Category: Tech News

  • Crowdstrike Outage and How to handle the issue.

    Crowdstrike Outage and How to handle the issue.

    Leading cybersecurity firm CrowdStrike encountered an issue due to a defect in one of its updates for computers running the Windows operating system.

    On Friday morning, widespread IT outages occurred worldwide, resulting in thousands of flight cancellations and disruptions in internal and external systems across various industries such as hospitals, banks, stock exchanges, and other institutions. The failure of some Microsoft-based computers caused these outages.

    CrowdStrike, an American cybersecurity technology firm providing cloud workload protection, threat intelligence, and cyberattack response services, stated that the outage was not due to a cyber attack; instead, it was caused by a software issue that has been identified and for which a fix has been deployed.

    CrowdStrike CEO George Kurtz mentioned in an interview with CNBC that some systems can be fixed and back up and running immediately, while for others, it “could be hours, could be a bit longer” before everything is back up and running. He also noted that more than rebooting systems will be required for some customers to work through fixes.

    Kurtz assured that CrowdStrike is actively collaborating with customers impacted by a defect found in a single content update for Windows hosts, while Mac and Linux hosts remain unaffected.

    In a letter to customers and partners, Kurtz apologized for the outage, attributing it to “a defect found in a Falcon content update for Windows hosts.”

    Kurtz also emphasized the importance of remaining vigilant, as adversaries and bad actors may attempt to exploit events like this, and encouraged everyone to engage only with official CrowdStrike representatives through the company’s blog and technical support channels for the latest updates.

    As the incident gets resolved, Kurtz committed to providing full transparency on how it occurred and the steps being taken to prevent similar occurrences in the future.

    Windows computers around the world are being hit by the dreaded Blue Screen of Death (BSOD). The issue has impacted everyone from banks to airlines, with flights grounded, grocery carts abandoned, and productivity even lower than usual for a Friday.

    Fortunately, CrowdStrike has since announced at 2:30 a.m. ET that it has identified the update causing the issue and rolled it back. The company also offered a workaround for anyone having problems:

    How to deal with the Blue Screen of Death.

    Of course, having to do this for every single computer in multiple companies across the globe is still likely to take some time.

    “CrowdStrike is actively working with customers impacted by a defect found in a single content update for Windows hosts,” CrowdStrike CEO George Kurtz said on X. “Mac and Linux hosts are not impacted.

    This is not a security incident or cyberattack. The issue has been identified, isolated and a fix has been deployed.”

  • Japan’s top three telcos to exclude Huawei, ZTE network equipment

    Japan’s top three telcos to exclude Huawei, ZTE network equipment and this is a big trying time for the company but we hope they are able to survive it as they have contributed alot to the IT world when it comes to wireless technologies.

    Japan’s big three telecom operators plan not to use current equipment and upcoming fifth-generation (5G) gear from China’s Huawei Technologies Co Ltd and ZTE Corp, Kyodo News reported on Monday.

    The news, for which Kyodo did not cite sources, comes at a time of heightened scrutiny of Chinese tech firms by Washington and some prominent allies over ties to the Chinese government, driven by concerns they could be used by Beijing for spying. Last week, from sources that Japan planned to ban government purchases of equipment from Huawei and ZTE to ensure strength in its defences against intelligence leaks and cyber attacks.

    A SoftBank Group Corp spokesman said Japan’s third-largest telco was closely watching government policy and is continuing to consider its options. The amount of equipment in use from Chinese makers “is relatively small”, he said.

    Japan’s top two telecommunications operators, NTT Docomo Inc and KDDI Corp, said the firms had not made any decision yet.

    Docomo does not use Huawei or ZTE network equipment, but it has partnered with Huawei on 5G trials. KDDI also does not use Huawei equipment in its “core” network, a spokeswoman said, adding it does not use any ZTE network equipment.

    Asked to comment on the report, Huawei referred to a Japanese government policy document issued on Monday concerning cybersecurity during procurement. That document states the aim of a “free, fair and secure cyberspace”.

    “These are ambitions Huawei shares and we look forward to continuing to work closely with customers in the Japanese market,” a Huawei spokesman said.

    ZTE declined to comment on the report.

    LOCKED OUT

    Huawei has already been locked out of the U.S. market, and Australia and New Zealand have blocked it from building 5G networks amid concerns of its possible links with China’s government. Huawei has said Beijing has no influence over it. Japan’s decision to keep it out would be another setback for Huawei, whose chief financial officer was recently arrested by Canadian officials for extradition to the United States.

    Chinese Foreign Ministry spokesman Lu Kang said China has already had “communication” with Japan about the issue.

    China has all along been asking Japan to provide an open, fair and non-discriminatory environment for Chinese companies operating in the country, and Beijing will continue to pay close attention to this issue, Lu told a daily news briefing.

    “We believe that Chinese companies’ normal operating activities should not be treated in a discriminatory way,” he added.

    World financial markets have been roiled since news of the arrest, on worries it could reignite a Sino-U.S. trade row that was only just showing signs of easing.

    Shares of SoftBank, which has the deepest relationship with Huawei among the big Japanese telcos, fell the most among the three top Japanese telcos on Monday, ending down 3.5 percent.

    Industry sources said SoftBank would find it difficult to replace pre-existing Huawei network equipment that is designed for the company and not easily interchangeable. Docomo and KDDI shares fell around 1 percent, in a wider market that closed down 2 percent.

    Earlier, SoftBank’s Japanese telecoms unit priced its IPO at an indicated 1,500 yen ($13.31) per share and said it will sell an extra 160 million shares to meet solid demand, raising about $23.5 billion in Japan’s biggest-ever IPO.

  • Huawei Is Said to Plan $2 Billion Cybersecurity Reboot

    Huawei Is Said to Plan $2 Billion Cybersecurity Reboot. China’s Huawei Technologies Co. is planning to overhaul its global software systems as it tries to avoid a ban in the U.K. and other European markets, after previous piecemeal fixes failed to assuage national security concerns, according to people familiar with the matter.

    Huawei is set to commit at least $2 billion in spending to make its equipment less vulnerable to hacking and snooping, said the people, who declined to be identified because the discussions are private.

    Huawei will offer to transform the way it engineers software, instead of merely applying one-off changes and workarounds in response to specific demands from companies and governments, and that work will continue until all security concerns are assuaged, they said.

    The pledge comes at a critical moment for Huawei’s ambitions in Europe, its second-biggest market outside of Asia. European phone companies are on the cusp of ordering tens of billions of euros worth of equipment for fifth-generation wireless networks and Huawei has spent more than a decade positioning itself to win much of that work.

    Its plans are now under threat as Western governments grow increasingly concerned that Huawei’s systems could be used as a Trojan horse by Chinese intelligence. Its reputation suffered a further blow when Chief Financial Officer Wanzhou Meng, the daughter of Huawei founder Ren Zhengfei, was arrested in Canada on Dec. 1 following allegations it had violated sanctions against Iran, amid a wider tussle on trade between the U.S. and China.

    Huawei declined to comment. The company has always maintained that it’s independent and doesn’t give the government access to its equipment.

    Company officials will present the details of the software revamp to Britain’s National Cyber Security Centre in coming days before it presents it to the public, said one of the people.

    The measures would move beyond smaller-scale fixes it has made in response to a critical July report by a body staffed with intelligence officials and industry representatives.

    In a sign of how tenuous Huawei’s position in the U.K. has become, the head of foreign intelligence agency MI6 said on Monday the government needs to decide whether Huawei should be banned from the country’s 5G networks.

    In the last four months it has received bans on 5G from the U.K.’s intelligence-sharing allies Australia and New Zealand, led by a campaign from the U.S., where it is also banned.

  • Italian regulator fines Facebook £8.9m for misleading users

    Italian regulator fines Facebook £8.9m for misleading users, company criticised over data misuse and ordered to issue an apology on its website and app

    Facebook has been fined €10m (£8.9m) by Italian authorities for misleading users over its data practices.

    The two fines issued by Italy’s competition watchdog are some of the largest levied against the social media company for data misuse, dwarfing the £500,000 fine levied by the British Information Commissioner’s Office in September – the maximum that body was able to issue.

    The Italian regulator found that Facebook had breached articles 21, 22, 24 and 25 of the country’s consumer code by:

    The company was specifically criticised for the default setting of the Facebook Platform services, which in the words of the regulator, “prepares the transmission of user data to individual websites/apps without express consent” from users.

    Although users can disable the platform, the regulator found that its opt-out nature did not provide a fully free choice.

    As an additional penalty, the authority has directed Facebook to publish an apology to users on its website and on its app.

    In a statement, a Facebook spokesperson said: “We are reviewing the Authority’s decision and hope to work with them to resolve their concerns. This year we made our terms and policies clearer to help people understand how we use data and how our business works. We also made our privacy settings easier to find and use, and we’re continuing to improve them. You own and control your personal information on Facebook.”

    Italy’s antitrust authorities have pressed hard against Facebook for data misuse. In 2017, the same authority issued a €3m fine against the company for “inducing” users of its WhatsApp messaging service to share data with the main Facebook app.

    In that ruling, the regulator criticised WhatsApp for misleadingly implying that users could continue to use the service only if they agreed to the data transfer.

    The fine issued on Friday is only Facebook’s second since the Cambridge Analytica scandal brought the company’s data protection practices to wider attention in March this year. But other regulators, including those in Ireland and California and the US Federal Trade Commission, have expressed interest in the company’s practices.

    In Ireland, an investigation into a data breach affecting 50m accounts could result in a fine of up to $1.6bn (£1.25bn) under the new regime established by the General Data Protection Regulation, which came in to force in May. However, Rowenna Fielding, a senior data protection lead at Protecture, warned that this sum was “a ceiling, not a stipulation”.

    News Source: https://www.theguardian.com

  • IoT Could Expand Cyberattack Surface by Bringing Offline Legacy

    IoT Could Expand Cyberattack Surface by Bringing Offline Legacy Infrastructure Online. Digital transformation is the latest jargon in the industry and there is probably no process across the globe that is not integrating new age technologies in their way of functioning.

    Nevertheless, while technologies like artificial intelligence (AI), Internet of Things (IoT), machine learning (ML) and big data analytics are doing a world of good, cybersecurity is a major concern when talking of these technologies as well. In an exclusive interview with DataQuest, Mr Ashish Sharma, Partner, Deloitte India, shares his views on the impact the above mentioned technologies have had on cybersecurity, some of the initiatives taken by the government, and the challenges faced by the cybersecurity industry in the current scenario.

    Impact of New Age Technologies on Cybersecurity Scenario

    New age technologies viz. Artificial Intelligence (AI), Blockchain, Internet of Things (IOT), 3D printing, Robotics, etc. have the potential of revolutionising the industries. While the results of these technologies are path-breaking, the cybersecurity vulnerabilities are also on the rise. One may owe this to the inadequate research for securing emerging technologies, absence of industry guidelines/frameworks, unclear responses from regulators on the adoption of technology or security guidelines, increase in attack surface or inability of the legacy infrastructure to secure new age technology riding on it, etc.

    For example, adopting IoT introduces a vast number of devices to an organisation’s network. The chances of exposure increases since IoT massively expands the attack surface by bringing the previously offline legacy infrastructure to the internet. Similarly, AI technologies are helping to solve today’s toughest business problems. However, the risk of an algorithm changing its course due to unauthorized interventions has been concerning to the industry.

    Preparedness of Current Indian IT Industry in Handling Technological Advancements like Blockchain, IoT, and Artificial Intelligence in terms of Cybersecurity

    Focus on Cybersecurity has been critical for both the Government and the Industry. Regular global cyber hacks have ensured that Cybersecurity is a topic in the Senior Government circles and amongst the Board of Directors in various companies.

    The adoption of the latest technological advancements such as AI, IoT etc. is not only driven by organizations in India but are also being the focus areas of the Indian government. For instance, the Government of India has proposed a multi-dimensional approach in its draft IoT policy to develop the IoT market in India by 2020.  Similarly, recognising AI’s potential to transform economies and the need for India to strategize its approach, Hon’ble Finance Minister, in his budget speech for 2018 – 2019, mandated NITI Aayog to establish the National Program on AI with a view to guiding the research and development in new and emerging technologies. The discussion paper on National Strategy for Artificial Intelligence (June 2018) suggests establishing data protection frameworks and sectorial regulatory frameworks, and promotion of adoption of international security standards.

    Importance of Data Breach Prevention

    Data breach prevention should be planned in two ways; by design and by operation. Organisations should develop a mind-set that has privacy at the forefront of the design, built and deployment of new technologies. Organizations have traditionally focused their investments on becoming secure. However, this approach is no longer adequate in the face of the rapidly changing threat landscape. Put simply, organizations should consider building cyber risk management programmes to achieve three essential capabilities namely: the ability to be secure, vigilant and resilient.

    A good understanding of known threats and controls, industry standards and regulations can guide organizations to secure their systems and data through the design and implementation of preventative, risk intelligent controls. Based on leading practices, organizations can build a ‘defence-in-depth’ approach to address known and emerging threats. This involves a number of mutually reinforcing security layers both to provide redundancy and potentially slow down the progression of attacks in progress, if not prevent them.

    The Reskilling Challenge Faced by Cybersecurity Industry

    Skilled workforce plays a vital role in cybersecurity as they impact an organization’s ability to protect its data, systems and operations. Getting a trained/experienced cybersecurity workforce remains a significant challenge for organizations. According to the 2017 Global Information Security Workforce, there is expected to be a shortage of 1.8 million workers in cybersecurity by 2022. With the rapid adoption of new technologies by organizations, the requirements for security experts in these fields have also risen. Whether it’s in the domain of cyber-security for AI, Blockchain or IoT, innovative employees who know how to protect digital information and can translate that knowledge into solving real-world security problems are in demand by both the private and public organizations. And that demand will continue to increase. Conventional education and policies may not adequately meet such demands.

    Upskilling and reskilling should be a constant effort in modern information security programs within every organization. Organizations should allocate sufficient budget specifically for training and certifications of their information security workforce and annual training calendars should be drafted for the wider organization.

  • Microsoft is embracing Chromium bringing Edge to Windows 7 and others

    Microsoft is embracing Chromium, bringing Edge to Windows 7, Windows 8, and macOS.  Microsoft yesterday embraced Google’s Chromium open source project for Edge development on the desktop. The company also announced it is decoupling the browser updates from Windows 10 updates, and that Edge is coming to all supported versions of Windows and to macOS.

    Microsoft launched Edge in July 2015 as the default browser for, and exclusive to, Windows 10. But it never saw much adoption. Sure, Microsoft claimed Edge had 330 million active devices back in September 2017, but it never did reveal an active user figure beyond “hundreds of millions” (Google said Chrome passed 1 billion active users in May 2015). Edge has 4.34 percent market share today, according to the latest figures from Net Applications.

    So Microsoft wants to make some big changes, which it says will happen “over the next year or so.” The first preview builds of the Chromium-powered Edge will arrive in early 2019, according to Microsoft.

    Chromium-based Microsoft Edge

    Adopting the Chromium project means a lot more for Microsoft. The Edge rendering engine EdgeHTML will be swapped out for the Blink rendering engine. The Chakra JavaScript engine will be swapped out for V8. Microsoft will even take some of the UI stack, for use on non-Windows 10 platforms.

    Also worth noting: Microsoft is not forking Chromium.

    Microsoft hopes moving to Chromium will “create better web compatibility for our customers” and “less fragmentation of the web for all web developers.” The former is certainly true, as the Edge web platform will thus become aligned with web standards and other Chromium-based browsers. The latter is not true in the short term (plenty of testing will be needed to accommodate the switch) but it is likely in the long term, as developers will have one fewer browser to explicitly test against.

    No longer wasting resources on building Edge’s backend will likely turn out to be a big win for Microsoft. It is a lot of work to constantly update a browser engine to be standards-compliant and compatible with the actual web. Microsoft has decided to let the open source community do that instead, which it will participate in, so it can focus on improving the browser itself.

    Again, Edge isn’t changing significantly. This is an “under the hood” transformation, and most Edge users won’t notice anything significantly different — save for some sites working as expected.

    The future of EdgeHTML and Chakra

    Edge uses Blink/Chromium on Android and WebKit/WKWebView on iOS. Thus, when Edge on desktop moves to Blink and V8, the main use case for EdgeHTML and Chakra will disappear overnight.

    Windows 10 apps that use EdgeHTML and/or Chakra will be able to keep using them, according to Microsoft. But, Microsoft will also eventually let app developers leverage the Chromium-based solution that Edge will use. This will likely impact regular apps that render web content but also Progressive Web Apps (PWAs), which are essentially mobile websites that mimic native apps.

    App developers will thus be able to choose to keep using the legacy option or switch to Chromium. Microsoft says it has no plans to stop maintaining EdgeHTML and Chakra, although if usage were to decline, developers could expect them to hit end of support eventually.

    Chrome extensions

    In addition to better web compatibility, Edge users stand to benefit from support for Chrome extensions. Microsoft expects that it will be very easy for developers to bring their Chrome extensions to Edge. It might even be the case that it requires no work at all in most cases, but it’s too early for the company to say so definitively.

    Microsoft’s intention is to support existing Chrome extensions in Edge, but how exactly this will work remains to be seen. Keep in mind that for years now, Google has been locking down the Chrome Web Store and Chrome extensionsin general — Microsoft will have to be careful with its solution.

    All supported versions of Windows

    So far, all this largely makes sense, but Microsoft also wants to port Edge to all supported versions of Windows. Edge is no longer going to be a Windows 10-only affair.

    That means Edge is coming to Windows 7 SP1 and Windows 8.1. For Windows 10, this means the Chromium-based Edge and future updates is coming to Windows 10 version 1607, version 1703, version 1709, version 1803, and version 1809. Those are all supported versions of Windows, so they’ll be getting the latest version of Edge until Microsoft ends support.

    Microsoft also currently supports Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server version 1709, Windows Server version 1803, Windows Server version 1809, and Windows Server 2019. The company hasn’t yet said if the latest version of Edge is coming there too.

    This is a massive undertaking that one can only justify through a corporate lens. It’s about letting IT departments offer a heterogeneous browser environment. Microsoft wants everyone on the latest version of Windows, but for those that cannot, or refuse to, upgrade, it has decided to bring the latest Edge to them. That means bringing Edge to older versions of Windows, including older versions of Windows 10. Within major organizations, there are computers running all sorts of Windows versions, and right now only a single one can get the latest version of Edge.

    macOS

    If you thought supporting old Windows versions was nuts, your jaw will drop when you hear Microsoft also wants to bring Edge to macOS. This is bizarre for several reasons, not even including that Microsoft ceased development of Internet Explorer for Mac in June 2003 and Apple killed Safari for Windows in July 2012. But the same heterogenous environment thinking applies: Microsoft wants all devices in an organization using the latest Edge, and that requires getting Macs onboard.

    Indeed, Microsoft doesn’t expect to get a lot of Mac users switching to Edge, the company said. Instead, the company simply wants to make it easier for more developers, many of whom use Macs, to test against Edge. Bringing Edge to macOS is about developers, not market share.

    More frequent updates

    Edge is updated every six months. Chrome and Firefox, meanwhile, are updated every six weeks.

    Even if you do have the latest Windows 10 version, Edge updates today are tied to Windows 10 updates, and half a year is a long time on the web. It’s a long time to wait for compatibility fixes, performance improvements, and new features.

    Could Edge get more frequent updates than Chrome and Firefox? I’m not holding my breath. But Microsoft does say that agility will be a focus going forward and does expect “a more frequent cadence” than the current six-month wait.

    Chrome updates hit Windows, Mac, and Linux all on the same day, while Firefox updates hit Windows, Mac, Linux, and Android on the same day. Microsoft wants the version of Edge on Windows and Mac to be the same, but we’re hearing it’s too early to commit to same-day updates across all supported versions of Windows and macOS.

    Chromium contributions

    Microsoft says it intends to become a “significant contributor” to the Chromium project. The company will try to improve Chromium not just for Edge, but for other browsers as well, and not just for PCs, but for other devices too.

    The priority will, however, be web platform enhancements to make Chromium-based browsers better on Windows devices. Microsoft stands to benefit if the web works well on Windows, as the impact trickles down to its customers, partners, and the overall business.

    Last month, Microsoft was spotted making contributions to the Chromium project for ARM-based Windows devices. The thought at the time was that Chrome was being ported to Windows 10 on ARM, but now we know Microsoft was thinking bigger. (Chromium-based browsers are 32-bit only, meaning they run emulated and negatively impact battery life. Microsoft wants to fix for all Chromium-based browsers, including Chrome and Edge.)

    Microsoft intends to continue work on ARM64 support, but it also hopes to improve Chromium’s web accessibility and take advantage of other hardware features like touch support. Indeed, Edge is the only major browser with a 100 percent HTML5Accessbility score and is known for having solid touch scrolling performance.

    In fact, Microsoft doesn’t want to switch to Chromium until some of that functionality has been contributed to the project. That way, Edge won’t lose features when the switch happens next year.

  • Amazon Web Services Customers Can Hack AWS Cloud And Steal Data

    Amazon Web Services Customers Can Hack AWS Cloud And Steal Data, Says Oracle CTO Larry Ellison.

    (Note: After an award-winning career in the media business covering the tech industry, Bob Evans was VP of Strategic Communications at SAP in 2011, and Chief Communications Officer at Oracle from 2012 to 2016. He now runs his own firm, Evans Strategic Communications LLC.)

    CLOUD WARS — Oracle founder Larry Ellison this week said businesses using arch-rival Amazon’s AWS cloud have become major cybersecurity threats because the AWS cloud architecture allows them to see and steal data belonging to other customers using the AWS cloud.

    Ellison made the remarks in a keynote at Oracle’s annual OpenWorld conference on Monday while extolling the advantages of Oracle’s new Generation 2 Cloud versus traditional cloud architecture such as what he said Amazon currently uses.

    The comments were striking because while cybersecurity has unquestionably become one of the major issues for business leaders in our increasingly digital economy, the blame for cyberattacks and cybercrime has rarely been put on customers—instead, organized teams of cybercriminals and/or nation-states looking to exploit digital weaknesses in other countries have almost always been named as the culprits.

    But Ellison on multiple occasions cited AWS “customers” as the agents or potential agents of data manipulation, data exfiltration and data theft—and I’ll offer verbatim examples from his keynote in just a moment.

    Before getting to those verbatim comments, I want to offer a few thoughts that help provide some context for Ellison’s remarks—because while cybersecurity and cyberattacks have been a major theme in some of Ellison’s recent public presentations, he has never, as far as I can discover, cited “customers” as the bad guys.

    So let’s take a look at Ellison’s verbatim comments about customers as cyber threats and cybercriminals, which I transcribed from the video archive of his keynote address:

    Those are very strong words about the business customer that are using the enterprise cloud. I asked the Oracle spokesperson if she could share any data that supports what Ellison was saying—for example, does Oracle consider that 10 percent of customers engage in cybercrime in the way Ellison described, or is it 25 percent, or something higher?—but Oracle did not offer any such facts. Here’s the statement I received from Oracle:

    “The point is that  bad actor can pose as customers on any public cloud, so from the perspective of an actual customer, a bad actor is a “customer.”

    “You can have bad actors using cloud instances for distributing unlawful content or performing otherwise forbidden tasks (crypt mining) while paying for their cloud instances with stolen credit cards. You can also deal with sophisticated attackers who will attempt to make use of malicious code and known vulnerabilities in an attempt to break multi-tenant separation (recent highly publicized vulnerabilities come to mind). So…Yes. Bad actors posing as customers in the cloud are potential cyber threats. We prevent bad actors from committing nefarious acts. Bad actors posing as customers are to clouds, what insider threats are to traditional on-premises environments…

    “There is nothing stopping operatives from a rogue nation, for instance, from posing as a business of some kind, and opening an account with any public cloud vendor. From that standpoint, they are a customer – but they are also a bad actor who, once set up inside Microsoft or Amazon or Google cloud, to name a few, can start using malicious code to either mess with the infrastructure’s control code or attempt to move sideways to steal data from other (legitimate) customers.

    “From the standpoint of a legitimate customer, using such a less-secure-than-Oracle cloud vendor, that bad actor LOOKS LIKE A CUSTOMER.

    Since public cloud vendors aren’t the FBI or other law enforcement, they can’t be in the business of vetting the legitimacy of customer x or customer y.

    Thus, bad actors posing as “customers” are a potential threat agent that Oracle can protect its other customers from by, among other security measures, isolating control code from software that manages the virtual machines or bare metal servers used by other customers.” (End of Oracle response.)

    To be sure, those are all very reasonable thoughts. But Larry Ellison’s a very reasonable guy—so why didn’t he at least allude to a couple of these points during his hour-long keynote?

    So Oracle’s just unveiled a sophisticated new “Generation 2 Cloud” to help customers avoid becoming victims of cyberattacks in the cloud, and Oracle’s also warning its good customers to watch out for its bad customers and/or truly bad guys posing as customers.

    All in all, more proof that life’s never dull in the Cloud Wars.

    I’ve analyzed and written about the enterprise-tech business for more than 20 years from the media side as an editor-in-chief and chief content officer, and more recently as Chief Communications Officer at Oracle from 2012-2016. I’ve written thousands of articles and columns…MORE

    As businesses jump to the cloud to accelerate innovation and engage more intimately with customers, my Cloud Wars series analyze the major cloud vendors from the perspective of business customers.

  • Microsoft overtakes Amazon as second most valuable U.S. company

    Microsoft overtakes Amazon as second most valuable U.S. company. Microsoft Corp (MSFT.O) regained its spot as the second most valuable U.S. company on Friday after a disappointing quarterly report from Amazon.com (AMZN.O) wiped $65 billion off the online retailer’s market capitalization.

    Apple Inc (AAPL.O) tops the list at over $1 trillion after crossing that threshold in September. Microsoft’s market capitalization was Wall Street’s highest in late 1998 through early 2000 before the dot-com bubble burst.

    Amazon’s shares dropped 7 percent, the most in nearly three years after its holiday season sales outlook missed targets, fanning concerns that Wall Street’s tech darlings are finally starting to face stronger competition.

    Microsoft fell a more modest 1.1 percent in a broad technology sell-off that was also driven by a weaker-than-expected report from Google-parent Alphabet Inc (GOOGL.O), leaving the Nasdaq composite index .IXIC down 1.9 percent late Friday afternoon.

    (Graphic: Market cap – Apple, Amazon and Microsoft – tmsnrt.rs/2ORT0Yq)

    Shares of Microsoft remain up nearly 4 percent from Wednesday, when the four-decade-old software company beat quarterly profit expectations, driven by its cloud computing business that competes with Amazon’s.

    Its stock market value on Friday stood at $823 billion, on track to close above Amazon’s for the first time since April, when it gave up its spot as second largest company by market capitalization.

    Amazon was worth $805 billion on Friday, after falling below Microsoft’s in extended trade on Thursday. The drop was equivalent to the combined values of Target Corp (TGT.N) and Corning Inc (GLW.N).

    Amazon’s tumble left it up around 40 percent year to date, while Microsoft has gained about 25 percent in 2018. On Wednesday, Amazon’s stock traded at the equivalent of 70 times expected earnings, its lowest level since 2011.

    The average analyst price target for Microsoft puts its market cap at $963 billion, while the average price target for Amazon values it at $1.068 trillion.

  • Phishing attacks: Why is email still such an easy target for hackers?

    Phishing attacks: Why is email still such an easy target for hackers? The majority of cyber attacks begin with one simple phishing email. So will it ever be possible to close this door to hackers, once and for all?

    Email is incredibly useful, which is why we all still use it. But chief among its downsides (along with getting caught in a group-cc’d message hell) is that email remains one of the most common routes for hackers to attack businesses.

    Around one in every hundred messages sent is a malicious hacking attempt. That might not seem like a large figure, but when millions of messages are sent every day, it adds up — especially when it just takes one employee to fall victim to a phishing message and potentially lead to a whole organisation being compromised.

    For example, the cyber attack against the Democratic National Committee that led to thousands of private emails being exposed in the run up to the US Presidential election started with just one successful phishing email, while countless espionage and malware campaigns have also gained entry to organisations via an email-based attack.

    But if email leaves us so vulnerable to attempts at hacking, why do we stick with it?

    “Email is still the main way that two entities who may not have a relationship get together and communicate. Whether it’s a law firm communicating with a business or a candidate applying for a job, email is still the bridge to getting these entities communicating. It’s not going away,” says Aaron Higbee, co-founder and CTO at anti-phishing company Cofense.

    As long as email is here, phishing will also remain a problem — and while some phishing campaigns are really sophisticated and based around cyber criminals performing deep reconnaissance on targets, other email-based attacks aren’t so sophisticated — and yet are still worryingly successful.

    Locky ransomware was often delivered to targets in blank phishing messages containing just an attachment. In the vast majority of cases, people didn’t open this, but given how Locky was successful, it’s evident that a number of people did. Why did they click the attachment in a blank message?

    “At the end of the day, we’re people and sometimes we make mistakes. Even careful and aware people could and would click on malicious attachments. Why is that? Because education isn’t enough; people will continue to click on things that look suspicious,” said Liron Barak, CEO and co-founder at security company Bitdam.

    “We can definitely see there’s been a rise in email attacks in the last year. And something that I believe is that attackers are becoming more and more sophisticated — attacks are bypassing Microsoft, Gmail and other channels,” she adds.

    Many phishing and spam messages do get blocked by mail providers but there are those that continue to sneak through — especially into consumer mailboxes, despite the efforts of email providers.

    While enterprises might not think too seriously about the actions their employees take using their personal inboxes, it could have serious consequences; not only is it likely that employees will examine their own emails at the office, many people use their personal email addresses to conduct business activity — and that’s a security risk.

    “One of the lessons that comes up very regularly is that one thing people often do wrong is when they conduct official business out of a consumer mailbox as they often don’t understand there’s no defence there,” says Matthew Gardiner, director of product at email security company Mimecast.

    “The lesson is to have good security defences on your business email and then use your business email for business, not your consumer email. Because once they’re into your personal account, they could be loading malware onto the machine you use for both,” he says.

    So, when this provides a potential risk to businesses, why is the security of some consumer mailboxes still so relatively poor compared with their enterprise cousins?

    “One of the sadder situations is here we are protecting the enterprise and they’re getting the full focus and top knowledge to protect them — but then when you go down to consumers and even small businesses, they’re not really looked after by the security industry,” says Ken Bagnall VP of email security at FireEye.

    There’s also the fundamental problem around email that it’s relatively simple to spoof names and addresses, allowing attackers to claim to be anyone — perhaps celebrities offering prizes or your boss asking you to look at a document or to make a transfer.

    “There’s really no embedded security in the basic internet for email. So you can claim to be anyone and send an email and the average person will probably trust that,” says Gardiner.

    Add to that how the make-up of phishing messages is changing all the time and you have an evolving problem.

    “While we continually evaluate and improve our automated screening protocols to help protect users, spam is an industry-wide ongoing challenge. Bad actors and opportunistic promoters quickly alter their approaches, which makes it difficult for any vendor to address 100 percent of spam,” says Jeff Jones, senior director at Microsoft.

    There’s even whole underground marketplaces dedicated to conducting phishing attacks, with professional hackers offering their services to crack specific inboxes.

    “Trying to guess what the next step of the attackers will be will always leave us behind, because there’s someone else controlling the landscape and trying to evade us and thinking strategically about bypassing security,” says Bitdam’s Barak.

    Much of the issue lies with the fundamental way in which email works and how this method of communication has become so pervasive in our everyday lives.

    “For email based phishing to really go away, we’re going to have to come together as a world and say this email protocol that was designed decades ago, it just isn’t working anymore,” says Higbee.

    There is one system that could help and it’s called DMARC — short for “Domain-based Message Authentication, Reporting & Conformance. It’s an email authentication protocol that enables users to determine what a legitimate email is and what’s spam, complete with a reporting function for ongoing improvement and protection.

    Many have argued that it would massively release spam, but it still isn’t widely used in industry as it can be tricky to implement, actually blocking all messages if set up incorrectly.

    Another solution to this could be a reputation score system — something that Dr Ian Levy, technical director at the UK’s National Cyber Security Agency (NCSC) wants to encourage the industry to pick up. He argues that it could make differentiating between trusted sources and malicious sources much easier for users — therefore reducing the risk of phishing attacks.

    “We’re trying to get the industry to do a reputation score,” he says. For example, if an email address has been in use for years, has never sent a bad message that’s one thing; an email address registered today via a Tor node sending its first email may be something that should be treated with a little more caution, he argues.

    “We want to give people that reputation information about email accounts so they can make decisions.”

    But for now, this is just an idea and phishing attacks against email users are as successful as they ever were — and some are resigned to this continuing to be a problem for a long time to come.

    “I saw my first phishing email professionally in 1998 — and if I thought I’d still be working on this phishing problem in 2018, it would’ve seemed unimaginable,” says Cofense’s Higbee. “It’s such a huge challenge that in five or ten years from now, the email phishing problem will be the same as it is today.”