Monday, January 22, 2018

iNews - Around The World This Week

1)     Understanding Supply Chain Cyber Attacks - Today's cybersecurity landscape has changed dramatically due to digitalization and interconnectivity. While the benefits of each push businesses toward adoption, security risks associated with interconnectivity between networks and systems raise major concerns. Everything-as-a-service removes traditional security borders and opens the door to new cyber-attacks that organizations might not be prepared to recognize or even deal with.

2)     Schneider Electric: TRITON/TRISIS Attack Used 0-Day Flaw in its Safety Controller System, and a RAT - Industrial control systems giant Schneider Electric discovered a zero-day privilege-escalation vulnerability in its Triconex Tricon safety-controller firmware which helped allow sophisticated hackers to wrest control of the emergency shutdown system in a targeted attack on one of its customers. Once the malware was inside the controller, it injected the RAT into memory by exploiting a zero-day vulnerability in the firmware, and escalating its privileges.

3)     Ransomware: Why the crooks are ditching bitcoin and where they are going next - The popularity of bitcoin is creating problems for criminals dealing in ransomware -- and some are already casting their gaze towards a less volatile cryptocurrency. While bitcoin has suddenly found itself in the public eye thanks to its rocketing -- and, more recently, plummeting -- value, it hasn't appeared from nowhere. We'll see a progressive shift in 2018 towards criminal use of cryptocurrencies other than bitcoin, making it generally more challenging for law enforcement to counter.

4)     Where to Find Security Holes in Serverless Architecture - Application security is getting a twist with the rise of serverless architectures, which introduce a new way of developing and managing applications - and a new wave of related security risks. Businesses are looking to serverless architectures to drive simplicity and reduce cost. Applications built on these platforms scale as cloud workloads grow, so developers can focus on product functionality without worrying about the operating system, application server, or software runtime environment.

5)     49% Indian companies not likely to secure sensitive data in cloud - While an overwhelming majority of global firms have adopted cloud services, there is still a wide gap in the level of security precautions applied by them, a survey has revealed. Almost half of Indian organizations say they are not likely to secure sensitive data in the cloud. Globally, organizations said only two-fifths of the data stored in the cloud is secured with encryption and key management solutions.

6)     Man pleads guilty to launching DDoS attacks against former employers - A man from New Mexico has admitted to launching distributed denial-of-service (DDoS) attacks against former employers, as well as possessing a firearm illegally. On Wednesday, the US Department of Justice (DoJ) said John Kelsey Gammell has pleaded guilty in a St. Paul, Minnesota court to directing DDoS attacks against former employers, business competitors, companies that refused to hire him and websites for law enforcement and courts, among others. Gammell not only set up the DDoS attacks, which launch traffic in such volumes that online services are disrupted, on his own computers but also paid DDoS-for-hire services to hammer victims further.

7)     Oman's stock exchange was easily hackable for months - The security flaw made the securities market an easy target and was only fixed after a security researcher sent more than half-a-dozen warning emails. A core router for Oman's stock exchange, the Muscat Securities Market, had both its username and password as "admin" for months, even after several attempts by a security researcher to warn the exchange of the security implications.

8)     Uber ignores security bug that makes its two-factor authentication useless - Uber has ignored a security bug that can allow an attacker to hack into user accounts by bypassing two-factor authentication because the ride sharing company says the flaw "isn't a particularly severe" issue. Two-factor authentication (2FA) is a vital part of protecting online accounts. It adds a second layer of security on top of your username and password -- which can be stolen -- by sending a code by text message to your phone, for example, which only you would have access to.

9)     Behavioral biometrics missing from cybersecurity - Recently, there’s been an uptick in the adoption of the NIST Cybersecurity Framework, a set of guidelines aimed at helping organizations improve their overall cybersecurity process. In December 2017, NIST released the second draft of its framework. Among the updates were two critical additions to the Identity Management, Authentication and Access Control guidance. Rather than being shocked by each new data breach, ransomware attack or instance of fraud, companies are increasingly working to improve their cybersecurity posture, and not just internal information security professionals.

Up to 40K Affected in Credit Card Breach at OnePlus - Chinese smartphone manufacturer OnePlus has reported a credit card breach affecting up to 40,000 users at oneplus.net. Users who entered their credit card data on the website between mid-November 2017 and January 11, 2018 could be at risk. The malicious script has been eliminated, the infected server quarantined, and all relevant system structures reinforced. Users who paid using a saved credit card, the "Credit Card via PayPal" option, or PayPal should not be affected, OnePlus reports.


Wednesday, January 17, 2018

iNews - Around The World This Week

1)     Hospital pays $55,000 in bitcoin to hackers after 'SamSam' ransomware locks systems - A US hospital has reportedly paid hackers $55,000 (£39,900) to restore control over its computer systems after they were infected with a strain of ransomware known as 'SamSam'. Last Thursday (11 January), staff at Hancock Regional Hospital, Indiana, found their computers had been infected with malware, which was demanding bitcoin to regain access. As reported, the hack impacted emails and health records, but no patient data is believed stolen.

2)     Privacy: The Dark Side of the Internet of Things - Before letting an IoT device into your business or home, consider what data is being collected and where it is going. There's a lot of buzz about the Internet of Things (IoT), but people aren't quite sure what to think of it. Back in fall 2016, there was a big attack on an Internet service provider in which a bunch of IoT devices became a botnet and made much of the Internet unavailable. It was a big moment that made people question the security of IoT. And although security risks are getting the headlines right now, and should certainly be considered, the bigger risk with IoT is privacy.

3)     Hackers hijack Twitter account of India's top diplomat to post photos of Pakistan's flag - The verified Twitter account of India's top diplomat to the United Nations was briefly taken over by suspected Turkish hackers early on Sunday, 14 January, morning. The Turkish hacking group Ayyıldız Tim claimed responsibility for the attack and managed to take over the president of the World Economic Forum's account over the weekend as well.

4)     IT Security Spending to Reach $96 Billion in 2018 - Worldwide IT security spending is expected to climb 8% next year to $96.3 billion, fueled by investments in identity access management and security services – two areas on tap to rise faster than the overall spending growth rate, according to a Gartner report released this week. Identity access management and security services to drive worldwide spending growth.

5)     The state of Israel’s cybersecurity market - The Equifax breach, WannaCry, NotPetya, the NSA leak, and many more cyber incidents – 2017 was certainly a busy year for hackers, illustrating yet again just how vital innovative cybersecurity solutions are in the fight against cyber threats. Second only to the U.S., in terms of cybersecurity investment 2017 was another excellent year for Israeli cybersecurity startups, with dozens of companies being formed, breaking fundraising records and producing solid exits. The 2017 data also suggest that the Israeli cybersecurity industry is maturing, as we see a shift in funding towards later stage companies.

6)     Top think tank warns cyberattacks could lead to 'inadvertent nuclear launches' - A new report from the Chatham House think tank has warned that cybersecurity vulnerabilities could lead to accidental nuclear war if countries carrying the hugely destructive warheads do not introduce new measures. While cybersecurity is a prevalent issue many sectors of society now have to consider, nuclear weapons systems were developed during a technological era when " little consideration was given to potential malicious cyber vulnerabilities", the report states.

7)     What is FakeBank? New banking malware can intercept SMS messages to steal sensitive data and funds – Security researchers have discovered a mobile malware strain that can intercept users' sensitive SMS messages to steal their banking details and funds, phone numbers, balance on a linked bank card and location data. According to Trend Micro researchers, the malware dubbed "FakeBank" has been spotted in several SMS/MMS management software apps and primarily targets victims in Russia and other Russian-speaking countries.

8)     Watch out for this Netflix phishing scam that will steal your credit card details - Netflix users are being warned to avoid clicking on any suspicious email links after a phishing scam was uncovered, which security experts say is designed to steal credit card details. Found by Australian cybersecurity firm MailGuard, and shared on Twitter by the New South Wales police, the fake emails use convincing social engineering tactics – including the official Netflix website layout – in an attempt to dupe recipients into entering financial details.


9)     Hyper-Converged Infrastructure To Accelerate IT Transformation - Technology is fast becoming the key pillar for organizations to stay competitive, spur innovations, and seize new growth opportunities. Despite increasing IT budgets, the traditional three-tier architecture, is proving to be a hindrance to meeting the rising business and market demands due to its inbuilt complexities. Apart from that, the stress to reduce operational costs and improve productivity is also forcing technology teams to explore alternative means to bring down complexity and costs through the adoption of agile architectures.

Blockchain Technology Goes Beyond Cryptocurrency - Cryptocurrency, the digital currency system that enables global monetary transactions between two parties without the need for a trusted third party financial institution, has gained tremendous momentum over the last few years. Bitcoin, the first cryptocurrency, came into existence in January 2009. Its inventor, Satoshi Nakamoto (an anonymous person or a group) published a whitepaper prior to this in October, 2008. Since then, numerous cryptocurrencies have come into existence. More recently, bitcoin has gained mainstream attention. Under the hood, the technological innovation is the blockchain that is seen as revolutionary foundational technology having a tremendous potential across different verticals.

Thursday, January 11, 2018

Making GDPR a priority for the year 2018

“ You can resist an invading army; you cannot resist an idea whose time has come,” once said Victor Hugo wisely.

Today, in India, that idea is privacy. To date, privacy has not put up much of a fight; that will change in 2018. After a couple of years of getting fringe interest, privacy has, quite quickly, hit a tipping point.
The advent of EU’s General Data Protection Regulation (GDPR), only adds to that movement. So, how is GDPR going to impact Indian organisations and what should you, the IT leaders, be doing to ensure that your organisation complies with GDPR regulations.
The EU General Data Protection Regulation (GDPR) becomes enforceable by law in May of 2018. It will require global organizations that hold the personal data of European Union residents to adhere to new requirements around control, processing and protection.
GDPR will have a far-reaching impact the digital economy
The GDPR probably won’t affect a large swathe of small and medium Indian businesses. But given the penalties (more on this later), that’s not a chance your business wants to take. Also, it is expected that many countries will follow the EU in terms of updating their regulations to match this new standard for data protection.
If not already, it is time to know if your company has or processes any data of a European company or a European citizen. Remember, the citizen doesn’t have to be residing in a country that’s part of the EU—just that she is a citizen. (Which countries are part of the EU?)
Given, the GDPR comes into force in May of 2018, it leaves Indian companies who haven’t started preparing only about two quarters to do so.
Preparing for GDPR is critical
Delaying preparation for GDPR isn’t the best approach. Procrastinating isn’t going to make the GDPR go away!
Like any law, the worst case only applies if your company has suffered a data breach and is challenged by a European company or citizen--and you can’t prove you have complied with the GDPR.
Any personal data breach impacting a European Union resident will need to be reported within 72 hours. Companies that do not comply will face fines of up to 20 million Euros or 4 percent of global turnover, whichever is higher. Infringements of a more technical nature call for penalties that amount to 2% of annual global revenue, or €10 million.  Those who have not budgeted for the long-term implications of the GDPR will struggle.
Complying with GDPRs Conditions
Our own research shows that complying with erasure (the right of EU nationals to scrubbed clean off your servers and the servers of your partners) is what concerns businesses the most (51%).
That said, there a host of that need to be met; how difficult they are to comply with comes down to maturity of your company’s data practices.
Here’s a slightly long, yet an-easy-to-read, list of changes that the GDPR has brought about.
What Needs to Change?
Plenty. The way your company asks for consent and collects data, how that data is stored and processed, the way your data supply chain is constructed, who your company shares data with, the number of technology partners your company uses for data back-up and archiving, the cloud services it chooses—all of this, and more, needs to change.
The majority of businesses will be stunned by the regulation’s impact on their operations, as it creates security challenges that cannot be solved solely with technology.
Smart companies will see this not just through the compliance lens but as a feature of their security policy. Fundamentally, the GDPR changes the way we look at data security.
Data is important because it belongs to people or is important to people, hence the focus on privacy. GDPR will put humans back at the centre of security debate. And is another idea whose time has come.

Tuesday, January 9, 2018

iNews - Around The World This Week

1)     Breach of India's Biometric Database Puts 1 Billion Users at Risk – A breach of the Unique Identification Authority of India's Aadhaar biometric system is putting personally identifiable information (PII) of more than 1 billion Indian residents at risk, reports the Tribune, an Indian publication. Attackers created a gateway to the biometric database, in which any Aadhaar user's ID number can be entered into a portal, the Tribune reports. Once the number is entered, it will pull up the resident's name, address, postal code, photo, phone number, and email address, according to the Tribune.

2)     Google Apps Script vulnerability could lead SaaS apps to download malware – Google Apps Script is vulnerable to exploits that could allow malware to be delivered via URLs. Attackers could automatically download arbitrary malware hosted in Google Drive to a machine -- and the victim would have no idea it was happening. This type of attack is different from phishing and malware distribution via links to Google Drive URLs, which are fairly common. These normally involve sending a Microsoft Office doc, which is enabled to run macros when the user gives permission.

3)     Android malware targets bitcoin, bank apps, including SBI, HDFC, Axis Bank: Report - If you are using banking or cryptocurrency apps on your mobile phone, you need to read on. An Android Banking Trojan called Flash Player has affected over 232 banking apps, many of which are mobile apps of prominent Indian public as well as private banks. Android mobile phone users having third party app stores - an online app market to install apps, just like Google Play but not owned by Android OS or Google - run the risk of accidentally downloading this malware, putting confidential security details like netbanking customer id and password at risk. Links to download this can also come through spam emails or SMS.

4)     Enterprise machine learning will double and jump start business growth and adoption, Deloitte predicts – Machine learning will intensify amongst medium and large-sized enterprises, doubling the number of implementations and pilot projects using machine learning technology in 2018 compared to last year, and then doubling again by 2020. According to Deloitte’s Technology, Media and Telecommunications (TMT) Predictions, advancements in machine learning technology include data science automation and a reduced need for training data as well as new chips in both data centers and mobile devices. The advancements will help establish the foundation, which will over the near term make machine learning mainstream across industries where organizations have limited talent, infrastructure and data to train models.

5)     Payment system, network security under RBI radar - The Reserve Bank of India has again flagged cyber risks faced by banks and said it would continue to do surprise drills and inspections to ensure that they have systems in place to deal with any threats to payment systems and network security. While the assessment is factored in the overall risk profile of a bank under risk-based supervision, certain specific areas like payment systems and network security are proposed to be subjected to more intensive scrutiny during the year.

6)     Meltdown and Spectre: ‘worst ever’ CPU bugs affect virtually all computers – Serious security flaws that could let attackers steal sensitive data, including passwords and banking information, have been found in processors designed by Intel, AMD and ARM. Everything from smartphones and PCs to cloud computing affected by major security flaw found in Intel and other processors – and fix could slow devices.

7)     Behavioral biometrics will replace passwords by 2022 – In just a few years, we can all safely forget those cumbersome passwords we use to secure and unlock our devices. And we will be able to thank on-device artificial intelligence (AI) for easing the strain on our memory. Smartphones will be an extension of the user, capable of recognizing them and predicting their next move. Gartner analysts believe on-device AI, as opposed to cloud-based AI, will mark a paradigm shift in digital security, and will do so sooner than most people think.

8)     SplashData reveals the worst passwords of 2017 and they're still astonishingly terribleAfter trawling through the more than five million passwords that have leaked over the past year, mostly in North America and Western Europe, the California-based company said any one of the passwords included in its list of 100 worst passwords of the year would put users at "grave risk" of identity theft. For the fourth year in a row, "123456" took the top spot as the worst password of the year followed by "password". Naturally, variations of these two such as extra digits or replacing the "o" with a "0" (zero) in "password" were also included in the list.

9)     The Future of Seamless Hybrid Clouds – In a world that appears to be dominated by clouds -- both public and private -- the underlying infrastructure that provides connectivity becomes largely invisible to users. Indeed, one of the major promises of cloud is that the pools of resources that power the cloud can reside anywhere, are elastically available, and are dynamically adjusted to accommodate the fluctuating needs of the applications they power. The cloud is already a fractured marketplace, a situation that will only get worse. As cloud becomes more mainstream for enterprises, they will each focus on the things that make themselves attractive. If we assume for a moment that each of them will have some success, the likelihood that enterprises end up putting all of their resources into a single cloud seems low.

Bitcoin price rise could lead to smart home attacks and higher bills, cyber security expert warns – People’s homes could come under attack as a consequence of bitcoin’s price surge, a cyber security expert has warned. “Cryptojacking” incidents, in which people’s devices are quietly hijacked and forced to mine digital currencies for other people, are on the rise. “Any device that is ‘smart’ now has the three key ingredients to provide the cyber bad guy with everything they need – internet access, power and processing.

Tuesday, December 26, 2017

iNews - Around The World This Week

                       

Date – 24th December, 2017
1)     Russia's Fancy Bear APT Group Gets More Dangerous – Fancy Bear, the Russian advanced persistent threat group associated with the infamous intrusion at the Democratic National Committee last year among numerous other break-ins, may have become just a little bit more dangerous. Encryption and code refreshes to group's main attack tool have made it stealthier and harder to stop, ESET says. The fourth and latest version of the malware comes with new techniques for obfuscating strings and all run-time type information. The techniques, according to ESET, have significantly improved the malware's encryption abilities. The Fancy Bear/Sednit group also has upgraded some of the code used for command and control (C&C) purposes and added a new domain generation algorithm (DGA) feature for quickly creating fallback C&C domains.

2)     Cybersecurity: A priority area for the Indian Government - India’s rapid transition towards digital economy coupled with national projects like Digital India, Smart Cities, National Broadband Network and so on are altering the digital landscape rapidly with direct impact on governance, transparency, and accountability. With the drive towards a digital economy, a large amount of consumer and citizen data will be stored digitally, and many transactions will be carried out online, by individuals, companies, as well as government departments. This rapid change towards a digital environment has brought to fore the challenges of certain security risks and concerns, particularly to human and nation’s cybersecurity.

3)     Comprehensive Endpoint Protection Requires the Right Cyber Threat Intelligence - A recent report from Grand View Research predicts that the cyber threat intelligence (CTI) market will reach $12.6 billion by 2025. This growth in demand isn't surprising when you consider the ongoing success of so many high-profile and extremely damaging attacks. This climate of increasingly sophisticated breaches has moved many organizations — particularly, those that handle and retain sensitive data — to upgrade their cybersecurity measures by adding CTI and incident forensics. CTI falls into three main categories -- tactical, operational, and strategic -- and answers questions related to the "who, what, and why" of a cyber-attack.

4)     Fileless Malware Attacks Hit Milestone in 2017 - Fileless malware attacks using PowerShell or Windows Management Instrumentation (WMI) tools accounted for 52% of all attacks this year, beating out malware-based attacks for the first time, according to Carbon Black's 2017 Threat Report. Non-malware attacks account for the majority of all attacks this year, and ransomware grows to a $5 billion industry, new data shows. Kryptik, Strictor, Nemucod, Emotet, and Skeeyah were the five top malware families this year, according to the report. And the top three industries hit this year by malware authors included finance, healthcare, and retail.

5)     Google Sheds Light on Data Encryption Practices - Google explains the details of how it secures information in the cloud and encrypts data in transit. Following a year of major cyberattacks and security threats, Google has published two whitepapers to explain how it secures data. One focuses on encryption of data in transit; the other on service-to-service communication using Application Layer Transport Security (ALTS).

6)     What's next for cybersecurity in 2018? - We live in a world that is networked together, where companies rely on networked systems and their data is stored in the cloud. The year 2018 will bring more connectivity, digital transformation initiatives, and data to companies, along with a number of new cybersecurity threats and landscape changes making cybersecurity one of the most crucial issues that need to be addressed in the present scenario.

7)     CROOKS SWITCH FROM RANSOMWARE TO CRYPTOCURRENCY MINING - Criminals behind the VenusLocker ransomware have switched to cryptocurrency mining in their latest campaign targeting computer users in South Korea. Instead of attempting to infect targeted computers with ransomware, the group is now trying to install malware on PCs that mines for Monero, an open-source cryptocurrency. Researchers said the shift by threat actors is also spurred by anti-ransomware mitigation efforts that have made infecting systems with malware harder.

8)     Digital Transformation Emboldens Cyber Adversaries—Can Cybersecurity Keep Up? - Businesses are accelerating their digital transformation, seeking to leverage their online presence to enrich products, deepen customer relationships, and boost their brand ecosystems. However, with this rapid growth comes difficulty. As organizations expand into digital channels, their digital footprint, i.e., all their external-facing assets including websites, email servers, social landing pages, and pages created outside proper protocol, also expands to potentially unmanageable proportions.

9)     The Internet of Things Is Going to Change Everything About Cybersecurity - Cybersecurity can cause organizational migraines. In 2016, breaches cost businesses nearly $4 billion and exposed an average of 24,000 records per incident. In 2017, the number of breaches is anticipated to rise by 36%. The constant drumbeat of threats and attacks is becoming so mainstream that businesses are expected to invest more than $93 billion in cyber defenses by 2018. Even Congress is acting more quickly to pass laws that will — hopefully — improve the situation. Despite increased spending and innovation in the cybersecurity market, there is every indication that the situation will only worsen. The number of unmanaged devices being introduced onto networks daily is increasing by orders of magnitude, with Gartner predicting there will be 20 billion in use by 2020.

10)  How AI is the Future of Cybersecurity - The frightening truth about increasingly common cyber-attacks is that most businesses and the cybersecurity industry itself is not prepared. Beyond the lack of preparedness on the business level, the cybersecurity workforce itself is also having an incredibly hard time keeping up with demand. By 2021, there are estimated to be an astounding 3.5 million unfilled cybersecurity positions worldwide.


Courtesy - Ivalue.



Thursday, December 21, 2017

Right to Privacy:

Right to Privacy: Why This Is a Big Win for People and Security of Their Personal Data

“You can’t have privacy without security” Larry Page, Google’s CEO, famously said at a TED Conference, a few years ago.
Today, closer home, that rings true. 
A few months ago when Right to Privacy found its way into the Indian Constitution, it marked a great first step towards recognizing the increasing—and often neglected—need to strengthen security to protect data and privacy.
Never before has there been a clarion call to create a robust regime for data protection. That’s something the Supreme Court has demanded of Indian organizations and the government. I think that’s quite significant.
That presents a remarkable opportunity for Indian organizations to step up their security efforts, and at the same time, build a culture that upholds the need to protect customer data. 
It evidently means here’s a chance for Indian companies to create a solid framework and a strong cybersecurity policy that ensures data protection. That, in itself, is a big win for the privacy of personal data.
Much to Gain
In the age of social media and e-commerce, as data increasingly becomes a commodity, protecting this data also becomes an imperative.
Simply put, the more important data becomes, the more important are the tools to protect data.
And when customers are confident that their data is in safe hands, they are more than willing to part with it. For businesses, this is an indicator of customer trust, which boosts customer retention and new customer acquisition, leading to increased revenue.
Recently, Nasscom’s President R. Chandrashekhar said that the Supreme Court ruling significantly boosts India’s attractiveness as a safe destination for global sourcing which according to him is “another win”. As a growing digital economy, that’s great news for Indian businesses who can take advantage of increased customer confidence. 
Outside Indian shores, the European Union’s General Data Protection Regulation (GDPR) requires all businesses—across the world--collecting data of EU citizens to become fully accountable for protecting any data categorized as ‘personal.’ With the Right to Privacy ruling, Indian businesses that cater to the European market will feel a step closer to ensuring they comply with GDPR.
Protecting Customer Privacy
In order to preserve the essence of privacy, Indian organizations need to provide an increased sense of visibility and control over confidential customer data.
To do so, they need to first recognize and assess the hands that hold customer data: Your employees.
That means there needs to be an increased focus on the people who create, touch and move customer data. One way to do that is to turn to Behavioral Analytics. It helps organizations monitor how their employees are handling customer data and detect suspicious behaviour.
That’s even more pertinent now that customer data has become the lifeline of most organizations. Industries like telecom, financial and healthcare services, e-commerce firms and government agencies that collect a large amount of sensitive personal data will have to re-evaluate their data strategy.
They will have to provision for new norms that vow to protect customer data and privacy, first and foremost. The Right to Privacy ruling has opened new doors for businesses by providing an opportunity to strengthen security to protect privacy, and thereby gain customer confidence.

Monday, December 18, 2017

iNews - Around The World This Week

1)     TRITON Malware Targeting Critical Infrastructure Could Cause Physical Damage – Security researchers have uncovered another nasty piece of malware designed specifically to target industrial control systems (ICS) with a potential to cause health and life-threatening accidents. Dubbed Triton, also known as Trisis, the ICS malware has been designed to target Triconex Safety Instrumented System (SIS) controllers —an autonomous control system that independently monitors the performance of critical systems and takes immediate actions automatically, if a dangerous state is detected. According to separate research conducted by ICS cybersecurity firm Dragos, which calls this malware "TRISIS," the attack was launched against an industrial organization in the Middle East.

2)     Newly Uncovered 'MoneyTaker' Hacker Group Stole Millions from U.S. & Russian Banks - Security researchers have uncovered a previously undetected group of Russian-speaking hackers that has silently been targeting Banks, financial institutions, and legal firms, primarily in the United States, UK, and Russia. In the past 18 months, the hacking group is believed to have conducted more than 20 attacks against various financial organizations—stolen more than $11 Million and sensitive documents that could be used for next attacks. Since its first successful attack in May last year, MoneyTaker has targeted banks in California, Illinois, Utah, Oklahoma, Colorado, South Carolina, Missouri, North Carolina, Virginia and Florida, primarily targeting small community banks with limited cyber defenses.

3)     Security Flaw Left Major Banking Apps Vulnerable to MiTM Attacks Over SSL - A team of security researchers has discovered a critical implementation flaw in major mobile banking applications that left banking credentials of millions of users vulnerable to hackers. The affected banking apps include HSBC, NatWest, Co-op, Santander, and Allied Irish bank, which have now been updated after researchers reported them of the issue. SSL pinning is a security feature that prevents man-in-the-middle (MITM) attacks by enabling an additional layer of trust between the listed hosts and devices. When implemented, SSL pinning helps to neutralize network-based attacks wherein attackers could attempt to use valid certificates issued by rogue certification authorities.

4)     Here's where 'Smart Hospitals' will make big tech investments in the near future - Building on top of today’s digital infrastructure, Smart Hospitals will focus on patient experience, outcomes, the Triple Aim and they’ll make expensive acquisitions between now and 2025. Smart hospitals optimize, redesign, or build new clinical processes, management systems and potentially infrastructure, enabled by underlying digitized networking of interconnected assets, to provide a valuable service or insight, which was not possible or available earlier, to achieve better patient care, experience, and operational efficiency. Digital transformation is happening in almost every industry and healthcare is no exception. Analyst house IDC earlier this year pegged the global DX market at escalating as high as $20 trillion in the coming years.

5)     The next big thing in pharmacy supply chain: Blockchain - With $200 billion lost to counterfeit drugs annually and patient safety issues, a chain-of-custody log that blockchain could enable holds promise. Blockchain has the potential to transform healthcare in general and the pharmacy supply chain in particular. The distributed ledger technology could offer legislative, logistical and patient safety benefits for pharmaceutical supply chain management. From a regulatory perspective in the United States, blockchain technological and structural capabilities, in fact, extraordinarily map to the key requirements of the Drug Supply Chain Security Act.

6)     Healthcare Faces Poor Cybersecurity Prognosis - The healthcare industry is underestimating security threats as attackers continue to seek data and monetary gain. Threat actors rarely attack with the intent of causing physical harm, most are looking for financial gain. eSentire reports patient records are worth between $0.05 and $2.42 USD each. Attackers can sell them on the Dark Web, use them for tax fraud or blackmail, or for conducting spear phishing campaigns. Opportunistic attacks are common because of the amount of vulnerable devices.

7)     As India Surveys Bitcoin Exchanges, West Toughens Its Regulations - Once voiced by a cryptocurrency enthusiast, “Bitcoin will do to banks what email did to the postal industry” has now been raised by Israel’s Prime Minister Benjamin Netanyahu while speaking of cryptocurrencies, exchanges and cryptocurrency regulations. “Is the fate of banks that they will eventually disappear? Yes. The answer is Yes. Does it need to happen tomorrow? And do we need to do it through Bitcoin? That’s a question mark!” stated the PM.

8)     Kaspersky Lab Detects 360,000 new Malicious Files Daily - The number of daily detected malicious files reflects the average activity of cybercriminals involved in the creation and distribution of malware. The number of daily detected malicious files reflects the average activity of cybercriminals involved in the creation and distribution of malware. This figure was calculated for the first time in 2011 and totaled 70,000 at that time. Since then it has grown five-fold, and as the 2017 data shows, it is still increasing. Most of the files identified as dangerous fall into the malware category (78 percent). However, viruses – whose prevalence significantly dropped 5-7 years ago, due to their complex development and low efficiency - still constitute 14 percent of daily detections.

9)     USB Encryption and Security Falls Well Short - A recent survey from Apricorn of more than 400 IT professionals from industries including education, finance, government, healthcare, legal, manufacturing, retail and manufacturing, reveals that most employees use USB drives, but that companies are leaving themselves open to data breaches and leaks by not effectively monitoring these devices and the data that gets written to them. However, eight out of 10 employees use non-encrypted USB drives such as those received free at conferences, tradeshow events or business meetings, which could be easily lost or stolen and fall into the wrong hands, or introduce malware into a company’s host system.

10)  We need to talk about mathematical backdoors in encryption algorithms - Governments and intelligence agencies strive to control and bypass or circumvent cryptographic protection of data and communications. Backdooring encryption algorithms is considered as the best way to enforce cryptographic control. Security researchers regularly set out to find implementation problems in cryptographic algorithms, but not enough effort is going towards the search for mathematical backdoors, two cryptography professors have argued.


Credits - Nagesh of Ivalue.