FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Thursday, July 1, 2021

Cyber Threat to UK Populace from latest WhatsApp Scam

UK’s Law enforcement department has issued a fresh set to of warning to all UK populace who are using popular messaging service WhatsApp. The alert is related to a widespread scam that is targeting users on the said video and image sharing service.

Going by the details of the scam provided by the British National Crime Agency, scamsters are seen targeting WhatsApp users in disguise of a known contact. They are asking them to send them a verification code sent to them via text or email and as soon as the code is received the cyber crooks take hold of the account and allow them to read messages and scam further contacts in the device list.

Issue seems to be serious and so WhatsApp has offered a dedicated page on its FAQ Page that provides information about the scam and provides users certain steps to be followed by users.

KnowBe4 was the first to discover this WhatsApp scam targeting the populace of UK. It was found in November last year. But as the scam vanished without a trace, it wasn’t taken seriously by the British Police.

But now, the scam seems to have resurfaced and seems to have targeted over a 1000 individuals, thus allowing the scammers to conduct snooping on many compromised business accounts.

WhatsApp is a messaging service that has become a hit among individuals, and businesses. And as the service entertained financial transactions, such scams have potential to cause a lethal blow to business & individuals.

The post Cyber Threat to UK Populace from latest WhatsApp Scam appeared first on Cybersecurity Insiders.


July 01, 2021 at 03:40PM

UK Salvation Army to negotiate with ransomware attackers

London based Salvation Army that is into philanthropic activities has been reportedly hit by a ransomware attack last month. And news is out that the officials of the charitable trust are left with no option rather than to negotiate with the ransomware spreading hackers and pay them a demanded sum to in exchange to the decryption key.

In what is known to our Cybersecurity Insiders, the data center of the Charitable Trust notices some unusual digital activity on their servers last month. And tried to mitigate the risks with the available resources.

Salvation Army Charity also informed the file encrypting malware attack to the Information Commissioner’s Office (ICO) and had a word with its partners and staff about the digital attack.

As per the Prima facie, no data related to the charity was accessed or ex-filtrated to the ransomware gang servers. However, as a precautionary measure the Christian Trust has asked its staff members and volunteers to keep a vigil on their bank account transactions for the next few months and report any suspicious activity.

Note 1-Founded in 1865, The Salvation Army (TSA) brought salvation in poor, destitute and the needful. It has its presence in over 132 countries and runs charity shops, offers shelter for homeless and conceptualizes humanitarian aid to those in developing countries- all as per the Christian Principles.

Note 2-The ransomware variant that hit the servers of the salvation army is yet to be disclosed to the public. But it appears as a work of a notorious international gang that indulges in double extortion tactics.

The post UK Salvation Army to negotiate with ransomware attackers appeared first on Cybersecurity Insiders.


July 01, 2021 at 03:38PM

Wednesday, June 30, 2021

What tools can be used in the fight against identity document fraud

Back in February 2021, we wrote a blog discussing how to prevent sophisticated physical document fraud, focusing on what the fraud looks like today and what can be done to reduce it. With the Secure Identity Alliance releasing a new report offering in-depth guidance on fighting passport fraud, now is a good time to revisit this subject.

There can be no doubt that document fraud is a serious crime and one that often leads to other significant threats for citizens, including human trafficking, drug smuggling, and terrorism. While it may seem like using fake passports is something reserved solely for spy, action or thriller movies, 47% of the fraudulent documents detected at European Union external borders in 2019 were passports. And, this problem is only set to grow, as criminals use more sophisticated techniques to forge documents. It is therefore essential that security experts and industry bodies come together to jointly develop innovative ways to protect ID documents, making them more intuitive to authenticate and fraud easier to detect.

Security is a gradual process, not binary

Ensuring document security protocols are up to date requires a close and consistent monitoring of technology evolution and threats, to keep a step ahead in that constant race against fraud. Passports, just like any other product, need to be protected from their conception using the principle of ‘cybersecurity by design’. Integrating security from the start of a product’s lifecycle is now a must-have in the fight against criminal activity. What’s more, in order to constantly stay one step ahead of fraudsters, the continued addition of new protective features, materials or techniques is essential.

Enhancing software security in passports

Securing the embedded software in a passport is also imperative. As demonstrated in eID cards, one way to enhance security in citizen credentials is to use open platforms – thanks to their post-issuance capabilities. This means if a key or algorithm is exposed in an attack, the issuer can switch to another algorithm, change the applet or deactivate faulty services – thus protecting citizens’ data. In essence, this addresses the natural security erosion over the life of a product as new types of attacks are developed.

Recent evolution in Common Criteria Certification

Over the last 25 years, Common Criteria certification has been the undisputed reference for securing a document’s embedded software. This certification has been essential in providing guidance for what cybersecurity assessments need to take place for all ID documents, both at their time of purchase and during their operational lifetime as well as within the secure document’s embedded software.

Until June 2019, Common Criteria certifications had no expiry date and were valid until the product was phased out. However, since then the EU Cyber Act & Common Criteria Recognition Arrangement has revised their approach regarding the lifetime security assessment. Instead, a five-year administrative validity period is now enforced. In practice, this means a security re-assessment is required before the five years end in order to extend the validity of the certificate.

The new regulation also strongly recommends that cybersecurity products offer the ability to be patched after their issuance, as part of a resilient strategy.

How governments can ensure the issuance of secure documents

When thinking about bolstering ID document security, governments should try to follow these four key principles: anticipate, resist, react, restore. This will allow them to deliver the intended outcome of protecting their citizens in spite of adverse cyber events.

Using this method, governments can ensure as many attacks as possible are prevented – making life difficult for hackers, the severity of attacks are reduced, the impact if an event happens is managed properly, and that they use these experiences to improve their future offering.

To fulfil this, governments need a long-term embedded software roadmap, with regular security surveillance and Common Criteria certification maintenance of the embedded software. They also need to make sure they are phasing out older products and migrating to new ones at regular intervals.

Finally, documents already in the field need to have upgradable features so the latest security upgrades can be made available to citizens through the use of a Document Lifecycle Management platform.

Using the information provided by the Secure Identity Alliance’s latest report, government authorities now have more guidance on the tools and techniques they need to fight document fraud. With this detailed analysis of the current document fraud landscape, public bodies are able to select the best security features when designing their documents to protect their citizens against fraud.

Only by deploying the latest security features, and through the use of emerging defensive technologies, can governments stay ahead in the permanent race against fraud. This revolves around actively monitoring any new threats to protect sensitive assets today, but also to anticipate future needs. This is our commitment to Cyber Resilience.

If you would like to know more about the security upgrade available in our latest secure embedded software range for identity documents, please tweet us @ThalesDigiSec or visit our dedicated webpage here.

The post What tools can be used in the fight against identity document fraud appeared first on Cybersecurity Insiders.


July 01, 2021 at 09:09AM

How have people proven their identity since the dawn of time?

The concept of human identity is something which has existed for thousands of years. Before we proved our identities with plastic cards or on our mobile devices, people proved their identity in several ways, such as language, physical identifiers or objects.

As part of our series on Digital Identity, this blog will look back on the personal identification techniques of previous eras to show how methods of identification have developed over the course of human history.

100,000 years ago – Jewellery

While drawing solid conclusions from evidence dating back hundreds-of-centuries is difficult, researchers and historians have been led to believe that cultures which existed nearly 100,000 years ago used items of jewellery as personal identifiers.

By studying artefacts found in modern day South Africa, Israel and Algeria, researchers believe that jewellery, such as beads, were used to communicate information such as wealth, familial origins and personal identity.

However, the method of using personal items as proofs of identity has not faded with history, with institutions such as the military using dog tags as individual identifiers for each soldier.

1046 BC – Tattoos

Another historical identification method was the use of tattoos. In numerous cultures, tattoos were considered valuable forms of identification because of their permanent nature. The use of tattoos as identification can be dated back as far as 1046 BC, where the Chinese authorities under the Zhou dynasty would use tattoos to mark prisoners.

However, arguably the most famous use of tattoos for identity purposes can be found amongst the Māori, the indigenous people of New Zealand. Lacking a written language, the Māori would use their facial tattoos (called Mokos) to identify themselves to other tribes. No two Mokos would be the same, each one detailing the individual heritage and history of the wearer’s family.

1415 – The first passport

The passport, one of the core identity documents of the modern world, was first created under the reign of King Henry V of England, following the Safe Conducts Act of 1414. Henry V created the passport for English citizens as a method of proving their identity in foreign countries.

Back then, passports were known as ‘safe conduct’ documents. However, they came to be known as passports around 1540, with the term ‘passport’ originating from a medieval document that was required to pass through the gate of a city wall or to pass through a territory.

1829 – Personal identification numbers

In 1829, the British Government enacted the Metropolitan Police Act, based on the reforms put forward by English statesman Sir Robert Peel. While this may seem initially unrelated to the history of identity, the Metropolitan Police Act saw police stations begin to store data in personal document files, each file being linked back to individuals using a unique numerical value. In short, this act was the inception of personal identification numbers, these later forming the basis of personal ID cards seen across the world today.

By 1936, the United States had begun rolling out their Social Security number cards, with other countries beginning to follow this example with the rise of electronic data processing.

1858 – First instance of biometric information being used for identification

It could be argued that the use of biometric identifiers, such as fingerprints, as identification has existed since pre-historic times. However, the first modern use of biometrics as an identifier was in 1858, when Sir William Herschel, an officer in the British Army stationed in India, recorded the fingerprints of workers on their employment contracts. He was later credited to be the first individual to use fingerprints as a practical means of identification.

1961 – The first computer password

Again, passwords are not a modern invention, with ancient societies such as the Romans using passwords in their military as means of identifying individuals entering restricted areas. However, passwords on computers, as we commonly use them today, were first developed at the Massachusetts Institute of Technology with the (CTSS), which was one of the first time-sharing operating systems.

While the use of passwords is a common reality for many of us, they are not without their flaws. This year, researchers have found that passwords are the primary means by which hostile actors hack into an organisation. In response to the ever-weaker protection offered by passwords, many organisations have turned to other methods, such as digital identity technology, to secure their data.

2004 – The development of advanced biometrics

A recurring theme in the later stages of our timeline, biometric technology took its quantum leap at the turn of the century. In 2004, for example, the U.S. states of Connecticut, Rhode Island and California established the first state-wide palm print databases. These databases were primarily used by law enforcement agencies to search unidentified palm prints against known offenders.

Six years later, the world’s largest biometric digital ID system, called the Aadhaar system, launched in India. The system was designed to speed up the verification process for government agencies while reducing fraud.

Today, biometric authentication is a constant feature in our lives, with many smartphones utilising facial or fingerprint recognition as a security measure.

With this rich history laying the foundations, we are now seeing the latest iteration of identification permeate societies across the world – Digital ID. With this comes the potential to unlock a wide spectrum of services which were previously which could have only been dreamt of in bygone times.

To find out more, read Thales’ recent eBook on digital identity. Follow us on Twitter @ThalesDigiSec to discover more about Thales DIS!

The post How have people proven their identity since the dawn of time? appeared first on Cybersecurity Insiders.


July 01, 2021 at 09:09AM

DoD Adds Two More (ISC)² Certifications to Requirements for Cybersecurity Staff

DoD AnnouncementEarlier this week, (ISC)² announced that the DoD approved both the HCISPP and CCSP certifications to its DoD 8570 Approved Baseline Certifications table on the DoD Cyber Exchange website.

Why does this matter?

This means that the entire roster of (ISC)² certifications are now required for different security workforce categories within the Department, depending on the functional area the role covers. Approval for these additions came from the DoD Senior Information Security Officer and a recommendation by the Cyber Workforce Advisory Group (CWAG) Certification Committee.

The HCISPP has been approved for the following categories:

  • Information Assurance Manager Level 1 (IAM 1)
  • IAM Level II (IAM II)

The CCSP has been approved for the following categories:

  • Information Assurance System Architect and Engineer Level III (IASAE III)
  • Information Assurance Technician Level III (IAT III)

This also points to a raised level of importance that the DoD sees related to healthcare privacy data and cloud security; two areas that have been under near-constant attack and part of high-profile ransomware breaches within the past year. As last week’s #RansomwareWeek here on the (ISC)² Blog showed, the level of threat is only increasing as ransoms are paid and precedents are set. Breaches of cloud platforms, whether direct hits or through a third-party supplier, are high-risk scenarios, and healthcare systems and data are particularly sensitive as hospital networks cannot sustain prolonged outages without endangering patient safety.

As Dr. Casey Marks, chief qualifications officer for (ISC)² expressed at the time, “The addition of the HCISPP and CCSP certifications to the DoD’s requirements for certain cybersecurity roles points to the growing need to protect and defend health information and cloud data from targeted attacks. These certifications attest that their holders have broad, experience-based mastery of security concepts in real-world situations. Adding such professionals to the front lines of national cyber defense is an encouraging step by the DoD.”

Government agencies have trusted (ISC)² to train and certify their cybersecurity personnel for more than two decades. (ISC)² offers nine distinct Information Assurance (IA) certifications that meet the requirements for 11 of the 14 work roles defined in DoDD 8140.01 and DoD 8570.01-M. In accordance with these two regulations, personnel performing Information Assurance (IA) functions are obligated to obtain one of the certifications required for their position, category/specialty and level in order to fulfill the IA baseline certification requirement.

To review all the (ISC)² certifications that are required for certain levels of DoD Information Assurance roles, please visit: https://www.isc2.org/-/media/876358A408FC4F7A953A12CB918CB8FB.ashx

The post DoD Adds Two More (ISC)² Certifications to Requirements for Cybersecurity Staff appeared first on Cybersecurity Insiders.


July 01, 2021 at 09:09AM

AI everywhere: How AI is being applied in 4 different fields

Image Source: Pexels
This blog was written by an independent guest blogger.
Historically, the idea of artificial intelligence (AI) saturating our world has been met with suspicion. Indeed, it’s one of the more popular tropes of science fiction — learning machines gain sentience that helps them take over the planet. While we’re not even slightly close to that dystopian reality, we have reached a point at which AI has been significantly integrated into various aspects of our society.
While this isn’t without its risks, largely from a security standpoint, there are huge benefits. Indeed, some of those cybersecurity risks are even being mitigated by utilizing AI to predict and combat breaches. Machine learning, while still very much in its infancy, is proving to be an agile tool to increase efficiency and assist innovation. 
It’s always important, though, to have a good…

Devin Morrissey Posted by:

Devin Morrissey

Read full post

     

The post AI everywhere: How AI is being applied in 4 different fields appeared first on Cybersecurity Insiders.


June 30, 2021 at 09:10PM

How we can use strong authentication to instantly activate digital banking cards

In today’s digital world, using our mobile phones to consume services is now a part of everyday life. With the average person now spending 2 hours and 51 minutes on their phone each day, service providers like ecommerce sites and entertainment channels have had to adapt their interfaces so that they also work on a smartphone.

The financial services industry is no exception. Based on our research, 80% of banked people now using their bank’s mobile app to review their transactions, check statements, and send money to others. This is due to a simple reason: the notion of waiting in line, as in branch, simply does not exist when using a smartphone.

Nonetheless, while accessing our bank accounts via a smartphone is easier and more convenient for customers, it presents a significant challenge to the financial services industry. These providers need to be able to grant/deny access to very sensitive information in real time and to someone they cannot authenticate physically using an unknown device.

Now, however, with Digital First mobile app technologies, providers can mitigate against this problem while still providing the same seamless user experience.

Onboarding with strong authentication, and identification

When designing their mobile app, all digital services providers need to choose what level of verification will be required to authenticate users and give them access to their services. This will vary depending on what the service is and what type of information it holds. Accessing your Netflix account on your mobile may only require a password, for example, whereas accessing an app containing your health records will require much stronger authentication methods.

On-boarding a sensitive service holding a lot of your personal data requires proof of identity. This is why, in order to open a bank account on your mobile, an ID verification process is needed. The customer most show proof of a valid ID document and some form of biometric authentication, like a selfie, to match them to this document. If the document is valid and if the person presenting that document is its genuine owner, then the service can be granted.

The trick here is ensure a smooth user journey for genuine customers wanting to open an account and also make sure attempts by fraudsters will be denied. In a Digital First mobile experience, all the above steps, plus additional black-list verification steps (for Anti-Money-Laundering for example), can be performed in less than 5 minutes.

What’s more, it is expected that this 5-minute figure will soon be closer to one minute with the proliferation of national digital identity schemes, and, as the ID document verification process becomes more familiar to customers.  Digital First provides the best digital banking and payment experience with optimized speed, security, and ease of use.

What about existing customers?

For an existing customer, Digital First will offer a variety of new services that the user will be able to access from their app, such as digital cards issuance, virtual card display, or PIN code management.

Why is this possible? Well, with Digital First, if ID proofing has been performed once at account opening, then, the user can be authenticated quickly and easily whenever the bank deems necessary using a strong, multifactor technique. ‘Strong’ authentication refers to using a combination of knowledge, possession, and inheritance factors to ensure that the candidate is the genuine, previously on-boarded user.

Don’t do the job twice. Delegate authentication to the mobile app…. if it’s well done.

While these authentication and identification concepts are not new, using them after ID proofing to activate sensitive services is a huge leap for the industry. The old school method would be to perform the job twice: The mobile app manages to verify you are who you say you are, and the payment schemes do too but separately. This usually would not be possible without resubmitting ID documents as occurred during the on-boarding process.

Digital First is a global willingness by all stakeholders to remove frictions for the user and team up between payment schemes, cards issuers and technology partners to focus only on one thing: a meaningful, fast, secure user experience.

The complexities behind Digital First

While the benefits of implementing a Digital First offering are numerous, it should be noted that the skills needed to help banks achieve this vision are tremendously complex to master because they come from three silos that have traditionally been completely independent. We have experience and expertise in all of these three pillars: payment, banking, and issuance and we manage these all under one single platform.

Join us on the Digital First journey and start giving your customers access to instantaneous financial services today.

The post How we can use strong authentication to instantly activate digital banking cards appeared first on Cybersecurity Insiders.


June 30, 2021 at 09:09PM