Home Blog Page 398

Russia behind February malware attack, says Italian foreign ministry

The Italian foreign ministry recently confirmed Russia’s involvement in the hacking attack on government’s field offices in February. The ministry said that the malware attack that took place between 2013 and 2016 is worse than first thought and lasted years, not months. The hackers allegedly used a malware tool with apparent links to the Gru, Russian military intelligence.

In February, the ministry ordered an inquiry into the breach that compromised the field offices’ email systems and affected thousands of email communications. The malware went undetected for over four months, but, according to the officials, didn’t affect any sensitive encrypted data. However, the attack did reportedly compromise Italy’s mission to the EU as well as NATO and Ecofin meetings. There was also heavy traffic reported when some other sensitive issues were discussed.

It was suspected at that time that Russia was behind the attack. “There were no attacks on the encrypted level. So the information – delicate, sensitive information – that is usually shared in this net, which is restricted by code, has never been attacked or part of this attack,” a government official told The Guardian. However, Moscow denied the accusation, saying Italian ministry had “no facts”.

Bandura hires top sales leaders to expand business

Bandura, LLC recently announced three important appointments in a move to expand the company’s partner program and build a sales team to expand the use of newly launched platform, BanduraONE SaaS. The company hired Mike Danforth as Sr. VP of Worldwide Sales, Paul Crutchfield as VP of Sales Engineering, and Tami Sarjeant as VP of Channel Sales Worldwide. The trio was formerly associated with Tenable Network Security and will join Bill McInnis, who was hired in February as the President and Chief Product Officer.

Bandura launched the BanduraONE SaaS platform that provides a single point of command of Poliwall and Policloud products that block millions of real-time threat indicators. This helps the organizations prevent cyberattacks and simplify management.  The technologies provided by the company are compatible with client’s security architecture and can easily integrate through an open API.

“Bandura’s technology is remarkable, but it is the problems we are pointing it toward that really excite me,” said Mike Danforth. “We give our customers a very easy way to keep millions of threats completely off their infrastructure at the scale and velocity required for today’s emerging global cyber threats. We make your existing security controls more effective, reduce security data and alert fatigue, and restore your ability to control your attack surface and reduce cyber risk.”

“We are excited to have these talented leaders join Bandura and bring their sales experience and extensive network to our mission and opportunity. This veteran sales team regroups at Bandura to expand product awareness into new verticals, capture market share, and grow sales both domestically and internationally.  Their winning combination of cyber industry knowledge and sales execution fosters confidence in Bandura’s ability to achieve breath-taking results,” remarked Suzanne Magee, CEO and co-founder of Bandura.

Top US Federal cybersecurity officials leaving: Reports

Concerns about the effect of the administration of President Donald Trump on the cybersecurity infrastructure of the U.S. federal government were heightened this week when four senior cyber safety officials reportedly resigned.

The chief information officer (CIO) of the Environmental Protection Agency (EPA) under Barack Obama, Ann Dunkin, stated her concern about the rash of resignations and pointed to an apparent effort to drive out career CIOs who served under the previous administration.

Those resigning were: Sean Kelley, the EPA’s chief information security officer; Richard Staropoli, the Department of Homeland Security’s CIO; Rob Foster, the Navy’s CIO; and Dave DeVries, the Office of Personnel Management’s director of information security and privacy.

It is speculated that the inability of the Trump administration to fill vacancies throughout the federal bureaucracy is part of what is driving such departures. Widespread vacancies in departments are creating an environment in which experienced career specialists are looking at other employment options.

The Partnership for Public Service, a nonprofit that advocates for greater government efficiency, finds that the Trump administration is far behind its predecessors at this point in its first term with regards to filling government positions. Of the more than 1,100 non-judicial posts requiring Senate confirmation, only 279 have been nominated thus far. This lack of leadership within agencies trickles down to its IT and cybersecurity departments.

According to Jake Williams, founder of Rendition Infosec and a former Department of Defense, the slow pace of the federal bureaucracy makes it hard for the government to keep up with cybersecurity issues.

On the campaign trail, Trump’s understanding of cybersecurity issues seemed very thin, including a statement in one debate that the “… security aspect of cyber is very very tough, and maybe it’s hardly doable.” His first official action on cybersecurity issues was a May executive order that largely followed policy recommendations passed on by the Obama administration. Its centerpiece was the establishment of a White House American Technology Council.

Over $20 billion in valuation raised by Toutiao

Startup

According to Reuters, Toutiao — a Chinese news aggregator that has backing from Sequoia Capital and CCB International whose name translates as “headlines” — is in the process of raising $2 billion or more of capital with a valuation of over $20 billion. This comes on the heels of raising $1 billion, with a valuation of over $11 billion, at the end of 2016.

One new investor, according to anonymous sources, is American private equity firm General Atlantic, though both Toutiao and General Atlantic would not comment on that possibility. Most of Toutiao’s revenue comes from online advertising. Its biggest competitors are Tencent’s Tian Tian Kuai Bao and Baidu’s newsfeed.

Founded in 2012 by Zhang Yiming, the tech startup is among China’s fastest growing. Its use of customized news feed models has blossomed in popularity and its value has increased by a factor of 40 since 2014.

Toutiao is part of a trio of tech companies — the other two being online services company Meituan-Dianping and Uber-like ride-hailing firm Didi Chuxing — that are referred to as “TMD.” Their rise is being compared to the tech heavyweight trio “BAT,” which consists of the Chinese companies Baidu, Alibaba, and Tencent.

Based on the use of algorithms and artificial intelligence, Toutiao suggests a wide variety of content for users, including news, online books, and videos. There were about 100 million daily users in the first quarter of 2017. The 2017 target revenue for the company is $2.5 billion.

Toutiao has faced legal scrutiny for its business model, with content generators filing court complaints claiming unfair competition. Tencent, which manages the messaging app WeChat, filed suit in April claiming copyright infringements.

Apparently, a Chinese court ruled in Tencent’s favor in early July. Last week the social media company Weibo, which was once an investor in Toutiao, also leveled public criticism about the unsanctioned use of its content that was perceived as a shot across the bow of Toutiao. Chinese officials apparently also have cyber security concerns about Toutiao’s operations.

Chinese Internet giants face investigation over cybersecurity violation

Three major Chinese companies Tencent, Baidu, and Weibo are under investigation by the Chinese internet regulating authorities on the grounds of violating the new cybersecurity law. The companies are issued notice in the lieu of hosting content that is spreading “violence and terror, false rumors, obscene pornography and other content that endangers national security, public safety and social order.”

The entities to come under the scanner are popular messaging app WeChat, run by Tencent, Baidu’s messaging board Tieba, and microblogging site Weiba by Sina Weiba. The notice of investigation was posted on the regulator’s website.

The Chinese cybersecurity law was made effective on June 1, 2017, and had been publicized as a milestone in data privacy regulation. If the companies facing an enquiry has indeed violated the law, they would be punished, according to a statement. However, no information about the magnitude of the punishment is released.

No statement was made by any of the companies after the announcement. The Chinese regulatory body also didn’t release any statement.

Ethical code crucial in digital age, survey says

A new survey by the Association of Chartered Certified Accountants (ACCA) points out the relevance of ethics and moral code for enterprises to gain trust of public. The survey report titled “Ethics and Trust in a Digital Age” gauged over 10,000 professionals and students from over 150 countries.

Nearly 77 percent of the respondents stated that ethics played a crucial role and is an important skill in today’s world, with nearly nine of 10 giving ethics top rating. Ethics was also top voted in among the not-for-profit and public sector. More than a quarter felt strong ethical leadership is the key, while the rest “called for guidance on a new code of ethics.”

“Professional accountants are often on the frontline of facing ethical questions in business,” said Maggie McGhee, Director of Professional Insights at ACCA. “What is clear is that the digital age creates new dilemmas where there are no easy answers. If you’re working in a business considering whether to start accepting bitcoin payments, or implementing cloud-based customer records, these are crucial questions. In the digital age, there needs to be more—not less— importance placed on the ethical and professional judgment of individuals.”

She added, “What many are calling for is guidance and leadership on how to respond. All those involved in decision-making levels in business should be aware of how new technologies can affect their reputation and consider how to support their employees in doing the right thing.”

Unfortunately, nearly one-fifth of the respondents stated that they felt the need to compromise ethics in the last one year with integrity being the most compromised principal.

“The professional accountants of the future will need, in addition to technical capability, a rounded skill-set that demonstrates key quotients for success in areas such as experience, intelligence, creativity, digital skills, emotional intelligence and vision,” said ACCA Head of USA Warner Johnston, “and at the heart of these lies the ethical quotient.”

The focus areas of the survey were different vectors of cyber-attacks, privacy, bitcoins, ethereum and other types of cryptocurrency, big data and analytics, artificial intelligence (AI), and technology solutions. The report also has case studies which highlight scenarios where the ethics of accountants and auditors are questioned.  It has also set aside guidelines for professional practice which include contents like integrity, objectivity, professional competence, confidentiality, et al.

US Senate plans to upgrade IoT cybersecurity

An effort in the U.S. Senate has been launched to impose tougher information security protocols for the Internet of Things (IoT). The IoT Cybersecurity Improvement Act would require that smart devices meet basic standards if they are to be used by federal agencies.

Many in the IoT community support the proposed legislation. Steve Brumer of 151 Advisors — a company specializing in IoT and cloud-based technologies — states that such regulations will be good for the industry, since government agencies will be forced to dedicate spending on upgrading their systems, an area that is oftentimes neglected by budget decision makers.

Brumer points to the WannaCry hack as an example of what can happen when security upgrades and patches have not been installed due to widespread bureaucratic inaction. He says the biggest threat to IoT security is the already known security weaknesses that can be patched by users with available security updates and software, but have not been. Hackers know of these weaknesses and can exploit them in many defenseless devices.

This kind of indirect government funding will help the private sector to continue to develop cyber safety products that will be less expensive moving forward. But Brumer adds that without global IoT standards, all such defenses will be “Band-Aid” in nature. He thinks widespread government security regulations will be a first step in forcing better standards to be developed. In 2015 the U.S. government’s IoT spending topped $9 billion.

In a survey carried out by Canonical, the maker of the Ubuntu operating system, nearly half of IoT professionals cited the need for better cybersecurity for their industry. The capability to remotely patch IoT devices was emphasized. Canonical Ubuntu Core system has remote patching integrated into it.

Schneider Electric and Claroty form cybersecurity partnership

Schneider Electric

A new strategic partnership to protect energy systems from cyber attacks has been formed. Schneider Electric, which specializes in the management of energy systems, and Claroty, which focuses on network protection systems, have signed a partnership agreement to facilitate better safety and cybersecurity for the industrial energy sector.

The deal will bring Claroty’s Operational Technology (OT) network security software directly to Schneider’s already existing customer base through a collaborative automation partner program (CAPP).

The OT platform monitors and protects industrial control systems for potential cyber attacks. It provides secure remote access so that system operations can be scrutinized at all times, while also restricting access to unauthorized access to the system and providing a record of all access to the industrial network. Claroty’s OT system thereby provides constant automated analysis of network activity, alerting managers to any system anomalies that could be a sign of an active cyber crime attack.

The partnership with Claroty upgrades and expands Schneider Electric’s IoT-enabled EcoStruxure cybersecurity program. The EcoStruxure platform is designed to provide layers of cybersecurity within a complex industrial system, providing redundant security protocols throughout the wide-ranging segments of an integrated industrial infrastructure.

According to David Doggett, senior director of cybersecurity at Schneider Electric, the partnership is a recognition of the high cyber security risk facing managers of energy systems and will give them enhanced “real-time network monitoring and anomaly-detection.”

The joint CAPP has already been heavily tested to ensure its operability in the field, with an emphasis on passive network intrusion detection. The goal is to catch and counter cyber attacks that have gone undetected by existing protocols, known as “boundary protections.” This includes attacks from unusual attack vectors and internally launched attacks.

The Clarity platform is capable of monitoring industrial networks at the deepest levels. Other IT cyber security systems depend on active queries or involve network footprints that can disrupt system operations. The passive-monitoring strategy of the Claroty system minimizes the risk of network disruptions.

The Chief Executive Officer of Claroty, Amir Zilberstein, states that his company recognizes the complex challenge of protecting energy systems and that this is best delivered when network security firms work hand-in-hand with leading equipment manufacturers.

Australian government to share spy data with small, medium businesses

Avaddon ransomware, Microsoft and Fortinet flaws, apt

In an attempt to counter the increasing incidents of cyber attacks, the Australian government has decided to share declassified cybersecurity data from the Australian Signals Directorate (ASD) with telcos and internet service providers (ISPs). The plan was announced back in May.

Telstra Director of Security Neil Campbell told a newspaper that the move would enable small and medium businesses to manage their security concerns in a better way and help cybersecurity companies create more cost-effective products for these businesses.

Commenting on the cyber threats to small businesses, Campbell said, “It’s our job to give them the products and services that allow them to manage that risk cost effectively without having to become an enterprise or cyber security expert.”

The data shared by the government would include indicators of compromise (IOCs) that suggest whether a compromise has been attemped or successful during different stages of a cyber attack. These IOCs can be linked to the IOCs of the internet service providers to create a database that can help the latter to analyse, identify, and develop solutions to a cyber breach.

The Australian government already suffers a combined loss of $1 billion every year to cyber attacks and has allotted a budget of $630 million to combat cyber breaches. According to Computer Emergency Response Team (CERT), 14,804 cases of cyber incidents have been reported to them between July 2015 and June 2016. Out of these cases, 418 intended to dislodge or damage systems of national interest and critical infrastructure.

Cybercriminals using Steganography in their attacks: Researchers

Steganography attack

Steganography, an ancient practice of hiding secret content and text messages inside non-suspicious messages, is being increasingly used by cybercriminals to attack the businesses around the world, according to a recent research by the Kaspersky Lab. The attackers are concealing stolen data and other potentially hazardous malware inside ordinary image or video files to communicate with control and command servers.

The research suggested that such minute modifications of video or image files to infiltrate the security systems can go unnoticed by the antimalware protections and the Advanced Persistent Threat (APT) tools. The researchers of Kaspersky Lab, Alexey Shulmin and Evgeniya Krylova, told a news website, “Most modern anti-malware solutions provide little, if any, protection from steganography.”

According to researchers, Steganography has already been used in at least three major cyberespionage campaigns in the past few months. There have also been several other instances where steganography was used with other malware like Zeus banking Trojan or the Shamoon Disk-erasing malware.

The researchers pointed out that attackers usually store the data in Stegcontainers, which can take multiple forms, including audio files, text files, or domain name. However, it becomes difficult for attackers to hide the size of the container, as hiding a lot of information would cause visual distortion, according to Krylova.