Smishing on the Rise

Smishing on the Rise

A new financial crime report by risk management tool developer Feedzai has found an increase in phishing scams perpetrated via text message, a practice known as smishing.

The report analyzed over 1.5 billion global transactions completed in the second quarter of 2021 to paint a picture of the state of financial crime, consumer spending habits, and the top fraud trends.

Purchase scams, where consumers pay for products or services that never arrive, topped the list of fraud scams, followed by scams involving social engineering, impersonation, and account takeover (ATO). 

Smishing, where scammers send text messages to trick consumers into clicking on dangerous links and sharing personal information, made it onto Feedzai’s top five list for the very first time as the fifth most common fraud scam.

Analysis of the data also revealed a continuous move to cashless transactions, with a 146% increase in peer-to-peer (P2P) payments and a 44% decrease in cash transactions. Online transactions grew by 109% to nearly double the number of in-person or card-present transactions. 

Financial criminals have exploited the shift, with the result being that the number of online card fraud attempts increased by 23% between April and July 2021.  

“Cashless payments were already on the rise, but the pandemic accelerated all forms of digital transactions when lockdowns hit,” said Jaime Ferreira, senior director of global data science at Feedzai. 

“Millions more people experienced just how convenient digital payments and banking are when they couldn’t go to a bank branch or a restaurant or grocery store.”

Ferreira warned that the convenience of cashless transactions comes with a cost. 

“Cashless transactions are not the future anymore, they are today,” he said. “Financial institutions and retailers need to address the financial risk and higher complexity attacks that arise with the digital evolution.”

Researchers analyzed the rate of fraud geographically in the United States to reveal the cities with the highest increase in fraud over the past year. Las Vegas, Nevada, which has seen a fraud increase of 411%, topped the list, with New York (up 396%) and Charleston, South Carolina (up 251%) in second and third place, respectively. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Friday Squid Blogging: Strawberry Squid

Pretty pictures of a strawberry squid (Histioteuthis heteropsis).

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Shaping the Future of Cybersecurity

Today marks a significant and exciting step forward for the combined McAfee Enterprise and FireEye businesses as we create a pure play, cybersecurity market leader.

I’m incredibly proud to be writing this as the newly appointed CEO of this combined business. Keeping nations and large enterprises safe is – I believe – one of the most important challenges facing the world today. We have already started working together to bring together the best of McAfee Enterprise and FireEye. Together, we see vast opportunities to develop an integrated security platform powered by artificial intelligence, machine learning, and automation that will offer an unbeatable security portfolio to protect customers across endpoints, infrastructure, applications, and in the cloud. With our combined energies, we will be able to bring these solutions to market faster, and with greater innovation than before.

And we will do this because of our incredibly talented team. Together, we have 5,000 of the best security professionals who have already been working tirelessly to protect our customers. I am energized about bringing together these two teams to relentlessly protect the world from cyberattacks. Our new company culture will be focused on continuing to deliver on this vision, particularly for our customers.

As a combined business, we have over 40,000 customers, including many of the most well-known businesses in the world. And supporting our customers to be more resilient and stay one step ahead of adversaries has always been a priority – that’s why the majority of our enterprise and government customers have worked with our companies for over 16 years. We are committed to continuing to deliver excellence to our customers through this integration.

Today is a monumental day for everyone in this team. It is also a monumental day for the future of threat detection, protection, and response. Together, we will deliver a new model that creates solutions that work together, in a continuous fashion, to secure our customers across the full attack continuum. We are already seen as market leaders, now our story keeps getting better.

The post Shaping the Future of Cybersecurity appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Patching Too Tortuous for IT Pros

Patching Too Tortuous for IT Pros

Patching vulnerabilities is too labor intensive and convoluted a process for most IT security professionals, according to new research by Ivanti

The Utah-based software company surveyed over 500 enterprise IT and security professionals across North America, Europe, the Middle East, and Africa about their patch management challenges. 

Nearly three-quarters of respondents (71%) found patching to be “overly complex, cumbersome, and time consuming,” with more than half (54%) saying that remote work has increased the intricacy and scale of patch management.

Despite the Equifax breach and WannaCry ransomware both involving the exploitation of unpatched vulnerabilities, 62% of IT pros said that other tasks often take priority over patching. 

Patching was reported to have an impact upon productivity, with more than half (60%) of respondents saying that the process disrupts the workflow of users. 

Receiving orders from line-of-business owners once a quarter to skip or delay patching to avoid system shutdowns was reported by 61% of IT and security professionals. 

“These results come at a time when IT and security teams are dealing with the challenges of the Everywhere Workplace, in which workforces are more distributed than ever before, and ransomware attacks are intensifying and impacting economies and governments,” said Srinivas Mukkamala, senior vice president of security products at Ivanti. 

“Most organizations do not have the bandwidth or resources to map active threats, such as those tied to ransomware, with the vulnerabilities they exploit.” 

The research comes as Untangle‘s fourth annual SMB IT Security Report, based on a global survey of 740 small-to-medium businesses conducted in August, found that 80% of SMBs feel more secure now than they did last year.

Most companies surveyed (71%) named finding and fixing vulnerabilities as their most important security priority. More than half (64%) said breaches were their top security concern. 

To protect their business, most companies surveyed (73%) employ firewalls and more than half (62%) use antivirus/anti-malware protection.

“With a changing workplace landscape, and a continued rise in cyberattacks, SMBs have shifted their mindset from ‘it can’t happen to me’ to taking security threats seriously,” said Untangle CEO Scott Devens.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#DTX2021: A Beginner’s Guide to Chaos

#DTX2021: A Beginner’s Guide to Chaos

What is chaos engineering is and how to get started? What are the different types of tests and how does it compare to other options? These were questions that Holly Grace Williams, founder of Akimbo Core, aimed to tackle during a technical session at the Digital Transformation EXPO Europe 2021.

The ‘A Chaos Podcast Presents: A Beginner’s Guide to Chaos’ session began by highlighting Facebook’s recent global outage, which lasted almost six hours. “Facebook runs ‘storm’ drills to ready itself to cope with outages,” Williams affirmed, and this is a form of chaos engineering. 

“But what is chaos engineering?” Williams questioned. Simply, chaos engineering is the concept that “we experiment on production systems in order to build confidence in how those systems will perform under duress.” 

Yet, there is a lot of “incorrect” ideas circulating regarding what chaos engineering is and the experiments involved. “Chaos engineers are not breaking things in production to prove production systems can handle it,” she emphasized. For Williams, chaos engineers are not bringing the chaos; “the chaos is the production system.” 

Examples of chaos engineering include “taking something down” — what happens when you cause a failure on some part of a system? Others include “slowing something down” — what happens if a certain system element performs slowly? 

A central benefit of chaos engineering is that, according to Williams, organizations can use it to identify vulnerabilities before a hacker does or before a system failure. In addition, changes made as a result of chaos engineering testing bolsters confidence in an organization’s systems. With the rise in cyber threats, businesses must ensure their physical resilience and the resilience of their IT systems, stressed Williams. 

Chaos engineering is significant in complex computing environments since these systems can break when unexpected situations occur. 

Williams mentioned that business people are not always open to the idea of “experimenting on production,” a crucial part of chaos engineering. Yet, there is “vast potential” for organizations if they leverage chaos engineering. 

Shifting the focus to practical steps organizations can do to implement forms of chaos engineering, the first is to “start small.” Additionally,”start in test, start on a schedule,” she said. Organizations should also “build-up to production.”

Despite the benefits that chaos engineering introduces, there are challenges. Williams told the audience to beware of the blast radius and cascading failures. Additionally, organizations that want to experiment less frequently “are more likely to slip back into bad practices.”

Wrapping up the session, an audience member queried what role AI and Automation can play in chaos engineering. Williams pointed to the role AI can play in helping track experiments organizations are performing. “Humans aren’t good at randomness,” she stressed. “Machine learning can help chaos engineers track and operate in different ways.” Crucially, ML can also help analyze systems to find problems in a system.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Creates National Cryptocurrency Enforcement Team

US Creates National Cryptocurrency Enforcement Team

The United States Department of Justice (DOJ) has formed a new task force to oversee complex investigations and prosecutions of criminal misuses of crypto-currency.

The creation of a National Cryptocurrency Enforcement Team (NCET) was announced yesterday by Deputy Attorney General Lisa Monaco.

“Today we are launching the National Cryptocurrency Enforcement Team to draw on the Department’s cyber and money laundering expertise to strengthen our capacity to dismantle the financial entities that enable criminal actors to flourish – and quite frankly to profit – from abusing crypto-currency platforms,” said Monaco in a statement dated October 6. 

She added that the DOJ was “poised to root out abuse on these platforms and ensure user confidence in these systems.”

The DOJ’s Office of Public Affairs said that the team’s focus would be on criminal acts committed by virtual currency exchanges, money laundering infrastructure actors, and mixing and tumbling services. 

Working under the supervision of Assistant Attorney General Kenneth Polite Jr., NCET will also assist in tracing and recovering assets lost to fraud and extortion, including crypto-currency payments to ransomware gangs.

NCET will also train and advise federal prosecutors and law enforcement agencies in developing investigative and prosecutorial strategies and provide guidance on matters including search and seizure warrants, restraining orders, criminal and civil forfeiture allegations, and indictment.

“The Criminal Division is already an established leader in investigating and prosecuting the criminal misuse of crypto-currency,” said Polite. 

“The creation of this team will build on this leadership by combining and coordinating expertise across the Division in this continuously evolving field to investigate and prosecute the fraudulent misuse, illegal laundering, and other criminal activities involving crypto-currencies.”

Team members will be drawn from the Department of Justice Criminal Division’s Money Laundering and Asset Recovery Section (MLARS), the Computer Crime and Intellectual Property Section (CCIPS), and detailees to the Criminal Division from US Attorneys’ Offices across the country.

The search is now on for “an individual with experience with complex criminal investigations and prosecutions, as well as the technology underpinning crypto-currencies and the blockchain,” to fill the role of NCET team leader, who will report to the assistant attorney general in the Criminal Division.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#DTX2021: AI Ethics in Practice: How to Turn AI Principles Into Practical Governance and Compliance?

#DTX2021: AI Ethics in Practice: How to Turn AI Principles Into Practical Governance and Compliance?

Where are we at with human interaction with AI? What impact in terms of ethics does this have at the moment? These were the focal topics of investigation during a panel discussion at the Digital Transformation EXPO Europe 2021.

Moderating the ‘AI Ethics in Practice: How to Turn AI Principles Into Practical Governance and Compliance?’ panel  was Sherin Mathew, CEO and founder of Innovation Exchange, who opened the panel by discussing AI through the lens of regulation, particularly how AI regulation can become governmental policy. 

Tim Clement-Jones, co-chair of the All Party Parliamentary Group of Artificial Intelligence, emphasized that accepting the need to put AI regulation into policy is “one the most important points to this question.” “We are at a crossroads,” he said. With the EU and the US already making inroads, the UK must ensure that it doesn’t fall behind. The EU approach “appears to be the best model,” he claimed. 

Minesh Tanna, global AI lead of law-firm, Simmons & Simmons and chair of Society for Computers and Law (SCL) AI Group concurred with Clement-Jones, praising the EU draft on AI regulation as “very good since it is detailed.” Ensuring that any policy is detailed will avoid significant “pitfalls.” 

Another central theme of the panel concerned what steps organizations can follow to ensure that they are regulation-ready. Sara El-Hanfy, innovation lead, machine learning and data at Innovate UK, brought attention to investing in workforce skills. “Employees must have lifelong learning around AI” she claimed. Simon Greenman, partner and member of the World Economic Forum’s Global AI Council, told the audience that organizations must figure out what AI they are using. Almost all attempts to regulate AI miss the critical question regarding what the AI being used is. “Figure out what AI you are using,” he stressed. 

The panel discussion quickly evolved into a debate about the benefits of regulating AI. Greenman argued that the competitive advantages of AI regulation would be “immense,” a view shared with Tanna, who remarked that contractual assurances are now more commonplace. In addition, ethical business practices as a paradigm was raised, with more customers choosing to shift to ethical consumerism. This point was highlighted by El-Hanfy, who highlighted AI regulation as an “immediate ethical opportunity.” 

The final question of the session concerned best practices for businesses to get regulation-ready. Most of the panelists were in agreement with Greenman, who delineated six practices that included: 

  1. Getting those at the board level involved in the conversation 
  2. Ensure effective teamwork 
  3. Emphasise leadership visibility 
  4. Don’t forget about controls 
  5. Use explainable language
  6. Be sure to have an AI “kill-switch”

Wrapping up the session, Clement-Jones highlighted digital literacy. One of the most significant pitfalls in achieving AI regulation, he said, is getting those on the board level to have a better digital understanding. “Time and time again, I see this problem,” he rued. “This is no good unless those sitting on a board are AI literate. AI regulation is not an issue for the future; it is an issue for the present.” 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#DTX2021: Adapt to Succeed During Times of Great Disruption, Says Astronaut Adam Steltzner

#DTX2021: Adapt to Succeed During Times of Great Disruption, Says Astronaut Adam Steltzner

Astronaut Adam Steltzner, NASA JPL, outlined six principles that organizations of all sectors need to embrace in order to navigate significant changes to their environment. His insights can be seen as especially relevant to cybersecurity teams that continue to deal with the digital shift and growing threat landscape during COVID-19.

Speaking during the keynote session on day two of the Digital Transformation EXPO 2021 (DTX) in Excel London, Steltzner explained the enormous challenges he and his team at NASA had to overcome to land the Perseverance land rover on the surface of Mars in February this year. This mission is part of an ongoing journey of discovery about the red planet, principally answering the question as to whether life has ever, or indeed currently, exists there.

NASA also successfully flew the helicopter Ingenuity above the surface of Mars during this mission, despite fears that it would be impossible to fly in a planet that contains atmosphere less than 1% of that of Earth’s.

None of this could be adequately tested on Earth, due to the atmospheric conditions being so far removed from that of Mars. Therefore, the key to ensuring the mission was successful was a willingness to adapt plans, and show “grit” to persevere in all conditions, according to Steltzner. He said that Ingenuity almost didn’t make it to Mars’ surface — the initial plan to fold it into two and be tucked between a pair of wheels had to be changed “late in the development” to ensure it could land safely.

Steltzner then set out lessons he learned from his experience working with Perseverance and Ingenuity, and argued these principles can be applied across all industries.

  • 1. Humans are able to adjust to tremendous disruptions: He noted that while humans generally dislike disruptions to the eco-system, they nevertheless are “capable of change.” However, adapting to new landscapes requires significant perseverance and “grit to adjust to the disappointments.” For example, the COVID-19 pandemic forced people throughout the globe to change their plans and miss out on great experiences. The lesson here is that “every tomorrow is not the universe we expect,” and “if we allow ourselves to embrace the truth of where we are, we will be in a much better place to be successful in the actual universe we live in.”

“If we allow ourselves to embrace the truth of where we are, we will be in a much better place to be successful”

Thankfully, humans are very good at adapting. For example, Steltzner noted that during the pandemic, he “learned to operate spacecraft from my house,” whereas previously he’d be in a control room with 60 colleagues.

  • 2. Being successful during disruption requires ingenuity: Steltzner pointed out that in the US, whole sectors of the economy boomed in the pandemic “because people saw the world as it really was and looked for opportunity in that world.” He added: “That’s what it takes to be successful in a pandemic, and what it takes to be successful any time in the future.” In regard to the late changes made to Ingenuity, this was a recognition “of what was working and what wasn’t.” Steltzner said: “That happens all the time in industry and technology – we have to assess what are the new opportunities for us and what can we leverage to be more successful.”
  • 3. Sort fact from opinion: Steltzner made the point that in periods of great disruption, “it’s challenging to know what you actually know.” Therefore, it is vital to distinguish facts from opinion. To do so, leaders need to understand the perspectives of the different teams within their organization. “It’s my job to look across their siloed perspectives and find a tempered, balanced perspective with which to lead the team.”
  • 4. Humans succeed as teams: “As individuals we might have a great idea, to succeed we have to come together in groups we call teams,” outlined Steltzner. He said the strength of a particular product is always a result of the strength of the teamwork that went into creating it. “You want everybody on your team contributing the most of themselves that they possibly can,” he added, stating it is the responsibility of leaders to establish an environment in which everyone enjoys themselves — “a supercharged, collaborative, lovefest!” as he put it.
  • 5. Talk less, listen more: Steltzner said this principle is particularly vital in the current world, which is more virtual and distant. “To really get the most from my team, I need to make the space in the room for their contributions to come out,” he said, adding that he realized he needed to “talk less” to ensure this was the case.
  • 6. Be curious: Steltzner pointed out that everyone enters the world as babies essentially “unprogrammed,” and it’s that child-like curiosity that enables us to learn how to navigate the environment we reside in. However, as humans get older, “we start expecting that tomorrow is going to be the tomorrow we thought it would be, and we stop looking to see the tomorrow as it really is.” This mindsight leads to lost opportunities, according to Steltzner, and it is therefore important that “we keep our minds curious like a child’s, as we will be more agile and more innovative.”

Steltzner concluded by stating: “If we take that [curiosity] and combine it with a culture of a team and weather the hardships that we might face in the future, there’s almost nothing a team of individuals can’t do.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#DTX2021: Houston, We Have a Breach: Cyber Preparedness Advice From Lisa Forte

#DTX2021: Houston, We Have a Breach: Cyber Preparedness Advice From Lisa Forte

At DTX in London Excel on October 6 2021, Red Goat Cyber Security founder, Lisa Forte, delivered a session on cyber breach preparedness. Forte used examples of mountaineering and caving to demonstrate how to prepare for a breach.

Themes of preparedness, communication and coordination ran through Forte’s talk, titled ‘Houston we have a breach!”

“Human beings are terrible decision makers under pressure. Cognitive processes are surpassed and we [fail to] work off facts.

“Why do humans fail under pressure? That falls into two categories — panic and choking.” The former, Forte explained, is a reversion to instinct. “When you panic, you think too little about things and experience a perpetual narrowing.”

In the latter category — choking — the opposite is true. “You overthink a situation and paralyse yourself with decision-making. You think too much, see too many options, and lose instinctual response.”

This is why it is essential that organizations practice breach preparedness, advised Forte. “You don’t want to realise that people on your crisis management team are incapable in the middle of a crisis,” said Forte, “that would be terrible.”

Forte advocated a six-step plan to ensure cyber breach preparedness:

  1. Plan — “do your research”
  2. Invest wisely — “consider what equipment you need”
  3. Train and rehearse — “Plans need to make sense and be tested for execution”
  4. Playbooks — “you need playbooks for the things you anticipate could happen to your company”
  5. Redundancy
  6. Debriefs — “The crucial last step is to debrief every relevant incident, even if it happens to a competitor rather than to you. Debrief the problems, the response, the criticism, and learn from it.”

“You can’t firefight whilst also looking at the bigger picture,” Forte explained. “You can’t make everything secure, safe and bullet-proof, but you can plan for every eventuality so you don’t have to make it up on the spot.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains