Tag Archives: cybersecurity

VIF Cyber Review: May 2022

NATIONAL

CERT-In issued advisory on Mobile-based Malware

On 30 May 2022, Indian Computer Emergency Response Team (CERT-In) issued advisory on mobile-based malware, along with methods and countermeasures. With the advent of smartphones and high-speed Internet connection, mobile accounts for more than 50 per cent of the Internet traffic worldwide, making it a worthwhile attack surface for cybercriminals.

The advisory included methods through which cybercriminals carried out activities, including fake applications, On-device fraud, Bypassing App store, fake calls, and where mobile-based malware are also using design practices like accessibility engines, infrastructure and C2 protocols that enable them to update their capabilities. Along with, the advisory also suggested countermeasures and best practices for users, including keeping OS (Operating System) and applications updated, use of strong authentication such as biometric and PIN, safe browsing practices, deleting data before discarding the device. [1]

Cisco Launched a tool of SMBs to assess Cyber Security Readiness

Cisco, on 26 May 2022, launched a cyber security tool for Small and Medium-sized Businesses (SMBs) based in Asia-Pacific region to assess their cyber security readiness amid of hybrid work environment. The tool’s concept is based on the premise that no attempt to access an organisation’s network architecture can succeed until trust is verified. As per Cisco’s cyber security for SMBs: Asia-Pacific businesses prepare for digital defense study, 62 per cent of Indian SMBs suffered cyber incidents in 2021 and cyber-attacks cost their business over ₹ 3.5 crore. Around 74 per cent SMBs also reported 85 per cent of customer information loss in cyber incidents.

“When a user accesses an application using a device, both the user and device are verified, with that trust continuously monitored. This helps secure the organisation’s applications and environments from any user, device, and location,” read the statement released by Cisco. The threat landscape for the SMBs becoming more sophisticated due to the digitisation at speed, therefore, securing their businesses is one of the top priorities for SMBs. “With new tool, the SMBs will ensure end-to-end protection across their workforce, and the workplace, with adoption of a zero-trust strategy to manage and strengthen their cyber security posture in a cloud-first world,” said Cisco India & SAARC’s Senior Director (System Engineering)— Anand Patil.[2]

The 7th Edition of India-Japan ICT Joint Working Group meeting recognised the importance of India-Japan Digital Partnership

On 13 May 2022, V L Kantha Rao (Additional Secretary, Department of Telecommunications, India) and Sasaki YUJI (Vice-Minister for Policy Coordination— International Affairs, Japan) virtually co-chaired the 7th edition of India-Japan ICT Joint Working Group (JWG) under the India-Japan ICT Comprehensive Cooperation Framework. Senior representatives from both governments and non-governmental stakeholders from industry, R&D, and Academia attended the meeting.

Recalling the India-Japan Summit held in March 2022, both sides recognised the need to strengthen the growing cooperation under India-Japan digital partnership, with a vision to enhance digital economy through promotion of joint projects for digital transformations. The JWG discussions were focused on enhancing further cooperation in various fields like 5G, Open RAN, Telecom Network Security, submarine cable systems, and Quantum Communications. [3]

Government of India proposed to set up India Data Management Office

Under the Digital India Corporation, India’s Ministry of Electronics and Information Technology (MeitY) will set up an India Data Management Office (IDMO), which will be responsible for framing, managing, reviewing, and revising the National Data Governance Framework Policy. The draft of the National Data Governance Framework Policy was released by the MeitY, seeking public comments on the draft till 11 June 2022.

The earlier version of the policy— India Data Accessebility and Use Policy had faced many criticism from experts, who believed that there was a lack of security safguards for anonymization, privacy infringement, and economic incentivisation. As per the draft of the data governance framework, the IDMO will design and manage the India Datasets platform which will in turn handle the requests of Indian researchers and start-ups which require access to non-personal or anonymised datasets. [4]

CERT-In issued discovery of Remote Code Execution (RCE) vulnerability in Apple products

On 20 May 2022, the Indian Computer Emergency Response Team (CERT-In) highlighted a Remote Code Execution (RCE) vulnerability in Apple watchOS, tvOS, and macOS, affecting Apple Watch, Apple TV, and Apple Mac systems. The vulnerability existed due to an out-of-bounds write issue in the AppleAVD component. Successful exploitation of this vulnerability may allow a remote attacker to execute arbitrary code with kernel privileges on the targeted system.[5]

INTERNATIONAL

Canada to ban China’s Huawei and ZTE from its 5G/4G networks

Following to the review by Canada’s independent security agencies and consultation with ‘closest’ allies, the Government of Canada decided to ban China’s Huawei and ZTE products and services from Canada’s 5G/4G communication networks. In a statement released on 19 May 2022, the Minister of Innovation, Science and Industry— Francois-Philippe Champagne has stated that “the Government of Canada is ensuring a long term safety of telecommunication infrastructure. As a part of that, the government intends to prohibit the inclusion of Huawei and ZTE products and services in Canada’s telecommunication systems.” [6]

As per the decision, the companies that already using the Huawei and ZTE equipment installed in their networks would be required to cease its use and remove it. The implementation of these measures are part of a broader agenda to promote security of Canada’s telecommunications networks, in consultation with industry.

Mastercard strengthen cyber security consulting practice with new Cyber Front threat simulation platform

In recent years, Mastercard invested in risk quantification, Always-On security monitoring and fraud prevention, to help its customers strengthen their cyber resilience. On 24 May 2022, Mastercard made an announcement of launching a new attack simulation and assessment platform— Cyber Front. The platform will assist businesses and governments enhance their cyber security operational resilience. Cyber Front is enabled by a strategic minority investment in Picus Security.

By leveraging a continuously updated library of more than 3,500 real-world threat scenarios, the Cyber Front highlights security gaps and provides mitigation insights in real-time so that organisations can improve upon security investments with continuous validation. The goal of Cyber Front is for organisations to understand if their current systems are effective and identify areas of exposure to ensure greater protection in both— immediate and long term.[7]

Spanish Prime Minister’s phone hacked with Pegasus tool

On 02 May 2022, the Spanish government informed that Prime Minister (PM) Pedro Sanchez’s phone was hacked with Pegasus software. Earlier, in May-June 2021, Spanish Defence Minister— Margarita Robles’ phone was also hacked using the same software. Pegasus software is an Israel-made digital hacking tool to snoop on phone communication.

Researchers investigate and revealed that in April 2022, several political figures in Catalonia were victims of digital espionage. [8] It is assumed that top European Union (EU), the United Kingdom (UK), Poland and Hungary officials may also been targeted with Pegasus software. The use of digital hacking tools such as Pegasus has helped security officials around the world fight crime and ward off national security concerns, therefore, European governments have been wary of delving into the intricacies of spyware programs.[9]

Amid foreign hacking threats, Pentagon contractors looking for software flaws through VDP

Considering Russia and China’s efforts to steal sensitive data from the United States (US) defence industrial base, Pentagon’s pilot program discovered an array of software vulnerabilities with dozens of defence contractors. The objective of pilot program— “Vulnerability Disclosure Program” (VDP) is to identify and fix flaws in the e-mail programs, mobile devices and industrial software used by the Pentagon’s defence contractors before hackers can take advantage of these vulnerabilities.

“We really wanted to focus on those smaller defence contractors that may not have the budget and resources,” said Melissa Vice, interim director of the Department of Defense (DoD) Cyber Crime Centre’s DoD VDP. In the business sector, VDPs are widespread practise, in which vetted cyber professionals scan systems for defects and report them internally. The Pentagon has been running a VDP since 2016, but after the pilot, the intention is to permanently expand the programme to include defence contractors.[10]

Cybercriminals used call forwarding technique to obtain WhatsApp accounts

Cybercriminals used call forwarding as a technique, allowing them to hijack a targeted WhatsApp account and gain control to messages and contact list. The method relied on the mobile carriers’ automated service to forward calls to a different phone number, and WhatsApp’s option to send a OTP (One-Time Password) verification code via voice call.

According to the founder and CEO of ‘CloudSEK’— a digital risk protection company— Rahul Sasi, after knowing the targeted WhatsApp account number and some social engineering, the attacker convinced the victim to make a call to a number that starts with Man Machine Interface (MMI) code that mobile carrier set up to enable call forwarding. A separate MMI code can send all calls to a terminal to a different number or merely when the line is busy or there is no reception, depending on the carrier. “First, you receive a call from the attacker who will convince you to make a call to the following number **67* or *405* (subject to be vary as per the mobile carrier). Within a few minutes, your WhatsApp would be logged out, and the attackers would get complete control of your account”, said Rahul Sasi.

As a protection against such attack, turning on Two-Factor Authentication (TFA) protection in WhatsApp is an effective measure. By requiring a PIN (Personal Identification Number) whenever you register a phone with the messaging app, this feature prevents malicious actors from gaining control of the account.[11]

Endnotes :

[1]India. “CERT-In Advisory CIAD-2022-0014”, Indian Computer Emergency Response Team, 30 May 2022, Available from: https://cert-in.org.in/
[2]“Cisco launches new tool for SMBs to assess their cyber security readiness”, Financial Express, 26 May 2022, Available from: https://www.financialexpress.com/industry/sme/msme-tech-cisco-launches-new-tool-for-smbs-to-assess-their-cybersecurity-readiness/2538348/
[3]India. “7th India-Japan ICT Joint Working Group meeting held under India-Japan ICT Comprehensive Cooperation Framework”, Press Information Bureau- Ministry of Communication, 13 May 2022, Available from: https://pib.gov.in/PressReleasePage.aspx?PRID=1825159
[4]ET Tech. “Government proposes to set up India Data Management Office”, ET Telecom, 28 May 2022, Available from: https://telecom.economictimes.indiatimes.com/news/government-proposes-to-set-up-india-data-management-office/91846155?utm_source=Mailer&utm_medium=ET_batch&utm_campaign=ettelecom_news_2022-05-28&dt=2022-05-28&em=YW51cmFnQHZpZmluZGlhLm9yZw==
[5]India. “Remote Code Execution vulnerability in Apple products”, Indian Computer Emergency Response Team , 20 May 2022, Available from: https://cert-in.org.in/
[6]Canada. “Statement from Minister Champagne on telecommunications security”, Ministry of Innovation, Science and Industry, 19 May 2022, Available from: https://www.canada.ca/en/innovation-science-economic-development/news/2022/05/statement-from-minister-champagne-on-telecommunications-security.html
[7] “Another arrow in the quiver: Mastercard strengthens cybersecurity consulting practice with new cyber front threat simulation platform”, Mastercard, 24 May 2022, Available from: https://www.mastercard.com/news/press/2022/may/another-arrow-in-the-quiver-mastercard-strengthens-cybersecurity-consulting-practice-with-new-cyber-front-threat-simulation-platform/
[8]Aarup, Sarah Anne. “Pegasus spyware targets top Catalan politicians and activists”, Politico, 18 April 2022, Available from: https://www.politico.eu/article/pegasus-spyware-targets-top-catalan-politicians-and-activists/
[9]Manancourt, Vincent. “Hack of Spanish PM’s phone deepens Europe’s spyware crisis”, Politico, 02 May 2022, Available from: https://www.politico.eu/article/pegasus-hacking-spyware-spain-government-prime-minister-pedro-sanchez-margarita-robles-digital-espionage-crisis/
[10]Lyngaas, Sean. “Pentagon contractors go looking for software flaws as foreign hacking threats loom”, CNN, 02 May 2022, Available from: https://edition.cnn.com/2022/05/02/politics/pentagon-defense-contractors-software-flaws/index.html
[11]Ilascu, Ionut. “Hackers steal WhatsApp accounts using call forwarding trick”, Bleeping Computer, 31 May 2022, Available from: https://www.bleepingcomputer.com/news/security/hackers-steal-whatsapp-accounts-using-call-forwarding-trick/

Africa Now – Weekly Newsletter (Week 12, 2022)

Welcome to Africa Now, your weekly newsletter for Africa, presenting the most important developments in the continent – news that matters.

COMMENTARY

Russia-Ukraine Crisis: Where do African Countries Stand?

On 21st February 2022, President Vladimir Putin recognised the independence of Ukraine’s breakaway regions, Donetsk and Luhansk and decided to support Moscow-backed separatists with a military operation. Three days later, when Russia started its air and missile strikes in Ukraine’s Donbas region, it transformed into a full-blown war. Click here to read…

NEWS

Tensions rise in Libya as risk of ‘parallel governments’ grows, Security Council hears

Amid a political impasse that threatens to see Libya fractured again by two parallel governments, the priority must be maintaining hard-won gains and fulfilling the electoral aspirations of nearly three million registered voters. Click here to read…

Tanzania is getting a political remake as President Hassan eyes the 2025 polls

The sudden death of Tanzania’s populist president John Pombe Magufuli on 17 March 2021 catapulted his then little-known vice-president, Samia Suluhu Hassan, to the helm of political leadership. Click here to read…

Somalia delays election process again as deadline lapses

Somalia has again pushed back the deadline for completing lower house elections, delaying until March 31 a process that is already more than a year overdue and has resulted in political sanctions. Click here to read…

West African bloc says it won’t abandon Burkina Faso after coup

A representative of West Africa’s regional bloc said it would keep working with Burkina Faso despite concerns about the military’s plan to hold power for three years after a January coup. Click here to read…

Ethiopia, Egypt, and Sudan hold secret talks on GERD dispute in UAE

Egypt, Ethiopia and Sudan are holding secret talks mediated by the United Arab Emirates on the filing and operation of the Grand Ethiopian Renaissance Dam (GERD). Click here to read…

Niger pushes for peace with jihadist talks

Niger is pressing ahead with an initiative to talk to jihadists whose attacks have shaken the country’s southwest, amid fears that a new wave of bloodshed lies ahead. Click here to read…

Sudan: Russian influence and Ukraine war stir domestic tensions

Officials courted Russian influence but the interference and the war in Ukraine are driving a wedge between its two most powerful men and stirring up domestic tensions. Click here to read…

Mali to suspend France 24 TV station and RFI radio

The Malian military government is moving to suspend broadcasts by French state-funded international RFI radio and France 24 television channel, accusing the news outlets of reporting “false allegations” that the army killed dozens of civilians. Click here to read…

‘Union will not remain silent’: Tunisia’s UGTT demands dialogue

Tunisia’s powerful UGTT labour union says it will not remain silent if authorities do not include it in negotiations over the country’s political and economic future, rejecting proposed reforms. Click here to read…

UK approves Rwandan envoy ahead of Commonwealth meet

The United Kingdom has approved Rwanda’s new envoy to the country, Johnston Busingye, despite calls from critics to London to reject the nomination. The approval comes three months before Kigali hosts the Commonwealth Head of Governments meeting slated on June 20. Click here to read…

Ambush and reprisals in western Ethiopia kill 64 – rights body

At least 53 people have died in western Ethiopia after an unidentified armed group attacked a civilian convoy and its military escort in a region plagued by ethnic violence. Click here to read…

South Africa’s Ramaphosa blames NATO for Russia’s war in Ukraine

South African President Cyril Ramaphosa blamed NATO for the war in Ukraine and said he would resist calls to condemn Russia, in comments that cast doubt over whether he would be accepted by Ukraine or the West as a mediator. Click here to read…

Russia, China Build Ties in Africa as U.S. Falls Behind

In a new “scramble for Africa”, Russia and China are cutting deals, extending loans, making friends and allies across the continent at a time when jihadists in many countries have posed a growing threat to citizens and national security forces. Click here to read…

US’s Blinken meets Ivory Coast PM to discuss trade, security

US Secretary of State Antony Blinken has welcomed Patrick Achi, prime minister of Ivory Coast, for bilateral talks on a number of trade and security issues at the US Department of State. Click here to read…

Complementing Rafales, US Could Sell Its ‘Top Dogfighters’ to Egypt as Cairo Moves Away from Russian SU-35 Jets

The Biden administration is planning to approve the sale of F-15 Eagles to Egypt, a top US military official said. This comes despite speculation that Washington might cut military aid to Cairo due to concerns about Egypt’s human rights record. Click here to read…

Chad military gov’t, armed groups peace talks in Doha on hold

A first round of negotiations between Chad’s ruling transitional military council (TMC) and representatives of armed groups set to kick off in Doha, the Qatari capital, has been delayed by 48 hours. Click here to read…

Nigeria moving ahead on nuclear power plant plan

Speaking at the Nigerian International Energy Summit in Abuja earlier this month, Idris said that Nigeria had had a small nuclear research reactor in operation for 18 years “so if anyone tells you Nigeria can’t manage a nuclear power plant – they are just telling you a story”.Click here to read…

Italy Negotiates with Libya, Algeria for Renewable Energy Deal

Italy is currently holding negotiations with Libya and Algeria for the mobilization and development of renewable energy resources. The European country is looking to diversify its energy mix, adopting clean energy sources from renewable-rich countries in northern Africa. Click here to read…

Rebel attacks in eastern Congo kill more than 60

Suspected Islamist militants have killed more than 60 people over five days of attacks on villages in eastern Democratic Republic of Congo, local residents said on Tuesday. Click here to read…

Western Sahara: Spain and Morocco near end to diplomatic row over disputed territory

Morocco and Spain have moved closer to resolving a decades-long dispute over Western Sahara. Spain’s Prime Minister stated that a proposed autonomous region under Rabat control is the “most serious, realistic and credible” solution, according to Morocco’s royal palace. Click here to read…

Cameroon’s separatist conflict spills into Nigeria

The peaceful Nigerian fishing village of Manga sits not far from Cameroon’s border, but its residents know all about the separatist war raging inside their West African neighbour. Click here to read…

What drives South Africa’s political violence?

South Africa has a history of political violence, including a culture of violent protests and political killings. Historically, the violence is rooted in diverse drivers such as ethnic and tribal differences, and political intolerance. Click here to read…

The Chagos archipelago: Between British colonial past, American interests and Mauritian sovereignty

Last month, while global attention was fixated on the Ukraine crisis, Mauritius sent an expedition, a first of its kind, to the Chagos archipelago, also known as the Chagos Islands. Click here to read…

OIC Africa Group in Solid Support of Gambia Hosting Summit

In response to false and misleading rumours emerging largely on social media, The Gambia OIC Secretariat wishes to inform the public that The Gambia maintains its role as the rightful host of the next OIC Heads of State and Governments Summit. Click here to read…

African Countries Build Capacity on Cyber security

Sixty-five participants from 32 countries are attending a forum in Accra to promote cybersecurity capacity building in Africa. Dubbed Africa Cyber Experts (ACE) Community Kick-Off Meeting, it is on the theme “Setting the Scene for Cybersecurity Status in Africa.” Click here to read…

President of Guinea-Bissau says he stands firm in his post

The President of Guinea-Bissau said on Thursday that the Guinean State is still standing and that he remains firm in his post. The president’s speech, delivered on Thursday, takes place after the attempted coup on the 1st of February. Click here to read…

Eswatini Air adds first aircraft, an E145

Eswatini Air – the new regional airline brand of state-owned Royal Eswatini National Airways (RENAC) – plans to debut by the end of 2Q22 on Southern African regional routes using two EMB-145EPs. Click here to read…

How China-African trade may evolve

China is taking a more cautious approach to trade and investment in Africa and shifting its focus from governments to multilateral institutions. Click here to read…

Uganda bids to host Africa drugs agency

Uganda has the required capacity to host the African Medicine Agency (AMA) following its investments in developing and manufacturing drugs over the years. Click here to read…

Kenya Receives A $750 Million Boost to Support Economic Transformation Post-Pandemic

In an effort to help accelerate Kenya’s ongoing inclusive and resilient recovery from the COVID-19 crisis, the World Bank has approved a $750 million Development Policy Operation (DPO) that will help strengthen fiscal sustainability through reforms that contribute to greater transparency and the fight against corruption. Click here to read…

Mauritania says fight against slavery an ‘irreversible priority’

Fighting slavery in Mauritania is “a constant and irreversible” priority for the authorities, one of the country’s top rights officials said Wednesday, in a rare public comment on the issue there. Click here to read…

Talks underway to resume iron ore project in Guinea

Company representatives and officials are actively seeking a joint solution to a quick resumption of work at the Simandou project in Guinea, which has the world’s largest untapped iron ore reserves, the Global Times has learned. Click here to read…

Zambia’s late former President Rupiah Banda buried

Zambian late former President Rupiah Banda, who ruled from 2008 to 2011 and died at 85 last week after a battle with cancer, was buried at Embassy Park in Lusaka, the capital. Click here to read…

Mozambique: Cyclone Gombe death toll rises to 53

Tropical Cyclone Gombe has killed at least 53 people since it hit Mozambique a week ago, a sharp rise from earlier estimates. Click here to read…

INDIA IN AFRICA

‘Green Triangle’ named after Mahatma Gandhi inaugurated in Madagascar’s capital as part of Azadi ka Amrit Mahotsav

As part of the ‘Azadi ka Amrit Mahotsav’ to commemorate India’s 75th year of independence, a “Green Triangle” named after Mahatma Gandhi was jointly inaugurated in Madagascar’s capital Antananarivo. Click here to read…

Delegation from Telangana announced for Namibia for diamonds and pharma sectors

The India Africa Trade Council organized the India Namibia Summit which was attended by the Business community in Telangana and Andhra Pradesh. Click here to read…

Indian-American Puneet Talwar Appointed New US Ambassador to Morocco

US President Joe Biden on Friday announced Indian American Puneet Talwar for Ambassador of Morocco as part of some key nominations for his administration, a White House press release said. Click here to read…

India, Namibia committed to partnership in pharma sector

Trade between India and Namibia stood at approximately $80 million in the last few years. Namibia imports drugs and pharmaceuticals, chemicals and agricultural machinery from India. Click here to read…

South Africa Tourism aims at 64% rise in arrivals from India

With 48 per cent of the total Indian visitors to South Africa travelling from Mumbai, the city is the leading source market for South African Tourism in India. Click here to read…

South Africa to soon start e-visa facility for Indian travellers

The South African Tourism Board has recently expressed that it’s eyeing 64% year-on-year growth in arrivals from India this year. Click here to read…

2022 Honda Africa Twin Adventure Sports launched in India at Rs 16.01 lakh, bookings open

Honda Motorcycle & Scooter India announced today that bookings for the new 2022 Africa Twin Adventure Sports are now open in India at Honda’s exclusive Big Wing Topline dealerships. Click here to read…

South Africa, India, EU, US reach compromise on Covid-19 vaccine patent

Any agreement must be accepted by the WTO’s 164 member countries in order to be adopted. If one country rejects the proposal, it could mean the end of the waiver. Click here to read…

India at UNSC calls for elections in Libya, hopes issues resolve peacefully

At the United Nations Security Council (UNSC) briefing on the situation in Libya, R. Madhu Sudan, Counsellor at Permanent Mission of India to the United Nations reiterated the imperative for holding the Presidential and Parliamentary elections in the North African country at the earliest. Click here to read…

34 countries, including India, confirm presence at Commonwealth Summit in Rwanda

The CHOGM or Commonwealth Heads of Government Meeting has been scheduled to start in the third week of June with President of Rwanda Paul Kagame being the host of the summit. Click here to read…

South Africa to issue e-visas for Indian travellers soon

As part of post-pandemic revival plans, South Africa will introduce e-visas for Indians to attract more tourists, business travellers and movie-makers, mainly from the south. Click here to read…
Click here to read…