Equifax is spending a ton of money on cybersecurity. Wall Street analysts don’t like it.

The Equifax data breach that compromised information on more than 147.9 million people continues to affect the company’s business prospects nearly two years after the incident was publicly announced. Financial ratings service Moody’s has downgraded its rating for Equifax from “stable” to “negative,” citing a high level of cybersecurity expenses and ongoing litigation following the massive 2017 security incident. This downgrade, announced Wednesday, marks the first time cybersecurity has been named as a factor in an outlook change, a Moody’s spokesman told CNBC. Breach litigation and related investigations cost Equifax $690 million in the first quarter this year, according to the report. Analysts predicted the credit-ratings firm will spend an additional $400 million on cybersecurity expenses and capital investments in both 2019 and 2020 before that rate declines to roughly $250 million in 2021. “The heightened emphasis on cybersecurity for all data-oriented companies, which is especially acute for Equifax, leads us […]

The post Equifax is spending a ton of money on cybersecurity. Wall Street analysts don’t like it. appeared first on CyberScoop.

Continue reading Equifax is spending a ton of money on cybersecurity. Wall Street analysts don’t like it.

European police seize BestMixer, saying it helped launder $200 million worth of cryptocurrency

European law enforcement has seized BestMixer.io, a bitcoin mixing website that authorities say served as one of the busiest cryptocurrency laundering services in the world. The Dutch Fiscal Information and Investigation Service (FIOD) shut down BestMixer Wednesday with help from Europol and investigative support from McAfee. BestMixer promised to shuffle bitcoin, bitcoin cash and litecoins that may have been “tainted” for their association in internet crime. The site helped turn over some 27,000 bitcoins, worth at least $200 million, since it began operating in May 2018, according to Europol. Virtual currency laundering is an essential part of the cybercriminal ecosystem. After hackers make off with a ransomware payment, they need to obfuscate that money before investigators trace those funds on the blockchain — bitcoin’s public ledger — where all transactions are visible. Security researchers used this technique to probe the hackers behind the 2017 WannaCry ransomware spree, for example. “A […]

The post European police seize BestMixer, saying it helped launder $200 million worth of cryptocurrency appeared first on CyberScoop.

Continue reading European police seize BestMixer, saying it helped launder $200 million worth of cryptocurrency

Real-time bidding, a thriving ad targeting technique, is becoming a GDPR dilemma

Data security advocates are taking action against a popular digital advertising technique that sends individuals’ information to perhaps hundreds of companies in less than a second, often without adequate protective measures. Real-time bidding is the subject of four alleged violations of the European Union’s General Data Protection Regulation (GDPR) filed Monday with regulators in Belgium, Luxembourg, the Netherlands, and Spain. Real-time bidding (RTB) is a targeted advertising technique that occurs when a user visits a website, and their personal information is broadcast to hundreds of marketers who bid in a near-instant auction to get their ad in front of that specific website visitor. U.S. advertisers spent an estimated $23.5 billion on the tactic last year, up from $6.4 billion in 2014. “It includes inferences on your sexuality, your religion, what you’re reading and unique identification codes as specific as your Social Security number,” Johnny Ryan, chief policy and industry relations […]

The post Real-time bidding, a thriving ad targeting technique, is becoming a GDPR dilemma appeared first on CyberScoop.

Continue reading Real-time bidding, a thriving ad targeting technique, is becoming a GDPR dilemma

KnowBe4 to acquire Norwegian assessment company CLTRe

The security training vendor KnowBe4 has acquired CLTRe, a Norwegian company that specializes in measuring clients’ security preparedness, according to an announcement scheduled for Tuesday. Florida-based KnowBe4 describes itself as the world’s largest security awareness training company. The firm is known for providing clients with a simulated phishing platform and partnering with Kevin Mitnick, the hacker-turned-consultant who now works as KnowBe4’s chief hacking officer. KnowBe4 was named among the fastest-growing apps corporate America, according to a survey released in February. CLTRe (pronounced “culture”) is a small firm that created its own security culture framework, which is meant to provide companies with information about how their security culture changes over time. The framework measures corporate behavior, responsibilities, cognition, norms, compliance, communication and attitudes, as all those factors relate to security, over time. Terms of the deal were not disclosed. KnowBe4 currently is integrating the CLTRe assessments into its platform, and does not […]

The post KnowBe4 to acquire Norwegian assessment company CLTRe appeared first on CyberScoop.

Continue reading KnowBe4 to acquire Norwegian assessment company CLTRe

Google to stop providing Huawei with key software amid trade war escalation

Google will cease to provide some services to smartphones manufactured by Huawei, a move that could dent the Chinese phone-maker’s business outside its native country. Google has suspended any business with Huawei that requires the transfer of proprietary hardware, software or technical services, Reuters first reported Sunday. Huawei will only be able to use the public version of Android and will not have access to Google apps and services, according to the Wall Street Journal. In practice, existing Huawei smartphones will largely continue to function as normal, though the devices may lose artificial intelligence capabilities and other protocols that rely on Google infrastructure, per WSJ. Future Huawei phones running on Android will lose access to the Google Play Store, Gmail, YouTube and other popular Google apps. “For users of our services, Google Play and the security protections from Google Play Protect will continue to function on existing Huawei devices,” a Google […]

The post Google to stop providing Huawei with key software amid trade war escalation appeared first on CyberScoop.

Continue reading Google to stop providing Huawei with key software amid trade war escalation

Cloud company CEO accused of orchestrating million-dollar IP fraud scheme

U.S. attorneys have charged a South Carolina man with operating a scheme that fraudulently obtained internet addresses worth roughly $14 million that later were used by spammers. Amir Golestan was charged this week with 20 counts of wire fraud for his alleged role in a plot to create fictitious companies, then use those firms to obtain more than 750,000 IP addresses. Golestan’s data center company, Micfo LLC, obtained those addresses from the American Registry for Internet Numbers, a nonprofit that oversees the release of IP addresses only to companies that meet ARIN criteria. By impersonating at least 10 companies, the indictment alleges, Golestan created his own secondary market for the IPv4 addresses, which the government alleges are worth $13 to $19 apiece. Then, he sold many of those IP addresses via a third party, according to the indictment. Many of those addresses later appeared on a blocklist of known spammers […]

The post Cloud company CEO accused of orchestrating million-dollar IP fraud scheme appeared first on CyberScoop.

Continue reading Cloud company CEO accused of orchestrating million-dollar IP fraud scheme

Venture capitalists predict more aggressive security tools will reap big bucks

A big payday could be in store for cybersecurity startups that borrow ideas from the hackers they’re trying to stop. Cybersecurity vendors that find a way to scale technology that translates offensive security lessons into defensive techniques could benefit from an influx of venture capital funding, a panel of investors said Thursday at the 2019 Cyber Investing Summit in New York. In practice, that could mean more efficient red team exercises, filling more open security jobs with former government hackers, or experimenting with new ways to sift through the false flags that hackers are starting to use to disguise their activities. Put another way: Don’t expect Fortune 500 companies to start retaliating against criminals by hacking back, but deploying more inventive ways to mitigate vulnerabilities. “We’re trying to move from being reactive to proactive,” said Bob Ackerman, founder and managing director at the early-stage venture firm Allegis Cyber and a board member at DataTribe. […]

The post Venture capitalists predict more aggressive security tools will reap big bucks appeared first on CyberScoop.

Continue reading Venture capitalists predict more aggressive security tools will reap big bucks

Hacking forums survive cybercrime dragnet as feds prioritize drug-market busts

It might be more difficult these days to conduct an anonymous drug deal on the dark web, but not every online criminal enterprise is feeling the pinch of international law enforcement. New research shows that as the FBI and other crime-fighting agencies have gone after dark web markets, cybercrime communities have avoided the heat. Stolen financial information, access to hacked social media accounts and malicious software tools are still widely available on forums accessible on the open web, without using the Tor anonymity software. Among those still operating are the prominent Russian-language marketplace Exploit.in, the “carding” forum Joker’s Stash and Hackforums, which offers guidance on how to become a hacker. Exploit, in particular, has gained nearly 1,000 new accounts over the past six weeks, with current membership at 44,433 user accounts as of May 13, according to research conducted by Digital Shadows exclusively for CyberScoop. The site is “fully gated,” meaning outsiders must pay $100 for […]

The post Hacking forums survive cybercrime dragnet as feds prioritize drug-market busts appeared first on CyberScoop.

Continue reading Hacking forums survive cybercrime dragnet as feds prioritize drug-market busts

Google to replace Titan keys for free after uncovering Bluetooth flaw

Google is recalling its Titan security key after discovering a Bluetooth vulnerability that could allow a hacker located within roughly 30 feet of the device to communicate with it, the company announced Wednesday. Google released the key-shaped Titan last August, offering the physical authentication tool as a remedy to phishing and other attacks. The device connects with other hardware via Bluetooth pairing. A misconfiguration in its protocol could allow attackers to communicate with the security key or communicate with the device connected to it, Google said. This vulnerability is difficult to exploit, the company said, and would require an outsider to already have obtained a victim’s username and password to access their account. Google is offering free replacements to affected users. “This security issue does not affect the primary purpose of security keys, which is to protect you against phishing by a remote attacker,” the company said in a blog post. “Security keys […]

The post Google to replace Titan keys for free after uncovering Bluetooth flaw appeared first on CyberScoop.

Continue reading Google to replace Titan keys for free after uncovering Bluetooth flaw