News – March 2016


Weakness in iOS enterprise hooks could let bad apps sneak in
March 31, 2016
Mobile device management API could be hijacked to install malicious apps.


Advanced Malware targeting Internet of the Things and Routers
March 30, 2016
The market fragmentation of IoTs or Internet-connected devices is a security nightmare, due to poor security measures implemented by their vendors.


Two more healthcare networks caught up in US outbreak of hospital ransomware
March 30, 2016
New server-targeting malware hitting healthcare targets with unpatched websites.


Trident upgraded to protect against cyber attack
March 29, 2016
Britain’s Trident nuclear deterrent is to be updated to protect it from cyber attack.


Taiwan targeted with new cyberespionage back door Trojan
March 29, 2016
Backdoor.Dripion was custom developed, deployed in a highly targeted fashion, and used command and control servers disguised as antivirus company websites.


Vaccine for CTB-Locker, Locky and TeslaCrypt Ransomware Released
March 29, 2016
Romanian security vendor Bitdefender has updated its vaunted anti-ransomware vaccine to add support for the latest versions of the CTB-Locker, Locky and TeslaCrypt ransomware families currently ravaging users all over the globe.


FBI Has Successfully Unlocked Terrorist’s iPhone Without Apple’s Help
March 28, 2016
The Federal Bureau of Investigation (FBI) has unlocked iPhone 5C involved in the San Bernardino shooting without the help of Apple.


US Agencies Recorded 77,183 Cybersecurity Incidents in 2015, 10 Percent Rise
March 26, 2016
The Office of Management and Budget (OMB) has published its annual cybersecurity report for Congress, as required by the Federal Information Security Modernization Act of 2014.


China launches first cybersecurity organisation: Report
March 26, 2016
China has launched its first cybersecurity public organisation aimed at better safeguarding national cybersecurity and guiding internet companies in perform their duties, the media reported on Saturday.


RFP in Maritime Security Research
March 26, 2016
The DHS Maritime Security Center (MSC) announces a competitive research opportunity to address challenges in maritime cyber security.


Cyber security firm: Wireless mice leave billions open to hacks (Video)
March 25, 2016
Bastille, a cyber security firm in San Francisco, tested wireless mice and observed billions of users may be vulnerable to hacking by third parties.


Attacks could speed revamp of Belgian cybersecurity laws
March 24, 2016
Belgian government says the legislation won’t overstep privacy boundaries.


Diplomat touts Israel as cybersecurity pioneer
March 23, 2016
Israel’s consul general, Ido Aharoni, told a New Jersey gathering of some 600 counterterrorism and law enforcement officials that his country is pioneering new weapons on the “modern battlefield” of war in the digital age.


Hackers Arrested for Attack that Cost the Market $80 Billion
March 23, 2016
It is well documented that cyber attacks are an incredibly costly problem. Grant Thornton estimates that computer hacking costs businesses around the globe an excess of $300 billion a year. In the US alone, firms lost an estimated $61 billion to cyber attacks last year.


Apple encryption case marks opportunity for cybersecurity coordination
March 21, 2016
In a letter to customers on February 16, Apple CEO Tim Cook stated that his company would not willingly override the security features of an iPhone belonging to one of the San Bernardino mass shooters, defying a court order obtained by the FBI.

Money managers starting to buy cyberattack insurance
March 21, 2016
Money managers increasingly are buying cybersecurity insurance to supplement their technology security strategies to both combat data breaches and deal with repercussions if hackers do break in.

Burner phones, not encryption, kept Paris terrorists off the authorities’ radar
March 21, 2016
New details of the Paris attacks carried out last November reveal that it was the consistent use of prepaid burner phones, not encryption, that helped keep the terrorists off the radar of the intelligence services.


Cybersecurity experts offer stern warnings, tips for security in mass-surveillance era
March 19, 2016
FaceTime is actually a pretty secure way to communicate. The FBI can access the camera on your laptop without you knowing about it. And lawyers should think twice before storing their confidential files on Dropbox.


Modern cars ‘increasingly vulnerable’ to cybersecurity threats, FBI warns
March 19, 2016
The FBI has issued a warning that modern cars are “increasingly vulnerable” to hacking after researchers proved it is possible to disable brakes and manipulate steering remotely.


Bank of England to work with new cybersecurity body
March 18, 2016
The first task of Britain’s new cybersecurity centre will be to work with the Bank of England, the government has announced.


Next generation of cyber security experts will be trained in Newport
March 18, 2016
The next generation of cyber security experts will be trained in Newport as the first cyber security academy in Wales is launched.


Once thought safe, DDR4 memory shown to be vulnerable to “Rowhammer”
March 18, 2016
New research finds “bitflipping” attacks may pose more risk than many admit.


Budget 2016: What about cybersecurity spending?
March 16, 2016
Anyone hopeful that IT would get more than a passing nod in today’s Budget 2016 speech will be hugely disappointed.

Our critical infrastructure is too vulnerable to cyberattacks
March 16, 2016
Last week, Sen. Charles Schumer (D-N.Y.) confirmed that, two years ago, the Bowman Avenue Dam in Rye Brook, New York was accessed remotely by Iranian hackers – a move characterized as “shot across our bow” and a clear indication of the tremendous risk that cyber attackers pose.


New Exploit to ‘Hack Android Phones Remotely’ threatens Millions of Devices
March 16, 2016
Millions of Android devices are vulnerable to hackers and intelligence agencies once again – thanks to a newly disclosed Android Stagefright Exploit.


Google Security Expert Criticises Meaningless Antivirus Excellence Awards
March 15, 2016
His problem came from the fact that, at this year’s RSA security conference held at the start of March, Verizon’s ICSA Labs awarded Comodo the 2016 Excellence in Information Security Testing Award.

Former FBI agent on where security leaders need to focus
March 15, 2016
Former FBI Special Agent Leo Taddeo talks about prevention, user experience, and the steps security leaders need to take to improve their profile and boost their results.

Cyber security study reveals lack of boardroom governance across UK industries
March 15, 2016
While 81% of UK boards have increased cyber security scrutiny after the TalkTalk breach, only 53% have data breach management plans in place, a survey has revealed.


Telecoms bosses falling behind on cyber security, economists say
March 15, 2016
Telecoms companies are the most vulnerable businesses in Britain to cyber attacks, yet spend the least on defending themselves against hackers, according to an industry-wide survey.


Google Security Expert Criticises Meaningless Antivirus Excellence Awards
March 15, 2016
One of Google’s top security researchers, Tavis Ormandy, published a blog post in which he criticized antivirus certification programs that award meaningless prizes to flawed security products.


Caribbean countries urged to strengthen cyber security efforts
March 15, 2016
The report analyses the state of preparedness of 32 countries based on 49 indicators.


Boardroom study exposes worrying attitudes to cyber security
March 15, 2016
Cyber security study reveals lack of boardroom governance across the UK’s major industries


Google Is Willing to Pay $100,000 for a Particular Chromebook Exploit
March 14, 2016
Google has updated its bug bounty program for the upcoming year and has doubled a reward for a particular type of Chromebook exploit which no researcher has managed to crack during 2015.


Team GhostShell: 24-year old Romanian claims he’s the man behind famous hacker group
March 14, 2016
A 24-year old Romanian from Bucharest claims that he’s the man behind the famous hacker group Team GhostShell, which has carried out some of the biggest cyber attacks in recent years on the FBI, NASA, and the Pentagon as well as on Russia.


Anti-DDoS Firm Staminus HACKED! Customers Data Leaked
March 14, 2016
Staminus Communications – a California-based hosting and DDoS (Distributed Denial of Service) protection company – is recovering a massive data breach after hackers broke down into its servers and leaked personal and sensitive details of its customers.


FBI threatens to Force Apple to Hand Over iOS Source Code
March 14, 2016
The Department of Justice (DoJ) has warned Apple that it may force the tech giant for handing over the source code to the complete operating system if it does not help the Federal Bureau of Investigation (FBI) unlock the San Bernardino shooter’s iPhone.


Homeland security experts gear up for Milipol Qatar 2016
March 14, 2016
Biennial exhibition and conference set to take place in Doha from 31 Oct – 2 Nov 2016


Hackers Botch $1 Billion Bank Heist Because of a Misspelled Word
March 11, 2016
Hackers that breached Bangladesh’s central bank account at the US Federal Reserve Bank of New York have botched a bank heist which would have pocketed them nearly $1 billion.


CYBER TRENDS – Future Cyber Security & Defence Conference, Czech Republic
March 11, 2016
This October, Prague will traditionally become the venue of a meeting of domestic and foreign defence and security leaders on the occasion of Future Forces Forum.


Dridex Botnet Has Replaced Banking Trojan with Locky Ransomware
March 10, 2016
Dridex botnet that has been distributing banking trojans for years, has now changed its profile entirely and is spreading ransomware instead.


U.S. to blame Iran for cyber attack on small NY dam
March 10, 2016
The Obama administration is planning to publicly blame Iranian hackers for a 2013 cyber attack against a small dam in New York state


Android Trojan Posing as Flash Player Steals Banking and Google Credentials
March 9, 2016
A new Android trojan that’s being detected as Android/Spy.Agent.SI is targeting users for the purpose of stealing their banking and Google account credentials.


China is building a big data platform for “precrime”
March 9, 2016
Using online profile and movements, government aims to catch “terrorists” in advance


Phishers are creating YouTube channels to document their attacks
March 9, 2016
Phishing attacks have linked back to YouTube channels where phishers explain their attacks and promote their tools while looking for buyers.


Worldwide Cybersecurity Spending Increasing To $170 Billion By 2020
March 9, 2016
IT security spending will soar to $101 billion in 2018, and hit $170 billion by 2020, according to a recent story in Investors Business Daily.


Cyber fraudsters reap $2.3 billion through email wire-transfer scams
April 8, 2016
Businesses have lost billions of dollars to fast-growing scams where fraudsters impersonate company executives in emails that order staff to transfer to accounts controlled by criminals, according to the US Federal Bureau of Investigation.


MoD to get Cyber Security Operations Centre
April 8, 2016
The UK’s Ministry of Defence (MoD) is to get its own Cyber-Security Operations Centre (CSOC), after an endowment was announced by defence secretary Michael Fallon.


 

Romanian hacker who exposed Bush family e-mails, photos will be extradited to US
March 7, 2016
“Guccifer” leaked George W. Bush’s amateur paintings, among other things.


The long road ahead: Obama’s cybersecurity action is a step toward change
March 7, 2016
President Obama’s recent announcement of the creation of the Cybersecurity National Action Plan (CNAP) made waves across government and tech audiences,


UK firms at risk due to employees’ lack of cyber-security awareness
March 7, 2016
UK organisations are putting their reputation, customer trust and competitive advantage at greater risk by failing to provide their staff with effective cyber-security awareness.


Apple Users Locked Out Of Files And Ransomed
March 7, 2016
A virus which locks computer users out of their files until they pay a ransom has started targeting Apple devices for the first time.


GCHQ: We Failed On Cybersecurity Despite £1bn Spend
March 6, 2016
UK spy agency GCHQ has admitted it is losing the cybersecurity battle on a national level, despite throwing money at the problem.


Pirates hack into shipping company’s servers to identify booty
March 4, 2016
Pirates used backdoor in shipping company’s website to target freighters.


US to renegotiate rules for exporting Western “intrusion software” to repressive states
March 3, 2016
Inter-agency panel decides just fixing US implementation of export controls isn’t enough.


Small agencies see the potential in OMB’s new cybersecurity plan
March 3, 2016
Small agencies say the administration’s new Cybersecurity National Action Plan (CNAP) could provide the path they need to collaborate and collectively address federal cyber challenges.


DROWN vulnerability could sink secure internet connections
March 2, 2016
New SSL/TLS vulnerability (CVE-2016-0800) could allow attackers to obtain encryption keys.


DIA: Russian Software Could Threaten U.S. Industrial Control Systems
March 1, 2016
Commanders urge Pentagon to bolster cyber defenses for critical infrastructure


More than 13 million HTTPS websites imperiled by new decryption attack
March 1, 2016
Low-cost DROWN attack decrypts data in hours, works against TLS e-mail servers, too.


Snapchat employee payroll data leaked
March 1, 2016
Incident occurred after employee responded to e-mail phish scam.