SCCyberworld

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, May 22, 2014

McAfee offers FREE instant protection Scan for mobile apps that overshare personal information

New Release of McAfee Mobile Security Enables Android Users to Instantly Check for Apps That Use Extensive Data Collection Techniques

Singapore – May 22, 2014 – Today McAfee, part of Intel Security, announced the latest version of McAfee Mobile Security that now enables consumers to instantly run free privacy and security scans.  These scans allow users to identify apps that are oversharing personal information. It also scans for and removes malware and looks for other security threats. McAfee makes it simple for users to perform these scans as soon as the product is installed. McAfee Mobile Security also allows users to easily remove apps that pose significant risks.

According to McAfee’s Consumer Mobile Security Report, 80% of mobile apps today collect location information about users, 82% know the device ID, and 57% track when people use their phones.  Additionally, the apps that aggressively and often unnecessarily collect data leverage potentially dangerous ad libraries, and 35% of these apps contain malware.

“Smartphone users download apps so regularly that it is easy to forget how these apps collect information – at times even putting its users at risk,” said David Freer, Vice President, Consumer – APAC at McAfee, part of Intel Security. “Keeping this in mind, McAfee Mobile Security helps users better protect their personal information and inform them of the kind of information their apps have access to.”

McAfee Mobile Security’s privacy scan provides key intelligence about the apps users have installed on a smartphone or tablet.  The scan determines how much information each app is able to access and share, then ranks them by level of privacy sensitivity, while also checking for risky URL associations.  When an app behaves significantly different than others in its category, the level of risk is raised and reflected in its privacy sharing score. At the conclusion of the privacy scan the user can uninstall suspicious apps with one-click.

The most worrisome permissions are apps that read users’ subscriber ID from their smartphones and tablets, anything that gets users’ precise location (as opposed to Wi-Fi network or cell tower), and anything that reads or tracks text messages that can contain private messages and information like online banking transaction authorizations.  To provide a deeper level of protection, the new version of McAfee Mobile Security instantly scans Android apps, files, SD cards and Internet downloads for malware using a method optimized for mobile to be light on resources and battery life.

McAfee Mobile Security
McAfee Mobile Security for Android is designed to prevent privacy invasions, data loss, identity theft and lost or stolen devices.  It includes anti-theft, antivirus, app protection, Web and Wi-Fi protection, along with call and SMS filtering. In AV-Test’s most recent effectiveness test for mobile security products, McAfee Mobile Security received a 100% detection score for the second time this year and was given a top ranking among the 30 vendors that participated in the independent test.  McAfee Mobile Security can be downloaded for free from the Google Play Store.

Thursday, May 15, 2014

Microsoft Reveals Shift in Cybercriminal Tactics

Exposing Trends to Help Ready People Against Deceptive Practices 

KUALA LUMPUR, 15 May 2014 — Today, Microsoft Corp. released new data indicating that as attacks against software are becoming more difficult and expensive, cybercriminals are increasingly turning to deceptive tactics for malicious purposes such as stealing people’s personal and financial information. In the last quarter of 2013, the number of computers that had to be disinfected as a result of deceptive tactics more than tripled.

According to data from Microsoft’s latest Security Intelligence Report (Volume 16 – full report, key findings), one of the most common tactics used was deceptive downloads. These downloads were identified as a top threat in 95% of the 110 countries/regions that Microsoft’s data examined. The top three deceptive threats in Malaysia during the fourth quarter of 2013 were Rotbrow, Brantall and Obfuscator:

  • Rotbrow – (Trojan Downloaders & Droppers) This family of trojans install browser addons that claim to protect you from other addons. These addons can make changes to your home page and also install a program that claims to protect your computer from browser add-ons, but actually installs more browser add-ons and other malware.  Rotbrow was encountered by 59 out of every 1000 systems that run our real-time antimalware products in 2H13.  It was the top threat family facing both enterprises and consumers in 4Q13.  
  • Brantall – (Trojan Downloaders & Droppers) Acts as an installer for various legitimate programs, installs itself as a service in some cases, installs both the advertised legitimate program, additional bundled applications and other malicious software.  Brantall was encountered by 36 out of every 1000 systems that run our real-time antimalware products in 2H13.  It was the second most common threat family facing both enterprises and consumers in 4Q13.  
  • Obfuscator – (Miscellaneous Trojans) A generic detection for threats that have been modified by malware obfuscation tools in an attempt to avoid detection by security software.


This increase in deceptive tactics corresponds with a 70 percent decline in the number of severe vulnerabilities exploited in Microsoft products between 2010 and 2013. This is a clear indication that newer products are providing better protection. Additionally, the increased adoption of several key security mitigations across the industry are making it more difficult and expensive for cybercriminals to develop software exploits.
Tim Rains, director, Trustworthy Computing, Microsoft Corp.

“Keeping cybercriminals on the run requires a robust security strategy,” said Tim Rains, director, Trustworthy Computing, Microsoft Corp. “The safest houses don’t just have locked doors, they have well-lit entry points and advanced security systems. It’s the same with computer security—the more we layer our defenses the better we are at thwarting attacks.”

Cybercriminals lure their victims with deceptive downloads by bundling malware with legitimate downloadable content such as software, music or videos found online. While the threat of deceptive downloads is on the rise, their impact is often not seen right away. Infected machines often continue to function, and the only observable signs of the malicious download might be a slower computer or unexpected search results popping up in a browser. Over time, fraudulent activity like click fraud generated from the infected computer can tarnish an individual’s online reputation.
Dr Amirudin Abdul Wahab, CEO of CyberSecurity Malaysia.

While deceptive downloads were identified as one of the most prevalent tactics used worldwide, ransomware is another deceptive practice that continues to affect people and can be devastating for those victimized by it. Ransomware often pretends to be an official-looking warning from a well-known law enforcement agency. It accuses its victim of committing a computer-related crime and demands they pay a fine to regain control of the computer. Ransomware is geographically concentrated, but for cybercriminals looking to make a quick profit, the data shows it is an increasingly alluring tactic. In fact, the top ransomware threat encountered globally increased by 45 percent between the first half and the second half of 2013.

In light of this new information on cyber-threats, Microsoft advises customers take a few actions to help keep themselves protected, including: using newer software whenever possible and keeping it up to date, only downloading from trusted sources, running antivirus, and backing up files.

Commenting on the latest findings in Microsoft’s Security Intelligence Report (Volume 16), Dr Amirudin Abdul Wahab, CEO of CyberSecurity Malaysia, the national cyber security specialist agency under the purview of the Ministry of Science, Technology, and Innovation (MOSTI) reminded Malaysians to develop, foster and maintain a culture of cybersecurity and become responsible digital citizens who are well-equipped with the knowledge and skills to be stay cyber-safe. He said, “As cybercriminals move towards more deceptive practices amidst a more ubiquitous use of computing among Malaysians, users have to become even more vigilant to safeguard their knowledge of cybersecurity best practices – whether it is in their homes or at school and work.”

Microsoft releases its cybersecurity report twice a year, which culminates data from more than a billion systems worldwide and some of the busiest online services. The report provides an in-depth analysis on the latest threat trends for 110 countries/regions worldwide and is designed to help inform people about the most prevalent global and regional threat trends so that they can better protect themselves and their organizations. Key findings from Volume 16 of the report includes new data from the second half of 2013. To learn more about the report findings visit www.microsoft.com/sir.

Tuesday, April 29, 2014

Kaspersky Lab’s Solution for Android-based Devices Proves its Effectiveness in Independent Testing

Petaling Jaya, April 29 - Kaspersky Internet Security for Android earned top marks in the independent testing of mobile security products conducted by AV-Test in March 2014. Kaspersky Lab’s solution successfully blocked all threats and its performance received the highest rating from the test lab.

AV-Test experts analyzed how effective the products from different vendors were at protecting against mobile cyber threats by testing them with 2,266 malware samples that were active at the time of testing. The products were also assessed for the number of false positives generated and their impact on performance, battery life and web traffic.

A total of 31 solutions were tested. During testing, the products used their default settings and were allowed to update their antivirus databases, use all available protection tools and query their in-the-cloud service. All products were tested on Android 4.3.

Kaspersky Internet Security for Android identified and neutralized 100% of the malware samples, compared with a 95% average score for all the participating solutions. It produced zero false positives and did not have any appreciable impact on the resources of the mobile device. This earned Kaspersky Internet Security for Android a score of 13 points out of 13, and a “Certified” award.

“The main task of a mobile security solution is to secure user data from cybercriminal actions and prevent the device from turning into a source of spam or other cyber attacks. When a user chooses a solution, its impact on the device’s performance often becomes a major factor. So it is important that a security product for smartphones and tablets ensures high-level protection against cyber threats and, at the same time, does not affect the user experience.

The AV-Test study has demonstrated that Kaspersky Internet Security for Android fully meets this requirement,” said Viktor Chebyshev, Mobile Threat Research Group Manager at Kaspersky Lab. Kaspersky Lab’s security solution for Android devices has repeatedly been hailed by independent testing laboratories. In January this year PC Security Labs awarded the product a first place in the Android Malware Detection Test for demonstrating high-level protection against mobile cyber threats.

Tuesday, April 15, 2014

Best practices can prevent and mitigate future incidences like the Heartbleed OpenSSL bug

By Steven Rosen, Chief Information Officer, Xchanging Malaysia

Recently, Malaysians were made aware of ‘Heartbleed’, a major encryption flaw that affects OpenSSL web servers. Known as one of the biggest security threats online, the flaw allows cybercriminals access to crucial and corporate information stored on the cloud across various websites such as Facebook, Google and Twitter. As such, patrons of these open platforms may have been exposing their crucial and private data for the past two years.

Since its inception in 2012, OpenSSL has been a popular choice amongst companies as it is a free platform. In fact, according to a recent Netcraft Web Server survey across 959 million websites globally, around 66% are powered by technology built around OpenSSL but some of the technology used to secure communication was jeopardised for over two years by the ‘Heartbleed’ bug.

While consumers have received alerts from several websites to update their passwords to protect their information, securing corporate information is much more complex. Companies need to track and assess their systems for exposures and may not be aware of what to do, or procrastinate. This delay creates an opportunity for hackers to seize the moment and exploit the data at hand.

What businesses can do to mitigate the risk
If businesses have been using OpenSSL, a quick reactive process should be in place to analyse and identify the risks they are exposure to, and take steps to immediately address them. After which, organisations should run an audit to ensure no other information has been compromised on the system.

However, the challenge businesses face is that the bug masks itself as a heartbeat, in a transparent form and makes it near impossible to trace if any information from memory has been compromised through this exploit.

To mitigate this issue, it is important for businesses to deploy adequate tools to help keep track of patches and bugs across systems. Here are some crucial tools businesses can take into consideration:

Implementing a standard operating environment (SOE) which helps to standardise all applications and tools that are in use  
A configuration management database (CMDB) which assesses all servers, network elements and collects configuration specific information and includes them into a single database
If an issue comes up, CMDB can run a report and businesses would immediately be aware of what areas have been compromised, and address them appropriately
IT Infrastructure Library (ITIL), which is the enterprise standard across the world on how IT should be structured
Part of ITIL is a patch management process, which ensures the SOE is healthy, functionally capable and secure. An added benefit is its ability to keep track of functional and security patches that can identify and quickly deploy patches for the system if there is a compromise

Many Malaysians may not be aware that Windows or iOS updates are in fact patches for functional or security issues. They are either mandatory or optional for certain software, and a robust management system can be designed to automate such updates on a weekly or monthly basis whenever they become available.

What companies can do if they want to continue using OpenSSL
Companies can choose to use wild card certificates with one encryption key for each subdomain, or generate a single encryption key for all subdomains. Security best practices would recommend that you use a separate key for each subdomain, but based on the criticality of the systems and data, it may be more cost beneficial to use a wild card certificate.

While organisations can still choose to use OpenSSL, it is also the company's responsibility to ensure that all security gaps associated with OpenSSL and other free tools or platforms are actively monitored and addressed.

Monday, April 14, 2014

THREE TEAMS TO ENTER THE FINAL ROUND FOR F-SECURE’S NATIONAL LEVEL IT COMPETITION

Kuala Lumpur, 14 April 2014 – It was an intense battle between nine teams at the 2014 F-Secure National Inter-Varsity IT Security semi-final competition. Three teams from University Sains Malaysia (Team N2L and Team The Bounty Hunter) as well as team Xposure from Multimedia University Malacca overcame all odds to make it through to the finals – one step closer for a chance to be crowned the champion.

This programme is the brainchild of F-Secure Malaysia. Together with Multimedia Development Corporation (MDeC), this initiative aims to develop local talents and encourage more Malaysian undergraduates to venture into the field of IT security through education.

(L-R, 3 individuals in a team, forming a triangle each) Teams Xposure, N2L and The Bounty Hunter will be competing for the title in the finale of 2014 F-Secure Inter-Varsity IT Security Competition.

Goh Su Gim, Security Advisor Asia Pacific, F-Secure Labs commented, “All full-time IT undergraduates enrolled in all Malaysian public and private universities have the opportunity to participate in this friendly competition. It provides an avenue for them to apply their academic knowledge and personal interest in the field of IT security. This annual competition has gained traction through the years since it was introduced five years ago and we are pleased to know that more and more students are taking part”.

Over the past month, officials from F-Secure set out to administer qualifying tests to almost 174 participants making up the 52 teams from 23 universities. The responses were encouraging with teams flown in from various states to participate in the Semi-Finals today.

The nine semi-finalists included:
UNIVERSITY
TEAM NAME
University Sains Malaysia
N2L
Multimedia University Malacca
Xposure
Taylors University
Flying Monkeys
University Putra Malaysia
3ecure
MSU
MsuOne
University Sains Malaysia
The Bounty Hunters
University Tenaga Nasional
CySec
Sunway University
Anony
University Malaysia Sabah
Eminence

This year, the level of excitement at the semi-finals has gone up a notch whereby the teams had to try and complete five hands-on technical puzzles of different complexity level. Upon completing a puzzle, only then will the team proceed to the next puzzle - the aim is to complete all five. The puzzles tested their programming skills and critical thinking skills, e.g. finding clues within a program to get to the next puzzle. 

“The top 3 teams were selected based on their understanding of the IT security domains such as malware and IT threats, as well as their ability to apply what they learnt in the classroom and their personal time into real world puzzles and problems. Criteria such as critical thinking, problem solving, presentation of the results and teamwork within the team (in a timely manner) determined their chances to proceed to the finals. They are basically the best of the best advancing into the finals”, explained Goh.
The nine teams gave their best in getting a spot into the finals while the committee members (those in yellow top) strived their best in developing the challenges for the participants.

One of the finalists, N2L team from University Sains Malaysia was overjoyed when they were announced as one of the finalists for the competition. Having the background of Computer Science, this first timer was made of Lim Yen Sheng (24), Lee Chi Ngan (23) and Law Jia Jge (23). “We never thought that we could make it into the finals as the hands-on challenge was pretty challenging,” Lim said. Lee continue, “For the upcoming final, we will be focusing on the topics shared and we will try our best in being a competitive opponent to the two other teams”.
  
On the other hand, team Xposure from Multimedia University Malacca who are currently pursuing an IT degree majoring in Security Technology were also ecstatic to know that they will be competing with two other teams. Leader of the team, Tan Chee Hong (21) along with two other members, Ling Cong Xiang (20) and Sia Hooi Lip (24), were also first-timers in this competition. Tan said, “The final round will be a tough one with two other strong opponents from USM but we will definitely be more prepared than ever to win the competition.”

The three finalists will advance to the final round on 25 April 2014 and will stand a chance to win the grand prize - three branded, high-end Windows 8 laptops worth RM5, 000 each, while the 1st runner-up team will receive three Android tablets worth RM2, 000 each and the 2nd runner-up team will walk away with three smart-watches worth RM500 each. 

“With the ever increasing reliance on our digital gadgets, be it smartphone, tablet, etc, most things are documented, stored and communicated through it. If we are not careful, our data can be accessible to simply anyone. It is important now than ever to protect our data. As IT progresses rapidly, the IT security industry is a burgeoning one as we will be liken to a police in a digital realm. We hope to increase genuine interest amongst the younger generation for internet security in Malaysia. With that, we look to continue investing in them and developing their knowledge and skills so that we can address as well as prevent IT security issues in the country,” Goh explained.

For more information about F-Secure Malaysia and their services, please visit            http://www.f-secure.com or call 603 2264 0200. You can also connect with F-Secure through Facebook at http://www.facebook.com/FSecure and follow them on Twitter at https://twitter.com/fsecure.

Wednesday, March 5, 2014

2014 F-SECURE NATIONAL INTER-VARSITY IT SECURITY COMPETITION

Attention to all IT undergraduates in Malaysia! It is time to showcase your academic knowledge and personal interest in IT security by participating in a friendly competition organized by F-Secure.

Each university will be able to submit up to 3 teams of 3 members each, with a team name and a team leader. The winning team will be awarded three branded, high-end Windows 8 laptops worth RM5, 000 each. The 1st runner-up team will receive three Android tablets worth RM2, 000 each and the 2nd runner-up team will receive three smart-watches worth RM 500 each.

The closing date for registration is on Friday, 7 March 2014, at 6.00 p.m.
For more information, kindly contact Marsyada Mazlan at +6012-314 5233 or
ext-marsyada.mazlan@f-secure.com.


Tuesday, February 4, 2014

The World’s First Mobile Malware Celebrates its 10th Birthday

2014 marks the 10th anniversary of Cabir, the world’s first mobile phone malware. To mark this occasion, Fortinet’s FortiGuard Labs is taking a stroll down memory lane to examine the evolution and significance of mobile threats during the last 10 years.

MALAYSIA, February 4, 2014 - From Cabir to FakeDefend, the last decade has seen the number of mobile malware explode. In 2013, Fortinet’s FortiGuard Labs has seen more than 1,300 new malicious applications per day and is currently tracking over 300 Android malware families and over 400,000 malicious Android applications.

Besides the sheer growth in numbers, another important trend to note is that mobile malware has followed the same evolution as PC malware, but at a much faster pace. The widespread adoption of smartphones and the fact that they can easily access a payment system (premium rate phone numbers) make them easy targets which can quickly generate money once infected. Furthermore, they have capabilities such as geo-location, microphones, embedded GPS and cameras, all of which provide for a particularly intrusive level of spying on their owners. Like PC malware, mobile malware quickly evolved into an effective and efficient way of generating a cash stream, supporting a wide range of business models.

In the following chronology, FortiGuard Labs looks at the most significant mobile malware over the last 10 years and explains their role in the evolution of threats:
2004: The first attempt!
Cabir was the world’s first mobile worm. Designed to infect the Nokia Series 60, its attack resulted in the word « Caribe » appearing on the screen of infected phones. The worm then spread itself by seeking other devices (phones, printers, game consoles…) close to it using the phone’s Bluetooth capability.

2005: Adds MMS to the Mix
Discovered in 2005, CommWarrior would access the infected phone’s contact file and send itself via the carrier’s MMS service to each contact.  The use of MMS as a propagation method introduced an economic aspect; for each MMS message sent, the phone’s owner would incur a charge from their carrier. 115,000 mobile devices were infected and more than 450,000 MMS were sent without the knowledge of victims, showing for the first time that a mobile worm could propagate as quickly as a PC worm.

2006: Following the Money
RedBrowser was designed to infect a phone via the Java 2 Micro Edition (J2ME) platform.  The Trojan would present itself as an application to make browsing Wireless Application Protocol (WAP) websites easier.  It was specifically designed to leverage premium rate SMS services.  The phone’s owner would typically be charged approximately US$5 per SMS, another step towards the use of mobile malware as a means to generate a cash stream.

2007-2008:  A Period of Transition:
During this two year period, even though there was stagnation in the evolution of mobile threats there was an increase in the number of malware that accessed premium rate services without the device owner’s knowledge.

2009: The Introduction of the Mobile Botnet
In early 2009, Fortinet discovers Yxes (anagram of « Sexy »), a malware which is behind the seemingly legitimate « Sexy View » application.  Once infected, the victim’s mobile phone forwards its address book to a central server.  The server will then forward a SMS containing a URL to each of the contacts.  By clicking on the link in the message, a copy of the malware is downloaded and installed and the process is repeated over and over again. The spread of Yxes was largely limited to Asia where it has infected at least 100,000 devices in 2009.

2010: The Industrial Age Of Mobile Malware
2010 marked a major milestone in the history of mobile malware; the transition from geographically localized individuals or small groups to large scale, organized cybercriminals operating on a worldwide basis.  This is the beginning of the era of « industrialization of mobile malware » where attackers realized that mobile malware can easily bring them a lot of money and decided to exploit them more intensely.

2010 was also the introduction of the first mobile malware derived from PC malware.  Zitmo, Zeus in the Mobile, was the first known extension of Zeus, a highly virulent banking Trojan developed for the PC world.  Working in conjunction with Zeus, Zitmo is used to bypass the use of SMS messages in online banking transactions, circumventing the security process.

Geinimi was one of the first malware designed to attack the Android platform and use the infected phone as part of a mobile botnet.  Once installed on the phone, it would communicate with a remote server and respond to such a wide range of commands, such as installing or uninstalling applications, that it could effectively take control of the phone.

2011: Android, Android and Even More Android!
With attacks on Android platforms intensifying, 2011 saw the emergence of even more powerful malware.  DroidKungFu, which even today is still considered one of the most technologically advanced viruses came into existence and had several unique characteristics. The malware included a well-known-exploit to “root” or become an administrator of the phone – uDev or Rage Against The Cage – giving it total control over the phone and thereafter contacting a command server. Plankton also arrived on the scene in 2011 and is still one of the most widespread Android malware.

2013: Game on – New Modes of Attack
2013 marked the arrival of FakeDefend, the first ransomware for Android mobile phones. Disguised as an anti-virus, this malware works in a similar way to the fake antivirus on PCs. It locks the phone and requires the victim to pay a ransom (in the form of an exorbitantly high Anti-Virus subscription fee, in this case) in order to retrieve the contents of the device.  However, paying the ransom does nothing for the phone which must be reset to factory settings in order to restore functionality.

What’s next? In the area of cybercrime, it is always difficult to predict what will happen next year and even more so over the next 10 years. The landscape of mobile threats has changed dramatically over the past decade and the cybercriminal community continues to find new and increasingly ingenious ways of using these attacks for one sole purpose – making money.

Beyond mobile devices, the most likely future target for cybercriminals is The Internet of Things (IoT). While extremely difficult to forecast the number of connected objects on the market in the next 5 years, Gartner estimates 30 billion objects will be connected in 2020 whereas IDC estimates that market to be 212 billion. As more and more manufacturers and service providers capitalize on the business opportunity presented by these objects, it’s reasonable to assume that security has not yet been taken into account in the development process of these new products. Will the IoT be “The Next Big Thing” for the cybercriminal?

Thursday, January 23, 2014

Kaspersky Internet Security named ‘Product of the Year’ by AV-Comparatives

January 23, 2014. Kaspersky Lab announces that Kaspersky Internet Security, its flagship home user product, has received the “Product of the year” award from the independent testing lab AV-Comparatives after it consistently demonstrated the best results in testing throughout 2013. Out of 22 participating products, Kaspersky Lab's solution was the only one to achieve the top Advanced+ ranking in all of the tests.

AV-Comparatives selects the winners of its annual awards based on the total ranking of each assessed product during that year’s tests. Some of the tests, such as Performance Test and File Detection Test, demonstrate the capabilities of separate protection subsystems. Real-World Protection tests evaluate how good solutions are at combatting cyber-threats while using the entire repertoire of protection tools available to them. Kaspersky Internet Security had a solid lead in all the tests it underwent.

Nikolay Grebennikov, Chief Technology Officer received award from AV-Comparatives.

As well as announcing the top-performing products of the year, AV-Comparatives also present an assessment of the usability of each security solution that was tested. Taken together, these results enable consumers to select a product which combines reliability and convenience.

AV-Comparatives’ experts rated Kaspersky Internet Security’s user interface as “excellent”, noting that all important information and functions are clearly displayed and easy to access. The testers also reported that the application’s interface has been successfully optimized for use on sensor screen devices, such as hybrid laptops transformable into Tablet PCs.

“The independent tests conducted by AV-Comparatives and similar organizations make it easier for end users to choose a security solution as well as helping manufacturers to further improve their cyber-threat control technologies. This ‘Product of the Year’ title is yet another acknowledgement of Kaspersky Lab’s leading position in this field. We are proud to be able to provide the most reliable protection to our users along with a comfortable user experience,” said Nikolay Grebennikov, Chief Technology Officer at Kaspersky Lab.

Kaspersky Internet Security repeated its success of previous years. Earlier AV-Comparatives named the product among the best in its 2012 testing; in 2011, the solution also won the “Product of the year” award from this testing lab.
AV-Comparatives’ complete report on the results of its 2013 tests is available on the testing lab’s web site.

Thursday, January 9, 2014

MCAFEE LIVESAFE SERVICE TO SHIP ON NEW HP COMPUTERS

New Relationship Offers Unlimited Cross-Device Security to Safeguard Consumers’ Digital Lives

SINGAPORE—08 Jan. 2014 – McAfee today announced it will deliver McAfee LiveSafe™ service worldwide as a preinstall on select new HP consumer and commercial PCs. McAfee LiveSafe is the first cross-device security service that protects consumers’ data, identity and all the PCs, Macs, smartphones and tablets a user owns. The service delivers on Intel’s vision to redefine the consumer security marketplace.

“We’re entering a new age in computing, where people expect to be able to work, play, invent and explore the digital world without fear,” said Mike DeCesare, president of McAfee. “By helping keep all devices safe, we are empowering people to take advantage of all the amazing things this connected world has to offer.”

McAfee LiveSafe service includes the Personal Locker feature that uses face and voice authentication technology to retrieve a user’s most sensitive personal information and sensitive documents, such as copies of passports and IDs, from a secure online location. In addition to protecting consumers from the latest online viruses and threats for each device a user owns, the McAfee LiveSafe service also offers simplified and automated management of usernames and passwords; privacy protection for smartphone and tablets; and several additional security capabilities.

Tuesday, December 31, 2013

Number Of The Year: Kaspersky Lab Is Detecting 315,000 New Malicious Files Everyday

December 31, 2013¬The overall global Internet threat level grew by 6.9 percentage points – in 2013, 41.6% of user computers were attacked at least once. In order to conduct all these attacks over the Internet in 2013, cyber criminals used 10,604,273 unique hosts, which is 60.5% more than in 2012. The USA and Russia are the leading hosts of malicious web resources - 45% of web attacks neutralized by Kaspersky Lab products were launched from these countries.

2013 also saw a further increase in the security issues around mobiles, with a new level of maturity in terms of the sophistication and number of these threats. Most malicious mobile apps principally aimed to steal money, and subsequently personal data. Android is still the main target, attracting a whopping 98.05% of known malware.

Day by day
Kaspersky Lab is detecting 315,000 new malicious files every day. Last year’s number was 200,000
Kaspersky Lab’s products repelled an average of 4,659,920 attacks on users every day when they were online.

Twice as dangerous
The number of browser-based attacks over the last two years has almost doubled to 1,700,870,654
Kaspersky Lab detected 104,427 new modifications of malicious programs for mobile devices, which is 125% more than in 2012
In October 2013 alone we saw 19,966 mobile malware new modifications. That’s 50% of the total that Kaspersky Lab found in the whole of 2012, uncovered in a single month.

Who’s at the highest risk?
Based on 2013’s figures, 15 countries can be assigned to a high risk group based on their risk level while surfing the Internet. Russia, Austria, Germany, several former Soviet republics and several Asian countries had 41-60% of Kaspersky Lab users reporting attempted web attacks on their computers.

Most popular vulnerable applications exploited by cybercriminals
90.52% of all detected attempts to exploit vulnerabilities targeted Oracle Java. These vulnerabilities are exploited in drive-by attacks conducted via the Internet, and new Java exploits are now present in lots of exploit packs.

Top malicious programs on the Internet
Seven of the Top 20 malicious programs on the Internet were threats that are blocked during attempted drive-by attacks. This is currently the most common attack method for web-based malware. The verdicts in Kaspersky Lab’s ranking are assigned to scripts that redirect to exploits as well as to the exploits themselves.

Mobile threats
“There is unlikely to be any slow-down in development of malicious apps, especially for Android. To date, the majority of malware has been designed to get access to the device. In the future, there is also a high probability that the first mass worm for Android will appear. Android ticks all the boxes for cybercriminals – it’s a widely-used OS that is easy to use for both app developers and malware authors alike”, Christian Funk, Senior Virus Analyst, Kaspersky Lab, commented.

Villain of the year
Obad, probably the most remarkable discovery in the mobile field in 2013, is being distributed by multiple methods, including pre-established mobile botnets. This malware is probably the most versatile piece of mobile malware found to date, including a staggering total of three exploits, a backdoor, SMS Trojan and bot capabilities and further functionalities. It’s a kind of Swiss Army knife, comprising a whole range of different tools.

Local threats
Kaspersky Lab products detected almost 3 billion malware attacks on user computers. A total of 1.8 million malicious and potentially unwanted programs were detected in these attacks.

The full report is available on securelist.com

The statistics are based on data obtained and processed using Kaspersky Security Network (KSN). KSN integrates cloud-based technologies into personal and corporate products, and is one of Kaspersky Lab’s most important innovations.

The following rating of vulnerable applications is based on data about exploits blocked by our products and used by cybercriminals both in Internet attacks and in compromising local applications, including users’ mobile devices.

Wednesday, December 4, 2013

Key security incidents that shaped threat landscape in 2013

Petaling Jaya, December 4 2013. Some of the revelations of the past year raised questions about the way we use the Internet nowadays and the type of risks we face. In 2013 advanced threat actors have continued large-scale operations, and cyber-mercenaries, specialist APT groups “for hire” which focus on hit-and-run operations emerged. Hacktivists were constantly in the news, together with the term “leak”, which is sure to put fear into the heart of any serious sys-admin out there. In the meantime, cybercriminals were busy devising new methods to steal money or Bitcoins.

Privacy loss: Lavabit, Silent Circle, NSA and the loss of trust

No ITSec overview of 2013 would be complete without mentioning Edward Snowden and the wider privacy implications of his revelations. One of the first visible effects was the shutdown of encrypted email services such as Lavabit and Silent Circle. The reason was their inability to provide such services under pressure from law enforcement and other governmental agencies. Another story which has implications over privacy is the NSA sabotage of the elliptic curve cryptographic algorithms released through NIST.

New “old” cyber-espionage campaigns: up to 1800 victim organizations in 2013
• The majority of the cyber-espionage campaigns that Kaspersky Lab’s analysts have seen were designed to steal data from governmental agencies and research institutions – Red October, NetTraveler, Icefog and MiniDuke all behave this way.
• The most widespread campaign of the year was NetTraveler espionage which affected victims from 40 countries all over the world.
• For the first time ever cybercriminals harvested information from mobile devices connected tothe victims’ networks – clear recognition of importance of mobile to hackers.
• Red October, MiniDuke, NetTraveler and Icefog all started by ‘hacking the human’. They employed spear-phishing to get an initial foothold in the organizations they targeted

 “We predicted 2012 to be revealing and 2013 to be eye opening. That forecast proved correct – 2013 showed that everybody is in the same boat. In truth, any organization or person can become a victim. Not all attacks involve high profile targets, or those involved in ‘critical infrastructure’ projects. Those who hold data could be of value to cybercriminals, or they can be used as a ‘stepping-stones’ to reach other targets. This point was amply illustrated by Icefog attacks this year. They were part of an emerging trend that appeared in 2013 – attacks by small groups of cyber-mercenaries who conduct small hit-and-run attacks. Going forward, we predict that more of these groups will appear as an underground black market for ‘APT’ services begins to emerge”, - Costin Raiu, Director of the Global Research and Analysis team, Kaspersky Lab commented.

Stealing money – either by directly accessing bank accounts or by stealing confidential data – is not the only motive behind security breaches. They can also be launched to undermine the reputation of the company being targeted, or as a form of political or social protest. Ongoing hacktivist activities have continued this year as well. ‘Anonymous’ group has claimed responsibility for attacks on the US Department of Justice, Massachusetts Institute of Technology and the web sites of various governments. Those claiming to be part of the ‘Syrian Electronic Army’ claimed responsibility for hacking the Twitter account of Associated Press and sending a false tweet reporting explosions at the White House – which wiped $136 billion off the DOW. For those with the relevant skills, it became easier to launch an attack on a web site than it is to co-ordinate the real-world protests.

Bitcoins ruling the world
The Bitcoin system was implemented back in 2009. In the beginning, this crypto currency was used by hobbyists and mathematicians. Soon, others – mostly ordinary people, but also cybercriminals and terrorists, joined them. They provide an almost anonymous and secure means of paying for goods. In the wake of the surveillance stories of 2013, there is perhaps little surprise that people are looking for alternative forms of payment. And it is gaining popularity – in November 2013, the mark surpassed the 400$ for one Bitcoin.

The methods used by cybercriminals to make money from their victims are not always subtle. Apart from Bitcoins, which could potentially be stolen, ‘ransomware’ programs became a popular means of making easy money – cybercriminals block access to a computer’s file system, or encrypt data files stored on the computer. Then they warn you that you must pay in order to recover your data. This was the case with the Cryptolocker Trojan. The cybercriminals give their victims only three days to pay up, accepting different forms of payment, including Bitcoin.

The full report is available on securelist.com.

Wednesday, November 27, 2013

GOVERNMENT LAUNCHES NATIONAL CYBER CRISIS MANAGEMENT POLICY AND MECHANISM

Policy to strengthen the national cyber defense readiness among the Critical National Information Infrastructure (CNII) agencies

KUALA LUMPUR - 27 November 2013 – In addressing the emerging issue of cyber threat which poses serious challenges to the economic wellbeing and security of the nation, the National Security Council (NSC) has organised the National Cyber Crisis Exercise 2013 (X-MAYA 5). This annual event aims to test the effectiveness of the procedures that have been developed under the Malaysian National Cyber Crisis Management Plan and to assess the readiness and preparedness of critical national infrastructure agencies against cyber attacks. X-MAYA 5 2013 marks a significant milestone in the history of the event with the achievement of highest number of participations, 98 public and private agencies across the 10 Critical National Information Infrastructure – namely Health, Water, Banking and Finance, Information and Communications, Energy, Transport, Defense and Security, Government, Food and Agriculture and Emergency Services.

The Honourable Tan Sri Dato’ Muhyiddin Bin Hj. Mohd Yassin, Deputy Prime Minister of Malaysia has officiated The Closing Ceremony of the National Cyber Crisis Exercise 2013 (X-MAYA 5) on 26 November 2013 at the Royale Bintang Damansara Hotel, Petaling Jaya, Selangor. The Deputy Prime Minister has also launched a national policy document, “National Security Council’s Directive No. 24: Policy and Mechanism of the National Cyber Crisis Management”. This executive directive outlines Malaysia’s strategy for cyber crisis mitigation and response through public and private collaboration and coordination. The roles and responsibilities of all CNII agencies are clearly defined in this document. There are six (6) main principles under this directive namely National Cyber Crisis Management Structure; National Cyber Threat Level; Computer Emergency Response Team (CERT); Cyber Security Protection Mechanism; Response, Communication and Coordination procedure and Readiness Programme.

Tan Sri Dato’ Haji Muhyiddin Mohd. Yassin, Deputy Prime Minister (middle) launching the National Security Council Directive 24: the National Cyber Crisis Management Policy witnessed by Datuk Seri Shahidan Kassim (left) and Datuk Mohamed Thajudeen Abdul Wahab (right) during the Cyber Drill 2013 Closing Ceremony (X-MAYA 5).

Over the time, the level of cyber preparedness among CNII sectors has improved as more organisations came to realize the importance of having a proper internal mechanism and procedure in managing cyber security incidents. During the drill, they were able to detect and respond to the attack in timely manner. In order to reduce the gap between agencies, the NSC will take the initiatives to facilitate those agencies so that they could further improve their cyber security response, communication and coordination procedure.

CyberSecurity Malaysia provided technical support and infrastructure for X-MAYA 5. "We leveraged our experience in organizing cyber drill for the Organisation of Islamic Cooperation - Computer Emergency Response Team (OIC-CERT) and the Asia Pacific Computer Emergency Response Team (APCERT) as well as in dealing with cyber security incidents through our Cyber999 Help Centre and Malware Research Centre," said Dr Amirudin Abdul Wahab, CyberSecurity Malaysia’s Chief Executive Officer.

Since Malaysia is progressing towards a developed digital economy by 2020 with the pervasive use of information and communication technology (ICT) in all aspects of the economy, it is vital to create a secured ecosystem within the cyber environment. X-MAYA provides a thorough evaluation of Malaysia’s CNII agencies to strengthen national emergency response by ensuring that proper procedures and mechanisms are in place for effective monitoring of the CNII, incident reporting and response, communications dissemination and business continuity management.

Sunday, November 24, 2013

It's all about money - online financial transactions are top Internet concern

Petaling Jaya, November 22, 2013  - According to a summer 2013 survey from B2B International and Kaspersky Lab, almost 98% of computer users enjoy the ease and convenience of shopping and banking on their PCs, Macs, tablets, and smartphones. That means just 2% of respondents say they never use their PCs or gadgets to pay for a film, a song, or a game; to book a train ticket or a flight; and to purchase items, pay other people, and organize their finances. But added convenience for law-abiding users almost always creates new security concerns, and cybercriminals are cashing in. Banking Trojans, ransomware, fakes of banking and shopping websites – the crooks have a sizeable arsenal of techniques to steal money.

Based on survey responses, online shopping is the most popular activity, with 95% of people using these services. Online banking is close behind, used by 91%, and about 74% regularly use e-payment services. The data also shows that most people use their PC or Mac for online financial transactions: 77% of respondents use these devices to make purchases from online stores and 71% for online banking.

But it’s not just the good guys who are aware of these services – cybercriminals are eager to launch lucrative financial cyberattacks and turn e-commerce into real world robbery.  In response, all reputable online services use a variety of technologies to protect their customers’ critical financial information. However, these measures alone are rarely enough to protect people from financial crime.

Stay ahead of the security game

Criminals out to steal money are ready to invest a lot of manpower and finances to organize sophisticated malicious attacks. The most effective way to combat them requires the use of online security, which is capable of staying ahead of new criminal activity and spotting attempts to intercept sensitive user data before financial credentials fall into the wrong hands.

This is the principle behind all of the protection technologies incorporated in Kaspersky Internet Security – Multi-Device, a comprehensive security solution for the devices working on Windows, OS X and Android operation systems.  First, all products integrated in this solution - Kaspersky Internet Security, Kaspersky Internet Security for Mac and Kaspersky Internet Security for Android – are in constant contact with the Kaspersky Security Network cloud service, giving security technologies swift access to data about the latest cyberthreats. Fraudsters hope that they can beat antivirus databases by using new, unknown malware, but if just one of the 60 million users registered on Kaspersky Security Network encounters the new suspicious program, all other Kaspersky Lab product users will be protected against the threat within minutes of its detection.

PCs running Windows are attacked more often than devices running under other operating systems. That is why Kaspersky Lab’s solution for Windows PCs - Kaspersky Internet Security -  now includes Safe Money, a high-class technology developed to protect the online financial transactions of customers.  This technology combines an impressive range of capabilities, including:

·       Automatically verifying security certificates for banks or e-pay sites

·       Performing a scan to highlight any vulnerabilities on the customers computers which could leave them vulnerable to an attack;

·       Activating two levels of data-entry security technology – Secure Keyboard and Virtual Keyboard – which ensure passwords and credit card details can be typed without fear of interception.

Like any technology, online financial services have their pros and cons. Kaspersky Internet Security – Multi-Device incorporates proactive protection technologies to eliminate the key problem – financial fraud – while multiplying the positives of Internet payments.

Thursday, November 21, 2013

MCAFEE LABS SEES NEW THREATS SUBVERTING DIGITAL SIGNATURE VALIDATION

Third Quarter Threats Report Identifies Android Malware That Bypasses App Validation as Signed PC Malware Continues to Surge; Bitcoin Popular in Illicit Trade and Cybercrime

SANTA CLARA, Calif. / SINGAPORE — Nov. 21, 2013 – McAfee Labs today released the McAfee Labs Threats Report: Third Quarter 2013, which found new efforts to circumvent digital signature app validation on Android-based devices.

The McAfee Labs team identified a new family of mobile malware that allows an attacker to bypass the digital signature validation of apps on Android devices, which contributed to a 30 percent increase in Android-based malware. At the same time, traditional malware signed with digital signatures grew by 50 percent to more than 1.5 million samples. Less surprising but no less daunting was a 125 percent increase in spam.

“The efforts to bypass code validation on mobile devices, and commandeer it altogether on PCs, both represent attempts to circumvent trust mechanisms upon which our digital ecosystems rely,” said Vincent Weafer, senior vice president of McAfee Labs. “The industry must work harder to ensure the integrity of these technologies given they are becoming even more pervasive in every aspect of our daily lives.”

The third quarter also saw notable events in the use of Bitcoin, for illicit activities such as the purchase of drugs, weapons, and other illegal goods on websites such as Silk Road. The growing presence of Bitcoin-mining malware reinforced the increasing popularity of the currency.

Weafer continued: “As these currencies become further integrated into our global financial system, their stability and safety will require both the financial monetary controls and oversight, and the security measures our industry provides.”

Leveraging data from the McAfee Global Threat Intelligence (GTI) network, the McAfee Labs team identified the following trends in Q3 2013:

Digitally signed malware. Digitally signed malware samples increased 50 percent, to more than 1.5 million new samples. McAfee Labs also revealed the top 50 certificates used to sign malicious payloads. This growing threat calls into question the validity of digital certificates as a trust mechanism.

New mobile malware families. McAfee Labs researchers identified one entirely new family of Android malware, Exploit/MasterKey.A, which allows an attacker to bypass the digital signature validation of apps, a key component of the Android security process. McAfee Labs researchers also found a new class of Android malware that once installed downloads a second-stage payload without the user’s knowledge.

Virtual currencies. Use of new digital currencies by cybercriminals to both execute illegal transactions and launder profits is enabling new and previously unseen levels of criminal activity. These transactions can be executed anonymously, drawing the interest of the cybercriminal community and allowing them to offer illicit goods and services for sale in transactions that would normally be transparent to law enforcement. McAfee Labs also saw cybercriminals develop Bitcoin-mining malware to infect systems, mine their processing power, and produce Bitcoins for commercial transactions. For more information, please read the McAfee Labs report “Virtual Laundry: The Use of Digital Currencies in Cybercrime.”

Android malware. Nearly 700,000 new Android malware samples appeared during the third quarter, as attacks on the mobile operating system increased by more than 30 percent. Despite responsible new security measures by Google, McAfee Labs believes the largest mobile platform will continue to draw the most attention from hackers given it possesses the largest base of potential victims.

Spike in spam. Global spam volume increased 125 percent in the third quarter of 2013. McAfee Labs researchers believe much of this spike was driven by legitimate “affiliate” marketing firms purchasing and using mailing lists sourced from less than reputable sources.

Each quarter, the McAfee Labs team of 500 multidisciplinary researchers in 30 countries follows the complete range of threats in real time, identifying application vulnerabilities, analyzing and correlating risks, and enabling instant remediation to protect enterprises and the public. To read the full McAfee Labs Threats Report: Third Quarter 2013, please visit: http://mcaf.ee/s4xfb

Thursday, November 14, 2013

Malaysian school children say it is important to learn about internet safety but many don't know how

DiGi CyberSAFE in Schools's inaugural digital resilience survey deepens understanding on children's knowledge and behaviour towards cyber safety in enabling a safer Internet For All

Partners of DiGi's CyberSAFE in Schools, a nationwide outreach programme aimed at raising the awareness of child safety on the Internet, today shared the results of an inaugural survey which polled views of almost 10,000 children from 460 schools nationwide on internet safety. The announcement was made at the CyberSecurity Malaysia Awards, Conference and Exhibition (CSM-ACE) 2013 to mark the completion of its second year programme which successfully doubled its reach to more students and teachers nationwide.

Themed 'Safety Net - Growing awareness among Malaysian school children on staying safe online', the survey gathered opinions of 9,651 students across all states in Malaysia from DiGi's CyberSAFE in Schools workshops, which were carried out from 26 April to 12 October this year. It is the single, largest survey in the country that gauges school children's level of awareness and understanding of cyber safety issues, their ability to safeguard themselves against online risks, and the impact DiGi's CyberSAFE in Schools workshop had on them.

DiGi's CyberSAFE in Schools is a smart public-private partnership initiated by Ministry of Education, DiGi Telecommunications Sdn Bhd (DiGi), and CyberSecurity Malaysia in 2011 to spread awareness and equip students and educators with the ability to enable a family-friendly internet experience through education.

At the launch, Shamsuddin Hassan, Deputy Director, Educational Technology Division, Ministry of Education Malaysia said, "The internet and broadband connectivity have literally brought the world to our children, and as technologies converge, the opportunities are endless. In order to ensure that the next generation reaches their greatest potential, we must ensure that they have access to a wealth of educational information in an environment that protects their personal information, physical safety, and healthy mental development.  Our mission is a quality education that equips our learners with the knowledge and skills of the 21st century."

Also speaking at the event was Christian Thrane, DiGi's Chief Strategy and Corporate Affairs Officer. He explained, "Beyond creating awareness, we've leveraged on our reach to students in 460 schools nationwide to better understand their usage and behavioral patterns, and knowledge of cyber safety. The results has given us a repository of information, the most comprehensive collation of statistics on the topic in the country, as a reference to better address real needs. We are pleased that a significant number of students have strengthened their awareness and equipped themselves with knowledge and skills to protect themselves online after attending the workshop.

"The internet brings substantial social, economic, educational and developmental benefits to children, youth and adults. At the same time, we are aware of rising risks from abuse of the internet associated with greater access. It is therefore important for us to step up the education on cyber safety particularly among our internet generation children to fuel digital resilience. In empowering school children to keep themselves safe online, we can nurture a family-friendly internet experience that allows our children to enjoy the convenience and far-reaching benefits of the internet," Thrane added.

Based on the polls, 68% of school children have access to the internet at home. Of this, a significant number of them spend an average of eight hours a week on the internet and 68% used it primarily for social networking purpose. More than half claimed that they were first introduced to the internet by their family members or relatives. Some of the key highlights from this survey include:

*       On awareness of cyber threats, 27% of students admitted to having been bullied online while 13% of students said they are still being bullied online today. The survey also recorded 49% of students saying they know of someone who has been bullied online. The most common types of online bullying recorded are sending or receiving nasty messages, being called mean names and having their online accounts hacked. The report highlighted that a significant number of students who have been bullied turn to their parents, siblings and friends for help while 6% of students admitted to keeping it to themselves. 32% of school children said they have only one password for all their online accounts making them an easy target for abuse while a third confessed to not making changes to their password even though they know it is weak.

*       With reference to cyber safety, 88% of students said it is important to learn ways to keep themselves safe online but 38% admitted to not knowing how to. The survey also revealed that 4 in 10 parents have never spoken to their children on the need to protect themselves online, with less than half admitting to not having parental control. Additionally, a third of parents are said to not impose rules for internet usage.

*       On the impact of DiGi's CyberSAFE in Schools workshops, 74% of students said they are now more confident of staying safe while on the Internet after attending the workshop, compared to about 50% before. 84% of students also felt they are now better informed on the issue with 28% of students saying their awareness on cyber bullying has increased significantly while38% of students said they will take action to improve their password security.

"CyberSecurity Malaysia realises the importance of reaching out to the younger generation and educating them about cyber security. Hence, we developed the CyberSAFE programme, which is short for CYBER SECURITY AWARENESS FOR EVERYONE. In September 2010, Deputy Prime Minister Tan Sri Muhyiddin Yassin launched the 'CyberSAFE in Schools' programme. Since then, various activities related to online safety awareness have been organised in Malaysian schools nationwide.

To date, more than 500 teachers from all over Malaysia have been trained as CyberSAFE Ambassadors, which means they are equipped with sufficient know-how to raise cyber security awareness in schools. We really hope the CyberSAFE programme will help to eradicate incidents of cyber-bullying, cyber-harassment and other cyber security issues among Malaysians, especially the young school students. I would like to thank the Ministry of Education Malaysia and DiGi Telecommunications for their contributions in making 'CyberSAFE in Schools' a successful programme," said Dr Amirudin Abdul Wahab, CEO of CyberSecurity Malaysia.

DiGi's CyberSAFE in Schools is primarily a series of educational workshops to share knowledge and techniques that equip and empower schoolchildren to keep themselves safe online. The programme which started in 2010 covered 7,000 students and educators from over 280 schools and 14 Pusat Jalurlebar 1Malaysia nationwide. In 2013, the programme successfully reached out to 14,800 students and educators from 460 schools nationwide.

The CyberSecurity Malaysia Awards, Conference and Exhibition (CSM-ACE) 2013 is an event that aims to catalyse innovation and growth for the cyber security industry and inculcate the cyber security culture at a national level.

For more information, please visit http://www.digi.com.my/digicybersafe/

Wednesday, November 13, 2013

MCAFEE SPOTLIGHTS THE “12 SCAMS OF CHRISTMAS” TO KEEP CONSUMERS’ DIGITAL LIVES SAFE

Cyber Scrooges Looking to Capitalize on the Year-End Shopping Season by Hijacking Popular Consumer Habits

SANTA CLARA, Calif./SINGAPORE—13 Nov. 2013 – McAfee today released its annual “12 Scams of Christmas” list to educate the public on the most common scams that criminals use during the upcoming year-end festive season and sales campaigns to take advantage of consumers as they shop on their digital devices. Cybercriminals leverage these scams to steal personal information, earn fast cash, and spread malware.

This year, fall holiday shopping sales are expected to soar to an estimated US$602 billion  in the US alone. E-commerce sales are predicted to rise 15% compared to last year’s digital sales to more than US$60 billion, with m-commerce comprising 16% of this number . Consumers should ensure that they are taking all precautions to protect the data saved on their devices. This is especially true for the 51% of US adults that bank online and 32% that use mobile banking .

“The potential for identity theft increases as consumers share personal information across multiple devices that are often under protected,” said Michelle Dennedy, vice president and chief privacy officer at McAfee. “Understanding criminals’ mindsets and being aware of how they try to take advantage of consumers can help ensure that we use our devices the way they were intended – to enhance our lives not jeopardize them.”

To help consumers stay alert for greedy Grinches as they surf the web for holiday travel deals and seek out gifts for their loved ones, McAfee has identified this year’s top “12 Scams of Christmas”:

1) Not-So-Merry Mobile Apps – Official-looking software for holiday shopping, including those that feature celebrity or company endorsements, could be malicious, designed to steal or send out your personal data.
2) Holiday Mobile SMS Scams – FakeInstaller tricks Android users into thinking it is a legitimate installer for an application and then quickly takes advantage of the unrestricted access to smartphones, sending SMS messages to premium rate numbers without the users’ consent.
3) Hot Holiday Gift Scams – Clever crooks will post dangerous links, phony contests on social media sites, and send phishing emails to entice viewers to reveal personal information or download malware onto their devices.
4) Seasonal Travel Scams – Phony travel deal links and notifications are common, as are hackers waiting to steal your identity upon arrival at your destination. A hotel’s Wi-Fi may claim that you need to install software before using it and instead infect your computer with malware if you “agree.”
5) Dangerous E-Seasons Greetings – Legitimate-looking e-cards wishing friends “Season’s Greetings” can cause unsuspecting users to download “Merry Malware” such as a Trojan or other virus after clicking a link or opening an attachment.
6) Deceptive Online Games – Be wary of games’ sources. Many sites offering full-version downloads are often laden with malware, and integrated social media pages can expose gamers, too
7) Shipping Notifications Shams – Phony shipping notifications can appear to be from a mailing service alerting you to an update on your shipment, when in reality, they are scams carrying malware and other harmful software designed to infect your computer or device.
8) Bogus Gift Cards – Deceptive ads especially on social sites usually claim to offer exclusive deals on gift cards or packages of cards and can lead consumers to purchase phony ones online.
9) Holiday SMiShing – During the holidays, SMiShing is commonly seen in gift card messages, where scammers pose as banks or credit card companies asking you to confirm information for “security purposes”.
10) Fake Charities – Cybercriminals capitalize on generosity and set up fake charity sites and pocket the donations.
11) Romance Scams – Many messages sent from an online friend can include phishing scams, where the person accesses your personal information such as usernames, passwords, and credit card details.
12) Phony E-Tailers – With so many people planning to shop online, scammers set up phony e-commerce sites to steal your money and personal data.

“While devices and computers provide convenience, it also opens up plenty of opportunities for cybercriminals to take advantage of consumers’ purchasing activities,” said Stephen Perchard, Vice President, Consumer and Mobile, Asia Pacific at McAfee. “To protect personal data, consumers should secure their devices before buying and installing applications. Users should also be weary of links offering deals that appear too good to be true and instead, order their purchases from retailers directly.”

If you do plan to search for deals online, use apps or open those shopping related emails, make sure your entire household’s devices have protection, such as McAfee LiveSafe™, which protects all your PCs, Macs, tablets and smartphones. It also includes malware detection software, McAfee® Mobile Security, to protect your smartphone or tablet from all types of malware. This app will guard you from the latest mobile threats and risky apps, offers enhanced privacy and backup features, location tracking and SiteAdvisor® technology to help you steer clear of dangers when searching on a mobile device.

Wednesday, October 30, 2013

Gartner says Asia Pacific IT Spending to Grow 5.5 Percent in 2014 as the Digital World Creates New Opportunities

Analysts To Discuss How Digitalisation is Changing Business and Government During Gartner Symposium/ITxpo

Kuala Lumpur, 30 October 2013 — IT spending in the Asia Pacific region is forecast to reach $767 billion in 2014, a 5.5 percent increase from 2013, but it’s the opportunities of a digital world that have IT leaders excited, according to Gartner, Inc.

Peter Sondergaard, senior vice president at Gartner and global head of Research, explained to an audience of more than 1,600 CIOs and IT leaders at Gartner Symposium/ITxpo, that the digital world is here.

This results in every budget being an IT budget; every company being a technology company; every business is becoming a digital leader; and every person is becoming a technology company. This is resulting in the beginning of an era: the Digital Industrial Economy.

“The Digital Industrial Economy will be built on the foundations of the Nexus of Forces (which includes a confluence and integration of cloud, social collaboration, mobile and information) and the Internet of Everything by combining the physical world and the virtual,” said Peter Sondergaard, senior vice president at Gartner and global head of Research.

“Digitalisation exposes every part of your business and its operations to these forces. It is how you reach customers and constituents; how you run your physical plant; and how you generate revenue or deliver services. Enterprises doing this today are setting themselves apart and will collectively lead the new Digital Industrial Economy,” Mr. Sondergaard said.

IT Spending Outlook for Asia Pacific and Australia
Spending on information technology products and services in the Asia Pacific region is forecast to grow 5.5 percent in 2014 to reach US$767 billion, up from $727 billion this year, and reach $933 billion in 2017.

In China, spending is forecast to grow 6.7 percent in 2013 and accelerate to 8.7 percent growth in 2014. According to Gartner, China’s very powerful growing middle class is having a huge impact on the rest of the economy and IT, moving consumer and enterprise markets. Automation of health, banking, government, communications and manufacturing are major IT drivers. These vertical industries will offer the greatest opportunities for technology vendors in the next 5 years.

In Australia, IT spending is forecast to reach almost A$77.2 billion in 2014, up 2.3% from $75.5 billion in 2013. The largest category of spending is IT services, forecast to reach $29.7 billion in 2014, followed by telecommunications services at $26.9 billion.

Spending on mobile devices is forecast to fall from more than $4 billion this year to $3.7 billion in 2014.

Software still represents the fastest growing category of IT spending in Australia, forecast to grow 7.8 percent from almost $7.1 billion in 2013 to more than $7.6 billion in 2014.

Economic Impact of the Internet of Things
In 2009, there were 2.5 billion connected devices with unique IP addresses to the Internet, most of these were devices people carry such as cell phones and PCs. In 2020, there will be up to 30 billion devices connected with unique IP addresses, most of which will be products.

This creates a new economy. In fact, Gartner predicts that the total economic value add for the Internet of Things will be US$1.9 trillion dollars in 2020, benefiting a wide range of industries, such as , healthcare, retail, and transportation.

“Computing power will be cheap and covert. We won’t know it is there; it will be in our jewelry and in our clothing,” Mr. Sondergaard said. “We will throw more computers into our laundry in a week than we’ve used in our lifetimes so far.”

“Digital changes the IT market in a big way through the Internet of Things,” Mr. Sondergaard said. “In the technology and telecom sectors, revenue associated with the Internet of Things will exceed US$309 billion per year by 2020.”

Mobile smart devices have taken over the technology world. By 2017, new device categories: mobile phones, tablets, and ultra-mobile PCs will represent more than 80 percent of device spending. Gartner also forecasts that by 2017, nearly half of first-time computer purchases will be a tablet. Therefore, Mr. Sondergaard said mobile is the destination platform for all applications.

Future of IT Suppliers
The digital world runs faster for many traditional IT suppliers. In the past, the top technology companies reigned over the industry for long periods of time. However, now the leaders in areas such as cloud and mobile were not on many CIO’s radar five years ago.

“What many traditional IT vendors sold you in the past is often not what you need for the digital future. Their channel strategy, sales force, partner ecosystem is challenged by different competitors, new buying centers, and changed customer business model,” Mr. Sondergaard said. “Digitalisation creates an accelerated technology-driven start up environment across the globe. Many of the vendors who are on top today, such as Cisco, Oracle, and Microsoft, may not be leaders in the Digital Industrial Economy.”

Big Data and Security
All of these “things” connected to the Internet generate data. People and their activities create data. Smart machines consumer and produce data, and mobile devices are the windows into data. Mr. Sondergaard said the effective digital enterprises harness that data to change their business.

With all of this valuable data within the IT organisation, cyber security will be an ongoing concern, both inside and outside the enterprise. Mr. Sondergaard said IT leaders should anticipate events and headlines that continuously raise public awareness or create fear.

“The security of embedded technologies that your organisation has right now may be the most important operational responsibility you will have in 2020,” Mr. Sondergaard said. “Digitalisation will create new infrastructures and new vulnerabilities in our infrastructures. We recommend that you build a portfolio of security vendors because no single vendor addresses more than a fraction of your problem. Everyone will need to establish more agile security processes.”

About Gartner Symposium/ITxpo
Gartner Symposium/ITxpo is the world's most important gathering of CIOs and senior IT executives. This event delivers independent and objective content with the authority and weight of the world's leading IT research and advisory organisation, and provides access to the latest solutions from key technology providers. Gartner's annual Symposium/ITxpo events are key components of attendees' annual planning efforts. IT executives rely on Gartner Symposium/ITxpo to gain insight into how their organisations can use IT to address business challenges and improve operational efficiency.

Thursday, October 24, 2013

MCAFEE SURVEY REVEALS OLDER DOES NOT MEAN WISER

According to Study, Social Network Drama Doesn’t Stop at 50

SANTA CLARA, Calif./SINGAPORE – Oct. 24, 2013 – McAfee today released findings from the company’s first survey dedicated to uncovering the online habits and behaviors of individuals ages 50-75. The study, “Fifty Plus Booms Online” indicates that the 50+ demographic is spending a great deal of time online these days (an average of five hours a day), instilling confidence in their attitude toward technology. Some 88% of participants say they consider themselves equally or more tech-savvy compared to others their age. Despite this proclaimed comfort level—or maybe because of it— Baby Boomer adults are socially engaging online, exposing themselves to social media reproach and dangerous security risks, including sharing personal information with strangers.

STRANGER DANGER STILL RELEVENT AT 50+
Many Baby Boomers have voluntarily shared personal information with people they have never met in person (this does not include online shopping or business transactions). Overall, 57% have shared information or posted online personal information. This includes 52% who have shared their email address, 27% who have shared their cell phone number and 26% who have shared their home address.

According to Michelle Dennedy, vice president and chief privacy officer at McAfee, the discovery that this confident, self-proclaimed tech-savvy group exhibits high-risk online behavior, is reason to raise awareness.

“The use of social networks among people 50+ is trending now that it’s become more commonplace across all age groups,” said Dennedy. “It seems counterintuitive that sharing personal information with strangers would not concern them, however. This further highlights their need to better understand the difference between the real and perceived dangers online and how to best protect themselves.

SOCIAL NETWORK DRAMA DOESN’T END WITH TEENAGERS
Despite the fact that social networks have a reputation among the younger generation as a hub for drama among friends, the survey found this to be the case even in this age group. Eight in ten use social media networks, 36% of which log in daily, opening the doors to the possibilities of social media drama. Sixteen percent admitted to experiencing negative situations while logged into their social media accounts. These rifts lead to 19% of claims that the incident was severe enough to end a friendship. Other results from those who had negative experiences include inappropriate posts from friends (23%) and having a fight with a friend, spouse, or partner (9%).

UNPROTECTED AND OVERSHARING
Despite their technological confidence, these adults revealed some concerning and surprising realities regarding online security.

Overall, 57% claimed they have shared and/or posted personal information online. Email addresses (52%), cell phone numbers (27%), and even home addresses (26%) have all been shared by these 57% (excluding instances where this information was necessary for online purchases). About 80% of smartphone users and 43% of tablet users post mobile photos online. Surprisingly, another 24% admit to using their devices to send personal or intimate messages in the form of text, email, or photo messages. Yet, more than 1/3 of them (33% of smartphone users and 38% of tablet users) admit to having no password protection on their devices to safeguard these risqué conversations from reaching the public. Worse still, while nearly all (93%) say their laptops and desktops have updated security software, only 56% of smartphone users and 59% of tablet users say their devices are protected from viruses and malware.

To learn more about this study, please visit:
Blog: http://blogs.mcafee.com/consumer/50plus-tech-savvy-but-still-at-risk
Twitter: @McAfeeConsumer – Use #babyboomers to join the conversation

Trend Micro Titanium Maximum Security 2014 Demystifies Social Networks Privacy Settings

Socially savvy Malaysians share too much personal information online

Kuala Lumpur, 23 October 2013 – Everything you do online leaves behind a digital footprint that can lead cyber criminals to you. A recent survey1 by Trend Micro, a global leader in security software, revealed that 69% of Malaysians disclose their date of birth on social networks. Further to that, 47% of the respondents have also previously ‘check-in’ their location. With half of the survey respondents posting on their social networks at least once a day, a wealth of information about Malaysians personal lives are being disclosed on the internet every single day.

In the age of online financial frauds, identity thefts and loss of data, where cyber criminals leverage readily available personal information for their own gain, Trend Micro has solved the riddle of social network privacy settings for Facebook, Twitter and Google+ with the launch of the Trend MicroTM TitaniumTM Maximum Security 2014. The latest solution features Trend Micro’s unique social network privacy technology which identifies privacy settings that may leave personal or inappropriate information publicly available or vulnerable to identity theft.

(From L to R) Cedric Lim, Consumer Sales Manager, Trend Micro, Terrence Tang, Senior Director of Consumer Business, APAC Center Sales and Marketing, Andrew Tan, Product Marketing Manager (Consumer), Southeast Asia, Trend Micro, and Lisa Chong, Marketing Manager of Consumer Business, Trend Micro.

“Privacy is a huge concern, and we urge consumers in Malaysia not to be complacent online. Personal information is immensely valuable to cyber criminals, who can leverage such information for their own gain, create false identities for criminal use or even leverage your network to target your friends and family,” said Terrence Tang, Senior Director of Consumer Business, APAC Center Sales and Marketing, Trend Micro.

Privacy Scanner identifies privacy loopholes in social network profiles
The Trend MicroTM Titanium™ Maximum Security 2014 is the latest iteration of the flagship all-in-one security solution, equipped with Web-threat protection that identifies and blocks dangerous links in websites, social networks, emails and instant messaging. It also detects spam emails containing phishing scams that can trick users into revealing private personal information.
(from L to R) Terrence Tang, Senior Director of Consumer Business, APAC Center Sales and Marketing, Trend Micro, Cedric Lim, Consumer Sales Manager, Trend Micro, Andrew Tan, Product Marketing Manager (Consumer), Southeast Asia, Trend Micro, and Lisa Chong, Marketing Manager of Consumer Business, Trend Micro.

Trend Micro’s robust Privacy Scanner now dramatically simplifies privacy settings on Twitter and Google+, and Facebook – for both Mac and PC. Facebook settings can also now be managed on-the-go via an Android app. It also gives users control over which apps can access biographical data, and who can tag and see photos.

In this ‘post first, think later’ era on social networks, the Privacy Scanner helps ensure that consumers share information only among those they know.

According to the August 2013 AV Comparatives report, Trend Micro Titanium offers the broadest combination of privacy and Web threat protections for Facebook, Google+, and Twitter across PCs and Macs among 31 security products reviewed (Social Network Protection Review, August 2013, AV Comparatives).
Vulnerability Quotient: How vulnerable are you online?
Trend Micro urges consumers to seek discretion when posting on social networks and diligence in maintaining strong passwords as ways to safeguard their personal lives.

Trend Micro has launched the Trend Micro Vulnerability Quotient, available at http://bit.ly/MYwhoami_qr or via a QR code – an app on Facebook that helps consumers determine how vulnerable they are online. Through a series of questions measuring consumers’ behavior on social networks and password management, amongst other security issues, consumers can find out what their Vulnerability Quotient is and how exposed they are to falling victim to cyber threats. The app also allows them to track how they fare among the rest of the population.
Additional features of Trend MicroTM TitaniumTM Maximum Security 2014
“Trend Micro encourages the building of safer digital social cultures, and aims to enable everyone to protect their digital lives,” said Andrew Tan, Product Marketing Manager (Consumer), Southeast Asia, Trend Micro. “More than just ensuring safe surfing habits, the Trend Micro Titanium Maximum Security 2014 offers consumers all-in-one, all-rounded protection against identity thefts, viruses and other online threats automatically so they can enjoy their online experiences safely and with a peace of mind.”

The Trend Micro Titanium is the flagship all-in-one security solution which utilizes state-of-the-art cloud-based technology to proactively stop threats before they reach users. Trend Micro Titanium features:
First-of-its-kind technology for social networking security – the Privacy Scanner for Windows now NEWLY EXTENDED to include Google+ and Twitter in addition to Facebook. It monitors privacy settings and flags potential privacy concerns.
Trend Micro™ DirectPass™ password management system that help you maintain multiple passwords and securely log on to websites. It also includes a secure browser to conduct safe online commerce that is specifically designed to support secure online banking.
Trend Micro™ Online Guardian™ and parental controls to monitor kids on social networks and online activities.
Tools for protecting data from loss or theft including Secure Erase file shredder, Trend Micro Vault with remote file lock and a 5GB Trend Micro™ SafeSync™ account  to protect, share and access files for Titanium Maximum products
Set-and-forget security – won't hassle users with alerts and pop-ups.  Intuitive interface is easy to install and use with simple screens and reports
Extended protection for up to multiple devices (for Titanium Maximum Security) Available for laptops, smartphones and tablets, running on Android, Mac or Windows including support for Windows 8 operating systems.

Pricing and Availability
Trend Micro TitaniumTM Maximum Security 2014 is available today from all leading IT retailers and Trend Micro Website at the recommended retail price of RM109 for 1 device and RM159 for 3 devices. Trend Micro TitaniumTM Internet Security 2014 is available at a recommended retail price of RM109 for 3 devices. For more information, kindly visit http://www.trendmicro.com.my/my/ or follow https://www.facebook.com/TrendMicroMY.