E-Business
Cyberoam 2014 IT Security Predictions Cite Hyper Attacks Underway

Cyberoam Technologies Private Limited, a global Network Security appliances company with a careful analysis of security and IT trends in the most recent past and a strong foresight that comes from years of industry experience and intelligent extrapolation of the past and the present, on Friday released it security predictions for 2014.
Cyberoam offers future-ready security solutions to physical and virtual networks in organizations with its Next-Generation Firewalls (NGFWs) and Unified Threat Management (UTM) appliances.
Thus, in its intelligent analyses of IT security in the new year came up with the following ten (10) predictions.
“Client-Side Software Exploits” – It Will Be!
Cyberoam Threat Research Labs foresees an increase in Client-side software exploits compared to the Server-side in next few years.
2013 has seen numerous such exploits where base client software like Microsoft and Adobe were exploited to spread the attack vectors across the network.
The recent Microsoft advisories indicating client side exploits also support this prediction. Reasons for this hike include increased scope of exploitation with increase in attack vectors, higher base of users who use these softwares, and lastly, the money involved in it.
The exploit kits used to exploit server side vulnerabilities cost much less than client side exploit kits, indicating the premium the latter demand. Realizing that client side exploits will bring in more money, the focus on exploiting client-side vulnerabilities will increase too!
Attack Vectors To Get More Intelligent
Attacks in 2013 have left us with one clear picture – the rising sophistication and professionalism among attackers. In times to come, Cyberoam predicts attacks, wherein the attackers will get more specific, both in terms of their objective and attack strategies.
Gone are the days when attacks were meant for the masses. Attackers now know whom and how they would attack and they are changing their attack strategies to hit straight on the bull’s-eye rather than shooting in the dark.
In addition to this, few attacks from 2013 indicate the evolution of attacks including proven components from already-used attacks, combined to form more detrimental attacks.
Attacks On Industrial Control Systems & Scada Systems To Continue
The amplified impact that an attack on Industrial Control Systems (ICS) can cause, justifies the interest attackers have on such systems. ICS/SCADA system attacks can cause catastrophic damage not only to a single unit but at times to an entire country/province.
It is the spread of impact compounded with lack of adequate security available in such systems that have made ICS/SCADA networks a lucrative target for attackers. As per statistics, there were 198 cyber attacks in 2012 and the numbers increased to 240 in 2013. Cyberoam predicts further rise in such attacks on ICS/SCADA networks in 2014 and beyond.
New Exploit Kits Will Be Explored And Used
Use of Blackhole exploit kit for attacks is a known fact. It is no secret that it was used extensively for attacks in the past. But with the arrest of ‘Paunch’ in 2013, the man behind the Blackhole exploit kit, new exploit kits are slowly showing up. In addition to this, as attacks utilising Blackhole exploit kit have been exposed, it emerges as a need among attackers to come up with new ways to target their victims.
Also, with recent trends showing rise in exploits based on client side vulnerabilities, Cyberoam predicts that this menace is only going to aggravate.
Increase In Need For Context-Aware Security
With increase in number of security features or solutions in an organization’s network to tackle emerging security risks, the job of security professionals is getting more complex. With rising number of devices, users and applications to monitor, this becomes even more difficult. The volume of data that the security appliance(s) offer on various parameters is becoming a problem for network administrators, presenting a need for context-aware security that enables faster decision making and action with the security intelligence it offers.
Cyberoam predicts an increase in demand for context-aware security for 2014. The rising need in context-aware security goes in continuation with Cyberoam’s prediction in 2013 regarding the rise in need for User Threat Quotient & Device Threat Quotient.
Security of Hybrid Cloud
In a generation of increased mobility where tablets and smart devices are displacing desktops and paper-based processes, more users are turning to Cloud, specifically the Hybrid Cloud, as it offers more efficiency , business optimization, access to real-time data and always-on availability.
However , the ability of Hybrid clouds to burst into the public cloud space when necessary is bringing up security concerns.
Although this capability is particularly useful to organisations, it may be a call for danger and users and security vendors are realizing this. Cyberoam predicts an increase in demand for security in Hybrid Cloud environments.
Browser-Based Attacks Are Still Hot!
In a bait to achieve sure-shot infection and victimize users, use of browser-based attacks like Water hole will further rise. This will include a rise in exploitation of browser vulnerabilities and also use of malicious websites. Attackers will continue to target users by directing them to trusted and commonly visited URLs which would be infected with malicious codes.
Water hole mechanism includes cyber offenders infecting websites that are frequently visited by their targets. In 2013, many have already agreed on the rise seen in watering holes. In fact a lot of hackers that were using spear phishing attacks to target users have also started using watering holes.
Mobiles Still Remain A Darling Of Malware Attackers And Exploits
Increasing base of smartphone users is a primary reason for attackers to find interest in attacking those devices. In addition to this, users use their personal devices to access work emails and connect to company networks, which aggravates this interest further.
Applications are the backbones of smart phones and most of the mobile apps lack adequate security, adding to the misery of security on mobile devices.
All of these factors collate to increase the interest attackers have in smart devices. 2014 is sure to experience newer and sharper mobile threats
“Internet of Things” Adds Security Risks For Home Devices
IOT- ‘Internet of Things’ is something we all are waking up to, these days. Everything seems to be on the Internet! Right from our work to social lives, and storage needs, Internet has also opened its doors to home devices now! As more and more home devices get connected to the Internet, it is obvious that attackers will soon find their way through them too.
Cyberoam predicts a rise in need for security solutions for home devices, besides your office devices. Because one thing is evident – the level of risk and quantum of vulnerability is similar, irrespective of whether the device resides in your home or in your office network.
Windows Users At Risk As Windows XP Comes To End-Of-Life
As Microsoft decides to stop supporting Windows XP after 8th April 2014, users will need to upgrade to newer Windows versions, and so will the attackers shift their focus to these versions.
Moreover, users who still continue to use Windows XP, will not have their vulnerabilities patched, leaving them open to exploits.
E-Business
Kaspersky Warns of a Phishing Campaign Abusing Microsoft Authentication Mechanism

Kaspersky has released a report about a phishing campaign where attackers abuse Microsoft’s authentication mechanism. The campaign spanned from early April to mid-May 2026 and was styled as a notice from a law firm.

The goal was to steal victims’ credentials and access their data. Previously Kaspersky warned about phishing exploiting Google Tasks, Google Forms, Bubble and Amazon Simple Email Service.
Microsoft’s authentication mechanism – the OAuth 2.0 Device Authorisation Grant – allows users to log into their Microsoft accounts on devices with limited input capabilities, such as smart TVs, by pasting a code or scanning a QR code on another device, like a smartphone or a PC. This convenience also creates an opportunity for attackers to abuse the flow, potentially hijacking accounts and maintaining control through stolen refresh tokens.
Attackers sent victims emails disguised as communication from a law firm, with a password-protected PDF file attached. After opening the PDF and entering the password, they were presented with a webpage that listed several documents.
Viewing these documents required clicking a provided link, which led to a legitimate Microsoft address. However, the URL parameters were configured to redirect the user to a phishing resource after they opened the Microsoft page.
The phishing page featured multiple CAPTCHAs, presumably deployed to filter out security bots which are used to check websites for threats. Once past the CAPTCHAs, the user was routed to a final page that instructed them to copy a one-time code. This code was the one that the attackers had already fetched by starting the login process on their side.
Clicking the displayed one-time code automatically copied it to the clipboard while simultaneously redirecting the user to Microsoft’s actual, legitimate authentication page where they were prompted to paste and enter the code.
After the user entered the code, the multifactor authentication process completed and the attackers got hold of the session’s tokens. This enabled them to read and send emails from the victim’s mailbox, exfiltrate files from OneDrive and access Teams conversations.
“Threat actors don’t always rely on harvesting credentials or deploying malware to access sensitive data – they can weaponise legitimate tools. Therefore, users must exercise vigilance not only when visiting suspicious sites, but also when navigating official platforms.
“We advise enterprise teams to evaluate the business necessity of the Device Code Flow within their corporate infrastructure. If this authentication mechanism is not required for daily operations, it should be disabled,” commented Roman Dedenok, Anti-Spam Expert at Kaspersky.
To establish a comprehensive defence against Device Code Phishing attacks, organisations should deploy robust email security solutions. For corporate users, Kaspersky Security for Mail Server with its multi-layered defence mechanisms powered by machine learning algorithms provides robust protection against a wide range of evolving threats and offers peace of mind to businesses in the face of evolving cyber risks. For individual users, Kaspersky Premium offers AI-powered anti-phishing features designed to help avoid phishing attacks and improve overall cybersecurity.
E-Business
Ovaloop Technologies Unveils Digital Tools to Formalize SMEs Operations Across Africa

Against the backdrop of struggles by small and medium enterprises in Africa to scale their businesses because of lack of formal processes, Ovaloop Technologies has unveiled an inventory solution aimed at supporting retailers across Nigeria and Africa to formalise their businesses.

Combining inventory management, payment processing, accounting and business intelligence, the platform enables retailers to generate accurate financial records, improve operational efficiency, reduce internal fraud and strengthen their ability to access credit.
The company said the expansion of Nigeria’s digital payment ecosystem has created the need for solutions that go beyond processing transactions to helping small and medium-sized enterprises (SMEs) manage their day-to-day operations.
Speaking during the company’s launch event in Lagos on Monday, Princewill Mba, CEO and co-founder of Ovaloop Technologies described the platform as an indigenous technology designed to grow and formalize Africa’s retail economy
“Ovaloop is an inventory management system, but we like to always define it as a retail operating system, so think about it as your Microsoft Office. For us, the whole idea is to manage how businesses are being run. So Ovaloop manages your business operation end-to-end, from how you’re taking stock, to how you manage your stock, how you make sales, and how you collect payments,” Mba said.
Mba further noted that the company aims to change the conversation from building products that simply process payments to developing technology that helps retailers manage their entire business operations.
According to him, the formalisation of retail operations will also bring onboard unbanked SMEs, unlocking access to credit facilities which remain one of the major challenges facing SMEs in Nigeria and Africa.
“Most of these retailers are not bankable. They make a lot of money but when they come to collect loans from financial institutions, they struggle, because their cash flow statement is not very accurate, the data they provide to the banks or other financial institutions is not very accurate, and then they can’t work with that data.
“But with Ovaloop, we can generate useful data for them that they circulate to these institutions to help them access funding, and you can’t shy away from the fact that funding is very imperative for businesses to operate smoothly,” he said.
Acknowledging the gap in the inventory space, the CEO disclosed that the company took time to understand business operations across Africa and has built a solution that manages business operations end-to-end.
Mba said there is a huge gap in inventory management solutions across Africa, noting that many businesses still rely on manual record-keeping or disconnected software.
“What we’ve built and why we took this long was for us to understand how Africans operate business, because whether you would like it or not, most businesses are still taking inventory and stock using basic books while others use fragmented tools.
“So there’s a tool that collects your payment. There’s a tool that runs your business and another tool that runs your accounting. But when we talk about Ovaloop, it’s taking all these activities into cognisance. So, from end to end, we can manage your inventory.”
Daniel Kilanko, co-founder and CTO of Ovaloop Technologies commenting on the platform noted that it is easily accessible with strong security software that verifies payments and detects fraud.
“Our Ovaloop Pay Protect will tie every sales transaction to verified payments. So with that, you don’t have to deal with fragmented tools. The tools you are using for your inventory, payments and everything synchronise properly.
“So no transaction can be completed unless a verified payment is linked to that transaction. And with this, we also hope that we will be connecting with other local technology so that you just have one central system that does everything for you end-to-end.”
Kilanko said Ovaloop can be accessed through the web, Android and iOS mobile phones which gives users a complete business overview from anywhere in the world.
The platform will also be linked to various supply chains, enabling users to access products within and outside the country.
Also speaking, Titilope Ejimagwa, chairperson, Ovaloop Technologies, inventory losses and employee theft remain major operational challenges for many entrepreneurs
Ejimagwa recalled losing inventory to trusted employees despite maintaining close oversight of her business, citing nearly four decades of experience in marketing and entrepreneurship.
She noted that technology such as the Ovaloop platform, which can track inventory, verify payments and improve operational transparency, could significantly reduce such losses for SMEs.
“As entrepreneurs, one of our biggest challenges is fraud and inventory losses. Having one platform that helps monitor operations and reduce those risks is a major advantage for businesses,” she said.
E-Business
Jumia Nigeria Expands Flexible Payment Options with Klump Partnership

Jumia Nigeria, the country’s e-commerce platform, has introduced a new instalment payment option on its marketplace through a partnership with Buy Now, Pay Later (BNPL) provider Klump, giving customers another way to pay for purchases without bearing the full cost upfront.

The new option allows eligible customers to spread payments for selected purchases over a period of up to 12 months after making an initial deposit of between 20 and 30 percent. The partnership is expected to widen access to products such as smartphones, electronics, home appliances, and other everyday essentials for consumers who may prefer structured repayment plans over one-time payments.
Customers selecting the option at checkout can compare financing offers from participating financial institutions, complete a digital credit assessment, and, once approved, begin repayment through fixed monthly instalments. The introduction of instalment payments comes as digital commerce continues to evolve in Nigeria, with retailers exploring payment options that respond to changing consumer spending patterns and the growing demand for financial flexibility.
Commenting on the partnership, Chief Executive Officer of Jumia Nigeria, Temidayo Ojo, said the initiative reflects the company’s commitment to making online shopping more accessible to a wider range of consumers.
“We are constantly looking at practical ways to remove barriers to online shopping. For many customers, affordability is not always about the price of a product but about having payment options that fit their financial reality. By introducing instalment payments with Klump, we are giving customers greater flexibility while making quality products more accessible.”
He added that expanding payment choices forms part of Jumia’s wider effort to improve the overall customer experience and support the company’s ambition of becoming Nigeria’s everyday retail destination.
“Whether we are strengthening our logistics network, expanding product selection, or introducing new payment solutions, the goal remains the same: to make shopping on Jumia simpler, more convenient, and more accessible for customers wherever they are,” Ojo said.
Founded to simplify access to goods across Africa, Jumia has continued to invest in technology, logistics, and payment solutions to make digital commerce easier for consumers in both major cities and emerging markets across Nigeria.
The addition of instalment payments complements the range of payment methods already available on the platform and comes at a time when consumer demand for flexible financing options is increasing across the retail sector.
Celestine Omin, Co-founder and Chief Executive Officer of Klump, said the partnership aligns with Klump’s objective of expanding access to responsible consumer credit.
“When we started Klump, our mission was simple: to give Nigerians access to affordable credit wherever they shop. Today, we’re pleased to partner with Jumia to bring flexible instalment payments to one of Africa’s largest e-commerce marketplaces, making it easier for more customers to access the products they need,” Omin said.
Under the arrangement, Klump will provide the financing infrastructure while customers complete the application process digitally during checkout. Financing offers are provided through participating financial institutions, subject to approval.
For Jumia, the partnership represents another step in expanding the range of services available on its marketplace while supporting broader efforts to deepen digital commerce and financial inclusion. As more Nigerians turn to online shopping, the availability of flexible payment options is expected to lower one of the barriers to e-commerce adoption, particularly for higher-value purchases.
Customers can access the instalment payment option by selecting Klump at checkout on eligible products available on the Jumia platform.
News3 days agoYEDC Warns Customers, Says 20 Percent Electricity Bonus is Scam
News3 days agoPFIPC Probe: Dollar, Pounds Accounts of Fake Agency Inactive – CBN
Broadcasting3 days agoNBC, INEC, Plan Joint Broadcast Monitoring Framework ahead of 2027 Elections
News3 days agoSTEM Africa Fest to Nurture Nigeria’s Future Innovators
E-Financial3 days agoNo Going Back on July 31 Deadline for Insurance Firms’ Recapitalisation – NAICOM
E-Business3 days agoJumia Nigeria Expands Flexible Payment Options with Klump Partnership
E-Business3 days agoLagos Unveils N10m Single-digit Loan Scheme for MSMEs
E-Financial3 days agoCourt Affirms FCCPC’s Power to Regulate Digital Lending


















