; to require signature on employment agreements, direct deposit, and tax forms; and to mail fake checks to individuals (in the hope that these “advances” would be cashed, thereby providing the perpetrators with bank account information and/or credit card information).  To date, we’ve been contacted by more than 50 would-be victims, and the names of at least six of our top editorial leaders have been used”, the press release further said. “Unfortunately, scams like this one are very common in today’s landscape.  We are actively working with law enforcement and are directing any intended victims to do the same.  We are also making information available about the scam on our websites and in the magazine.”

So far, at least 50 people have alleged that they ended up becoming a victim of Atlanta phishing scam. Meanwhile, Atlantic Media has put notifications on its site and magazine, and has also alerted law enforcement.

 

US NSA contractor under radar over pilferage; Russia denies involvement

NSA

Days after the U.S. Senate barred the federal agencies from using products from Kaspersky Lab, Russian hackers have reportedly stolen data from the country’s National Security Agency (NSA) contractor’s home computer, according to a Wall Street Journal report.

The contractor, who has not been named yet, reportedly downloaded a cache of classified information from his workplace and loaded it onto a personal computer at home, even though he was aware of the consequences that moving such a classified and confidential data without approval is not only against NSA policy, but also comes under criminal offence. His personal computer was equipped with Kaspersky Antivirus.

This is the third such incident, when an NSA employee has come under the radar of either exposing or leaking the classified information. The first case goes back to the high-profile and infamous case of Edward Snowden, who was accused of data theft in 2013 and second case is of the recent arrests of contractor Harold Martin and Reality Winner, who were accused of physically removing classified information from NSA facilities.

Following the pilferage, the federal government has already initiated the investigation. Some experts suspect that this leak may be directly linked to the mysterious Shadow Brokers group.

According to the WSJ report, “But how the antivirus system made that determination is unclear, such as whether Kaspersky technicians programmed the software to look for specific parameters that indicated NSA material. Also unclear is whether Kaspersky employees alerted the Russian government to the finding.”

While explaining NSA contractor’s machine compromise, Joe Stewart, a security researcher with Cymmetria, said, “Any time you’ve got a situation where software running on a machine has an update process, it can be compromised.”

Kaspersky denies wrongdoing

In a statement, Kaspersky Lab rejected the report and said, “Kaspersky Lab has not been provided any evidence substantiating the company’s involvement in the alleged incident reported by the Wall Street Journal on October 5, 2017, and it is unfortunate that news coverage of unproven claims continue to perpetuate accusations about the company. As a private company, Kaspersky Lab does not have inappropriate ties to any government, including Russia, and the only conclusion seems to be that Kaspersky Lab is caught in the middle of a geopolitical fight.”

The company statement further said, “The company actively detects and mitigates malware infections, regardless of the source.  Kaspersky Lab products adhere to the cybersecurity industry’s strict standards and have similar levels of access and privileges to the systems they protect as any other popular security vendor in the U.S. and around the world.”

In September 2017, the U.S. Department of Homeland Security banned the Moscow-based cyber security firm Kaspersky Lab, citing concerns the company may be linked to Kremlin and Russian spy agencies.

Deloitte hack: Iranian hackers lured firm’s employee via Facebook ‘honey trap’

Deloitte Acquires Zimbani to Boost its Cybersecurity Practice

It has been revealed that Iranian hackers were behind the major data breach at Deloitte, one of the ‘big four’ accountancy firms. They pulled it off via a seriously convincing fake Facebook post. The highly-active hacker crew known as OilRig, which is believed to be sponsored by the Iranian regime, created a “Mia Ash”, a fictional female to execute its plot.

The perpetrators reportedly penetrated into the systems way back in July 2016 after Mia’s puppeteers targeted a Deloitte cybersecurity employee, engaging him though the social network in conversations about his job, Forbes reported. The newly-found friendship between the Deloitte employee and his ‘virtual’ friend Mia Ash proved a disaster. She somehow managed to convince the Deloitte staffer to open a file purportedly containing some of her photos on a work laptop.

According to the sources, the malware illustrated the ability of the puppeteers to gain the employee’s trust. Mia Ash’s fake Facebook profile is full of alluring images and is convincing enough to gain the trust of an Asia-based cybersecurity professional. After sending messages on Facebook from July 2016 to February 2017, Mia Ash disappeared from the social networking site.

Sources revealed that the account only required a single password login that gave them “access to all areas” of Deloitte’s global email server. Earlier, Deloitte confirmed to Guardian that only a small number of its clients had been “impacted,” but KrebsOnSecurity later reported that all its administrator accounts and internal email system were compromised.

Meanwhile, Deloitte chose not to comment since the incident came to light. Apparently, the Mia Ash attack is different from the one on Deloitte data hosted on Microsoft’s Azure.

James Andrew Lewis, senior vice president at the Center for Strategic and International Studies (CSIS) questioned why the Deloitte employee was targeted and whether it was because of the entities he worked with rather than his role at the consultancy.

“In a couple instances the Iranians have been really clever: they don’t go after the primary target, they go after the secondary… the Deloitte guy might have been interesting only because of who he was connected to,” said Lewis.

Facebook security chief Alex Stamos said the social network would be taking more of a manual approach to dealing with fake personas set up with malicious ends in mind.

Cybersecurity continues to threaten CIOs: Survey

Cybersecurity governance

An annual global survey conducted on September 3, 2017, during Gartner Symposium/ITxpo in Ontario revealed that issues such as cybersecurity and Artificial Intelligence (AI) are in the priority list of CIOs. Ninety-five percent of CIOs surveyed believe that cyber threats are going to increase and impact their organizations in 2018, a CIO media release said.

The “2018 Gartner CIO Agenda” survey gathered data from 3,160 CIO respondents in 98 countries and all major industries. The results showed that 95 percent of CIOs expect their jobs to change or be remixed due to digitalization.

CIOs surveyed rank AI, followed by digital security and the Internet of Things (IoT), as the most problematic technologies to implement. The respondents agreed AI demands new skills. The survey also found that CIOs are spending more time on the business executive elements of their jobs compared with three years ago.

3,160 CIOs in 98 countries and all major industries, representing approximately $13 trillion in revenue/public sector budgets and $277 billion in IT spending, were part of the survey. Respondents were categorized as top, typical and trailing performers in digitalization said.

The survey found that growth is the top CIO priority for 2018, as reported by 26 percent of CIOs. At least 84 percent of top CIOs surveyed have responsibility for areas of the business outside traditional IT.

Seventy-nine percent of CIOs reported that digital business is making their IT organizations more “change-ready,” which suggests that now is a good time to implement change to the IT organizations, and, in turn, should make the transition to the new job of the CIO easier.

Seventy-one percent of the top performers have a separate digital team to help them scale their digitalization efforts.

Andy Rowsell-Jones, vice president and distinguished analyst at Gartner, said, “In response to these concerns, the survey found that digital security ranks high on the CIO agenda as 35 percent of respondents said they have already invested and deployed some aspect of digital security, and 36 percent are in the process of planning to implement some form of digital security.”

“CIOs are also increasingly adopting AI in their organizations. Predominantly, AI is being used initially, either to boost the customer experience or to fight fraud,” he added.

“The CIO’s role must grow and develop as digital business spreads, and disruptive technologies, including intelligent machines and advanced analytics, reach the masses,” said Rowsell-Jones.

 

More than one-third of UK SMBs not allocating cybersecurity budget: Survey

Even as cybersecurity remains one of the top threats, protection against the same is surprisingly not a major issue for UK-based small and midsized business (SMBs). Cybersecurity company Duo Security recently conducted a new research with YouGov and 1,009 senior decision makers across the UK were surveyed to determine how much they are spending on cybersecurity.

One of the objectives of the survey was to find out whether government initiatives such as Cyber Essentials and Cyber Risk Aware have been effective at protecting SMBs from cyber threats. The survey found out that 36 percent of UK small businesses are putting their online safety on risk by operating at or below the “security poverty line”.

This year, 38 percent of small businesses had spent nothing to protect themselves from cybersecurity threats, the survey revealed, while 30 percent of respondents said that less than 3 percent of their overall budget was allocated for cybersecurity.

Forty-five percent of respondents do not see themselves to be possible victims for hackers. Wendy Nather, Principal Security Strategist at Duo Security, said, “When an organization is IT-poor, it is subjected to a number of complex dynamics that keep it from implementing effective security. Simply lowering the price point on security products is not enough; they need expertise, resources, and influence on the vendors that supply their systems and software. Moreover, small businesses may not be able to tell whether they’ve been breached if they don’t have proper security monitoring in place; this prevents them, and us, from grasping the full scope of the problem.”

Information and technology governance needs more work: ISACA Research

Technology Governance

There is lot more to be done in information and technology governance, suggested a new research led by Information Systems Audit and Control Association (ISACA). In terms of overall governance, cybersecurity policies and defenses were cited as top corporate governance technological challenges.

The study further revealed that board of directors and team of leaders are emerging as chink in the cybersecurity armor. As a result, many leadership teams are increasing funding for cybersecurity and risk management programs.

Matt Loeb, CEO of ISACA, told Security Brief, “The boardroom must become hyper-vigilant in ensuring a tight linkage between business goals and IT goals, fully leveraging business technology to improve business outcomes while diligently safeguarding the organization’s digital assets”.

“There is much work to do in information and technology governance”, Loeb said, while adding “Committing to a boardroom with technology savvy and experience strongly represented provides the needed foundation for organizations to effectively and securely innovate through technology.”

Here are the survey findings:

  • 90 percent of surveyed business leaders agreed that strong technology governance contributes to improved business outcomes.
  • 69 percent reported that their leadership and board of director teams need to establish a clearer link between business and IT goals.
  • 55 percent of respondents said their leadership team and board are ‘doing everything they can’ to safeguard their organization’s digital assets and data.
  • 21 percent of senior leadership and boards are briefed on risk topics at every senior leadership meeting.
  • 33 percent of organizations assess risk related to technology use on a monthly or more frequent basis.
  • 48 percent will prioritize funding expansion in cyber defense improvements, more than the number that intend to significantly expand funding for digital transformation (33 percent) and cloud (27 percent).
  • 27 percent also intend to fund increases in spending for security consultants, while 25 percent are going to invest in upgrades to network perimeter defenses and 17 percent on cyber insurance.
  • 64 percent have already increased spending on risk management in the past year versus last year, while 33 percent intend to increase spending in enterprise risk management programs over the next 12 months.
  • When it comes to tackle internal cyber threats, 61 percent said the board or senior leadership team believes there is huge risk from both internal and external threats.
  • With no plans to increase funding for next year, 35 percent intended to invest in data security training for employees, while 15 percent on cybersecurity training for board members, and 21 percent on employee privacy training.

General Data Protection Regulation (GDPR) remains a problem

Thirty-two percent are satisfied with the progress they’ve made to prepare for GDPR, 35 percent are unsure about their progress, and 40 percent are taking a wait-and-see approach to see how GDPR will impact their organizations.

Top organizations with best technology governance

Out of over 150 companies, Microsoft, Google, and IBM emerged as the best companies doing an exemplary job of business technology governance.

Massive breach: Data of over 6,000 Indian companies affected

SideCopy Malware Campaign

In one of the biggest data breaches ever reported in India, Seqrite Cyber Intelligence, a unit of BSE-listed Quick Heal Technologies, on Tuesday, October 3, 2017, tracked a broadcast advertisement that claims to have “secret access” to database dump of over 6,000 Indian entities, including government agencies and private organizations.

Seqrite, along with its partner seQtree InfoServices, in a statement said it has “tracked an advertisement on DarkNet announcing secret access to the servers and database dump of over 6,000 Indian businesses.”

The affected organization has been identified as Indian Registry for Internet Names and Numbers (IRINN), which comes under National Internet Exchange of India (NIXI). In an email response to PTI, NIXI said, “The hacker has no capacity to cause any damage or initiate distributed denial of service to any entity who has been allocated Internet resources through IRINN System.”

Following this breach, security protocol has been further strengthened and review of existing infrastructure has also been initiated, NIXI said.

“We have alerted the government authorities well within time. If someone gets control over this massive data that is currently up for sale on DarkNet, the concerned organizations and enterprises can get affected,” Rohit Srivastwa, Senior Director, Cyber Education and Services at Quick Heal, was quoted in an IANS report.

The unidentified hacker has reportedly put up for sale the data of government organizations such as Unique Identification Authority of India (UIDAI), Defence Research and Development Organization (DRDO), Indian Space Research Organization (ISRO), Reserve Bank of India (RBI), Employees’ Provident Fund Organization (EPFO), State Bank of India (SBI), Bharat Sanchar Nigam Limited (BSNL), among several others.

Bombay Stock Exchange (BSE), Idea Telecom, Flipkart, Aircel, TCS, and ICICI Prudential Mutual Fund are some of the major Indian organizations which have been threatened by this massive data breach.

The seller has priced the information at 15 Bitcoins (around Rs 41.89 lakh). Researchers have suggested that the seller claims to have the ability to manipulate the IP allocation pool, which could result in a serious outage or Denial of Service (DoS) like condition.

“If the hacker gets an interested buyer, then an attack on the system could disrupt Internet IP allocation and affect Internet services in India”, Seqrite said.

Along with the access, the hacker is also selling credentials, Personal Identifiable Information (PII) and various contractual business documents and claims to have access to a large database of Asia Pacific Network Information Centre (APNIC).

To churn out more information from the seller, the Seqrite team posed as an interested buyer. During the inspection, the firm was able to get a list of 6,000 emails, that brought them to a conclusion that the affected organization was IRINN.

Cybersecurity firm Seqrite said that if the database was sold, then an attack on the system could disrupt Internet IP allocation and in-turn affect Internet services in India.

All 3 billion Yahoo accounts hacked in 2013 data breach, says Verizon

Yahoo

In December 2016, Yahoo had claimed that more than one billion accounts were compromised in the infamous 2013 breach. However, Verizon Communications that acquired Yahoo for $4.48 billion on Tuesday revealed that all three billion of company’s accounts were compromised, as it directs users to a site set up.

In a post titled, “Yahoo 2013 Account Security Update FAQs”, the company said, “Yahoo is providing notice to additional user accounts affected by an August 2013 theft of user data previously announced by the company in December 2016. This is not a new security issue. In 2016, Yahoo previously took action to protect all user accounts”.

Back in 2016, Yahoo had issued a statement saying, “The hack exposed user account information, which includes name, email address, hashed passwords, birthdays, phone numbers, and, in some cases, “encrypted or unencrypted security questions and answers”. However, the company’s investigation confirmed that credit card and bank account data was not hacked in the breach.

“Three billion figure included many accounts that were opened but that were never, or only briefly, used”, a Yahoo official said.

David Kennedy, chief executive of cybersecurity firm TrustedSEC LLC emphasized that “the investigation underscored how difficult it was for companies to get ahead of hackers, even though they knew that their networks had been compromised”.

Bitglass CEO Rich Campagna said, “Back when the breach was first disclosed, we noted that many large enterprises lack the necessary controls to limit unauthorized access. While this remains the case, a breach where virtually all Yahoo users are affected is unprecedented”.

Carl Wright, CRO at AttackIQ, termed the incident an “epic failure” and called for companies to “seriously, find protection failures before the adversary does”.

Lucy H Koh, a district judge in San Jose, California on August 30 ruled that Yahoo! will have to face action for a series of data breaches. According to company securities filing in May, Yahoo already faces at least 41 consumer class-action lawsuits in the U.S. federal and state courts.

 

More than 1,000 attacks reported to NCSC in 12 months, report says

data breaches, Verizon Data Breach Investigation Report

National Cyber Security Centre (NCSC), a part of the United Kingdom’s intelligence agency Government Communications Headquarters, recently revealed in an annual study that more than 1,000 cyber attacks were reported to the organization since October 2016. More than half of these incidents posed significant threats, according to the study. NCSC published the report on the occasion of its first anniversary.

As per the NCSC, 1,131 attacks were reported in the last 12 months out of which 590 were marked as significant and more than 30 were classed serious enough to attract government’s attention. The NCSC head Ciaran Martin warned of more cyber attacks in the near future.

Martin said, “The UK faces threats from across the globe on a daily basis and while we have brought together unprecedented expertise to defend the UK, it’s not a question of ‘if’ cyber attacks will happen, it’s a matter of when”.

“The NCSC’s first duty is to manage and mitigate against attacks. Our anniversary report shows the progress we have made working with government, industry and individuals to create a truly lasting national asset”, he added. “We are proud of what we have achieved in our first 12 months, but there is so much more to do in the years ahead to counter this threat to our values, prosperity and way of life.”

One of the biggest cyber attacks was the infamous “wannacry,” that hit 3,00,000 PCs worldwide and almost led to a global crash in the economy. The cyber attack on UK parliament was also mentioned in the report.