Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Saturday, December 7, 2019

Ericsson reaches resolution on U.S. FCPA investigations to resolve criminal charges

Ericsson has entered into a three-year Deferred Prosecution Agreement (DPA) with the U.S. Department of Justice (DOJ) to resolve criminal charges related to violations of the FCPA. This relates to accounting violations of the FCPA in five countries including in Djibouti where there is also a charge of bribery. 

In the agreement, the DOJ agrees to defer the prosecution of those charges and to have them dismissed at the end of the term in exchange for Ericsson complying with the conditions of the DPA. Conditions include a payment by Ericsson of a fine of USD 520,650,432. As part of the resolution with the DOJ, Ericsson's Egyptian subsidiary has entered a guilty plea to the bribery charge in Djibouti. 


Separately, Ericsson agreed to resolve civil charges brought by the Securities and Exchange Commission (SEC) relating to allegations of violations of the bribery and accounting provisions of the FCPA.  

Ericsson agreed to the entry of a judgment enjoining it from future violations of the FCPA and it agreed to pay a financial sanction of USD 458,380,000, plus pre-judgment interest of US$81,540,000.


As part of the settlement, Ericsson has agreed to engage an independent compliance monitor for a period of three years while the Company continues to undertake significant reforms to strengthen its Ethics & Compliance program.

The resolution relates to historical FCPA breaches ending Q1 2017. While the company had a compliance program and a supporting control framework, they were not adequately implemented. Specifically, certain employees in some markets, some of whom were executives in those markets, acted in bad faith and knowingly failed to implement sufficient controls. They were able to enter into transactions for illegitimate purposes and, together with people under their influence, used sophisticated schemes in order to hide their wrongdoing.


The resolution marks the end of the FCPA-related investigations into Ericsson and its subsidiaries undertaken by the DOJ and the SEC.
The DOJ proceeding is a criminal enforcement action and the SEC proceeding is a civil enforcement action.  

The agencies resolve their investigation independently of one another using their own discretion and applying different standards of proof.  As a result, the DOJ and SEC have come to different conclusions based on the same facts.

Monday, November 25, 2019

Nyotron releases RIPlace technique that renders ransomware invisible to security software

Nyotron announced it has discovered a new Microsoft Windows file system technique that enables cyberattackers to maliciously encrypt files in a way that existing anti-ransomware products cannot detect. The company has alerted security vendors of the threat it has named "RIPlace," and released a free tool that allows users to check their systems for exposure to the technique.



Ransomware has been around since 1989, yet remains one of the most common and successful attack types, causing billions of dollars in damages worldwide every year. 


The Verizon 2019 Data Breach Investigations Report (DBIR) states that ransomware accounts for nearly 24 percent of all incidents where malware was used last year, making it the second most common type of malware reported. 



The combination of timely patching and using modern antivirus solutions helps stop some ransomware. However, RIPlace can bypass these defenses by using a legacy file system "rename" operation. It takes only two lines of code for hackers to unleash this technique.



Nyotron's free tool enables users and organizations to check their systems for the RIPlace vulnerability. If the system is deemed to be at-risk, the tool provides solution recommendations.

Wednesday, October 30, 2019

New SpyCloud offering, Third Party Insight, helps to measure and mitigate supply chain breach risks

SpyCloud launched Tuesday their new Third Party Insight solution to help companies understand risk and remediate exposures to the potential threat of account takeover emanating from supply chain vendors. Businesses can use this tool to evaluate risks presented by vendors, partners or acquisition targets based on several factors that stem from the threat of account takeovers.

Third Party Insight provides SpyCloud customers with a risk ranking (specific to the threat of account takeover) for each third party they work with, plus specific data on executive credentials, potentially infected employees, and the rate of password reuse across exposed data. 


Companies can share this data with partners for free and work with them to remediate exposures, reducing the risk of a breach due to account takeovers in their supply chain.  

Some of the most infamous data breaches occurred after the compromise of a third-party account. Memorably, Target's systems were reportedly compromised in 2013 after an HVAC vendor's credentials were used to access Target's web services for vendors, eventually leading to the propagation of credit card-stealing malware on point of sale systems.


More recently in March 2019, Citrix, which provides virtual private network services to most of the Fortune 1000, fell victim to a breach that emanated from an account takeover attack. Criminals had access to emails, project files, employee information and more over a six-month period before the breach was detected. 


"Your employees are open doors to your network, your data and your intellectual property, but your third-party relationships extend that attack surface even further," explained David Endler, chief product officer and co-founder of SpyCloud. "Our new Third Party Insight solution gives businesses a way to evaluate supply chain risks and work cooperatively with their vendors to mitigate them, in turn strengthening their overall security posture while building goodwill with key partners and suppliers."


"In addition to helping assess how vendors and partners may increase your attack surface, Third Party Insight can also help you understand exposures you may inherit through mergers and acquisitions," said Ted Ross, CEO and co-founder of SpyCloud. "When news of an acquisition leaks to the press, the parties involved become ideal targets for criminals. We can now proactively improve the security posture of these parties ahead of these events."

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...