Connect with us

E-Business

User Mistakes Aid most Cyber Attacks – Report

Published

on

cyber.jpg
Kindly share this post

When a cyber security breach hits the news, those most closely involved often have incentive to play up the sophistication of the attack.

If hackers are portrayed as well-funded geniuses, victims look less vulnerable, security firms can flog their products and services, and government officials can push for tougher regulation or seek more money for cyber defenses.

But two deeply researched reports being released this week underscore the less-heralded truth: the vast majority of hacking attacks are successful because employees click on links in tainted emails, companies fail to apply available patches to known software flaws, or technicians do not configure systems properly.

These conclusions will be in the minds of executives attending the world’s largest technology security conference next week in San Francisco, a conference named after lead sponsor RSA, the security division of EMC Corp.

In the best-known annual study of data breaches, a report from Verizon Communications Inc to be released on Wednesday found that more than two-thirds of the 290 electronic espionage cases it learned about in 2014 involved phishing, the security industry’s term for trick emails.

Advertisement

Because so many people click on tainted links or attachments, sending phishing emails to just 10 employees will get hackers inside corporate gates 90 percent of the time, Verizon found.

“There’s an overarching pattern,” said Verizon scientist Bob Rudis. Attackers use phishing to install malware and steal credentials from employees, then they use those credentials to roam through networks and access programs and files, he said.

Verizon’s report includes its own business investigations and data from 70 other contributors, including law enforcement. It found that while major new vulnerabilities such as Heartbleed are being used by hackers within hours of their announcement, more attacks last year exploited patchable vulnerabilities dating from 2007, 2010, 2011, 2012 and 2013.

Another annual cyber report, to be released on Tuesday by Symantec Corp, found that state-sponsored spies also used phishing techniques because they work and because the less-sophisticated approach drew less scrutiny from defenders.

Once inside a system, however, the spies turned fancy, writing customized software to evade detection by whatever security programs the target has installed, Symantec said.

Advertisement

“Once I’m in, I can do what I need to,” said Robert Shaker, an incident response manager at Symantec. The report drew on data from 57 million sensors in 157 countries and territories.

Another troubling trend Symantec found involves the use of “ransomware,” in which hackers encrypt a computer’s files and promise to release them only if the user pays a ransom. (Some 80 percent of the time, they do not decrypt the files even then.)

The new twist comes from hackers who encrypt files, including those inside critical infrastructure facilities, but do not ask for anything.

The mystery is why: Shaker said it is not clear whether the attackers are securing the information for resale to other spies or potential saboteurs, or whether they plan on making their own demands in the future.

At next week’s RSA Conference, protecting critical infrastructure systems under increasing attack will be a major theme.

Advertisement

Another theme will be the need for more sharing of “intelligence” about emerging threats – between the public and private sectors, within the security industry, and within certain industries.

While many of the biggest breaches of the past two years involved retailers, the healthcare industry has figured heavily in recent months.

Former FBI futurist Marc Goodman said that both spies and organized criminals are likely at work, the former seeking leverage to use in recruiting informants and the latter looking to cash in on medical and insurance fraud.

Verizon’s researchers said that to be most effective, information-sharing would have to be essentially in real time, from machine to machine, and cross multiple sectors, a daunting proposition.

Another section of the Verizon report could help security executives make the case for bigger budgets.

Advertisement

The researchers produced the first analysis of the actual costs of breaches derived from insurance claims, instead of survey data.

Verizon said the best indicator of the cost of an incident is the number of records compromised, and that the cost rises logarithmically, flattening as the size of the breach rises.

According to the new Verizon model, the loss of 100,000 records should cost roughly $475,000 on average, while 100 million lost records should cost about $8.85 million.

Though the harder data will be welcome to number-crunchers, spending more money cannot guarantee complete protection against attacks.

The RSA Conference floor will feature vendors touting next-generation security products and anomaly-spotting big-data analytics. But few will actually promise that they can stop someone from clicking on a tainted email and letting a hacker in.

Advertisement


Kindly share this post

Nigeria CommunicationsWeek believes that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. So since 2007, we have devoted our energy to independent reportage of technology and how they affect lives.

Continue Reading
Advertisement
Comments

E-Business

NDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Students’ Data Misuse

Published

on

Kindly share this post

Nigeria Data Protection Commission (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank and Hackerbella Ltd over alleged violations of data protection laws involving students’ personal information.

NDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Students’ Data Misuse

The investigation follows public complaints alleging that students’ personal data were used to open bank accounts without a lawful basis.

Dr Vincent Olatunji, national commissioner and chief executive officer of the NDPC, directed the investigation team to conduct a comprehensive assessment of the circumstances surrounding the collection, processing, use and disclosure of the affected students’ personal data.

The investigation will also determine the respective roles and responsibilities of UNILAG, Lotus Bank and Hackerbella in the alleged processing of the data.

According to the Commission, the investigation will assess the data protection compliance obligations of the parties under the Nigeria Data Protection Act, 2023 (NDP Act), as well as potential risks posed to the rights and freedoms of the affected data subjects.

Advertisement

The NDPC said the probe would cover several areas, including Data Protection Impact Assessments (DPIAs), the lawfulness and transparency of credit scoring or profiling activities, and the use of automated decision-making systems.

It will also examine the adequacy of privacy notices, data-sharing arrangements, lawful bases for processing, data minimisation and purpose limitation.

Other areas include data retention policies and the adequacy of technical and organisational measures put in place to safeguard the rights and personal data of affected students.

The Commission reiterated that institutions entrusted with the personal data of students, staff and other members of their communities have a heightened responsibility to ensure that such information is processed lawfully, fairly, transparently and securely.

The NDPC therefore warned educational institutions that are yet to comply with its existing data protection compliance directives to take immediate steps to achieve compliance.

Advertisement

The Commission said it would continue to exercise its regulatory mandate to protect the privacy rights of Nigerians and ensure that organisations processing personal data comply with the provisions of the Nigeria Data Protection Act, 2023.

Kindly share this post
Continue Reading

E-Business

Microsoft to Unveil Next-generation AI Chip in September

Published

on

Kindly share this post

Microsoft is planning to unveil its new Maia 300 AI chip this fall, potentially as soon ​as next month, The Information reported on Monday, citing ‌people with direct knowledge of the plans.

The company introduced its Maia AI chip in November 2023 but has lagged rivals such as Alphabet and ​Amazon in scaling up its in-house chip efforts as ​it seeks to reduce its reliance on Nvidia’s costly ⁠processors.

Google began recognizing revenue from direct sales of its custom ​AI chips, called Tensor Processing Units, in the quarter ended June, ​while Amazon has also seen growing adoption of its processors, including its Trainium chips.

Microsoft has been in talks with chipmaker TSMC to secure manufacturing ​capacity for more than 300,000 units of the chip for ​delivery in 2027, according to the report. It is also looking to significantly ramp up ‌production ⁠and persuade major cloud customers such as Anthropic to adopt the chip.

Microsoft ultimately ​aims to ⁠secure capacity for more than 1 million Maia 300 chips, though component supplies and ongoing capacity ​negotiations with TSMC could constrain its plans, according ​to the ⁠report.

Advertisement

It unveiled its second-generation Maia 200 in January, built by TSMC using 3-nanometer technology.

Microsoft packed the chip with a significant amount of ⁠SRAM, ​a type of memory that can provide ​speed advantages for AI systems handling large numbers of user requests.

 

Kindly share this post
Continue Reading

E-Business

X Replaces Revenue Sharing wit New Creator Rewards Programme

Published

on

Kindly share this post

X has announced plans to discontinue its Revenue Sharing programme and introduce a new Original Content Rewards programme to reward creators for producing original content on the platform.

X Replaces Revenue Sharing wit New Creator Rewards Programme

The social media company announced the changes at the weekend in a post on its X Creators handle, saying the new programme would reward creators who contribute original content.

“Today, we’re introducing the Original Content Rewards Program, a new way to reward creators who bring original ideas, expertise, reporting, creativity, and commentary to X,” the company said.

X said it would stop accepting new enrolments into the Revenue Sharing programme from Friday, while existing participants would continue earning until September 7, 2026.

“Starting today, we’re no longer accepting new enrollments into Revenue Sharing,” it said.

Advertisement

According to the company, existing Revenue Sharing participants will receive three final payouts, with two scheduled for August 14 and August 28, while the final payment for earnings accrued through September 7 is expected around September 11.

X said existing Revenue Sharing participants would begin getting access to apply for the new programme from September 8, subject to meeting its eligibility requirements.

The first payout under the Original Content Rewards programme will be made on August 28, 2026, while existing Revenue Sharing creators who enrol in the new programme from September 8 will receive their first payment on September 25.

Under the new programme, eligible creators will earn from qualified impressions generated by their original content, with payments made every two weeks.

X defined qualified impressions as unique impressions from Premium users on the Home Timeline feed, where at least 50 per cent of a post is visible.

Advertisement

On the other hand, “The following are excluded from qualified impressions: impressions from the same account counted more than once per post; paid, promoted, or artificially generated impressions; and fraudulent impressions,” it said.

To qualify, creators must be at least 18 years old, live in a country where the programme is available, maintain an account in good standing and have either a personal or vusiness account.

They must also subscribe to X Premium, Premium+ or Premium Business, have at least 500 verified followers and record at least 500,000 Home Timeline impressions from verified users within the previous 90 days.

X said creators must also regularly post original content to remain eligible.

“We want to recognize creators who break news, share expertise, tell stories, create entertainment, and contribute meaningful perspectives to the conversation,” the company said.

Advertisement

The platform said original content could include threads, videos, memes, graphics, illustrations, reporting, analysis, commentary and reactions that add meaningful value to existing conversations.

It said creators who use content produced by others would need to add meaningful commentary, context, analysis, humour or creative transformation for such posts to qualify.

“Building on existing conversations is a core part of X, but simply reposting someone else’s content is not enough,” it said.

X said minor edits such as cropping, filters, borders, watermarks, speed adjustments or simple text overlays would generally not qualify as meaningful transformation on their own.

It also warned that content copied or substantially reproduced from another creator, content downloaded and re-uploaded from X or another platform without being the original author’s, automated content, disinformation and misleading content would be ineligible.

Advertisement

The company said accounts that violate the programme’s requirements could be temporarily or permanently removed from it, depending on the severity of the violation.

It added that creators would be responsible for ensuring they had the necessary rights, permissions or licences to use content created by others.

“Original content is content you personally create that reflects your own voice, perspective, expertise, or creativity,” X said.

The company said the new programme was intended to reward creators who make the platform more valuable by bringing original ideas and perspectives to its conversations.

“The Original Content Rewards Program is designed to reward the creators who start them, shape them, and move them forward,” it said.

Advertisement

Kindly share this post
Continue Reading

Trending