Retail News CRM

Tag: Security

  • New iOS 17.3 feature will keep a thief out of your iPhone and your banking apps

    New iOS 17.3 feature will keep a thief out of your iPhone and your banking apps

    Now that Apple released iOS 17.2, the first iOS 17.3 developer beta has been released and includes a new feature that might frustrate iPhone thieves. Stolen Device Protection uses certain tools to prevent criminals from employing a stolen iPhone passcode to have the run of an iPhone that is at a location normally not associated with the owner of the device. If an iPhone is at such a location and Stolen Device Protection is enabled, the handset will require that Face ID or Touch ID be used before allowing certain actions to be made.

    Actions that require either Face ID or Touch ID when an iPhone is in an unusual location include viewing passwords stored on the device and wiping the phone. A one-hour delay will be called for when creating a new Apple ID password. After the hour, Face ID or Touch ID will still be required to change the password. The delay is essentially buying time for the owner to report his phone stolen.

    Apple adds another layer of biometric protection to the iPhone in iOS 17.3; Image Credit Beta Profiles.

    Other actions that require biometric approval when Stolen Device Protection is enabled and an iPhone is away from the user’s usual locations include applying for an Apple Card, turning off Lost Mode, and accessing and using payment methods stored in Safari. If Face ID or Touch ID fails and Stolen Device Protection is enabled, the user cannot use his/her passcode to sign in.

    The following actions will require Face ID or Touch ID when Stolen Device Protection is enabled:

    • Viewing/using passwords or passkeys saved in iCloud Keychain
    • Applying for a new Apple Card
    • Viewing an Apple Card virtual card
    • Turning off Lost Mode
    • Erasing all content and settings
    • Taking certain Apple Cash and Savings actions in Wallet
    • Using payment methods saved in Safari
    • Using your iPhone to set up a new device

    The following actions require Face ID or Touch ID and the final action is delayed by one hour:

    • Changing your Apple ID password
    • Updating select Apple ID account security settings, including adding or removing a trusted device, trusted phone number, Recovery Key, or Recovery Contact
    • Changing your iPhone passcode
    • Adding or removing Face ID or Touch ID
    • Turning off Find My
    • Turning off Stolen Device Protection

    Stolen Device Protection is supposed to prevent a scam that starts when someone makes friends with an iPhone user or spies on one in order to obtain his/her passcode. Sometimes this is done by looking over the shoulder of the iPhone user or by asking to see a photograph and watching as the iPhone user unlocks his handset using his/her passcode.

    The thief then steals the iPhone, enters the purloined passcode, resets the Apple ID password, disables Find My, performs a factory reset, and sells the device. A working iPhone is more valuable in the black market than one that is locked down; the latter device is generally sold for parts. Alternately, the thief could use the passcode to steal passwords for banking and other financial apps, email passwords, and more that are stored in the iCloud Keychain.

    If Apple keeps the new feature in the final version of iOS 17.3, most iPhone users won’t get this feature until sometime early next year. If you installed the first developer beta of iOS 17.3, you can enable Stolen Device Protection by going to Settings > Face ID & Passcode > Stolen Device Protection.

  • Apple patching a serious WebKit flaw by disseminating iOS 16.5.1 (c)

    Apple patching a serious WebKit flaw by disseminating iOS 16.5.1 (c)

    Back on June 21st, Apple disseminated iOS 16.5.1 and iPadOS 16.5.1. But soon it was discovered that the updates had a flaw in the WebKit browser engine that could lead an attacker to create an arbitrary code execution which would allow said attacker to run any command or code on a targeted device. That is a serious problem and to top it off, Apple said that it had reports that the vulnerability was being actively exploited.
    Instead of having to develop iOS 16.5.2 and iPadOS 16.5.2, Apple decided to use its Rapid Security Response feature to push out iOS 16.5.1 (a) and iPadOS 16.5.1 (a). These updates can be installed in a matter of minutes and can be quickly disseminated to Apple device users to patch a serious vulnerability such as the one that was supposed to be patched by Monday’s update. Note that we said that the update was “supposed” to patch the flaw. That’s because the updates sent out to fix the WebKit issue on Monday had issues of their own.
    According to several iPhone and iPad users, the updates changed the user agent for Safari. The user agent tells server information about the device requesting content from it so the server knows what information to send out. For example, the user agent will determine whether a request to see a phone manufacturer’s website should return the U.S. site with models sold in the States priced in Dollars, or whether it should show the site created for European buyers that lists models offered on the continent with prices posted in Euros.
    As a result of the issue with the user agent, iPhone, and iPad users complained that they were not able to access sites like Zoom, Facebook, and Instagram after installing iOS 16.5.1 (a) and iPadOS 16.5.1 (a). Apple, realizing that there was a problem with the updates, pulled them yesterday and even included directions on how to delete them. But if you haven’t deleted the updates, don’t worry. Apple has now released iOS 16.5.1 (c) and iPadOS 16.5.1 (c).
    We said the other day that the vulnerability was too serious for Apple not to push out another patch right away, and now it has happened. To download and install the updates, go to Settings > General > Software Updates and follow the directions. Hopefully, Apple won’t be taking these updates back.
  • 1Password rolls out support for Passkeys in beta for browsers

    1Password rolls out support for Passkeys in beta for browsers

    Following its announcement that 1Password was all in on passkeys and were ready to say goodbye to the old-fashioned password, the company is now rolling out passkey support to its users. This initial roll out will only be available in beta, with some caveats.

    Just as major players such as Google, Apple, and Microsoft have joined the FIDO alliance in order to come up with a solution that can replace the use of passwords, and therefore make logins more secure, 1Password made the move last year to join as well. This solidified 1Password’s commitment to taking the next big step and provide passkey support in its very popular password manager.
    Today, the company announced that the day is here and that its users can now begin to save and sign in to online accounts using passkeys. This can only be accomplished using the beta version of the 1Password extensions for Chrome, Firefox, Edge, and Brave (on MacOS, Windows and Linux), and Safari on MacOS.
    Additionally, the 1Password apps for Mac, iOS, Windows, Android, and Linux have also been updated so that users can view, modify, move, share, and delete any passkey that have already been generated using the beta extensions. Also, 1Password’s Watchtower feature — which alerts you when a site has been hacked and recommends when you should change your password — has also been updated in beta to alert you when a site that you log in to has added passkey support.
    To get started with using passkeys on 1Password, you will first need to make sure you have installed the beta extension for the supported browsers mentioned above. Once installed and logged in to, you should be able to open a passkey-enabled website.
    If this is the first time you visit that site, you can create an account for it with the option to use a passkey instead of a password. However, if you are visiting a site you already have an account for, you can sign in as usual and then search for the passkey login option in your account settings and update/save your passkey credentials.
  • Samsung Internet’s latest release focuses on privacy and security

    Samsung Internet’s latest release focuses on privacy and security

    The 17th iteration of Samsung Internet is finally ready for primetime, the South Korean company confirmed this week. We’ve previously reported about the beta version of Samsung Internet 17.0, but if you missed the news, here is what’s coming in this release.

    As the title says, this release mainly focuses on privacy and security. First off, Samsung Internet 17.0 further improves the AI-powered Smart anti-tracking feature, which is now turned on by default. The privacy function is meant to prevent third parties attempting to track users’ personal information from being successful at that.

    Additionally, Samsung Internet 17.0 offers users an interesting overview of how the browser is protecting their web experience. The updated version of the browser features a visual snapshot of a user’s privacy dashboard via the Quick Access page, which provides a detailed record of weekly activities and settings that can be adjusted.

    The latest version of Samsung Internet now allows users to take advantage of external security or on-device security keys as an alternative for SMS or app-based two-factor authentication.

    Last but not least, Samsung Internet 17.0 comes with several improvements to its overall user experience such as the ability to drag and drop tabs into custom tab groups. Also, the update brings enhanced search experience across bookmarks, history and saved pages. The official version of Samsung Internet 17.0 is now available for download on Google Play and Galaxy Store.

  • Samsung Internet browser adds new privacy and safety features, User Experience improvements

    Samsung Internet browser adds new privacy and safety features, User Experience improvements

    Samsung’s internet browser app is about to get another big update that focuses mainly on security and User Experience improvements. Released as Samsung Internet Beta 17, the most recent app build brings new features that further enhance privacy and safety.

    The highlight of Samsung Internet Beta 17 is Smart Anti Tracking, a privacy and security feature that allows smartphones to automatically remove tracking cookies. Everything is possible thanks to the on-device machine learning, which identifies trackers used by a website and removes them.

    The Smart Anti Tracking feature will be turned on by default in regions like Europe, South Korea and the United States, which means users these parts of the world won’t have to worry about enabling it. The rest of the world can look for the new feature in the setting menu and choose to Always enable it or just when Secret mode is active.

    Furthermore, Samsung Internet Beta 17 make HTTPS scheme the default way to browse websites. Unlike the previous HTTP scheme, HTTPS provides a much safer way to transfer data between the browser and a server.

    Another interest new feature is the addition of a new panel to the Quick Access Page called “privacy board.” This is where you can get an overview of your security and privacy settings for easy access, and it also provide the ability to see Privacy reports.

    More importantly, Samsung Internet Beta 17 introduces “Live Text,” a new feature that allows users to copy, translate or web search on text within an image on the internet. To do that, you just have to long press on an image in the web page and a new Live Text UI should pop up to let you choose what you want to do.

    Along with these new features that focus on privacy and safety for the most part, Samsung has included a bunch of UX enhancements. Here are the most important ones:

    • Bottom URL bar: When tapping the URL bar using the ‘bottom layout’, the URL bar will be shown directly above the keyboard when editing. All the basic functions and interactions are the same as the top layout.
    • Shortcut to move to Customize menu: Move to Customize menu when long pressing on any button of Tools menu to make it easier to edit items
    • Drag and Drop in Bookmark: Provides Drag and drop to move bookmark item in the Bookmark bar
    • Video subtitle position enhancement: Subtitle position enhancement of Subtitle extension for Fullscreen video.

    Samsung Internet Beta 17 is available as a separate download via the Galaxy Store. If you don’t feel like testing a non-final version of the software would be a good idea, you can definitely wait for the stable version to come out in the just a few weeks (hopefully).

  • Samsung allegedly fell victim to a data breach

    Samsung allegedly fell victim to a data breach

    There has been a new security breach in the tech industry. This time, the victim was reportedly Samsung Electronics. The hackers taking responsibility for the data breach are from the Lapsus$ hacking group. Lapsus$ has leaked around 190GB of what it claims to be confidential data from Samsung, which includes source code and biometric unlocking algorithms.

    As proof of the data breach, Lapsus$ has also provided a screenshot of C/C++ code directives, alleging that they came from Samsung. In a description of the 190GB of stolen data the hacking group teased before the big leak, they wrote that these 190GB contain “confidential Samsung source code” and listed exactly what the hacking group managed to steal from Samsung.

    With its hack, Lapsus$ got its hands on the source code for every Trusted Applet (TA) installed in Samsung’s TrustZone. Samsung TrustZone is a secure environment utilized for operations such as hardware cryptography, binary encryption, and access control.

    Lapsus$ also managed to steal algorithms for all biometric unlock operations, the source code used for booting all recent Samsung devices, and confidential source code allegedly originating from Qualcomm. With its attack, Lapsus$ also stole the source code for Samsung’s activation servers, аs well as that used for authorizing and authenticating Samsung accounts, including APIs and services.

    Although the information above is what Lapsus$ listed as the stolen data, it is unknown if Lapsus$ stole additional secret information from Samsung. What is known, however, is that the hacking group has split the leaked data into three compressed files and made it available for download via a torrent.

    As for a comment from Samsung about the data breach, Samsung officials told the media outlet that they ‘are now assessing the situation.’

  • Credit Suisse Securitizes Yachts With Derivatives

    Credit Suisse Securitizes Yachts With Derivatives

    Credit Suisse used complex derivatives to offload the risks of billions in loans to oligarchs and tycoons to hedge funds.

    Credit Suisse securitized a portfolio of loans linked to the yachts and private jets of its wealthiest clients using derivatives, allowing the bank to offload the risks from lending to ultra-wealthy oligarchs and entrepreneurs. The loans amounted to about $2 billion.

    The securitization was handled by a unit in the bank which had been sanctioned previously. Due to the unusual collateral underlying the securitization, it offered an interest rate of more than 11 percent to attract hedge funds to the $80 million transaction, the report said, citing an investor presentation.

    The presentation revealed that a third of the 12 defaults on its yacht and aircraft loans in 2017 and 2018 were related to US sanctions against Russian oligarchs. Earlier press reports said that oligarchs Oleg Deripaska and brothers Arkady and Boris Rotenberg had to cancel their private jet leases with the bank.

    The Swiss bank, which only began lending to yachts in 2014, has expanded the business with outstanding loans topping $1 billion last year.

    In a statement sent to finews.com,  Credit Suisse said:  This synthetic risk-weighted asset transfer, which priced in line with other significant risk transactions, offered competitive investment and hedging terms for our professional investor clients while increasing the capital flexibility of the bank.

  • Google VPN now available on iPhone

    Google VPN now available on iPhone

    Google’s VPN feature, part of the Google One service, just received three new features on Android. The new features are:

    • Safe Disconnect enables you to use the internet only when the VPN is active.
    • App Bypass allows you to choose specific apps to use a standard connection rather than the VPN.
    • Snooze allows you to disable your VPN temporarily.

    In addition to these new features, Google has also made its VPN service available on iOS, which means that users can now use Google’s VPN on an iPhone as well. But sadly, the new features mentioned above may not be accessible on an iPhone at this time.

    According to Google’s blog post, privacy and security are ‘always core to everything’ Google makes. In this regard, Google’s VPN utilizes ‘advanced’ built-in security, which prevents anybody from linking you to your browsing activity.

    Google also stated that its VPN service has a ‘full certification’ from the Internet of Secure Things Alliance, and because it is an open-source service, it has been audited by an independent party. So, if you have any doubts about whether you can trust Google with your “private” internet browsing, you can even see the report from the audit.

    Google’s VPN service is available only in 18 countries. Some of them are the US, Canada, the UK, Germany, Spain, Italy, France.

    You can use Google’s VPN on your Android phone or your iPhone by subscribing to Google One’s Premium subscription plan, which costs $9.99 per month or $99.99 per year.

  • Singapore, UK sign MOUs on digital trade, digital identities and cybersecurity

    Singapore, UK sign MOUs on digital trade, digital identities and cybersecurity

    Singapore and the United Kingdom will work more closely to facilitate digital trade between the countries, as part of a partnership that will make digital transactions by businesses easier, safer, and cheaper.

    The partnership was deepened by the inking of three memorandums of understanding (MOUs) by the two countries on Monday (Nov 29).

    The MOUs will strengthen the digital connectivity between them, said Singapore’s Ministry of Communications and Information and the UK’s Department for Digital, Culture, Media and Sport in a joint statement.

    “In 2019, 70 percent of UK cross-border services exports to Singapore were digitally delivered,” said the government organizations. The exports amounted to £3.2 billion (S$5.8 billion) in value.

    “These MOUs will further support opportunities to grow digital delivery of cross-border services between the UK and Singapore, provide a basis for working closely with like-minded digital partners, and help set a global benchmark on high-standards digital cooperation to bring economic and societal benefits to both countries,” they added.

    The MOUs will also support the shared goals and key tenets of the UK-Singapore Digital Economy Agreement, which seeks to promote trusted, robust and connected digital markets for people and businesses.

    The agreement, which is being negotiated, will establish rules to enable trusted cross-border data flows and ensure high standards in data protection.

    Singapore’s Minister for Communications and Information Josephine Teo and the UK’s Secretary of State for Digital, Culture, Media and Sport Nadine Dorries signed the MOUs in London on Monday.

    Mrs. Teo is also in London to attend the London Future Tech Forum, which aims to facilitate discussion on the role of technology in supporting open societies and tackling global challenges, among other things. Participants include governments and those from academia.

    Under the first MOU, the countries will share knowledge and implementation of pilot projects in areas such as electronic trade documents and invoicing.

    This will help drive the development and adoption of digital trade facilitation solutions at a bilateral and international level, said the ministries.

    Benefits to the digitalization of trade include improving accessibility for small and medium-sized enterprises to engage in cross-border trade, among other things.

    “The sharing of best practices will also influence the creation of secure global supply chains and interoperable digital ecosystems,” added the ministries.

    Under the second MOU, Singapore and the UK will work more closely to develop mutual recognition of digital identities between the countries.

    The MOU is “an important step in the route to achieving interoperability of digital identity regimes between different jurisdictions”, which can allow for more reliable identity verification and faster processing of applications, among other things, the ministries added.

    “This would, in turn, reduce barriers in cross-border trade and enable businesses and individuals to navigate the international digital economy with greater ease, confidence and security.”

  • China Tells Firms To Boost Cyber, Data Security Oversight On Connected Vehicles

    China Tells Firms To Boost Cyber, Data Security Oversight On Connected Vehicles

    China’s industry ministry published a notice on Thursday telling companies to step up cyber and data security oversight over connected vehicles, saying that security risks in the industry had become increasingly prominent.

    All relevant companies should establish data security management systems and regularly assess risks from network attacks, the Ministry of Industry and Information Technology said in a statement.

  • DBS Digital Exchange to Grow Security Token Offerings

    DBS Digital Exchange to Grow Security Token Offerings

    The platform plans to tap on the growing popularity of cryptocurrencies and digital assets among corporate investors, accredited individuals and family offices.

    DBS plans to list at least half a dozen security tokens by end-2022 on DDEx, the bank’s institutional-focused digital asset exchange, the exchange’s chairman said on Monday.

    According to Eng-Kwok Seat Moey, who is also head of capital markets, the bank’s position as one of the biggest wealth managers in Asia and its expertise in originating deals in capital markets would help it attract users and grow trading volume.

    The bank listed its first security token on the platform in May 2021, in the form of a S$15 million digital bond.

    Eng-Kwok repeated CEO Piyush Gupta’s target of growing the digital exchange’s investor base to about 1,000 customers this year, and said DBS wants to grow this number by 20-30 percent annually for the next three years as digital tokens gain acceptability.

    DDEx was launched in December 2020 with an initial offering that covered cryptocurrency trading. As of August 2021, it housed around 400 investors with close to S$130 million ($95.8 million) of digital assets in its custodial services.

  • Instagram introduces new security feature against hackers

    Instagram introduces new security feature against hackers

    Instagram is taking a powerful new step to combat account hacking and malicious activity on their social media platform. If you yourself haven’t experienced your Instagram account getting compromised, you probably know at least a couple of friends who have. It’s a fairly widespread phenomenon, as unpleasant as it may sound, and it’s about time something is done about it.

    As of Tuesday, Instagram is introducing a new feature on the platform called Security Checkup, which is aimed to maximize account security and facilitate recovery for anyone whose personal account may be at risk.

    No matter whether they have already been compromised or are simply vulnerable in some way, Security Checkup will prompt users to go through all the necessary steps to secure their account, which includes updating necessary profile information and account settings.

    In a recent news post, Instagram announced that “Security Checkup will guide people, whose accounts may have been hacked, through the steps needed to secure them. This includes checking login activity, reviewing profile information, confirming the accounts that share login information and updating account recovery contact information such as phone number or email.”

    Even if you haven’t necessarily been hacked, Security Checkup will prompt you to take all the important measures to ensure there is an infinitesimal chance of that ever happening in the future.

    Instagram already strongly encourages you to have two-factor authentication, which drastically decreases the chances of that and can be easily set up by going to Profile > Settings > Security > Two-factor authentication.

    With 2FA enabled, anytime there is a login attempt from an unrecognized location, you’ll be immediately alerted with the option to approve or deny the request from your personal device. Instagram also keeps track of all devices which have recently logged into your Instagram, and which can be viewed by going to Settings > Security > Login Activity. From there, you can remotely log out of any devices you don’t recognize on the list.

    You should also make sure your e-mail and phone number are the ones you are using currently, as keeping that info up to date will ensure smooth verification should any suspicious activity be detected.

    Instagram also emphasizes that one of the most common ways in which malicious parties gain entry into personal accounts is through impersonating Instagram itself, and sending out DM’s pretending they are working for the platform.

    “They may tell you that your account is at risk of being banned, that you are violating our policies around intellectual property, or that your photos are being shared elsewhere,” the post warns. These are apparently fairly common tactics scammers use in an effort to bully people into sharing their login credentials.

    Instagram stresses that it will never, ever try to contact users of the platform via Direct Messages. This means that if you see such a message claiming it’s from Instagram or asking for any personal info, you should automatically know it is malicious and immediately report the message to Instagram and block the account.

    • To report an Instagram post, tap on the three dots appearing at the top right
    • To report a message, tap and hold on it until a menu appears
    • To report an account, go to the profile and tap on the three dots at the top right

    If Instagram ever needs to contact you for any reason, rather than DM-ing you, they can reach you through an “Emails from Instagram” tab in the app’s settings. That is “the only place you will find direct and authentic communication from Instagram on the app,” the company says.

    Thanks to some new updates to the Support Inbox on Instagram, you can now easily view the status of any and all messages, posts, or accounts you have reported, and find out whether or not Instagram has taken any action. You can also keep track of your own posts’ status, to see if they are breaking any rules—and if they are, you can directly repeal them from there.

  • Huawei’s 7th Cyber Security and Privacy Protection Transparency Center opens its doors in China

    Huawei’s 7th Cyber Security and Privacy Protection Transparency Center opens its doors in China

    Huawei has opened its 7th and largest Global Cyber Security and Privacy Protection Transparency Center in Dongguan, China, with representatives from GSMA, SUSE, the British Standards Institution, and regulators from the UAE and Indonesia speaking at the opening ceremony. During the opening ceremony, H.E. Dr. Mohamed Hamad Al Kuwaiti, head of cybersecurity, UAE, delivered a keynote on the importance of cyber cooperation for a resilient and vibrant digital future.

    Along with the opening of the new center, Huawei also released its Product Cyber Security Baseline, marking the first time the company has made its product security baseline framework and management practices available to the industry as a whole. These actions are part of the company’s broader efforts to engage with customers, suppliers, standards organizations, and other stakeholders to jointly strengthen cybersecurity across the industry.

    “Cybersecurity is more important than ever,” said Ken Hu, Huawei’s rotating chairman, at the opening of the Dongguan center. “As an industry, we need to work together, share best practices, and build our collective capabilities in governance, standards, technology, and verification. We need to give both the general public and regulators a reason to trust in the security of the products and services they use on a daily basis. Together, we can strike the right balance between security and development in an increasingly digital world.”

    Over the past few years, industry digitalization and new technologies like 5G and AI have made cyberspace more complex than ever, compounded by the fact that people have been spending a greater portion of their lives online throughout the COVID-19 pandemic. These trends have led to a rise in new cybersecurity risks.

    During his speech, Hu also emphasized the importance of cybersecurity and shared responsibility to Huawei. Huawei has been committed to cooperative cybersecurity as early as 2000. There are now more than 3,000 cybersecurity R&D personnel in Huawei. Moreover, Huawei’s annual R&D investment in cybersecurity and privacy protection accounts for about 5% of its total R&D expenses.

    Huawei opened the new Global Cyber Security and Privacy Protection Transparency Center in Dongguan to address these issues, providing a platform for industry stakeholders to share expertise in cyber governance and work on technical solutions together. The center is designed to demonstrate solutions and share experience, facilitate communication and joint innovation, and support security testing and verification. It will be open to regulators, independent third-party testing organizations, and standards organizations, as well as Huawei customers, partners, and suppliers.

    H.E. Dr. Mohamed Hamad Al Kuwaiti, head of cybersecurity, UAE, said, “A public-private partnership will be critical to build collaboration among private, public and government entities so as to establish a globally trusted digital oasis in the UAE.”

    To further a unified approach to cybersecurity in the telecoms industry, organizations like GSMA and 3GPP have also been working with industry stakeholders to promote NESAS Security Assurance Specifications and independent certifications. These baselines have seen wide acceptance in the industry, and will play an important role in the development and verification of secure networks.

    Mats Granryd, director general of GSMA, spoke at the opening of Huawei’s new center. “The delivery of existing and new services in the 5G era will rely heavily on the connectivity provided by mobile networks and will fundamentally depend on the underlying technology being secure and trusted,” he said. “Initiatives such as the GSMA 5G Cybersecurity Knowledge Base, designed to help stakeholders understand and mitigate network risks, and NESAS, an industry-wide security assurance framework, are designed to facilitate improvements in network equipment security levels across the sector.”

    Hu also highlighted the importance of knowledge sharing. At the event, Huawei also released its Product Cyber Security Baseline, the culmination of over a decade of experience in product security management, incorporating a broad range of external regulations, technical standards, and regulatory requirements. The Baseline, together with Huawei’s other governance mechanisms, helps ensure the quality, security, and trustworthiness of the company’s products. Over the years, Huawei has built over 1,500 networks that connect more than three billion people across 170 countries and regions. None of these networks have ever experienced a major security incident.

    Hu emphasized that the more knowledge and best practices we share, the more effectively we can strengthen cybersecurity as a community.

    According to Huawei, the baseline covers 15 categories, 54 requirements, and 112 specific implementation instructions and interpretations, ensuring the high-quality, security, and trustworthiness of Huawei products. It includes 4 categories of legal compliance requirements (prevention of backdoors, prevention of malware and malicious behaviors, protection of user privacy and protection of communication freedom) and 11 categories of security and functional assurance requirements (including secure coding, compilation, sensitive data protection, encryption, secure boot, integrity protection, and lifecycle management).

    “This is the first time we’ve shared our security baseline framework with the entire industry, not just core suppliers,” said Sean Yang, director of Huawei’s Global Cyber Security and Privacy Protection Office. “We want to invite all stakeholders, including customers, regulators, standards organizations, technology providers, and testing organizations, to join us in discussing and working on cybersecurity baselines. Together, we can continuously improve product security across the industry.”

    At present, the industry still lacks a standards-based, coordinated approach, especially when it comes to governance, technical capabilities, certification, and collaboration.

    “Cybersecurity risk is a shared responsibility,” concluded Ken Hu in his opening remarks. “Governments, standards organizations, and technology providers need to work closely together to develop a unified understanding of cybersecurity challenges. This must be an international effort. We need to set shared goals, align responsibilities, and work together to build a trustworthy digital environment that meets the challenges of today and tomorrow.”

    Two years ago, Huawei opened a similar center in Brussels, with others located in the UK, Canada, Germany, Italy, and the UAE.

  • VietinBank Securities expects surge in profits

    VietinBank Securities expects surge in profits

    VietinBank Securities targets pre-tax profits of VND180 billion ($7.8 million) this year, up 20 percent from 2020, as the stock market continues to rise.

    The company secured a $30-million loan from a consortium of four Taiwanese banks in March and another $60 million from Korea’s Woori Bank and Taiwan’s Fubon Bank and Cathay United Bank a month later.

    It is its highest profit target since 2017, with CEO Tran Phuc Vinh explaining that the low deposit interest rates which are diverting funds into the stock market, and the increasing number of new investors are the factors for the optimism.

    The loans provide it with funds for margin financing and investing in corporate bonds and certificates of deposit, Vinh said.

    It reported a 20 percent rise in revenues to VND610 billion last year and an 8 percent increase in pre-tax profits to VND151 billion.

    Vietnam’s benchmark VN-Index has risen 10.5 percent from the end of last year to 1,219.75 points Tuesday. Brokerage FPT Securities forecast that VN-Index could hit 1,351-1,400 points this year.

    The stock market saw nearly 258,000 new trading accounts opened in the first quarter, accounting for 65 percent of the figure recorded in 2020 as a whole, according to the Vietnam Securities Depository (VSD).

    This took the total number of accounts to nearly 3.02 million as of last month, equivalent to 2.8 percent of Vietnam’s population.

  • IronNet Cybersecurity adds new integrations to Collective Defense Platform

    IronNet Cybersecurity adds new integrations to Collective Defense Platform

    IronNet Cybersecurity, the leader in network detection and response and collective defense, announced new integrations with leading cloud, endpoint, and firewall platforms. These integrations enhance and expand the benefits of IronNet’s Collective Defense Platform for security operations teams.

    New capabilities in this release include integrations with:

    • Amazon Web Services (AWS): Adding new IronNet sensors that enable customers to leverage IronNet’s Collective Defense Platform to secure their AWS deployments.
    • Crowdstrike Falcon EDR: Enabling security analysts to seamlessly investigate threats detected by IronNet from the network to the host, and to contain compromised hosts.
    • Palo Alto Networks Strata Next-Generation Firewalls Native Response: Enabling security teams to generate firewall responses and stop threats detected by IronNet.
    • ZScaler Nanolog Streaming Service (NSS) Analysis: Enabling IronNet customers to apply IronNet’s IronDefenseⓇ NDR behavioral detection to HTTP/HTTPS logs.
    • Microsoft Office 365: Adding IronDefense behavioral detection of malicious login attacks targeting Microsoft’s productivity SaaS suite.

    In addition to these integrations, the new release includes:

    • New User & Entity Behavior Analytics (UEBA) to detect identity- and authentication-focused attack techniques.
    • Improved lateral movement and port-scanning detection.

    “The ability to correlate cloud, network, endpoint, and other security telemetry data into a richer, more complete picture of a risk-based event helps organizations more effectively evaluate and mitigate a threat. And that is the real value that network intelligence and threat analytics solutions like IronNet offer,” said Christopher Kissel, Research Director, Security & Trust Products, IDC. “IronNet’s additional capability to share information anonymously across a community of peers and enable security analysts to collaborate on threats is a noticeable differentiator in light of the rise of nation-state level cyber-attacks.”

    This expansion of IronNet’s capabilities continues the company’s momentum of growth in both technology and partnerships. David Lathrop, Vice President of the Utility Strategic Business Unit with Unlimited Technology, Inc., said, “IronNet’s latest release is exactly the kind of ecosystem support that helps us provide the unique, comprehensive cyber solutions we offer through the Enterprise Security Program Review.” Unlimited Technology is a founding partner, along with IronNet, DirectDefense, and Exero, of the ESPR, announced in January.

    “Empowering security teams and maximizing the effectiveness of their security investments against cyber threats targeting their enterprise, industry, or region is core to our Collective Defense mission,” said Don Closser, IronNet’s Chief Product Officer. “Together with our security ecosystem partners, IronNet can offer our customers a true, defense-in-depth approach that helps them reduce time to detection and scale up their ability to respond to cyber threats. This is especially important as factors like digital transformation and expanding supply chains are increasing the threat landscape exponentially.”