Home Blog Page 397

Thailand ranked among top 20 nations focusing on cybersecurity

According to the latest Cybersecurity Maturity Index, Thailand is now ranked among the top 20 nations focusing on cybersecurity. With the growth of its cyber economy and continuing expansion of devices linked to the Internet of Things (IoT), Thailand continues to take steps to manage information security. The survey was conducted by RSA, a U.S. provider of security software solutions.

Leonard Kleinman, the chief cyber security adviser for RSA, said Thailand is in a good position to deal with the increased risk that its cyber growth will create. Kleinman praised Thailand’s leaders for putting cybersecurity “on their national agenda.” He added that creating such a culture of prioritizing cyber issues will help Thailand attract and retain professionals in the cybersecurity field, which is facing a significant global shortage of workers.

According to Kleinman, a two-level strategy is important, with both exceptional professionals working the trenches in “a methodical manner” and a cadre at the leadership level who manage “the overall security strategy.”

RSA partners with educational institutions and governments to create strategies for increasing network and information security. In nearby Singapore, RSA is in partnership with Temasek Polytechnic and Republic Polytechnic to create training programs that lead to a Diploma of Cybersecurity and Digital Forensics. The goal is for students to enter the field as Level 1 and 2 Analysts or Cyber Security Operations Centre Managers.

Kleinman is a strong advocate of cybersecurity awareness being an aspect of core education curriculum, since it’s an issue that will not be going away and is simply a permanent aspect of the Internet. He believes cybersecurity should be embedded in high school computer courses and perhaps be a required topic at the college level.

He points out that many universities around the world are now offering cybersecurity courses and that this is a sign of the vibrant growth in the field.

After FC Barcelona, Real Madrid falls prey to Twitter hack

Shortly after breaking in to the social media account of Futbol Club Barcelona, the Ourmine hacking group breached the Twitter account of the Real Madrid Club de Futbol. The hackers sent out tweets in English and Spanish that announced the joining of major rival player Lionel Messi. The attackers posted a video footage from an earlier match which showed Messi scoring for Barcelona against Real Madrid.

The hackers sent a few prank tweets in English and Spanish welcoming Messi to the club. One of the tweets said, “Benvingut Messi! B!Bienvenido Messi! Welcome Messi! Bienvenue Messi! £Messi,” The tweets were visible for almost 90 minutes on the football club’s handle, but were removed later. The welcoming post of Messi had grabbed the attention of the fans by then as the tweet received almost 2800 likes and 3100 retweets.

The Ourmine group also posted a series of tweets to claim responsibility for the hack, one of which said, “Internet security is s*** and we proved that.” The tweets were deleted later, according to ESET blog post.

Last week, when the group broke in to the Twitter account of FC Barcelona, they staged a similar prank as they announced the signing of Paris Saint-Germain player Angel Di Maria. Any connection between the two hacks is uncertain.

The Ourmine group is an anonymous group of hackers known for several high profile social media breaches in the past. The victims include Wikipedia co-founder Jimmy Wales, Facebook co-founder Mark Zuckerberg, Google CEO Sundar Pichai as well as organizations such as Buzzfeed. The group also breached the social media accounts of HBO earlier this month. Ourmine claims that the cybersecurity breaches by them are done to show the weaknesses in the victim’s system and promote its own cybersecurity services.

Keep records of people posting online comments, Chinese govt. tells companies

global data security initiative

In a major blow against privacy and continuing the crackdown against free speech on the internet, the Chinese government has instructed companies to keep a record of identities of people who post comments online. According to the new regulations, “all message board providers must authenticate users’ identities from October 1.”

An official spokesperson has stated that, “Online comments . . . give rise to false rumors, filthy language and illegal messages, which damage the online environment,” while observers have pointed out that the new regulations are directed at controlling mockery and criticism against the leadership of the country. The regulation seems also to be aimed at keeping the country’s political environment controversy-free, ahead of the upcoming 19th national congress of the Communist party.

The new regulation comes after a series of memes that were circulated online which compared President Xi Jinping to cartoon character Winnie-the- Pooh. One showed Xi walking with former United States President Barack Obama in a frame and Winnie the Pooh walking with his friend Tigger in another. Another meme showed the president shaking Japanese Prime Minister Shinzo Abe’s hand beside a still of the bear doing the same with the donkey Eeyore, another Disney character from the series. Post this, the tech companies were instructed to censor the jokes. The searches for Pooh’s Chinese name “Little Bear Winnie” then turned up error messages, which said that the content was illegal in the country. Even WeChat had to remove Pooh stickers from its official gallery.

Commenting on the incident, Beijing-based historian Zhang Lifan, in an interview with the Financial Times said, “This is a way of threatening the general population and media, especially online media. It affects everyone. They are using lots of different methods to restrict people’s ability to criticize or mock officials — this is not normal, even for China.”

The new regulation takes a page or two from the recent China Cyber Law which gives the government the authority to punish companies for noncompliance. A recent statement from the official Xinhua news agency states: “Those who violate the provisions and infringe on personal information will face hefty fines.” This is China’s first attempt to implement sweeping protections and regulations for the data of Internet end users. Previously, a wide range of uncoordinated laws and regulations has governed the Internet in China.

Seven members of Trump’s cybersecurity team resign

As many as seven of the 27 members of the National Infrastructure Advisory Council have resigned from their offices. In a group resignation letter, the advisors cited concerns over Donald Trump and his administration’s approach toward cybersecurity. The letter that was published by Nextgov stated that the Trump administration has undermined the “moral infrastructure” of the country.  The members resigned on August 21 and the resignation was acknowledged by the White House the next day.

Most of the advisors who resigned were appointed during Barrack Obama’s tenure as the president. Some of them include former U.S. Chief Data Scientist DJ Patil and former Office of Science and Technology Policy Chief of Staff Cristin Dorgelo.

The advisors criticized Trump decision to withdraw from the Paris climate accords and his controversial statements after the Charlottesville attacks. The letter further stated that the administration was not “adequately attentive to the pressing national security matters within the NIAC’s purview, or responsive to sound advice received from experts and advisors.”  It went on to say that the administration is giving “insufficient attention to the growing threats to the cybersecurity of the critical systems upon which all Americans depend,” including election systems.

The Trump government had been under scrutiny since the suspected Russian intervention during the 2016 presidential elections. Recently, a cybersecurity alliance with the Russian intelligence unit was also proposed by Trump during the G-20 summit. However, he later turned down the proposal. He also failed to present a cybersecurity plan within the self-imposed deadline.

Airtel partners with Symantec to offer cybersecurity solutions to Indian enterprises

Telecommunications services provider Airtel and cybersecurity solutions provider Symantec Corp. have joined hands to offer enterprises in India telco services combined with cybersecurity solutions. Under the terms of the agreement, Airtel will be the exclusive cybersecurity services partner for Symantec in India, and will distribute Symantec’s enterprise security software.

The partnership will provide Indian enterprises with the best of both worlds, Symantec’s security, visibility and control of critical assets, users and data; and support from Airtel’s expansive outreach within India. It will leverage Airtel’s penetration in India’s Business to Business (B2B) segment, helping businesses address the challenges of the cloud generation.

Gopal Vittal, MD and CEO (India & South Asia), Bharti Airtel said, “Increasingly sophisticated cyber threats with a potential to disrupt business continuity are the new normal in today’s digitally connected world. Enterprises need to guard against these emerging threats and Airtel, with its experience in serving businesses with integrated connectivity solutions, is uniquely positioned to serve them. We are delighted to partner with Symantec and offer its world-class Integrated Cyber Defense Platform and solutions to customers in India. It will help us add value to our existing enterprise relationships and further consolidate our leadership position in the B2B space.”

Airtel business serves over 2,000 large enterprise accounts, plus more than 250,000 corporate and tech startups with its integrated telecom solutions. In addition, it has a strong presence in Central and State Government departments/divisions in India. Symantec cybersecurity services prepares organizations for every stage of the attack lifecycle through global threat intelligence services, managed security services, incident response services and cyber skills development services to protect organizations from internal and external attacks.

“The partnership between Airtel and Symantec presents massive value to businesses in India. Airtel is one of the most forward-thinking telcos and Symantec’s Integrated Cyber Defense Platform focuses on empowering businesses to protect their on-premise as well as fast growing cloud environment through every stage of an attack lifecycle by combining the broadest and deepest set of threat intelligence in the industry,” Symantec’s CEO Greg Clark said. “With this partnership, Symantec will expand its outreach in India exponentially and Indian organizations will be able to strengthen their cyber defense and respond to new threats as they emerge at a significantly lower operational cost, under one service level agreement.”

Indian court puts right to privacy as fundamental

Addressing the privacy of billions of citizens, the Supreme Court of India has made a landmark judgement stating that Right of Privacy is a Fundamental Right. The apex court overruled an earlier bench judgment and ordered that Right to Privacy is intrinsic to Right to Life granted under Article 21 of the Constitution of India.

This order follows an array of petitions which challenged the mandatory use of Aadhaar cards. The Aadhaar database was collected over the years in biometrics format. “Aadhar is an instrument for identification and authentication. Any initiative linked with identification and authentication cannot be seen as violative of the right to privacy,” said PP Chaudhary, the junior Law Minister, in a statement.

This ruling may also be a huge blow to the Digital India campaign, but has occurred in the wake of several attacks and breaches. From the beginning of 2017, numerous reports had emerged stating a massive amount of data breach. Information of the citizens, like address, Aadhaar number, and other sensitive data like bank details were reportedly published online. This information was gathered by critical departments and ministries sites. Experts have been fearing the Aadhaar might be a tool that will infringe the privacy of billion plus citizens.

“There is a massive scale of data that needs to be managed, and we are still reaching that level of technological advancement to handle incidents like these,” Prabhu Ram, Chief Strategy Officer and MD of Paynear, an Omni-Channel transaction solution provider from India while interacting with CISO MAG. “India adopted one of the most futuristic methods of data collection; incorporating biometrics, iris scans, etc., creating a unique identity scheme that removes every scope of duplication in the future. But like every new initiative, even these had flaws. To err is human. We will learn from our mistakes.”

The court has not commented on the issue which mandates the use of Aadhaar cards linkage for to all financial transactions. There would be a separate bench which will review the case.

The opposition party, Indian National Congress Vice President Rahul Gandhi welcomed the verdict and stated that it is a major blow to the “fascist forces,” adding that the ruling party believes in “suppression through surveillance”.  “Welcome the SC verdict upholding Right to Privacy as an intrinsic part of individual’s liberty, freedom and dignity. The SC decision marks a major blow to fascist forces,” he tweeted on his twitter handle.

There is still apprehension, “All fundamental rights come with reasonable restrictions,” said senior lawyer Prashant Bhushan, who was party to the case. Whether Aadhaar can be seen as a reasonable restriction has yet to be decided, he cautioned.

Black Sea incident: New frontier in cyberwarfare

Russia, Moscow, fake digital passes

Reports have emerged stating that Russia might be testing systems that can interfere with Global Positioning System (GPS) signals by overriding them with fake ones. The system which is notoriously called GPS spoofing is now being feared as a new tool for next generation cyberwarfare.

The incident came to fore in the high seas after the Maritime Administration of United States Department of Transportation issued a safety alert, “A maritime incident has been reported in the Black Sea in the vicinity of position 44-15.7N, 037-32.9E on June 22, 2017, at 0710 GMT. This incident has not been confirmed. The nature of the incident is reported as GPS interference. Exercise caution when transiting this area.”

It all began on June 22 when the master of a ship off the Russian port discovered that his GPS had pointed him 25 nautical miles inland near Vnukovo Airport.  He reported to the U.S. Coast Guard Navigation Center stating, “GPS equipment unable to obtain GPS signal intermittently since nearing the coast of Novorossiysk, Russia. Now displays HDOP 0.8 accuracy within 100m, but given location is actually 25 nautical miles off; GPS display…” The coast guard requested the master of the ship to check for anomalies and even check for software updates.

When the coast guard contacted other nearby ships, it was found that all their automatic identification system (AIS) pointed to the same location at the Vnukovo Airport affecting nearly 20 ships traversing the Black Sea.

This is not the first time where GPS spoofing has been effectively deployed. In 2013, students of University of Texas sent a $80 million yacht off course by using a custom-built GPS spoofer. The students with owner’s permission misdirected the yacht by mimicking the GPS signal. “The yacht’s on-board navigation system detected the signal (fake) and used it as a triangulation point; no alarms were triggered, and the crew obeyed their computer and changed course,” states a report in The Verge.

Todd Humphreys, who was involved with the project back in 2013, told New Scientist after the Black Sea incident, “The receiver’s behavior in the Black Sea incident was much like during the controlled attacks my team conducted,” says Humphreys. Humphreys is of the opinion that Russia is experimenting with a new kind of electronic warfare. “My gut feeling is that this is a test of a system which will be used in anger at some other time.”

The report goes on to describe further details of the incident and note that hundreds of thousands of cell phone towers in Russia are equipped with GPS jamming devices as a defense against US missiles–and also that Russia has previously jammed GPS signals in Russia and in Ukraine. “This is probably for defensive reasons; many NATO guided bombs, missiles and drones rely on GPS navigation, and successful spoofing would make it impossible for them to hit their targets,” it states.

In 2012, North Korea was also accused of producing electronic signal jammers near its South Korean borders. The device affected the GPS navigation of passenger aircraft, ships, and in-car navigation.

As for now, the Black incident has affected only ships, but GPS spoofing, if engaged as a tool of attack, may be disastrous. Guided missiles, drones, smart bombs, and even several other surface combat systems rely on GPS navigation. What if a missile targeted to Syria lands at Istanbul? Well, that only time can tell.

Nigerian man attacks 4000 companies single-handedly

According to a Check Point Research Team investigation, a Nigerian man attacked 4,000 companies in energy, mining, and construction sectors in several countries, including Croatia, Abu Dhabi, Egypt, Kuwait, and Germany over a period of four months. The Nigerian didn’t use any sophisticated method but was able to infect the companies’ networks, steal their data, and commit fraud by using emails that lacked proper social engineering. The malware used in the email is called Netwire. The attacker also uses a freeware scraping tool to obtain email addresses. Check Point did not reveal the magnitude of the attack or the damage from it.

The researchers at Check Point found out that the Nigerian man used a simple phising emails similar to those sent by Saudi Arabian oil giant Saudi Aramco, and targeted the financial sources inside victim companies. The email, sent with a Sir/Ms. opener to multiple people, drops a malware when opened, or tricks the recipient to reply with their banking details. The emails indicated that hacker is not extremely skilled and even lacks the understanding of social media.

While revealing the identity, Check Point said that the man behind the attack is a Nigerian national and uses “Get Rich or Die Tryin” saying by 50 Cents as his social media motto. In their report the Check Point wrote, “The malware used is NetWire, a remote access Trojan which allows full control over infected machines, and Hawkeye, a keylogging program. The campaign has resulted in 14 successful infections, earning the criminal thousands of dollars in the process.”

HBO’s social media handles compromised

HBO

The barrage of cyber attacks on HBO continues. Still recovering from the attack in July and subsequent leaks of “Game of Thrones” episodes, the network was again targeted on August 17 when OurMine, a self-proclaimed white hat hacker group, broke into HBO’s social media handles as well as the Twitter account of “Game of Thrones.”

The group posted on the page stating, “Hi, OurMine are here, we are just testing your security. HBO team please contact us to upgrade the security – ourmine .org -> Contact.” The post was deleted by HBO after regaining control of the accounts.

HBO is already battling several issues of data leaks and security breaches for the past few weeks. On July 31, hackers broke into the network’s infrastructure and stole 3.4 terabytes of data, including forthcoming episodes and scripts of popular TV shows “Game of Thrones,” “Ballers,” and “Room 104” along with personal data of the employees. A week post the hack, the attackers leaked the personal phone numbers, email addresses, and home addresses of the cast members of the TV series. They also asked for an undisclosed amount as a ransom to prevent further data leak.

The attackers leaked the fourth episode of “Game of Thrones” series on August 4, 2017. HBO’s distribution partner ‘Star India’ was held was accountable for the leak. On August 16, HBO Spain mistakenly telecast the sixth episode of the TV series before its official air date. The episode eventually landed on peer-to-peer sites, and was downloaded globally,

To fight underrepresentation, scholarships for women galore Hacker Halted

EC-Council and IBM announced a scholarship program for women to attend EC-Council’s Hacker Halted security conference free of charge. Funded by IBM Security, the scholarship is designed to help address the underrepresentation of women in cybersecurity and help women further their skills and expertise in this high-demand field.

The cybersecurity industry is facing a talent shortage that is anticipated to reach 1.8 million open and unfilled information security jobs within the next several years. With women representing only 11 percent of the information security workforce, creating more opportunities for women in security is a critical part of improving the talent pool in the fight against cybercrime.

Hacker Halted will take place October 9-10, 2017 in Atlanta, Georgia and is hosted by EC-Council, creators of the Certified Ethical Hacker (CEH) certification. IBM has sponsored the Hacker Halted conference and Global Cyberlympics for the past three years. This year, for the first time, IBM will fund a scholarship that allows all women who are interested in attending the event to do so free of charge.

“Improving the diversity of the cybersecurity workforce is essential to overcoming the growing threats and challenges facing the industry – and supporting growth opportunities for women in this field is a critical part of that equation,” said Diane Delaney, Worldwide Talent Manager at IBM Security. “By providing scholarships at conferences like this, IBM hopes that more women will be encouraged to attend the event and stay up to the latest trends and techniques which will help them become even more successful in the field.”

The theme for Hacker Halted 2017 is the “The Art of Cyberwar: Lessons from Sun Tzu.” 2,500 years ago, Sun Tzu wrote 13 chapters on military strategy. Fast forward to today and we are still learning from those chapters and applying them in our newfound digital age. In an age where war is waged over cables and microchips instead of battlefields, one challenge is defining what war is and when war should be declared. The conference presentations will address cyber security issues from the perspective that like it or not, our global society is engaged in a constant and ever growing cyber war.

Hacker Halted’s agenda showcases several prominent women of cyber including Georgia Weidman, Shevirah founder and CTO; Dr. Catherine J. Ullman, Senior Information Security Analyst, University at Buffalo; and Laura Samsó Pericón, Executive Vice President, Centurion Technologies Consulting LLC.

Women who wish to register for Hacker Halted under the IBM scholarship should visit https://www.hackerhalted.com/registration/ and use registration code HH17IBM for free entry.