E-Business
SophosLabs 2018 Malware Forecast Shows No Platform Immune from Ransomware

By peter oluka
Sophos, a global leader in network and endpoint security, today announced its SophosLabs 2018 Malware Forecast, a report that recaps ransomware and other cybersecurity trends based on data collected from Sophos customer computers worldwide during April 1 to Oct. 3, 2017.
One key finding shows that while ransomware predominately attacked Windows systems in the last six months, Android, Linux and MacOS platforms were not immune.
“Ransomware has become platform-agnostic. Ransomware mostly targets Windows computers, but this year, SophosLabs saw an increased amount of crypto-attacks on different devices and operating systems used by our customers worldwide,” said Dorka Palotay, SophosLabs security researcher and contributor to the ransomware analysis in the SophosLabs 2018 Malware Forecast.
The report also tracks ransomware growth patterns, indicating that WannaCry, unleashed in May 2017, was the number one ransomware intercepted from customer computers, dethroning longtime ransomware leader Cerber, which first appeared in early 2016. WannaCry accounted for 45.3 percent of all ransomware tracked through SophosLabs with Cerber accounting for 44.2 percent.
“For the first time we saw ransomware with worm-like characteristics, which contributed to the rapid expansion of WannaCry. This ransomware took advantage of a known Windows vulnerability to infect and spread to computers, making it hard to control,” said Palotay. “Even though our customers are protected against it and WannaCry has tapered off, we still see the threat because of its inherent nature to keep scanning and attacking computers. We’re expecting cyber criminals to build upon this ability to replicate seen in WannaCry and NotPetya, and this is already evident with Bad Rabbit ransomware, which shows many similarities to NotPetya.”
The SophosLabs 2018 Malware Forecast reports on the acute rise and fall of NotPetya, ransomware that wreaked havoc in June 2017.
NotPetya was initially distributed through a Ukranian accounting software package, limiting its geographic impact. It was able to spread via the EternalBlue exploit, just like WannaCry, but because WannaCry had already infected most exposed machines there were few left unpatched and vulnerable.
The motive behind NotPetya is still unclear because there were many missteps, cracks and faults with this attack. For instance, the email account that victims needed to contact attackers didn’t work and victims could not decrypt and recover their data, according to Palotay.
“NotPetya spiked fast and furiously, and did hurt businesses because it permanently destroyed data on the computers it hit. Luckily, NotPetya stopped almost as fast as it started,” said Palotay. “We suspect the cyber criminals were experimenting or their goal was not ransomware, but something more destructive like a data wiper. Regardless of intention, Sophos strongly advises against paying for ransomware and recommends best practices instead, including backing up data and keeping patches up to date.”
Cerber, sold as a ransomware kit on the Dark Web, remains a dangerous threat. The creators of Cerber continuously update the code and they charge a percentage of the ransom that the “middle-men” attackers receive from victims. Regular new features make Cerber not only an effective attack tool, but perennially available to cyber criminals. “This Dark Web business model is unfortunately working and similar to a legitimate company is likely funding the ongoing development of Cerber. We can assume the profits are motivating the authors to maintain the code,” said Palotay.
Android ransomware is also attracting cyber criminals. According to SophosLabs analysis, the number of attacks on Sophos customers using Android devices increased almost every month in 2017.
“In September alone, 30.4 percent of malicious Android malware processed by SophosLabs was ransomware. We’re expecting this to jump to approximately 45 percent in October,” said Rowland Yu, a SophosLabs security researcher and contributor to the SophosLabs 2018 Malware Forecast. “One reason we believe ransomware on Android is taking off is because it’s an easy way for cyber criminals to make money instead of stealing contacts and SMS, popping ups ads or bank phishing which requires sophisticated hacking techniques. It’s important to note that Android ransomware is mainly discovered in non-Google Play markets – another reason for users to be very cautious about where and what kinds of apps they download.”
The SophosLabs report further indicates two types of Android attack methods emerged: locking the phone without encrypting data, and locking the phone while encrypting the data. Most ransomware on Android doesn’t encrypt user data, but the sheer act of locking a screen in exchange for money is enough to cause people grief, especially considering how many times in a single day information is accessed on a personal device. “Sophos recommends backing up phones on a regular schedule, similar to a computer, to preserve data and avoid paying ransom just to regain access. We expect ransomware for Android to continue to increase and dominate as the leading type of malware on this mobile platform in the coming year,” said Yu.
E-Business
82% of Organizations Concerned about AI Risks Even as Adoption Accelerates – Survey Reveals

At its recent Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region Kaspersky shared the results of a global study conducted by its internal research center which surveyed 1,800 IT and cybersecurity decision-makers and specialists from organisations across 18 countries and multiple industries.

The report shows that the pace of AI integration across organisations is rapid, despite associated risks. The company’s experts stressed that while AI adoption delivers clear efficiency gains, it must be accompanied by robust cybersecurity solutions, well-defined internal procedures, and comprehensive employee education programmes.
The report highlights a clear organisational preference for AI-enhanced technology: 68% of respondents said they would recommend a solution with AI features built in, while a mere 5% indicated they would prefer to avoid AI-enabled tools. This overwhelming endorsement underscores how deeply AI has embedded itself as a value driver across the modern enterprise.
AI has become a mainstream productivity tool spanning many business functions. The global survey findings confirm that employees across departments are already relying on AI tools for a wide range of everyday tasks, including: data analysis & visualisation (54%), project management (49%), search for information (47%), department-specific tasks (46%), text generation and editing (41%).
While organisations recognise the tangible benefits AI tools bring – including improved process efficiency and enhanced quality of deliverables – they also see the associated dangers. 82% of respondents voiced concerns about the risks AI poses to their organisation. These concerns are grounded in real-world experience.
Among the 87% of organisations worldwide that faced a cyber incident in the past year, 13% reported that they had experienced threats stemming specifically from AI-related vulnerabilities.
Notably, 74% of respondents believe that these risks can be effectively mitigated through employees’ responsible behaviour — pointing to the critical importance of security awareness and training in the AI era.
“The speed at which organisations are embracing AI is remarkable, but it must be matched with an equally strong commitment to security. We are already seeing a growing range of threats directly tied to AI adoption – whether it’s malware camouflaged as popular AI tools, vulnerabilities introduced through unsecure vibecoding, or leaked access credentials to corporate AI platforms and malicious skills by AI agents.
Managing these risks requires a holistic approach: the right technology, well-defined procedures, and a security-aware workforce,” comments Brandon Muller, senior security consultant for the META region at Kaspersky.
E-Business
How Temu Helped a Madagascan Vanilla Family Business Sell Direct to Consumers Across Europe

Malagasy Vanilla has transformed its decades-old wholesale business by embracing direct-to-consumer sales through Temu, enabling the family-run company to reach customers in 14 European markets while significantly reducing logistics costs.

For years, premium Madagascan vanilla supplier Malagasy Vanilla sold exclusively to restaurants, bakeries and wholesalers because the cost of shipping a single pack to individual customers often equalled the value of the product itself. That changed after the company joined Temu’s Local Seller Program in November 2025.
The Belgian-based business, which sources high-quality vanilla from Madagascar, has leveraged Temu’s logistics network to cut domestic shipping costs by nearly half through a partnership with Belgian postal operator Bnode. The move has enabled the company to enter the retail market for the first time and quadruple its sales within four months.
According to Belinda Rabenandrasana, co-Chief Executive Officer of Malagasy Vanilla, Temu has opened up an entirely new customer segment for the company.
“Temu opened a new avenue for us,” she said. “We were finally able to explore selling to individuals.”
The platform now contributes between five and 10 per cent of the company’s overall revenue.
Expansion into 14 European Markets
Malagasy Vanilla is among businesses participating in Temu’s Local Seller Program, launched in Europe in 2024 to help local merchants expand beyond their domestic markets.
Through partnerships with more than 150 logistics providers across Europe—including Bnode in Belgium, La Poste in France and DHL Group in Germany—Temu offers sellers access to affordable shipping and delivery infrastructure without requiring major investment in logistics.
After successfully establishing direct-to-consumer sales in Belgium, Malagasy Vanilla expanded into 14 European countries, including Germany, France, Spain and Poland.
Rabenandrasana said the logistics support, competitive shipping rates and seller assistance provided by Temu made the expansion possible.
“Without Temu and its partnership with Bnode, it would have been very difficult for a small business like ours to start selling directly to consumers,” she said.
She added that Temu also assists sellers in managing regulatory requirements such as the European Union’s Extended Producer Responsibility (EPR) compliance, making cross-border operations easier for small businesses.
Three Generations of Vanilla Expertise
Malagasy Vanilla traces its roots to three generations of the Rabenandrasana family in Madagascar’s vanilla industry.
Belinda’s grandfather began trading vanilla locally, while her father expanded operations across Madagascar. She launched the company’s international business in 2017, supplying premium Madagascan vanilla to European restaurants, pastry shops and food wholesalers before establishing operations in Belgium in 2023.
The company partners with growers and producer associations in Madagascar, where between 20 and 40 workers oversee the six- to 10-month curing process that transforms green vanilla pods into premium black vanilla.
Operations in Belgium focus on packaging, quality assurance and distribution.
Customer Reviews Drive Growth
Under its Lavani brand, Malagasy Vanilla sells gourmet-grade whole vanilla pods targeted at both professional chefs and home baking enthusiasts.
Rather than relying heavily on paid advertising, the company has benefited from Temu’s product discovery tools and customer reviews, helping the niche brand gain visibility organically.
According to Rabenandrasana, strong customer feedback has played a significant role in increasing traffic and boosting sales.
The brand currently maintains a customer review rating exceeding 99 per cent on the platform.
Future Plans
Looking ahead, Malagasy Vanilla plans to expand its European footprint further by establishing a warehouse in France and increasing sales across the continent.
The company is also developing new products, including vanilla extract and vanilla sugar, while planning to open a physical retail and production facility in Belgium later this year.
In addition, it intends to launch a social-impact initiative aimed at supporting vanilla-growing communities in Madagascar.
Reflecting on the company’s evolution, Rabenandrasana said the business continues to build on her family’s legacy.
“My grandfather worked locally, my father expanded nationally, and now we are building internationally,” she said.
E-Business
FG Must Consider Data Security, Sovereignty in 3MTT Initiative – Stakeholders

Stakeholders in Nigeria’s digital economy have urged the Federal Government to review its partnership with global recruitment platform Hello.cv under the 3 Million Technical Talent (3MTT) programme, citing concerns over data security, digital sovereignty and the country’s “Nigeria First” policy.

3MTT
The concerns follow the Federal Ministry of Communications, Innovation and Digital Economy’s announcement on May 6 of a 10 million-dollar partnership with Hello.cv aimed at increasing the global visibility of Nigerian technology professionals.
Under the initiative, 20,000 selected 3MTT fellows will receive a global professional profile package, including an Artificial Intelligence (AI)-powered job search agent, a professional curriculum vitae (CV) writer and a personal .cv domain, valued at 500 dollars per participant.
While stakeholders acknowledged the programme’s potential to improve global employment opportunities for Nigerian tech talent, they expressed concerns about the implications of hosting participants’ digital identities and data on a foreign domain.
Chief Executive Officer of Cyberchain and Global Digital Economy Strategist, Engr. Jude Ozinegbe, said the arrangement raised important questions about data ownership and jurisdiction.
According to him, registering domains under an entity outside Nigeria gives that entity a degree of control over activities associated with the domain.
“When you register your domain under a different entity outside your jurisdiction, that entity will have access to whatever is happening within that domain.
“In the long run, the Nigeria Data Protection Commission (NDPC) may have to examine the agreement and assess the security implications of such domain ownership,” he said.
Ozinegbe urged the NDPC to review the security protocols employed by Hello.cv to ensure compliance with Nigeria’s data protection regulations.
Also speaking, Ugonma Egwuatu of ECAM Global Services, an information and communications technology and data protection firm, said the security of data belonging to 20,000 fellows should be of significant interest to regulators.
She noted that while the ministry had the authority to determine how the programme was implemented, there was a need for greater transparency regarding the handling of participants’ personal information.
“The NDPC requires its registered Data Protection Compliance Organisations (DPCOs) to subscribe to the .ng domain.
“If a government ministry permits trainees to operate on a foreign domain, then the commission should examine the arrangement because we are dealing with the data of 20,000 Nigerians,” she said.
Egwuatu also called for clarity on how data generated through the platform would be processed, stored and protected.
“There should be explanations regarding the backend. What are they doing with the data of people who visit these sites? Why use a foreign domain instead of the .ng domain? These are legitimate questions that deserve answers,” she said.
She added that government should ensure appropriate third-party agreements and safeguards were in place before implementing such initiatives.
On his part, Chief Executive Officer of DNS Africa, Dr. Adebunmi Adeola Akinbo, said the objectives of the programme could still have been achieved while leveraging Nigeria’s country code top-level domain.
According to him, Hello.cv could have registered a hello.cv.ng or hellocv.ng domain in collaboration with the Nigeria Internet Registration Association (NiRA).
“The .ng domain can conveniently accommodate such a platform. If Hello.cv intends to onboard millions of Nigerians, it can work with NiRA to create a local domain structure.
“That way, the investment remains within Nigeria, strengthens the digital economy and supports local internet infrastructure,” he said.
Akinbo argued that excluding the .ng domain from the initiative undermined Nigeria’s digital identity and sovereignty.
“As good as the programme may sound, leaving the .ng domain outside this engagement and taking Nigerian data outside the country’s digital jurisdiction is not the best approach,” he said.
Also commenting, Founder and Chief Executive Officer of Precise Financial Systems Ltd., Yele Okeremi, stressed the importance of ensuring that investments in Nigeria’s digital economy create long-term domestic value.
According to him, building a sustainable technology ecosystem requires more than developing skilled professionals.
“Investment, particularly in technology and the knowledge economy, is not just about having smart people.
“It is also about who owns the infrastructure and who ultimately benefits from the value created. Nigeria must ensure it retains as much of that value as possible,” he said.
Similarly, Chief Executive Officer of the Internet Exchange Point of Nigeria (IXPN), Muhammed Rudman, described the use of foreign domains for a government-sponsored initiative as inconsistent with efforts to promote Nigeria’s digital economy.
“I don’t know where this idea came from, but it is unpatriotic for Nigerian companies funded by Nigerian resources to adopt .cv domains instead of .ng.
“Global companies such as Google register country-specific domains like google.ng when operating locally. Registering 20,000 additional .ng domains would improve Nigeria’s online visibility and strengthen the local internet ecosystem,” he said.
Rudman urged the Federal Government to support indigenous digital infrastructure by encouraging the use of the .ng domain.
The 3 Million Technical Talent (3MTT) programme is a flagship initiative of the Federal Ministry of Communications, Innovation and Digital Economy aimed at equipping Nigerians with globally relevant digital skills.
The programme provides free training in areas including software development, artificial intelligence, cloud computing, cybersecurity, data analytics, machine learning, animation, DevOps and user interface/user experience design through a hybrid learning model.
Stakeholders maintained that while the partnership with Hello.cv could expand international employment opportunities for Nigerian technology professionals, greater attention should be paid to safeguarding the country’s digital assets, promoting local internet infrastructure and ensuring compliance with Nigeria’s data protection framework.
E-Financial3 days agoAccess Bank Debunks Shutdown Report, Vows Action against Perpetrators
E-Business2 days agoHow Temu Helped a Madagascan Vanilla Family Business Sell Direct to Consumers Across Europe
Broadcasting2 days agoDavido Shares Past Suicidal Thoughts, Drops Oriadé Album
General News2 days agoMTN Nigeria Posts N707.5bn H1 Profit, Declares N26 Interim Dividend
E-Business2 days ago82% of Organizations Concerned about AI Risks Even as Adoption Accelerates – Survey Reveals
News2 days agoAfCFTA Urges Africa to Stop Exporting Raw Materials
News2 days agoCisco Explores AI for Nigeria Farmers
General News2 days agoGavi Okays $500m for Vaccines, PHCs in Nigeria











