Home Blog Page 400

Director of NSA Rejects Joint U.S.-Russian Cybersecurity Unit

NSA security advisory

The director of the U.S. National Security Agency (NSA) has publicly stated his objection to any cooperative U.S.-Russian cybersecurity unit. It has been reported that President Donald Trump and Russian President Vladimir Putin supposedly discussed the idea in private at the recently concluded Group of 20 Summit Meeting in Hamburg, Germany.

The idea comes amid the ongoing and expanding investigation into Russian interference in the 2016 U.S. election and possible collusion between the Trump campaign and Russian agents. U.S. intelligence agencies have already concluded that there was Russian interference in the election and the scope of it continues to be investigated.

While attending the Aspen Security Forum and questioned about the possibility of a joint cyber security effort, NSA Director Mike Rogers said: “I’m not a policy guy here … I would argue now is probably not the best time to be doing this.”

Once the idea was floated publicly, Trump backed off of it on Twitter, saying: “The fact that President Putin and I discussed a Cyber Security unit doesn’t mean I think it can happen. It can’t.”

Lawmakers in Congress, including senior Republicans, rejected the idea.

Rogers concluded by saying the idea was “something that you might want to build over time were we to see changes in (Russia’s) behavior.”

Snap acquires Strong.Codes

Snap

Sources report that the company behind Snapchat has acquired Strong.Codes, a Swiss company that specialized in creating barriers to the lifting of code from software. Snap recently hired Laurent Balmelli, the co-founder and software engineer of Strong.Codes. Apparently, Balmelli joined the California-based social media company and brought much of the Strong.Codes staff with him.

There are only a few employees left at Strong.Codes former headquarters in Switzerland, apparently on the Snap payroll. Snap had spent months in Europe looking for cyber security staff. This was seen as part of a strategy to expand into Europe.

Snap’s growth potential is currently tied to the dominant position of Facebook in the social media sector and the ability of Facebook to incorporate some of Snapchat’s most popular features into its stable of features. It is believed the acquisition of the Strong.Codes portfolio is an attempt to limit Facebook’s ability to adapt popular Snapchat features, though it is not clear that Facebook is basing new features on Snapchat code.

Snap’s stock price recently dropped to a record low of $14.65 per share as it works on rebranding as “a camera company” that is also still active in the social media world. But the company’s co-founder and CEO Evan Spiegel has downplayed the share price slide, claiming that the company will bounce back once its new media partnerships and initiatives have coalesced into a functioning whole.

Blackstone Group eyeing to buy 40% stake in Israeli firm NSO Group

Blackstone

According to reports, Blackstone Group is in advanced stage of negotiations with Israeli cybersecurity firm NSO Group to acquire 40% of the stakes at an estimated value of $400 million. As a second buyer, Clearsky is expected to collaborate with Blackstone for 10% of the stocks, as reported by Israeli business newspaper Calcalist. None of the firms made any comment regarding the deal.

The Blackstone Group is a multinational company based in New York, and specializes in private equity, credit, and hedge fund investment strategies.

The NSO Group, a maker of spyware for mobile devices, was founded in 2009 by Omri Lavie and Shalev Hulio, and is headquartered in Herzliya, Tel Aviv. The firm is known for the development of Pegasus software that targets mobile phones to gather information and provides “authorized governments with technology that helps them combat terror and crime.”

Prior to the deal with Blackstone Group, private equity firm Francisco Partners owned majority of the NSO Group stakes. The new deal will see the stakes of Francisco Partners reduce to 40%, with Blackstone and Clearsky jointly also holding 40%. The owners will account for 6% each while the 500 employees of the company will hold another 8%.

NSO Group had been recently under the scanner of the international community due to the alleged use of the Pegasus software by the Mexican government on the devices of opposition lawmakers and private citizens, including human rights lawyers and journalists. The Mexican government denied any such involvement by terming the allegations as false rumors and had called for investigation.

EU Digital Chief Andrus Ansip eyes new cybersecurity center

EU

European Commission vice-president and digital chief of European Union, Andrus Ansip, is planning to set up a new office to certify the cybersecurity level of the technology products to make them competitive on a global scale.

In September, Ansip will announce a set of new measures on cybersecurity certification that will also include a system to grade the cybersecurity products. However, he did not specify if the system will be mandatory for the members to adopt.  He said that the new cybersecurity office will only focus on the products and would different to NATO’s center that tests its members’ capabilities of reacting to a cyber attack, and researches on several cybersecurity aspects.

The proposed announcement would also unveil a new strategy to counter cybersecurity issues and building a new legal basis for ENISA. There have been discussions from the ENISA’S directors about an increase in budget, so they can strengthen their workforce and ensure better information sharing in case of an attack on weekend or during the night.

According to Ansip, the move to open a new office will bolster EU’s ability to respond to cyber attacks. He said that it was pretty much evident during the recent WannaCry attack that EU countries are not equipped with enough manpower or resources to stop cybersecurity breaches once they’re attacked. However, with the new office and new set of measures for cybersecurity certification, the situation would improve.

There are also concerns about the new cybersecurity office becoming a direct competition to ENISA. According to Steve Purser, ENISA’s director of operations, a number of EU offices have already created their own units to handle cybsercurity, thus, creating fierce competition. Purser stressed that “it does make sense to have hundreds of people at the European level, but not hundreds of organizations.”

 

Illicit Dark Web sites shut down

BigBasket Allegedly Suffers Data Breach, Customer Data on Dark Web for Sale

The attorney general of the United States, Jeff Sessions, announced the shutdown of two “dark web” marketplaces, AlphaBay and Hansa. These sites were clearing houses for the illegal trade of products such as guns and drugs, including fentanyl and heroin.

Both were Tor-based anonymous sites. Tor is a network of over 7,000 Internet relays used to conceal the location and usage of users, in effect acting like money laundering for Internet users.

The investigation that led to the shutdowns included law enforcement agencies in throughout the world, led by the Federal Bureau of Investigation (FBI), the Drug Enforcement Agency (DEA), and the Dutch National Police.

AlphaBay servers were seized by law enforcement agencies in Thailand, Lithuania, Canada, Britain, and France. Alexandre Cazes, a Canadian citizen and founder of AlphaBay, was arrested in Thailand. He apparently committed suicide within a week of being taken into custody.

Europol estimates that AlphaBay had over 200,000 users and 40,000 vendors. Digital currencies, including Bitcoin, were used to process transactions. The largest online black market before being shut down, AlphaBay processed transactions worth hundreds of thousands of dollars and had taken over much of the market after Silk Road was shut down in 2013. According to FBI acting director Andrew McCabe, AlphaBay was 10 times bigger than Silk Road at its height.

Servers for Hansa were seized in Lithuania, the Netherlands, and Germany under the coordination of the Dutch National Police. Prior to shutting down the site, authorities took “covert control” of it so as to track migration from the shutdown AlphaBay site to Hansa.

The executive director of Europol, Rob Wainwright, said this strategy paid off, as users “flocked to Hansa in their droves” and authorities monitored this activity. Usernames and passwords of buyers and sellers were captured and will subject to follow-up investigations. He called the investigation “really special” and said it was one of the most sophisticated cyber crime investigations ever carried off.

Malware threats to Apple iOS triple, study says

iOs

The number of malicious apps dedicated to attacking the Apple iOS — which is the system for devices such as the iPad, iPhone, and iPod Touch — has more than tripled over the past three quarters. The amount of such malicious targeting Android devices has remained flat over the same time period.

The findings were part of a report released by Skycure, a company specializing in cybersecurity for mobile devices. Its Mobile Threat Intelligence report scans devices for “high-severity” malicious apps and tracks the volume by quarter. The data comes from Skycure enterprise customers and those who download Skycure’s free tracking app. The cybersecurity industry leader Symantec recently announced plans to acquire Skycure.

According to Skycure’s Vice President of Marketing Varun Kohli, hackers appear to be focusing on iOS because Apple’s products are popular with more affluent consumers and cyber criminals are focusing on this market in order to follow the money.

Already in 2017, a total of 192 exploitable flaws have been detected in the iOS system, a significant increase from the 161 that were discovered in the entire year of 2016. Such vulnerabilities are projected to hit 643 for 2017, a year-over-year increase by a factor of four. The number of vulnerabilities in the Android system is expected to fall slightly, from 523 in 2016 to 500 in 2017.

A silver lining in the report is that greater likelihood that iOS users updating their software regularly, especially in comparison to Android users. Over 90 percent of iOS have migrated to the most recent iOS 10, while only 21 percent of Android users are using the most recent Android 7.

But according to Kohli, updating the iOS system is not a panacea, especially considering the other threats to mobile devices, including physical loss, attacks on the WiFi networks the device might be connected to, and vulnerability exploits.

Specific threats that were found by Skycure include the XcodeGhost, AceDeceiver, and Yispecter malware programs, all of which can appear to be legitimate downloads that are actually cyber attack software.

Rise of medical IoT devices may pose risk, report says

Healthcare IoT, Fitness Trackers

The healthcare field has incorporated a wide variety of IoT devices into its infrastructure in recent years. Both doctors and nurses use everything from glucometers to infusion pumps to laptops, but there may be assumptions about the cybersecurity of these devices that are unwarranted.

A recent survey found that 75 percent of IT managers are “confident” or “very confident” that the network security for their IoT devices was strong and not easily susceptible to cyber attacks. Many information security professionals would not be so confident.

The survey was part of a report produced by ZingBox, an IT security company specializing in IoT devices. Over 200 healthcare IT professionals were part of the survey and it found that even as the number of devices being used has proliferated, network security protocols are still rooted in the laptop/server world.

It was found that a typical hospital bed involves the use of 10 to 15 IoT devices in a day, with the definition being Internet-connected devices that are portable.

The fact is many IoT devices are not protected by traditional network security protocols, which tend to focus on protecting data on the server. But these types of established network security systems can allow access to individual IoT devices with relative ease. Cyber attacks can take control of an individual IoT device and turn them into a botnet, which will create a doorway through which malicious software can enter into the network.

In a recent study made public by the Ponemon Institute — which is an independent research foundation specializing in privacy, data protection, and information security — it was found that 67 percent of medical IoT device makers have an expectation that their products will be attacked in the following 12 months. But only 17 percent have serious policies in place to prevent such attacks.

One of the biggest issues is the difference between medical IoT devices and more traditional laptop/server protocols. Security patches and system updates can be quickly shared to laptops and other mobile devices, but that’s usually not possible with IoT medical devices, which cannot receive such network-wide software updates.

The regulation of medical IoT devices by the U.S. Food and Drug Administration (FDA) also creates barriers to making it easy for the devices to receive third-party software patches. Such procedures might invalidate FDA certification, a process that can take up to five years to achieve. No medical IoT device maker currently allows third-party security software to be uploaded to their products.

Ken Gonzalez to join Trident Capital Cybersecurity as Managing Director

Cybersecurity

Former senior vice president of corporate development and global alliances at FireEye, Ken Gonzalez is joining Trident Capital Cybersecurity (TCC) as a managing director. TCC is a $300 million cybersecurity venture firm, mainly focusing on investment in early stage and select growth equity companies. Ken will join fellow managing directors Alberto Yépez, Don Dixon and Sean Cunningham, with a primary investment focus on securing the Internet of Things (IoT), next generation identity platforms, behavioral data analytics, privacy, and secure payments and fraud prevention.

Ken had worked with Avast Software as the chief strategy officer, prior to working with FireEye. He also worked as the senior vice president of corporate development at McAfee before his tenure at Avast. He took care of the licensing, acquisitions and partnership while in McAfee. He graduated from Harvard Business School and United States Military Academy at West Point and served in the U.S. Army as infantry officer with the 2nd Airborne Division and the 75th Ranger Regiment.

Welcoming the new managing director on board, Yepez said, “TCC, one of the most experienced investment teams in cybersecurity, is on an incredible growth trajectory. We are adding experienced operational executives with demonstrated success to help us identify early stage cybersecurity companies with the potential to grow into industry powerhouses.” Yepez further said, “Ken brings the mind-set of corporate buyers of cybersecurity startups, excellent strategic insight and a global network of trusted channel relationships that will help scale our portfolio companies. Throughout his career, Ken completed 23 acquisitions in cybersecurity and fostered multiple OEM licenses and global alliances — experience that will become handy to help entrepreneurs grow their businesses.”

The spending on cybersecurity solutions are projected to grow rapidly in the next 5 years, and the optimism is evident from Ken’s reaction. He said, “Moving into the investment side of the cybersecurity business is a natural progression for me. I have led teams that made more than twenty successful cyber acquisitions in my career. Today, cyber is an excellent investment market and I wanted to be part of the next wave of cybersecurity investing.” He also explained the reason for him to choose TCC by saying, “I chose Trident Capital Cybersecurity because of its stellar cyber investment record, its understanding of technology and because it is renowned for its connections in the cyber ecosystem. The firm also pays close attention to helping entrepreneurs build their companies and is active on their boards. That’s important to me.”

Jamaica Grabs Top Position in Caribbean Region in Cybersecurity Rating

Jamaica cyber

Jamaica has recently grabbed the top position in cybersecurity in the Caribbean on the Global Cybersecurity Index, according to a report produced by the International Telecommunication Union (ITU). The Index featured 134 member states who responded to questions based on the core areas of the ITU Global Cybersecurity Agenda (GCA).

The survey, which was conducted in 2016 through an online platform, also measured the efforts taken by all the 193 member states to improve their cybersecurity structure by working on legislations, projects and programs, cooperation, and capacity building.

Though Dr. Andrew Wheatley, the Minister for Science, Energy, and Technology, was optimist about the rewards and recognition, and the efforts of the Cyber Incident Response Team (CIRT), MOCA and Communications Forensics and Cybercrimes Unit (CFCU), he said that more efforts are needed to maintain the stature and show consistent improvement.

The cybersecurity scenario in Jamaica has changed a lot in the recent times, but the government is eyeing opportunities to improve its public education system. Commenting on the situation, Wheatley said, “There is room for capacity building and cooperation between the public and private sector at all levels but we remain committed to meeting all international standards and best practices.”

Corelight raises $9.2 million in Series A Funding

corelight

Corelight, a provider of network visibility solution for cybersecurity, has closed $9.2 million in Series A funding from Accel Partners, a venture capital firm. The Series A round also saw participation of Osage University Partners and Riverbed Technology.

Commenting on the funding, Eric Wolford of Accel Partners, said, “We often invest in very widely-used open source projects. But it’s uncommon for them to have much enterprise market traction. And what’s highly unusual for a Series A company like Corelight is to have a shipping product built on battle-hardened open source software and dozens of paying customers including six of the Fortune 100, plus one of the largest private companies in the US. I’ve never seen that before.”

The funding will be used invest in sales, marketing, and engineering, as well as to boost the company’s growth plans. Founded by Dr. Vern Paxson, Robin Sommer, and Seth Hall, Corelight delivers network visibility solutions on an open source framework called Bro.

Its product, Corelight Sensor, has often been dubbed as a ‘flight data recorder’ due to its capability to go back in time to understand and analyze cyber-attacks. Corelight Sensor has also been efficiently deployed to prevent network attacks from all major threat vectors.

“We help our customers solve cybersecurity problems faster than they can today, often decreasing the time to resolve incidents from hours and days down to minutes. This new investment will accelerate our progress,” said Greg Bell, CEO of Corelight. “We’re busy working on a series of new features customers are asking for so they can focus effort away from sensor management and towards higher-value activities like data analysis, threat hunting and incident response.”