Cybeats Technologies Acquired by Relay Medical

Cybeats Technologies Acquired by Relay Medical

Relay Medical Corporation has completed the acquisition of an Internet of Things (IoT) cybersecurity firm based in Toronto, Canada.

The completion of the deal to acquire Cybeats Technologies Inc was announced yesterday, just 20 days after news of the transaction was published.

Cybeats was founded in 2016 by Peter Pinsker, Dmitry Raidman, and Vladislav Kharbash. The company is known for developing an integrated security platform that is designed to secure and safeguard high-value connected IoT devices. 

Cybeats’ solution can eliminate malicious code in seconds without affecting the normal operation of the infected IoT device. 

Relay acquired all the issued and outstanding shares of Cybeats for $7,180,000, making a cash payment of $500k. 

Under the deal, Cybeats has become a wholly owned subsidiary of Relay and has placed all its technologies, trade secrets, and intellectual property into Relay’s care.

Relay Medical Corp. CEO Yoav Raiter said that the acquisition was well timed to take advantage of the booming IoT market.   

He said: “The IDC report predicts there to be over 55 billion connected devices by 2025. The global IoT market is growing in an unprecedented way which has left a crucial delta in the cybersecurity of over 20 billion devices worldwide. 

“With this acquisition I believe we are well prepared to address this opportunity, as we already have first-hand experience of applying the value proposition to our own devices.”

CTO of Cybeats Technologies Inc., Dmitry Raidman, said that the cybersecurity of IoT devices is under constant threat. 

He said: “Connected devices became a lucrative target for attackers. We learn on a daily basis about a new type of attack or a new vulnerability exploited in the field and affecting billions of connected things.”

Raidman said that the security of IoT devices had been impacted by the outbreak of Covid-19.  

“There is an endless battle between cybersecurity defenders and attackers,” said Raidman. 

“The transition to working from home and the dependency on smart and remote functionality required for controlling various systems only worsens the problem.”

Relay revealed plans to target several connected devices OEM and ODM companies in sectors such as aerospace, energy, oil & gas, critical infrastructure, and medical.  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#IMOS21: How to Better Understand and Secure Modern Data

#IMOS21: How to Better Understand and Secure Modern Data

Speaking in the opening keynote session of Day Two of the Spring Infosecurity Magazine Online Summit, Wendy Nather, head of advisory CISOs at Duo Security (Cisco), analyzed the chemistry of data, exploring data’s power (for good and bad), creating formulas for data security requirements and driving a data-centric security approach.

Nather outlined that, over the past 40 years, there have been vast changes in how data is stored, accessed and utilized, particularly with the growth of widely distributed, mobile computing and with consumers/enterprises both using the same hardware, software and services.

A consequence of that is that business data and personal data has become blurred, which Nather said, “greatly affects how we view data” and secure it.

Today, it is very difficult to tell the difference between business and personal data, and we are no longer able to only use traditional indicators to distinguish between different data sets. Nather listed such indicators as:

  • When data was created
  • What format it’s in
  • Where it’s located
  • Where it’s used and stored
  • How it was created

Therefore, Nather continued, new indicators must also be considered to better understand and successfully secure modern data. Those indicators are: time, context changes, formulas and delivery methods.

Nather advised security professionals to work to know and better understand:

  • What someone could do with data
  • How time and events affect it
  • When to prune data
  • What business decisions change security and privacy requirements

“Data can be anything and anywhere, so think about context and content,” Nather concluded.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Drug Maker to Pay $50m for Destroying Data

Drug Maker to Pay $50m for Destroying Data

A drug manufacturer in India has been fined $50m for hiding and erasing records ahead of an inspection by the United States Food and Drug Administration (FDA).

The deception occurred at a drug manufacturing plant in Kalyani, West Bengal, that makes active pharmaceutical ingredients (APIs) used in several different cancer drugs distributed to terminally ill patients in the US. 

The plant, which was owned and operated by Fresenius Kabi Oncology Limited (FKOL), was due to undergo an FDA inspection in January 2013. According to documents filed in a federal court in the District of Nevada, records proving that drugs were being manufactured in contravention of FDA requirements were removed from the facility or deleted from the plant’s computers before the inspection took place.

The concealment and erasure of records was carried out by employees at the behest of FKOL management. 

“Kalyani plant employees removed computers, hard copy documents, and other materials from the plant and deleted spreadsheets that contained evidence of the plant’s non-compliant practices,” said a spokesperson for the Department of Justice. 

The United States charged FKOL with the misdemeanor offense of violating the Federal Food, Drug and Cosmetic Act by failing to provide certain records to FDA investigators. 

To resolve the charges, FKOL agreed to plead guilty to the offense. On March 23, the company was sentenced to pay a criminal fine of $30m by US District Judge Jennifer Dorsey, who further ordered FKOL to forfeit $20m.

FKOL was also ordered to implement an ethics and compliance program that will detect, prevent, and correct any future violations of US law relating to the company’s manufacture of cancer drugs intended for terminally ill patients.

The case was investigated by the FDA Office of Criminal Investigations, Los Angeles Field Office, with the assistance of the Central Bureau of Investigation in India. 

Acting US Attorney Christopher Chiou said his office was committed to holding accountable companies that disregard FDA regulations and put consumers’ health at risk.

“Together with our agency partners, we will continue to ensure that drug manufacturers fully comply with their obligations to maintain the integrity of records and data,” said Chiou.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Breach at California State Controller’s Office

Breach at California State Controller’s Office

The California State Controller’s Office (SCO) has suffered a data breach after falling victim to a phishing attack.

Threat actors were able to access email and files after a member of the staff clicked on a malicious link and unwittingly shared their credentials. 

In a data breach notice published March 20, the SCO said: “An employee of the California State Controller’s Office (SCO) Unclaimed Property Division clicked on a link in an email they received and then entered their user ID and password as prompted, unknowingly providing an unauthorized user with access to their email account.”

The SCO said that it had “reason to believe” that personal identifying information contained in unclaimed property holder reports was accessible to whoever compromised the employee’s email account.

An investigation into the incident revealed that the unauthorized user had access to the employee’s email account from 1:42pm on March 18 to 3:19pm on March 19. During this brief window of opportunity, the unauthorized user sent potentially malicious emails to some of the SCO employee’s contacts.

“A notice was emailed to all contacts who were sent an email from the unauthorized user, advising them to delete the email and not click on any links therein,” said the SCO.  

James McQuiggan, security awareness advocate at KnowBe4, commented: “This event supports the issue that all organizations need to educate and phish their employees regularly to ensure they are aware of and know how to spot and report socially engineered emails.”

He advised organizations to take steps to alert users when they receive an external email. 

“A banner or bolded text at the top of the email informing the employee that they are reading an external email, alerts them to pay extra attention, as it could be malicious with attachments or phishing links,” said McQuiggan.

He also advised employees to hover over links to verify if they are legitimate. 

“Sometimes it can be challenging to determine if it is a real link or not. Having an alert tool within the organization where the employees can report potential phishing emails can reduce the risk of attacks and ensure that the employee is taking the proper actions to protect the organization,” said McQuiggan.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

LogMeIn Appoints Michael Oberlaender as CISO

LogMeIn Appoints Michael Oberlaender as CISO

Cloud-based security provider LogMeIn has announced the appointment of Michael Oberlaender at its new chief information security officer (CISO).

Oberlaender has been given responsibility for managing and growing the firm’s security program, both for internal systems and its portfolio of software products. This covers areas such as infrastructure, applications and overall data security.

In this role, he will lead a global security team encompassing IT security, security operations, assurance, engagement, governance, risk management, compliance and more. He will be able to lean on his 30-year career in the industry to fulfil this remit, which has included CISO and advisory positions at Vodafone Deutschland, Cisco systems and Netskope.

Oberlaender also has significant involvement in a number of certification bodies, serving on the board for the ISACA Greater Houston Chapter. He is also a member of (ISC)², ISACA, ISSA and InfraGard (FBI). Additionally, he holds numerous security certifications, including CISM, CGEIT, CISSP, CISA, CRISC, GSNA, ACSE, TOGAF9, CNSS-4016 and CDPP.

Commenting on the appointment, Ian Pitt, chief information officer at LogMeIn, said: “Michael is an established information security leader with a proven track record of developing and leading corporate IT and information security programs for global organizations. We are thrilled to have him join the team at LogMeIn.

“With Michael’s experience, we gain a strategic partner to establish and improve the software development lifecycle and optimize the company’s security culture. We believe his security acumen and leadership abilities will contribute significantly to the success of our security operations and growth of the entire organization.”

Oberlaender stated: “LogMeIn has been at the forefront of the work-from-anywhere era, delivering essential, secure technologies that keep people connected. I wanted to be part of a company that values and engrains security into everything they do, which LogMeIn continually demonstrates.

“I’m excited for the opportunity to combine my industry experience and vision and partner with so many different teams to drive LogMeIn’s security program to the next level, ensuring our products, employees and customers have access to best in class security.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Proton Founder Accuses Apple of “Giving in to Tyrants”

Proton Founder Accuses Apple of “Giving in to Tyrants”

The founder of a privacy centric email and VPN service has hit out at Apple for putting profits before human rights.

Andy Yen is the CEO of Proton Technologies, which produces the ProtonMail and ProtonVPN offerings. He argues that the services were created in part to enable activists, protesters, journalists and others to communicate privately and “overcome internet blocks.”

However, Apple recently blocked a ProtonVPN security update after taking offense at the app’s description in its App Store, which stated: “Whether it is challenging governments, educating the public, or training journalists, we have a long history of helping bring online freedom to more people around the world.”

Apple claimed that in order to resolve the issue, Proton should “ensure the app is not presented in such a way that it encourages users to bypass geo-restrictions or content limitations.”

Yen hit back, arguing that Apple’s actions are at best insensitive in light of current events around the world, and at worst show the tech giant “giving in to tyrants” in order to preserve market access.

“Today, apps like ProtonVPN are a lifeline to the rest of the world for the people of Myanmar who are being massacred. By preventing us from informing users that ProtonVPN can be used to bypass internet restrictions, Apple is making it harder for people to find this lifeline. Apple’s decision will make it even more difficult for the citizens of Myanmar to send evidence of crimes against humanity to the United Nations,” Yen claimed.

“Apple’s actions are also hypocritical. Apple has no problem challenging governments when it is in its own financial self-interest (e.g. avoiding EU taxes or evading anti-trust charges). However, when Proton does it for human rights reasons, it’s suddenly against Apple’s policies.”

As Yen pointed out in his blog post, this is not the first time Apple appears to have “put profits ahead of human rights.”

During the Hong Kong protests of 2020, it removed two apps from its China App Store used by residents to keep up-to-date with local events, after complaints from Beijing.  

In the meantime, Apple continues to push privacy as a key pillar of its marketing campaigns.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Forex Broker Leaks Billions of Customer Records Online

Forex Broker Leaks Billions of Customer Records Online

Over 20TB of sensitive customer data has been accidentally leaked online by a popular online trading broker, after it misconfigured a cloud database.

Researchers at reviews site WizCase spotted the Elasticsearch server left wide open without any encryption or password protection.

They quickly traced it back to FBS, one of the world’s busiest online brokers for foreign exchange (forex) trading, which boasts as many as 16 million global traders.

According to the report, the database contained over 16 billion records, exposing millions of customers’ personally identifiable information (PII).

These included: full names, email and billing addresses, phone numbers, IP addresses, passport numbers, social media IDs and ID verification scans including national ID cards, driver’s licenses, bank account statements, utility bills and credit cards.

Other details included FBS user IDs, unencrypted passwords, login history, loyalty data and password reset links, according to WizCase.

With this kind of trove of PII, scammers could impersonate victims online to commit identity fraud, and/or use the information to obtain even more sensitive details from victims via follow-on phishing attacks.

With scans of both sides of users’ credit cards, cyber-criminals could also quite easily carry out payment fraud, while the leaked password information may lead to account takeover attacks.

Those whose transactions indicate significant wealth may even be targeted at their home address or blackmailed, warned WizCase.

WizCase discovered the leak on October 1 2020 and reached out to FBS the next day. The firm secured the server on October 5, although it’s unclear how long it had been left open before that. Customers are therefore encouraged to contact the broker to check if they’ve been affected by the breach.

WizCase urged those users to change their passwords and enable two-factor authentication on their online accounts, check for unusual bank account activity and to be on guard for phishing attacks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk