Tag: hacker

  • IronNet Cybersecurity adds new integrations to Collective Defense Platform

    IronNet Cybersecurity adds new integrations to Collective Defense Platform

    IronNet Cybersecurity, the leader in network detection and response and collective defense, announced new integrations with leading cloud, endpoint, and firewall platforms. These integrations enhance and expand the benefits of IronNet’s Collective Defense Platform for security operations teams.

    New capabilities in this release include integrations with:

    • Amazon Web Services (AWS): Adding new IronNet sensors that enable customers to leverage IronNet’s Collective Defense Platform to secure their AWS deployments.
    • Crowdstrike Falcon EDR: Enabling security analysts to seamlessly investigate threats detected by IronNet from the network to the host, and to contain compromised hosts.
    • Palo Alto Networks Strata Next-Generation Firewalls Native Response: Enabling security teams to generate firewall responses and stop threats detected by IronNet.
    • ZScaler Nanolog Streaming Service (NSS) Analysis: Enabling IronNet customers to apply IronNet’s IronDefenseⓇ NDR behavioral detection to HTTP/HTTPS logs.
    • Microsoft Office 365: Adding IronDefense behavioral detection of malicious login attacks targeting Microsoft’s productivity SaaS suite.

    In addition to these integrations, the new release includes:

    • New User & Entity Behavior Analytics (UEBA) to detect identity- and authentication-focused attack techniques.
    • Improved lateral movement and port-scanning detection.

    “The ability to correlate cloud, network, endpoint, and other security telemetry data into a richer, more complete picture of a risk-based event helps organizations more effectively evaluate and mitigate a threat. And that is the real value that network intelligence and threat analytics solutions like IronNet offer,” said Christopher Kissel, Research Director, Security & Trust Products, IDC. “IronNet’s additional capability to share information anonymously across a community of peers and enable security analysts to collaborate on threats is a noticeable differentiator in light of the rise of nation-state level cyber-attacks.”

    This expansion of IronNet’s capabilities continues the company’s momentum of growth in both technology and partnerships. David Lathrop, Vice President of the Utility Strategic Business Unit with Unlimited Technology, Inc., said, “IronNet’s latest release is exactly the kind of ecosystem support that helps us provide the unique, comprehensive cyber solutions we offer through the Enterprise Security Program Review.” Unlimited Technology is a founding partner, along with IronNet, DirectDefense, and Exero, of the ESPR, announced in January.

    “Empowering security teams and maximizing the effectiveness of their security investments against cyber threats targeting their enterprise, industry, or region is core to our Collective Defense mission,” said Don Closser, IronNet’s Chief Product Officer. “Together with our security ecosystem partners, IronNet can offer our customers a true, defense-in-depth approach that helps them reduce time to detection and scale up their ability to respond to cyber threats. This is especially important as factors like digital transformation and expanding supply chains are increasing the threat landscape exponentially.”

  • Over 100 Financial Firms Hit by DDoS Attacks

    Over 100 Financial Firms Hit by DDoS Attacks

    More than 100 financial firms were victims of distributed denial-of-service attacks by the same threat actor with North America and Europe overwhelmingly making up the dominant share, according to a recent report.

    Cyber intelligence sharing group FS-ISAC said that over 100 financial services firms were targets of a wave of distributed denial-of-service (DDoS) attacks – a method of overloading a web system with requests in order to prevent it from functioning properly.

    Interestingly, the report claims that the attacks were conducted by the same threat actor within a short period of time.

    The criminals sent extortion notes threatening to disrupt the firms’ websites and digital services, the report said. The threat actor methodically moved across jurisdictions in Europe, North America, Latin America, and Asia Pacific, hitting dozens of institutions within weeks.

    According to the report, North America and Europe made up an overwhelming share of the DDoS attacks with 43 percent and 38 percent, respectively. Asia (15 percent) and Latin America (3 percent) made up less than one-fifth.

    By sub-sectors, retail banking dominated the list, accounting for 41 percent of the DDoS attacks. This is followed by exchange (15 percent), payments (13 percent) and, securities and investment (10 percent).

    In 2021, we have already seen new cyber threats in the form of supply chain attacks, which we can expect to proliferate and evolve quickly, said FS-ISAC’s chairman of the board Jerry Perullo  «The only way to stay ahead of these ever more sophisticated threat actors is to collaborate. Now more than ever, we need global leaders to model what effective sharing looks like to the rest of our community as well as the industry at large.

  • Apple is giving out a special iPhone that can lead to a $1 million reward

    Apple is giving out a special iPhone that can lead to a $1 million reward

    Apple is giving out special versions of the iPhone to security researchers who have the opportunity to collect as much as $1.5 million from Apple. Announced last week at the Black Rock cybersecurity conference in Las Vegas (where ironically Apple earlier this year put up a billboard reading “What happens on your iPhone stays on your iPhone”), the tech giant is giving these experts the task of hacking into the iPhone to find vulnerabilities and security flaws. Apple security chief Ivan Krstic says that these special iPhones come with “advanced debug capabilities.” Unlike the units sold to consumers, these will allow researchers to access parts of iOS that are off-limits to most users.

    The so-called iOS Security Research Device Program will get underway next year and while anyone can apply to receive one of the special iPhone units, Apple says that there will be a limited amount handed out. Most likely only qualified security researchers will be able to obtain one of these devices. Even though they will be much more open than a store-bought iPhone, the researchers won’t have the same access that Apple’s own internal security team has on their iPhones.

    Companies like Apple and Google pay these researchers to find flaws as an incentive. In addition, Apple would prefer that a security expert who finds a vulnerability tell the company about it instead of selling it or using it for their own evil intentions. Flaws found on iOS are said to bring researchers as much as $1 million from hackers willing to pay that much. Apple announced last week that a researcher can receive $1 million by finding a flaw allowing him or her to take over full control of an iPhone without the owner touching the handset. Other flaws can also handsomely reward a researcher as Apple is willing to pay up to $500,000 for the information. Google announced last month that it will pay up to $30,000 to a researcher finding flaws in its Chrome browser while paying $150,000 if it is told about a flaw that can compromise its Chrome OS.

    “We want to attract some of the exceptional researchers who have thus far been focusing their time on other platforms. Today many of them tell us they look at our platform and they want to do research but the bar is just too high. We have by far the highest maximum payouts in the industry, and we have the iOS security research device program for exceptional researchers that are new to our platform”-Ivan Krstic, head of security engineering and architecture, Apple

    Researchers who find a vulnerability in code found on beta software will receive a 50% bonus from Apple. That is to reward an expert who has identified a problem before the bug is passed along to the public, and brings the top possible award handed out by Apple to $1.5 million. As the company’s security chief points out, “The second-best reason to have a bug bounty is to find out about a vulnerability that’s already in the users’ hands and fix it quickly. The number one best reason is to find a vulnerability before it ever hits a customer’s hands.”

    Apple’s new program might have received more applause if it wasn’t for the limited number of special iPhones it is handing out. As iOS security researcher Will Strafach noted, “It’s a huge step, but I do think it would be great if there were a bit more wide availability of the devices.” Apple might be concerned that the wider availability of these units might lead to several ending up in the wrong hands, creating more problems for the company. Still, with all this money at stake, regular iPhone owners should benefit from the incentives that Apple is throwing at security experts.

  • India bank hack ‘similar’ to US$81m Bangladesh central bank heist

    India bank hack ‘similar’ to US$81m Bangladesh central bank heist

    Hackers who tried to steal nearly US$2 million from India’s City Union Bank this month used tactics similar to those employed in the unsolved cyber heist of US$81 million from Bangladesh’s central bank in 2016, City’s CEO said on Monday (Feb 19).

    The unknown hackers disabled the City printer connected to global payments platform SWIFT on Feb 6, preventing the bank from receiving acknowledgement messages for three fraudulent payment instruction sent that evening until the next morning.

    “Nobody suspected that it was an attack and thought it was a systemic network failure,” N Kamakodi said on phone. “The system department people, everybody assembled, analysed the problem, rebooted, they closed shop only around 10.00pm to 10.30pm.”

    The next morning, bank officials managed to reconcile the previous day’s transactions and found out “three transactions which were not originated from our bank”.

    The bank had been able block only one of the transfers worth US$500,000, while attempts were under way to retrieve the rest, he said. It first disclosed the heist on Saturday.

    In the case of Bangladesh Bank, hackers infected the system with malware that disabled the SWIFT printer. Bank officials in Dhaka initially assumed there was simply a printer problem.

    The hackers stole the money from Bangladesh Bank’s account at the Federal Reserve Bank of New York using fraudulent orders on SWIFT. The money was sent to accounts at Manila-based Rizal Commercial Banking Corp and then disappeared into the casino industry in the Philippines.

    Nearly two years later, there is no word on who was responsible and Bangladesh Bank has been able to retrieve only about US$15 million, mostly from a Manila junket operator.

    “We definitely see similarities between the Bangladesh case, and the similarities are being factored into the investigation,” Kamakodi said.

    City Union, a small private lender based in south India, said the three money transfer instructions were sent via correspondent banks to accounts in Dubai, Turkey and China.

    He said SWIFT was helping it investigate the matter, and that the hack happened despite the bank adding new security measures days before.

    “It’s a cat and mouse game,” he said.

    SWIFT said it did not comment on individual customers or entities.

    Russia’s central bank said last week that unknown hackers stole 339.5 million roubles (US$6 million) in an attack via the SWIFT international payments messaging system in Russia last year.

     

  • Heightened danger in Singapore as cyber attacks increase

    Heightened danger in Singapore as cyber attacks increase

    Ransomware has rapidly moved from a “nuisance” to a public threat which could now endanger lives, a director of Singapore’s Cyber Security Agency told the CommunicAsia2017 conference on Tuesday.

    Ho Ka Wei, a director at the National Cyber Threat Analysis Center at the Cyber Security Agency of Singapore, said an increase in attacks in recent weeks-including the global WannaCry attack-has put agencies on “high alert” and led to “sleepless nights and non-stop action.”

    Ransomware attacks on the health system and facilities such as hospitals have the potential to threaten people’s lives, he said.

    “The number of attacks is increasing,” said Ho. “No one is spared.”

    “Critical infrastructure and government institutions continue to be attractive targets, and we see new sophisticated forms of ransomware and malware,” he said. “And now they are coming in malicious combos like WannaCry-which is both ransomware and a worm.”

    Attacks were also increasing in strength and power, with some measured at over one terabyte per second, where previously “20 gigabytes a second was considered quite high.”

    Ho outlined recent Advanced Persistent Threat (APT) attacks at two Singapore Universities in April, which were “carefully planned” with perpetrators seeking to steal government information and research.

    The APTs were designed to gain unauthorized access to networks and lurk there for long periods to access information.

    These attacks, at NTU and NTS, were identified and computers were isolated and then replaced.

    The threat environment, said Ho, escalates on a monthly basis, and will reach new levels with the unstructured rise of the IoT if rigorous action is not taken and standards enforced.

    “If IoT devices are unsecured by default, then they can be controlled and used,” said Ho. “The level of escalation is serious.”

    Singapore created the Cyber Security Agency two years ago under the auspices of the Prime Minister’s Office, and the country announced its first Cyber Strategy in October last year.

    Ho outlined four pillars to the strategy: to build a resilient infrastructure, create safer cyberspace, develop a vibrant cybersecurity ecosystem, and strengthen international partnerships.

    Digital technology, he said, was critical to Singapore’s “smart nation efforts” and the increased number of attacks from “new vectors” was a key national risk to overcome.

  • Singtel teams with SIT to train cybersecurity talent

    Singtel teams with SIT to train cybersecurity talent

    Singtel has announced a new partnership with the Singapore Institute of Technology (SIT) to train cybersecurity talent.

    The work-study program will support SIT students in the areas of Information Security and Software Engineering, which is expected to lead to career pathways such as cyber security R&D, product development, and management, cyber analysis and forensics, operations and cyber architects.

    Singtel country CEO and CEO, Group Enterprise Bill Chang said the undertaking aims to address two critical skills needs locally – the short supply of trained software engineers and the growing worldwide threat posed by cyber threats.

    “The economy is in great need for trained cybersecurity professionals,” he said.

    Under the work-study programs, participating students are trainees of the supporting company. They get to gather meaningful work experiences through industry induction, close mentorship, attachments and capstone projects to deepen industry-relevant skills.

    The students would acquire skills and experience relevant to the needs of the company while the company gains a productive contributor and an avenue to recruit, assess, groom and retain talent.

    Singtel has also worked with the InfoComm Development Authority of Singapore (IDA) on the Cyber Security Associates and Technologists Program.

  • Massive data breach exposes all Philippines voters

    Massive data breach exposes all Philippines voters

    The Philippines’ 55 million voters are now susceptible to fraud and other risks after a massive data breach leaked the entire database of the Commission on Elections (Comelec), security firm Trend Micro has warned.

    The defacement of the Comelec website by a hacker group called Anonymous Philippines happened at near midnight on March 27. In a message to the government, the group said they want the poll body to implement tighter security measures on the precinct count optical scan (PCOS) machines to be used in the May 9 polls.

    “But what happens when the electoral process is mired with questions and controversies? Can the government still guarantee that the sovereignty of the people is upheld?” the hackers posted in the defaced Comelec website.

    A report said a second hacker group called LulzSec Pilipinas posted within day an online link to the Comelec’s whole database. The following day, the group also reportedly updated the post to add three mirror links to an index of files that could be downloaded.

    Trend Micro said the leak may turn out as the biggest government-related data breach in history, surpassing the Office of Personnel Management (OPM) hack in 2015 that leaked personally identifiable information (PII), including fingerprints and social security numbers (SSN) of 20 million US citizens.

    While the Comelec has given assurances to the public the day after the hacks that the no sensitive information was compromised and the country’s second automated polls will be secure, the securty firm believes otherwise.

    “Based on our investigation, the data dumps include 1.3 million records of overseas Filipino voters, which included passport numbers and expiry dates. What is alarming is that this crucial data is just in plain text and accessible to everyone,” the security firm said in a blog post.

    “Interestingly, we also found a whopping 15.8 million record of fingerprints and a list of people running for office since the 2010 elections,’” it added.

    “Among the data leaked were files on all candidates running on the election with the filename VOTESOBTAINED. Based on the filename, it reflects the number of votes obtained by the candidate. Currently, all VOTESOBTAINED file are set to have NULL as figure.”

    Regardless whether the hacking could affect the elections, the security firm said there is still the issue of all voter information that was leaked.