Category Archives: Internet Security

Report Indicates ’10 Concerts’ Facebook Trend Could Compromise Your Internet Security – Complex

The New York Times often takes an analytical look at trends, and when the NYT speaks, the country listens. The subject of todays analysis: the recent popular 10 concerts post train on Facebook.

The premise is simple: users post 10 concertsnine of which they have attended, one of which is a lie. It seems innocuous enough. But the Times is reporting that engaging in this trend could pose a threat to your online security.

Does this sound like theyre taking it way too seriously? Maybe. But the case holds some weight when you consider the following: Privacy experts cautioned it could reveal too much about a persons background and preferences and sounds like a security questionname the first concert you attendedthat you might be asked on a banking, brokerage or similar website to verify your identity, according to the report.

In other words, if you have this as a security question, and you continue the Facebook trend, you might get hacked and lose all your money.

Michael Kaiser, executive director of the National Cyber Security Alliance, added another point: the list could reveal personal information that target marketers will use to reach you with their products. Pretty creepy.

You are expressing things about you, maybe in more subtle ways than you might think, Kaiser said.

The experts interviewed by the Times recommended being hyper-vigilant and maybe even a little paranoid.

People always have to have their eyes wide open when theyre on the internet, Kaiser said. Its the way of the world.

This might be an overreaction, for sureit might sound a lot like your mom lecturing youbut at least its something to consider before posting about those 2 Chainz and Drake concerts you hit up last year. The more you know.

Link:
Report Indicates '10 Concerts' Facebook Trend Could Compromise Your Internet Security - Complex

NSA To Limit Some Collection Of Internet Communication – NPR

The National Security Administration (NSA) campus in Fort Meade, Md. Patrick Semansky/AP hide caption

The National Security Administration (NSA) campus in Fort Meade, Md.

The National Security Agency is scaling back the way it spies on some communications over the Internet.

The NSA says it discovered what it called "lapses" in compliance with U.S. law.

They're called "about" communications: The NSA not only watches messages traveling to and from a foreign target, but those that mention one.

That can mean the NSA sometimes sweeps up data from Americans without a warrant. In the past, officials said the spy agency was still mindful of citizens' privacy.

But now NSA says it has discovered "several inadvertent compliance lapses," which it reported to Congress and a secret court that oversees intelligence gathering.

There aren't many more details, but the NSA now says it will, quote, "stop the practice to reduce the chance that it would acquire communications of U.S. persons or others who are not in direct contact with a foreign intelligence target."

Here's the full statement from the NSA:

NSA Stops Certain Foreign Intelligence Collection Activities Under Section 702

The National Security Agency is instituting several changes in the way it collects information under Section 702 of the Foreign Intelligence Surveillance Act.

Section 702, set to expire at the end of this year, allows the Intelligence Community to conduct surveillance on only specific foreign targets located outside the United States to collect foreign intelligence, including intelligence needed in the fight against international terrorism and cyber threats.

NSA will no longer collect certain internet communications that merely mention a foreign intelligence target. This information is referred to in the Intelligence Community as "about" communications in Section 702 "upstream" internet surveillance. Instead, NSA will limit such collection to internet communications that are sent directly to or from a foreign target.

Even though NSA does not have the ability at this time to stop collecting "about" information without losing some other important data, the Agency will stop the practice to reduce the chance that it would acquire communications of U.S. persons or others who are not in direct contact with a foreign intelligence target.

Finally, even though the Agency was legally allowed to retain such "about" information previously collected under Section 702, the NSA will delete the vast majority of its upstream internet data to further protect the privacy of U.S. person communications.

The changes in policy followed an in-house review of Section 702 activities in which NSA discovered several inadvertent compliance lapses.

NSA self-reported the incidents to both Congress and the FISC, as it is required to do. Following these reports, the FISC issued two extensions as NSA worked to fix the problems before the government submitted a new application for continued Section 702 certification. The FISC recently approved the changes after an extensive review.

The Agency's efforts are part of its commitment to continuous improvement as we work to keep the nation safe. NSA has a solemn responsibility and duty to do our work exactly right while carrying out our critical mission.

Excerpt from:
NSA To Limit Some Collection Of Internet Communication - NPR

Avira Internet Security Suite v15.0.26 – TechCentral.ie

AviraInternet Security Suiteprovides strong antivirus protection anda host of other extras.

The core antivirus engine is a good one, which normally scores very well with the independent testing labs. Itranked5th out of22 in theSeptember 2014 AV-ComparativesReal World Protection tests, for instance (equivalent to Bitdefender),with a very creditable detection rate of 99.2%.

The program also provides capable browsing protection, though, detecting and blocking malicious websites before they can even load, and preventing drive-by downloads.

Integration with the Avira Protection Cloud improves performance,with unknown files classified in real time.

The Browser Tracking Blocker helps to maintain your privacy online by preventing more than 600 networks from recording your web activities.

The Website Safety Advisor adds icons to your search results (if theyre carried out via the Avira toolbar), warning you of potentially dangerous sites before you click.

Integration with the free Avira SocialShield helps protect your kids on Facebook, Twitter, Google+ and others.

Security Suite also includes Aviras System Speedup module to tune your PC for maximum performance.

The 2015 edition adds little, other than your products cannow be managed through Avira Online Essentials, a web dashboard for installing and displaying information on all your Avira apps and devices (computers, tablets and phones).

Please note, there is no stand-alone trial of Avira Internet Security Suite. The download link gets you Avira Antivirus Pro. To add other features sign in at my.avira.com, find your device (if youve more than one), scroll to the bottom of the screen and click Add for whatever extras you need (Browser Safety, System Speedup, Identity Safeguard and Dropbox again).

Whats new in update 26?

Rework the user interface flow of update in case predictable reboots. New Scanner (shell extension scanner) writes specific warnings from AIRS, Engine and LocalDecider into the scanner log file (separate log files for each scan session). New Scanner users can scan their EFS-encrypted files.

Originally posted here:
Avira Internet Security Suite v15.0.26 - TechCentral.ie

Cloudflare debuts a security solution for IoT – TechCrunch


TechCrunch
Cloudflare debuts a security solution for IoT
TechCrunch
Cloudflare, the content delivery network that promises speed and security for websites, announced today that it's moving into the internet-of-things industry with a security product called Orbit. Now, instead of just securing websites, Cloudflare wants ...
A Clever Plan to Secure the Internet of Things Could Still Have Big DrawbacksWIRED
The Internet of Thieves? Why IoT urgently needs to be securedDATAQUEST
Cloudflare Shores Up Defenses For Internet Of (Easily Hackable) ThingsFast Company
CSO Online -The Register -Yahoo Finance
all 13 news articles »

See the original post:
Cloudflare debuts a security solution for IoT - TechCrunch

Russian-controlled telecom hijacks financial services’ Internet traffic – Ars Technica

Enlarge / A map that visualizes network changes being announced by Rostelecom.

On Wednesday, large chunks of network traffic belonging to MasterCard, Visa, and more than two dozen other financial services companies were briefly routed through a Russian government-controlled telecom under unexplained circumstances that renew lingering questions about the trust and reliability of some of the most sensitive Internet communications.

Anomalies in the border gateway protocolwhich routes large-scale amounts of traffic among Internet backbones, ISPs, and other large networksare common and usually the result of human error. While it's possible Wednesday's five- to seven-minute hijack of 36 large network blocks may also have been inadvertent, the high concentration of technology and financial services companies affected made the incident "curious" to engineers at network monitoring service BGPmon. What's more, the way some of the affected networks were redirected indicated their underlying prefixes had been manually inserted into BGP tables, most likely by someone at Rostelecom, the Russian government-controlled telecom that improperly announced ownership of the blocks.

"I would classify this as quite suspicious," Doug Madory, director of Internet analysis at network management firm Dyn, told Ars. "Typically accidental leaks appear more voluminous and indiscriminate. This would appear to be targeted to financial institutions. A typical cause of these errors [is] in some sort of internal traffic engineering, but it would seem strange that someone would limit their traffic engineering to mostly financial networks."

Normally, the network traffic bound for MasterCard, Visa, and the other affected companies passes through services providers that the companies hire and authorize. Using BGP routing tables, the authorized providers "announce" their ownership of the large blocks of IP addresses belonging to the client companies. On Wednesday afternoon at around 3:36pmPacifictime, however, Rostelecom suddenly announced its control of the blocks. As a result, traffic flowing into the affected networks started passing through Rostelecom's routers. The hijacking lasted five to seven minutes. When it was over, normal routing was restored. The event is nicely captured in a graphic here.

The hijacking could have allowed individuals in Russia to intercept or manipulate traffic flowing into the affected address space. Such interception or manipulation would be most easily done to data that wasn't encrypted, but even in cases when it was encrypted, traffic might still be decrypted using attacks with names such as Logjam and DROWN, which work against outdated transport layer security implementations that some organizations still use.

Madory said that even if data couldn't be decrypted, attackers could potentially use the diverted traffic to enumerate what parties were initiating connections to MasterCard and the other affected companies. The attacker could then target those parties, which may have weaker defenses.

According to shareholder information provided by Rostelecom, the Russian government owns 49 percent of the telecom's ordinary shares. The US Department of Commerce lists Rostelecom as a state-owned enterprise and reports that one or more senior government officials have seats on Rostelecom's board of directors. Rostelecom officials didn't respond to e-mail seeking comment for this post.

The affected company networks also included those belonging to security provider Symantec and technology company EMC. A list of 36 affected network prefixes and registered owners and locations of those prefixes are:

The above list filtered out 14 Russia-based prefixes that Rostelecom announced around the same time.

Such hijacks underscore the implicit trust governments and corporations all over the world place in BGP routing announcements. For years, engineers have proposed a variety of measures to ensure service providers can announce only those networks they're authorized to carry. At the moment, however, there is no authoritative way to do so. Dyn, BGPmon, and similar services do a good job detecting when unauthorized announcements are made, but those detections inevitably come after improper redirections or hijackings have already occurred.

Read more from the original source:
Russian-controlled telecom hijacks financial services' Internet traffic - Ars Technica

Mucheru urges private sector to boost investment in internet security – The Standard (press release)

NAIROBI, KENYA: Mr. Joe Mucheru, the ICT Ministry Cabinet Sectretary has urged the private sector to bolster investment in cybersecurity to curb the growing incidences of cybercrime targeting Kenyas digital economy.

Though a recent report by Jumia Business Intelligence and GSMA Mobile showed that Kenya is leading Africa in internet penetration with over 30 million having access to the internet, the positive trajectory has seen a sharp rise in cybercrime targeting financial Institutions and mobile money transaction platforms.

Mr. Mucheru urged the private sector to invest in cybersecurity infrastructure to complement ongoing Government efforts to curb the vice, citing investment opportunities for players in the internet security space to ensure security infrastructure matches current threat trends.

We have the Computer and Cybercrimes Bill, 2016 which is headed to parliament. We want to introduce stiffer penalties for cybercrime and online corporate espionage, said Mr Mucheru when he presided over a funds drive to improve the infrastructure of Lenana School.

The Kenya Cybersecurity Report 2016 published by Serianu Limited, estimates that about 44 percent of financial institutions run on a paltry cybersecurity budget of $1-1,000 annually, whilst about 33 percent of financial institutions in Kenya have $0 spend on all matters cybersecurity.

With more than 75.3 percent of Kenyan citizens formally included in financial services, one would logically expect a correspondent increase in cybersecurity investments in the financial services sector. Regrettably this is the opposite in the case of Kenyan banks, said Teddy Njoroge the ESET East Africa Country Manager during the recent Connected Summit 2017.

Mr. Mucheru said jobs were moving online with the freelancing economy in the United States clocking US$1 trillion and about 34 percent of Americans working online.

The very essence of introducing Ajira Digital in partnership with Rockefeller Foundation and the Kenya Private Sector Alliance was to tap online job opportunites for the youth. We will not relent on this initiative because of challeges posed by cybercrime, he added.

Over one-third of organizations that experienced a breach in 2016 reported substantial customer, opportunity and revenue loss of more than 20 percent, this is according to the Cisco 2017 Annual Cybersecurity Report.

In the report, Chief Security Officers cited budget constraints, poor compatibility of systems, and a lack of trained talent as the biggest barriers to advancing their security postures. Business leaders also revealed that their security departments are increasingly becoming complex environments with 65 percent of organizations using between six and 50 security products, thus raising the potential for security effectiveness gaps.

The CS urged local businesses to focus on opportuntines in addressing potential challenges around Internet of Things (IOT) and mobile communications that are fast becoming new targets of attack by cybercrimials.

In the next one year we expect that over 40 million new devices, mainly smart phones will be imported into the country, all these are potential new targets especially if users are ot aware of the cyber risks, he explained.

ESET East Africa, that specilises in internet security notes that effective infrastructural cybersecurity measures come at a budgetary cost which must be respected by C-Suite executives if organisations are to tame the constantly evolving cyber threat landscape.

While it is laudable that up to 63 percent of financial organisations in Kenya have an in-house cybersecurity department, the Serianu report 2016 indicates that only 29% of the employees within in-house cybersecurity departments in financial organisations are cybersecurity trained certificate holders.

Go here to see the original:
Mucheru urges private sector to boost investment in internet security - The Standard (press release)

Homeland Security warns of ‘BrickerBot’ malware that destroys unsecured internet-connected devices – ZDNet

A new kind of attack is targeting unsecured Internet of Things devices by scrambling their code and rendering them useless.

Security firm Radware first spotted the newly found "BrickerBot" malware last month after it started hitting its own honeypots, logging hundreds of infection attempts over a few days. When the malware connects to a device with their default usernames and passwords -- often easily found on the internet -- the malware corrupts the device's storage, leading to a state of permanent denial-of-service (PDoS) attack, also known as "bricking."

In other words, this attack "damages a system so badly that it requires replacement or reinstallation of hardware," said Radware.

It's a novel take on an ongoing security problem with Internet of Things devices: Botnets controlled by hackers, like the Mirai malware, typically infect unsecured devices that are enlisted as part of wider bandwidth-stealing attacks to bring down websites and services by overwhelming them with internet traffic.

Like the Mirai botnet, most famous for bringing down wide swathes of the US internet last year in a massive distributed denial-of-service (DDoS) attack, the BrickerBot also uses "the same exploit vector" by brute-forcing telnet accounts with lists of available usernames and passwords.

Radware doesn't have a list of internet-connected devices, like webcams, toys, and even smart bulbs, at risk of being attacked, but it pointed to several kinds of Linux-based devices that run the BusyBox toolkit that have their telnet port open and are exposed publicly on the internet.

The researchers said that the attackers also have an affinity for targeting devices on Ubiquiti networks, which have been targeted by attackers before.

Once inside, the malware runs a sequence of commands, which "try to remove the default gateway, wipe the device through rm -rf /* and disable TCP timestamps as well as limiting the max number of kernel threads to one," which would scramble the device's memory.

The researchers also said that the malware adds extra commands "to flush all iptables firewall and NAT rules and add a rule to drop all outgoing packets," effectively wiping any trace of its infection.

"Unfortunately, even after performing the factory reset, the camera was not recovered and hence it was effectively bricked," said Radware.

(Image: Radware)

And, because the device-bricking bot conceals its location through the Tor anonymity network, there's no way to know where the attack came from, the researchers said.

The emergence of BrickerBot has prompted Homeland Security's Cyber Emergency Response Team (CERT) to issue an updated warning, noting that "no information is available at this time about the type and number of devices used in performing these attacks."

"Control systems often have Internet accessible devices installed without the owner's knowledge, putting those systems at increased risk of attack," said the advisory.

The researchers said that a device search could point to at least 21 million devices at risk, but the motivations for this new attack aren't known.

Homeland Security suggests changing a device's default credentials and disabling telnet.

Employees will hand over work passwords to hackers for money

Excerpt from:
Homeland Security warns of 'BrickerBot' malware that destroys unsecured internet-connected devices - ZDNet

A Global Industry First: Industrial Internet Consortium and Plattform Industrie 4.0 to Host Joint IIoT Security … – Business Wire (press release)

HANNOVER, Germany--(BUSINESS WIRE)--The Industrial Internet Consortium (IIC) andPlattform Industrie 4.0 are pleased to announce their plans to host a joint demonstration at Hannover Messe, April 24-28, 2017, in Hannover, Germany, highlighting Industrial Internet security, interoperability and collaboration.

With the rise of the Industrial Internet of Things (IIoT) and Industrie 4.0, manufacturers are adding more connected devices, sharing operational data with IT systems within both their own factories and businesses, as well as extending information exchange across their entire value chain. This increased digitization offers a host of benefits to manufacturers, their partners, suppliers and customers.

In a connected world, this robust connectivity amplifies the importance of security both within a single manufacturers plant and across every participant in the value chain. There is no single, homogeneous security environment; rather there are multiple companies and systems that need to work together.

The joint real-time demonstration at Hannover Messe shows how the IICs recently released Industrial Internet Security Framework and the concepts of secure cooperation in cross company environments developed by the Plattform Industrie 4.0 can be applied to solve this challenge. Mimicking a real-world, multi-vendor, distributed environment, the demonstration integrates Hannover Messe demos from over 20 IIC member companies and Plattform Industrie 4.0 partner companies respectively into a single security demonstration. It spans multiple booths at Hannover Messe and remote sites around the world.

The IIC and Plattform Industrie 4.0 have been collaborating for just over a year to combine the cross-domain approach of the IIC with Plattform Industrie 4.0s focus on the manufacturing industry. The concept of this demonstration was launched only four short months ago.

The demonstration highlights how multiple unique, existing security systems can be consolidated in a set of interacting industrial security systems, leveraging products and technologies available today that demonstrate secure integration of existing systems without disrupting operations. Security events are shared across the entire ecosystem, letting each member in the value chain see all security events that are relevant to them.

Its really terrific to see so many global IIC members from multiple disciplines, working together with Plattform Industry 4.0 to achieve this industry first manufacturing-based real-time demo in a secure environment, said John Tuccillo, Chair of the IIC Steering Committee, and Senior Vice President, Schneider Electric.

The joint demonstration is an important milestone in our cooperation. It shows that the exchange between the partners creates practical and transferable solutions. We are very thankful to our Joint Technology Group Security for this successful work, said Henning Banthien, General Secretary of the Plattform Industrie 4.0.

Security is critical to industrial deployments and the Hannover Messe demonstration highlights the fact that deploying a robust industrial security monitoring solution in a heterogeneous environment across multiple companies and organizations can be achieved using todays technology, said Sven Schrecker, Co-Chair of the IIC Security Working Group and Chief Architect,IoT Security Solutions, Intel.

Our work result illustrates: secure data exchange across domains can be done. This means a central precondition for secure cross-company value networks is met, adds Michael Jochem, Robert Bosch GmbH and Chair of the Plattform Industrie 4.0 Working Group Security of Networked Systems.

Live Demonstration at the Hannover Messe The central presentation can be found in Stands C24 and D24 of Hall 8 of Hannover Messe and live demonstrations can be found in many participating member stands and halls throughout the event, in other parts of Germany and in other parts of the world.

There will be a joint press conference on April 25, 2017 from 9 10 am CET at the Hannover Messe, Convention Center, Saal 15. You can join the live telephone conference via this link where you can submit written questions.

About the Industrial Internet Consortium The Industrial Internet Consortium is the worlds leading organization, transforming business and society by accelerating the Industrial Internet of Things. Our mission is to deliver a trustworthy Industrial Internet of Things in which the worlds systems and devices are securely connected and controlled to deliver transformational outcomes. The Industrial Internet Consortium is managed by the Object Management Group (OMG). For more information, visit http://www.iiconsortium.org.

About the Plattform Industrie 4.0 Plattform Industrie 4.0 is the central network to advance digital transformation towards Industry 4.0 in Germany. In close cooperation with politics, industry, science, associations and trade unions over 300 players from 159 organizations are actively involved in the platform. The platform develops and coordinates information and networking services to make Industry 4.0 solutions better known among companies and to deploy them on site. As one of the largest international and national networks, it supports German companies particularly small- and medium-sized companies in implementing Industry 4.0. It provides companies with decisive impulses through examples of company practices from across Germany as well as concrete recommendations for action and test environments. The numerous international cooperation of the platform underscores their leading role in the international discussions on industry 4.0. For more information, visit http://www.plattform-i40.de

Note to editors: Industrial Internet Consortium is a registered trademark of OMG. For a listing of all OMG trademarks, visit http://www.omg.org/legal/tm_list. All other trademarks are the property of their respective owners.

Read more:
A Global Industry First: Industrial Internet Consortium and Plattform Industrie 4.0 to Host Joint IIoT Security ... - Business Wire (press release)

Internet Security Firm Confirms WikiLeaks ‘Vault 7’ At Least 40 Cyberattacks Tied to the CIA – The Ring of Fire Network

According to a blog posted Monday, internet security giant Symantec has linked real-world cyberattacks to the tools detailed in the Vault 7 WikiLeaks dump.

Since 2011, Symantec has tracked a group they called Longhorn, that used sophisticated software exploits against organizations that would be of interest to a nation-state attacker. The blog post never specifically mentions the CIA, instead assessing that the Longhorn group exhibited behavior which is consistent with state-sponsored groups and that there were indicators that Longhorn was from an English-speaking, North American country. Longhorn even used SCOOBYSNACK as a code word in their malware.

Symantec says that they found that the group infected 40 targets in at least 16 countries across the globe:

Longhorn has infiltrated governments and internationally operating organizations, in addition to targets in the financial, telecoms, energy, aerospace, information technology, education, and natural resources sectors.

To tie the WikiLeaks information to their investigation of Longhorn, Symantec found that the software detailed in Vault 7 followed a development timeline that they saw in real-world scenarios. One piece of software known as Corentry to Symantec and referred to as Fluxwire by WikiLeaks provided particularly compellingevidence:

New features in Corentry consistently appeared in samples obtained by Symantec either on the same date listed in the Vault 7 document or several days later, leaving little doubt that Corentry is the malware described in the leaked document.

Symantecs investigation found that the attacks were carried out across the Middle East, Europe, Asia, and Africa. On one occasion a computer in the United States was compromised but, following infection, an uninstaller was launched within hours, which may indicate this victim was infected unintentionally. According to Reuters, Symantec did not track any mass surveillance tools and all of the targets held national security value. However, Symantecs Eric Chien told Reuters that,

there are organizations in there that people would be surprised were targets.

Symantecs Stephen Doherty told Wired that they had been tracking the Longhorn group for many years, but Vault 7 was key in pin-pointing their identity. [T]he tools and activity we had been tracking from Longhorn closely match some of the information disclosed in Vault 7, said Doherty.

Symantecs efforts mark the first real-world example of the Vault 7 tools being used. However Doherty said that they have not yet found additional links:

We track a lot of groups and a lot of actors and we havent seen any specific details that would link to any other malware at the moment.

While the CIA understandably denies the authenticity of the tools and documents contained in Vault 7, the government has attempted to blockthe leaks from being admitted into court cases because they should be considered classified. That action, paired with expert analysis by industry leaders like Symantec, shows that the WikiLeaks collection is likely real.

See original here:
Internet Security Firm Confirms WikiLeaks 'Vault 7' At Least 40 Cyberattacks Tied to the CIA - The Ring of Fire Network

Internet Security Analysts: North Korea Is Planning a Global Bank Heist – Breitbart News

SIGN UP FOR OUR NEWSLETTER

According to the report, they have plans to robover a hundred banks around the world, including institutions like the World Bank, the European Central Bank and big American companies including Bank of America.

SIGN UP FOR OUR NEWSLETTER

An attack on over 20 Polish banks near the end of 2016 was evidently thwarted without any money being lost. When security analysts pulled apart the virus software sent to these banks, they discovered a huge list of Internet addresses for other financial institutions, making up the target list described by Symantec.

TheTimesdiscusses the size and desperation of North Koreas cybercrimering:

The list of targets, which has not been previously reported, is part of a growing body of evidence showing how North Korea, a country that is cut off from much of the global economy, is increasingly trying to use its cyberattack abilities to bring in cash and making progressively bolder attempts to do so.

North Koreas hacking network is immense, encompassing a group of 1,700 hackers aided by more than 5,000 trainers, supervisors and others in supporting roles, South Korean officials estimate. Because of the countrys poor infrastructure, the hackers typically work abroad, in places like China, Southeast Asia and Europe. Like other North Koreans allowed to work abroad, the hackers are constantly monitored by minders for possible breaches in allegiance to the government.

Thus far, the biggest score for the North Korean operation appears to be ahackof Bangladeshs central bank, revealed by Bangladeshi authorities in May 2016. The $81 million stolen from the bank ended up in the Philippines, but investigators were certain from early in the investigation that the thieves were not from either Bangladesh or the Philippines.

Early indications suggested Chinese hackers might have been responsible for the attack, but Symantec researchers soon isolated malicious code linked to North Korea. Similar code and hacking techniques had previously been used against banks in Vietnam and Ecuador. According to theNew York Times,analysts with the National Security Agency saw evidence the Bangladesh bank robbery was linked to the attack on Sony Pictures, which is generally seen as the work of North Korea.

The thieves were actually trying to steal abilliondollars from Bangladesh with fraudulent money transfer requests to the New York Federal Reserve, but only $81 million in bogus requests got through.

The attack on Polands banks was carried out with a watering hole hacking technique, which involves planting malware in locations the targets are likely to visit. Disturbingly, the watering hole for the Polish caper was the website of Polands banking regulator. Symantec mentioned similar watering hole traps have been laid for banks in Mexico and Uruguay, while virus attackshavebeen made already against a few targets in the United States.

An important point made by security analysts about these bank robberies is that huge amounts of manpower were involved, making state sponsorship of the attacks likely. The malware used in these assaults can lurk in targeted systems for weeks, going active during very limited windows of opportunity, so a large team of computer technicians has to work around the clock to supervise the intrusion.

Only one Chinese bank appeared in the target list distilled from captured viral code in Poland, a detail some analysts find significant. There are lingering suspicions that Chinese hackers assisted in pulling off the Bangladesh attack. This could become a major topic of conversation when Chinese president Xi Jinping meets with President Trump next month.

Security firm FireEye, which was instrumental in past actions against Chinese hackers, has reported a significant decline in Chinese industrial cyber-espionage over the past two years, coupled with an increase in Russian mischief. CEO Kevin Mandia warnedFortunelast week that American companies are still getting sucker punched pretty bad.

North Korea has denied involvement in the wave of cyber attacks on financial institutions, claiming the United States reached despicable heights with its accusations. Pyongyang called America a hacking empire, the worst of bullying countries and said the hacking allegations were a pretext to launch a pre-emptive strike against North Korea.

More here:
Internet Security Analysts: North Korea Is Planning a Global Bank Heist - Breitbart News