Connect with us

E-Business

Sophos Releases Scaring 2016 Cyber Security Predictions

Published

on

Cyberthreats.jpg
Kindly share this post

 

In the ever changing and increasingly complex landscape of cyber security, Sophos experts offer their top predictions for 2016: Android Threats Will Become More Than Just Headline-Grabbers

Next year will see an increase in the number of Android exploits becoming weaponized (as opposed to bugs like Stagefright which was heavily reported earlier in 2015 but was never fully exploited).

There are significant vulnerabilities on the Android platform which can take months to patch. Although Google claims that nobody has actually exploited these vulnerabilities to date, it will ultimately be an invitation too tempting for hackers to ignore.

SophosLabs has already seen samples that go to extreme lengths to avoid App Store detection and filtering—giving Apps a better chance of surviving on App stores.

Advertisement

For example, some hackers will design an App that loads harmless games if it thinks it is being tested, but then loads the malicious payload when it detects it is ‘safe’ to do so.

And more recently, we saw mobile users using third- party app markets, being tricked into granting malicious apps from the adware family Shedun with control over the Android Accessibility Service.

Once they’ve handed over control the app has the ability to display popups that install highly intrusive adware, even if a user has rejected the invitation to install it. Because the apps root the device and embed themselves into the system partition they can’t easily be uninstalled.

Android malware can be complicated and consumers cannot necessarily trust the App Store to detect these vulnerabilities in every instance.

Will 2016 Be The Year iOS Malware Goes Mainstream?

Advertisement

We’ve already seen the Apple App Store get hit a few times this year, once with the InstaAgent app, which snuck through the vetting processes and which both Google and Apple pulled from their respective app stores, and before that, with XcodeGhost, which tricked Apple app developers into incorporating the code into their apps, thereby infecting them but cleverly hidden behind what looked like Apple code.

With more and more apps coming onto the market (both Apple and Google have more than a million apps each in their official marketplaces to date), it is not hard to imagine more criminals trying their hand at getting past the existing vetting processes.

Nevertheless, the nature of Android, in particular support for the flexibility of third party markets will continue to contribute towards Android being an easier target than iOS.

IoT Platforms – not yet the weapon of choice for commercial malware authors – but business beware

Every day, more and more technology is being incorporated into our lives. Internet of Things devices are connecting everything around us and interesting new use cases are appearing constantly.

Advertisement

IoT will continue to produce endless scary stories based on the fact that these devices are insecure (early 2015 saw many stories focusing on webcams, baby monitors and children’s toys and latterly cars have become a hot topic – researchers hacked a jeep in July).

However, we won’t see widespread examples of attackers getting IoT devices to run arbitrary code any time soon. Because they are not general purpose computing devices with the same broad suite of interfaces that we have on desktops/mobiles, IoT devices are relatively protected.

What we will see is more research and PoCs demonstrating that non-vendor code can be installed on these devices because of insufficient validations (lack of code-signing, susceptibility to MitM-class exploitations) by the IoT vendors.

Sophos said that we can expect an increase in data-harvesting/leakage attacks against IoT devices, wherein they are coaxed to disclose information that they have access to, e.g. video/audio feeds, stored files, credential information for logging into cloud services, etc.

And as IoT devices evolve in their utility and ability to interact with their surrounding, i.e. as they become “roboticized” – an app-controlled Roomba for example – the set of security concerns around IoT will start becoming very similar to the set of security concerns around SCADA/ICS, and the industry should look toward the best guidance that NIST, ICS-CERT and others have formulated.

Advertisement

 SMBs Will Become A Bigger Target For Cybercriminals

Throughout 2015, the focus has been on the big glamorous hacking stories like Talk Talk and Ashley Maddison, but it’s not just big businesses that are being targeted.

A recent PwC report revealed that 74% of SMBs experienced a security issue in the last 12 months, and this number will only increase due to SMBs being perceived as ‘easy targets’.

Ransomware is one area where criminals have been monetizing small businesses in a more visible way this year.

Previously, payloads – such as sending spam, stealing data, infecting websites to host malware – were far less visible so that small businesses often didn’t even realize they had been infected. Ransomware is highly visible and has the potential to make or break an SMB if they do not pay the ransom.

Advertisement

This is why, of course, criminals are targeting SMBs. Expect to see this ramp in 2016.

Lacking the security budgets of large enterprises, SMBs often apply a best-effort approach to security investments, including equipment, services, and staffing.

This makes them vulnerable as hackers can easily find security gaps and infiltrate the network. On average, a security breach can cost a small business anywhere up to £75,000 – a significant loss for any business. It’s important therefore that SMBs take a consolidated approach to security.

This requires a thoughtfully planned out IT strategy to prevent attacks before they happen. Installing software that connects the endpoint and the network will mean a comprehensive security system is in place where all components communicate, and ensure there are no gaps for hackers.

Data Protection Legislation Changes Will Lead To Increased Fines For The Unprepared

Advertisement

In 2016, the pressure on business to secure customers’ data will increase as the EU data protection legislation looms closer. In future, business will face severe penalties if data isn’t robustly secured. This will have a far reaching impact for how businesses deal with security, including the high risk area of employee personal devices.

Two major changes will be the EU General Data Protection Regulation (GDPR), and the Investigatory Powers Bill in the UK. The EU Data Protection regulation will come fully into force across Europe by the end of 2017, so companies need to start preparing in 2016.

It has numerous components, but one key takeaway is that European businesses will now be held responsible for the protection of the data they process, including cloud providers and other third-parties.

In the UK, the Investigatory Powers Bill will modernise laws surrounding communications data. This will give the police and other intelligence bodies the ability to access all aspects of your communications on ICTs, whether you are suspected of a criminal offence or not.

As this is due to go ahead in 2016, it will be interesting to see how this bill is shaped and shifted, and if people will start prioritising data security.

Advertisement

In the US, data protection is complicated by the fact there is no single overarching law. This has the effect that data protection tends to be less strict than in Europe, which has led to issues around the Safe Harbor agreement.

Over time the US and Europe will hammer out their differences, but it seems unlikely that we will see a new agreement any time soon.

VIP Spoofware Is Here To Stay

We’ll see a growth in the use of VIP spoof wire transfers as we move into 2016. Hackers are becoming increasingly talented at infiltrating business networks to gain visibility of personnel and their responsibilities, and then using this information to trick staff for financial gain.

For example, sending an email to the finance team that appears to be from the CFO requesting the transfer of significant funds. This is just one of the ways we’ll see criminals continue to target businesses.

Advertisement

 
Ransomware Momentum

Ransomware will continue to dominate in 2016 and it is only a question of time before we see things beyond data being ransomed.

It is perhaps some time off before we have a sufficient mass of internet-enabled cars or homes, but we should be asking the question: how long before the first car or house is held for ransom? Attackers will increasingly threaten to go public with data, rather than just taking it hostage and we have already seen websites being held ransom to DDoS.

Many Ransomware families are using Darknets for either command or control, or for payment page gateways, as we saw with the likes of CryptoWall, TorrentLocker, TeslaCrypt, Chimera, and many more in 2015.

 
Social Engineering Is On The Up

Advertisement

As cybersecurity comes to the fore and social engineering continues to evolve, businesses will invest more in protecting themselves from such psychological attacks.

They will achieve this through investing in staff training, and ensuring there are strict consequences for repeat offenders.

Employees need to be trained on how to be security savvy when on the company network.

Basic tips we would recommend incorporating into training include: Teaching staff about the implications of a phishing email and how to identify one; Ensuring staff don’t click on malicious links that might be found in unsolicited emails; Encouraging staff to be wary that mis-spelt emails could be a sign of a scam; and to watch out for sites that ask for sensitive information, such as card PIN and national insurance number.

Another golden rule is never to share a password. Each of us can help here by sending a signal to the market: let the providers who store your most valuable data (your bank, your health insurance company, your payroll management service, etc.) know that you demand strong security.

Advertisement

If they don’t give you the option to use multi-factor authentication, ask them why not? Or better still, just switch to a provider who does.

 
Both Bad And Good Guys Will Be More Coordinated

The bad guys will continue to use coordinated attacks but the cyber security industry will make significant strides forward with information sharing.

For some time the bad guys have been coordinating and collaborating, re-using tactics and tools, and generally keeping one step ahead of the cyber security industry.

But the industry is now evolving and we expect to see the promising activity that has begun around information sharing and workflow automation continue and begin to deliver big differences in 2016 and onward.

Advertisement

 
Commercial Malware Authors Will Continue To Invest Heavily

Commercial malware authors will continue to reinvest at ever greater rates, bringing them towards the ‘spending power’ of nation-state activity. This includes purchasing zero days. These bad guys have lots of cash and they are spending it wisely.

Exploit Kits Will Continue To Dominate On The Web

Exploit kits, like Angler (by far the most prevalent today) and Nuclear, are arguably the biggest problem we have on the web today as far as malware goes and this looks set to continue thanks to the thousands and thousands of poorly secured websites out there on the internet.

Cyber criminals will exploit where they can most easily make money and therefore exploit kits have simply become stock tools of the trade, used by criminals to attempt to infect users with their chosen malware.

Advertisement

 

 
 

 

 

Advertisement

Kindly share this post

Nigeria CommunicationsWeek believes that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. So since 2007, we have devoted our energy to independent reportage of technology and how they affect lives.

Continue Reading
Advertisement
Comments

E-Business

Nigeria Leads Africa in Online Gambling Regulation – GCI

Published

on

Kindly share this post

Nigeria has emerged as one of Africa’s most regulated online gambling markets, even as illegal operators continue to dominate the continent, according to a new report by Gaming Compliance International (GCI).

Nigeria Leads Africa in Online Gambling Regulation - GCI

The report, the first comprehensive assessment of online gambling across all 54 African countries, showed that Africa’s online gambling Gross Gaming Revenue (GGR) reached $23 billion in 2025.

However, only $5.2 billion (23 per cent) was generated by licensed operators, while $17.8 billion (77 per cent) remained in the unregulated market.

In West Africa, total online gambling revenue rose to $4.8 billion in 2025 from $4.3 billion in 2024. Of the 2025 figure, regulated operators accounted for $1.5 billion (31 per cent), while $3.3 billion (69 per cent) flowed to unlicensed platforms, highlighting the region’s persistent enforcement challenges.

Nigeria stood out as the region’s strongest performer, recording the lowest unregulated market share at 56 per cent, compared with the West African average of 69 per cent and the African average of 77 per cent.

Advertisement

The study also found that online gambling participation across Africa increased from 198 million people (13 per cent of the population) in 2024 to 215 million (14 per cent) in 2025.

Despite this growth, GCI estimated that illegal operators deprived African governments of about $3.55 billion in tax revenue in 2025. The number of unlicensed gambling platforms targeting African consumers also rose to 4,129, up from 3,644 in 2024.

Commenting on the findings, Matt Holt, chief executive officer, GCI, said the report provides regulators with the first continent-wide benchmark for strengthening oversight and consumer protection.

Ismail Vali, president, GCI, urged governments to develop competitive and well-regulated markets that encourage consumers to patronise licensed operators, boost public revenue and attract greater investment.

Online gambling in Nigeria is regulated by the Nation Lottery Regulatory Commission.

Advertisement

Kindly share this post
Continue Reading

E-Business

Kaspersky Warns Mobile‑data Buyers about Scammers Posing as Telecoms Operators

Published

on

Kindly share this post

At the height of the Northern Hemisphere tourist season, demand for communications and mobile Internet services rises sharply. Kaspersky’s security experts have uncovered scams that target anyone purchasing mobile connections or SIM cards worldwide.

Fraudsters create counterfeit websites that look like the portals of major regional and international telecom providers to trick users into revealing their phone numbers, personal details or banking information.

Kaspersky is sharing several examples of these fake login pages that mimic legitimate telecom operator sites and giving recommendations on how not to be deceived.

In the first case, scammers exploit the brand name of an international telecommunications company operating services in Asia, Africa and Europe. Fake authentication pages encourage users to put in their phone number and credentials.

While the first example shows the different design, the second scam site closely mimics the original log in page, making it hard for users to tell the difference and spot a fake. Entering authentication or payment data on fraudulent web sites may result in money or data loss and become a reason for more frequent spam and fraudulent calls.

Advertisement

Another example is a scam page which poses as another international communications company, working in North Africa, the Middle East and Southeast Asia. In this scheme scammers encourage users to top up their mobile data/Internet plans by entering their personal information and bank cards details.

Kaspersky experts have also identified a scam when cyber criminals suggest users enter their personal data to check and pay a bill inquiry. Such scam schemes are usually aimed at gaining victims’ personal data for further fraud or account hacking and stealing money.

“Because of the active use of AI, scammers can now create fake pages with ever increasing accuracy and speed, targeting the most popular user interest areas. We constantly see scams revolving around sports events, music concerts, seasonal sales and holidays. Unfortunately, the telecoms industry is no exception.

To keep your data and money safe, be vigilant when purchasing mobile or Internet plans online. Using an eSIM – purchased through an official app – is one way to avoid fake telecom sites, as it eliminates the need to enter personal details on questionable web pages.

If you’re unsure about a site’s legitimacy, search for the brand name directly in a search engine and enable a security solution that blocks phishing links for you,” comments Tatyana Kulikova, cybersecurity expert at Kaspersky.

Advertisement

 

Kindly share this post
Continue Reading

E-Business

NITDA, NAWOJ Partner to Advance Women’s Digital Inclusion, Digital Literacy

Published

on

Kindly share this post

In a strategic push to bridge the gender digital divide, the National Information Technology Development Agency (NITDA) has partnered with the Nigeria Association of Women Journalists (NAWOJ) to advance women’s digital inclusion and drive the nation’s transformation agenda.

NITDA, NAWOJ Partner to Advance Women's Digital Inclusion, Digital Literacy

Dr Aristotle Onumo and some NITDA staff, pose for a group photograph with the President of the National Association of Women Journalists (NAWOJ), Comrade Aisha Ibrahim, and members of the delegation following a strategic engagement at the Agency’s Headquarters in Abuja.

The partnership was cemented during a courtesy visit to NITDA Director General, Kashifu Inuwa, CCIE, by a NAWOJ delegation led by National President Comrade Aishatu Ibrahim, who introduced the agency to the forthcoming Women in Security (WINSEC) Summit & Awards 2026.

Inuwa, represented by Dr. Aristotle Onumo, the Director of the Stakeholders Management and Partnerships Department, assured the association that NITDA would not only participate in the conference, but also support the success of the conference.

Inuwa hailed the NAWOJ for creating a platform for peacebuilding, dialogue on security and women’s inclusion, which he described as one of the critical areas NITDA is focused on to ensure that more women obtain digital literacy and skills under the National Gender Inclusive Strategy.

Beyond NITDA’s plan to participate in the conference, the DG noted that a robust partnership between the organisations would engender meaningful opportunities and initiatives through which many more women can access digital literacy.

“Inclusivity is the key to everything we do at NITDA. We clearly defined that 40 per cent of our programmes must recognise the issue of gender. We ensure that women are adequately represented and positioned to benefit greatly from the programmes that we organise in the agency.

Advertisement

“We graciously accept to participate actively in that conference. Apart from acquiring skills among journalists themselves, partnership with NAWOJ will also serve as a platform through which we can also reach out to various women’s groups across the federation,” Inuwa said.

Earlier, Comrade Ibrahim commended the DG for his visionary and transformational leadership which has continued to position NITDA as the catalyst for Nigeria’s digital economy through its various programmes.

She explained that the Women in Security (WINSEC) Summit and Awards 2026 is an initiative of NAWOJ designed to promote collaboration among government institutions, security agencies, technology experts, the media, and other stakeholders to address contemporary security challenges.

According to Comrade Ibrahim, the association also aims to recognise outstanding individuals and institutions that have demonstrated excellence in security, governance, and innovation while fostering meaningful dialogue on the role of technology in building a safer and more resilient Nigeria.

“We deeply appreciate your exemplary leadership, passion for innovation, and unwavering commitment to building a digitally empowered Nigeria. We respectfully invite the agency to partner with NAWOJ in making this landmark initiative a success.

Advertisement

“We look forward to establishing a long-term partnership with NITDA that will empower women journalists with cutting-edge digital skills, support digital inclusion and contribute to innovation, digital literacy, and human capital development,” the NAWOJ president added.

Both organisations expressed optimism that the meeting would lay a solid foundation for a rewarding partnership agreement with specific and clearly defined objectives that will support digital inclusion and contribute to innovation, digital literacy, and human capital development.

Kindly share this post
Continue Reading

Trending