Google Search

Showing posts with label National. Show all posts
Showing posts with label National. Show all posts

Monday, October 21, 2013

Australia’s National Consumer Fraud Week starts today – the motto is, “Outsmart the scammers!”

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Do you know someone who's been scammed online?

Chances are that you do - or you may have been scammed yourself.

Sadly, if you have been scammed, you may find some of your friends or family strangely unsympathetic.

There's still a widely-held belief that anyone who falls for an online scam must be both greedy and gullible.

? In some cases, it's true that the venality of the victim is a factor. If you send money to someone who has openly requested it as a bribe to persuade a corrupt official to pay out $22,000,000 for an oil pipeline that was never built, you have been both greedy and gullible. (You've also been a crook yourself. Don't expect sympathy.)

But there are dozens of popular online scams these days that don't require any risky character traits in the victim except a trusting nature.

Here are some examples:

Skimming. Crooks fit a duplicate card reader to an ATM so your card gets read twice when you use it.Phishing. Crooks trick you into logging in on a site that looks like your bank, but isn't.Fake competitions. Crooks persuade you to hand over personal information for geeky "prizes" that don't exist.Fake anti-virus. Crooks trick you into paying $50 for anti-virus software to "clean" malware that was never there.Fake support. Crooks pretend to be from Microsoft and offer a remote "cleanup" session for malware you don't have.

The reason I'm mentioning all of this at this particular moment is that the Australian National Consumer Fraud Week 2013 starts today.

At Sophos we enthusiatically support this sort of event, because every time anyone gets scammed - even if they lose only a modest amount, such as $10 - it hurts our society and economy as a whole.

That means that helping other people to avoid scams can be considered an important civic and economic duty for all of us.

Here are five handy "outsmart the scammers" advice points from the Australasian Consumer Fraud Taskforce:

Think twice - if a deal looks too good to be true, it probably is.Find out what other shoppers say - make sure the person that you are dealing with, and their offer, is the real deal.Protect your identity - your personal details are private and invaluable; keep them that way and away from scammers.Keep your computer secure - install software that protects your computer from viruses and unwanted programs and make sure it is kept up-to-date.Only pay via secure payment methods - look for a web address starting with ‘https’ and a closed padlock symbol. Never use a wire transfer to send money to anyone you do not know and trust, and do not share your financial details with anyone.

There's also a very handy taxonomy of scams on the Aussie government's SCAMwatch site.

Why not support National Consumer Fraud Week yourself?

Tell your less security-conscious friends and family about the SCAMwatch website, and get them to take a look at some of the many scams that are explained there.

Let's all learn to outsmart the scammers!

Follow @duckblog

If you're interested, Sophos provides a range of free security tools to help you stay safe online. Choose from Sophos Mobile Security for Android, Sophos Anti-Virus for Mac Home Edition, our Virus Removal Tool and the Sophos UTM Home Edition.


View the original article here

Saturday, December 8, 2012

National security threat or not? Huawei offers Australia unrestricted access to code

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Huawei and AustraliaHuawei is offering unrestricted access to its code and hardware in an attempt to prove that it's not a security threat.

The Chinese telecom giant made the offer to Australia, which has blocked Huawei's bid to work on its national broadband network.

John Lord, chairman of Huawei's Australian arm, blamed the company's lousy communication for what he called "myths and misinformation" that have led to the company being shunned by multiple countries.

In a speech to Australia's National Press Club, he told the audience that Huawei must be more open, according to the BBC:

"Huawei has done a very poor job of communicating about ourselves and we must take full responsibility for that."

According to the BBC, Lord also said that Huawei will give the Australian authorities "complete and unrestricted access" to its software source code and equipment.

He also suggested that Australia set up a cyber evaluation centre to test communications network equipment, funded by telcos and operated by "security-cleared Australian nationals".

Lord said that such a centre has been established in the UK and that Huawei has already given British security agencies access to source code so they can check the security bona fides on its equipment.

He said that it shouldn't be up to a single vendor, country, agency or telco to solve computer security issues:

"It requires a collaborative approach by all to ensure we can create the most secure telecommunications environment possible."

Huawei also pitched the concept to US lawmakers during the Committee on Intelligence's investigation of the company.

The committee's report rejected the proposal on the grounds that Huawei's equipment is too complex, making it too difficult to assess whether the goods could be manipulated.

As it is, the US has already suggested that Huawei and another Chinese firm, ZTE, be banned from the US market because their products could be used to undermine domestic cyber security, given the potential for spying and espionage they could enable.

Circuit boardHuawei has a lot of people to convince.

India, for one. In 2010 the country banned telecoms from importing Chinese networking equipment, fearing that it's infested with spyware.

Then in March of this year, Australia banned Huawei from participating in multi-billion dollar deals to supply equipment for its national broadband network, given similar fears that the Chinese government could exploit the equipment to carry out cyber attacks.

The company's track record isn't helping to assure anybody.

Reuters on Thursday reported that an Iranian partner of Huawei last year offered to sell banned US antenna equipment to an Iranian mobile phone operator.

The would-be buyer told Reuters that it nixed the deal when it learned that the equipment was outlawed under US sanctions.

In spite of the deal falling through, the fact that Huawei tried it at all backs up the US's wariness about the company.

The US just isn't convinced that Huawei complies with international sanctions or US export laws, as the House Intelligence Committee charged in its report [PDF], which it issued earlier in October.

The documents and interviews Reuters relied on point to the almost-sale being an error on the part of the Iranian Huawei partner, rather than an intentional premeditated breach.

Whatever the truth of the matter, the facts point to Huawei being, in the very best case scenario, sloppy.

Follow @LisaVaas
Follow @NakedSecurity

Tags: australia, ban, China, cyber attack, cyber espionage, Huawei, Iran, John Lord, National Press Club, sanctions, spying


View the original article here

Monday, December 3, 2012

National Weather Service website hacked by Kosova Hacker's Security

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Hackers have breached servers belonging to the US National Weather Service by exploiting a vulnerability in the weather.gov website, releasing sensitive data from the government systems.

A post on pastebin.com by a group identifying itself as "Kosova Hacker's Security" took credit for the hack and posted lists of files allegedly copied from the servers as proof.

KHS Pastebin posting

The group exploited a local file inclusion vulnerability on the weather.gov servers, according to information in the Pastebin document, which said the attack was in retaliation for American aggression against Muslim nations, including cyber attacks.

The leaked information includes a listing of administrative account names, which could open the hacked servers to subsequent brute force attacks against the accounts.

Kosovo Hacker's Security

According to media reports, the hacking group cited the release of the Flame and Stuxnet malware as instigation for the attack.

"They hack our nuclear plants using STUXNET and FLAME like malwares , they are bombing us 27*7, we can't sit silent - hack to payback them," The Hacker News (THN) reported the hackers as saying.

The local file inclusion vulnerability was patched and the weather.gov site remained up Thursday. However, at least one other vulnerability, a cross site scripting hole, was subsequently identified on the site.

Little is know about the group claiming responsibility for the attack. However, they allege that the weather.gov hack was just one of many US government hacks the group had carried out and that more releases are pending.

Attacks against government systems and banks are raising alarms in the U.S. and elsewhere.

US Secretary of Defense Leon Panetta invoked the image of a "digital Pearl Harbor" in a speech last week, warning that the country is as unprepared for a large scale cyber attack, as it was for the 9/11 terrorist attacks.

Follow @paulfroberts
Follow @NakedSecurity


View the original article here

Wednesday, November 23, 2011

Hacking threats that lurk within the Web - The National

Tony Glover

$(document).ready(function() {$.get('/national/overrides/ajax/article_detail_date.jsp', {'vcmid':'b80ae98dafbb3310VgnVCM200000e66411acRCRD'}, function(data) { $("#article_date").html(data);});});

Companies around the world are facing a rapidly mounting assault in the form of industrial espionage conducted over the internet. UAE companies are identified as being particularly at risk.

Industry Insights e-newsletter Stay ahead of the pack and get the pick of the premium Business content straight to your inbox. Sign up

The problem has gained new attention after a US national counterintelligence executive (NCE) report warning of the growing risk of corporate computer hacking emanating from Russia and China. The report went beyond previous US official assessments of the scale of the problem to assert that hackers and illicit programmers in China and Russia are pursuing US technology and industrial secrets, jeopardising an estimated US$398 billion (Dh1.46 trillion) of US research. The most heavily targeted areas include pharmaceuticals, information technology, military equipment and advanced materials and manufacturing processes.

But security analysts believe that the problem could be even more widespread in the UAE, where hacking is over four times more common than in the US. According to the cyber security firm Sophos, hackers targeting the UAE are using a broad selection of tools to attack local organisations. These range from the casual insertion of a USB memory stick into any unattended PC or laptop to sophisticated computer worms and viruses transmitted via the internet.

According to research carried out by Sophos on a 10,000-strong test group in the UAE, hacking software, known as malware, was detected on 31 per cent of systems. This contrasts with only 7 per cent in the US and 6 per cent in the UK.

"The most common threats blocked in UAE is Autoinf - 10.42 per cent of detections - and this is usually associated with malware spreading via USB keys," says Mark Harris, the vice president of SophosLabs.

He adds that the computer worm Conflicker accounts for 8.9 per cent of UAE hacks and that commonplace viruses such as Sality (3.65 per cent of detections) and Palevo (3.62 per cent) are also a threat.

The risk consultancy firm Kroll also believes that the threat may be far wider than that identified by the US NCE report.

"The report indicated that there were a number of nations who had the capability to conduct large-scale cyberattacks," says Alan Brill, the senior managing director of Kroll's cyber security and information assurance practice. "In addition, there have been cases of hacking groups with similar capabilities to infiltrate networks and steal important information over extended time periods.

"The technology that they use has become more commonly available with time, increasing the population of potential adversaries. We've seen individuals - such as disgruntled employees with access to intellectual property - steal it where no government or hacker group is involved. So you protect the property against all forms of threat, regardless of the source of the threat."

Organisations in the UAE must therefore take steps not only to safeguard their IT systems from hackers based in other countries, but also from disloyal or discontented staff carrying USB sticks.

The introduction of corporate information technologies such as remote computing, known as the "cloud", whereby company information is stored by third parties, and the increasing use of smartphones also present a growing threat.

"Both cloud computing and the advent of mobile devices like smartphones and tablets have complicated the issue … It isn't always clear where services in the cloud actually store and process your data," Mr Brill says. "The use of smartphones, tablets and mobile devices of all kinds has also become a real issue. How do you secure these devices? Who controls them? Can you limit the devices to those provided by the company, which have the security features and software selected by the company, or can employees utilise a personal device?"

Security experts also believe that the speed of innovation is a danger for companies when employees use IT extensively not only in their work lives but also for personal reasons.

"Companies need to view security as a whole, and it is only as strong as its weakest link," Mr Harris says. "So, for example, if a user decides to share a company confidential document in the cloud, but uses the same password as for their gmail account, and that password gets compromised, they've effectively lost the data."

But although companies must be aware of the scale of the cyberhacking threat, it is also important to avoid developing a culture of paranoiain which access to IT is guarded to such an extent that efficiency is threatened.

"For a UAE-based company, I think they have to do a careful assessment of their intellectual property to see how important and desirable to others it is, and then take appropriate steps to safeguard it," Mr Brill says. "Not everything has to be locked away in a vault. It has to be reasonably usable, but you need to identify and implement the right level of control to both safeguard the information and have a way to know if it is being attacked."

business@thenational.ae


View the original article here

Tuesday, July 5, 2011

Hackers attack India's NSG (National Security Guards) website; probe begins - Digit

The spate of cyber attacks continues with the hackers hitting the official website of National Security Guard (NSG). According to multiple media reports, anonymous programmers attacked the website – www.nsg.gov.in, and corrupted some of its e-mail domains.

The NSG officials, though, turned down the possibilities of major damage and said that a formal probe into the suspected hacking attempt had been initiated. It is being speculated the source of attack exists outside the country. In the meantime, the officials are renewing the passwords and other confidential data to ensure optimum safety.

The reports say the hackers have struck the NSG website several times but the latest one is being described as a “serious” one, especially considering the sensitive data the NSG website hosted.

National Informatics Centre (NIC). The infamous hacking group Anonymous had taken credit of the attack on NIC website. The group said it attacked the website to express solidarity with the ongoing movement against corruption in the corruption.

Anonymous also attacked a website of the Indian Army but soon retracted after it was received criticism from several quarters. The frequent incidents of cyber attacks have exposed the vulnerability of network security to the Internet marauders.

Outside India, the situation seems the same. The IMF, the CIA, Sega and so on, the list of brands and institutions coming under cyber attack is ever-increasing.

Cyber attacks are now a very common nuisance and we throw a question to you - can these attacks be ever stopped? They say the hacking is for a purpose and very noble agenda behind it, is that so? Let us know what you think in the comments section below

Also read,


View the original article here