News, sports websites vulnerable to cyber attacks: study

June 11, 2017

London, Jun 11: News and sports websites have some of the lowest levels of security adoption, making them vulnerable to cyber attacks, a new study has found.newsweb

Researchers looked at the security protocols used by the top 500 sites in various industries and online sectors. They found that fewer than 10 per cent of news and sports websites used basic security protocols such as Transport Layer Security (TLS).

Even those that do are not always using the "latest or strongest protocols", researchers said.

"It is like news and sport content providers do not value the security of their content," said Professor Alan Woodward, a cyber-security expert at the University of Surrey in the UK. "They are leaving themselves vulnerable to attacks like cross-site scripting, where an attacker can pretend something has come from a website when it has not," said Woodward.

The study shows that some sectors seem much more security-conscious than others, 'BBC News' reported.

The websites of computer and technology companies and financial organisations showed a much higher level of adoption than shopping and gaming sites, for example.

A quarter of the shopping sites studied were using TLS, which offers tools including digital certificates, remote passwords, and a choice of ciphers to encrypt traffic between a website and its visitors. The study was published in the Journal of Cyber Security Technology.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 12,2020

Mumbai, Jun 12: Following an overwhelming response for the mega rights issue of Mukesh Ambani-owned Reliance Industries, the partly paid-up rights shares are set to debut on stock exchanges on June 15.

The biggest ever Rs 53,124 crore rights issue was subscribed 1.59 times and received bids worth Rs 84,000 crore on June 3.

Reliance said the rights issue saw a huge investor interest, including from lakhs of small investors and thousands of institutional investors, both Indian and foreign.

In 2019, Ambani said in the Reliance's annual general meeting that the company will be net zero debt by March 2021. The company is on course to achieve its target ahead of the deadline.

"In spite of the COVID-19 crisis and the lockdowns, the due-diligence by Saudi Aramco for the planned investment in the O2C business is on track as both the parties are committed and actively engaged," he said recently.

"With a strong visibility to these equity infusions, Reliance is set to achieve net zero debt status ahead of its own aggressive timeline. We believe rights issue was a part of the company's strategy of deleveraging its balance sheet," said Ambani. 

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
July 18,2020

New Delhi, Jul 18: India's national cybersecurity agency CERT-in, has warned people of credit card skimming spreading across the world through e-commerce platforms.

Attackers are typically targeting e-commerce sites because of their wide presence, popularity and the environment LAMP (Linux, Apache, MySQL, and PHP), the Computer Emergency Response Team (CERT-In) said in a notice on Thursday.

Recently, attackers targeted sites which were hosted on Microsoft's IIS server running with the ASP.NET web application framework, it said.

Some of the sites affected by the attack were found to be running ASP.NET version 4.0.30319, which is no longer officially supported by Microsoft and may contain multiple vulnerabilities, CERT-In said.

The notice also included a list of best practices for website developers including the use of the latest version of ASP.NET web framework, IIS web server and database server.

The advisory is based on research by Malwarebytes which found that this skimming campaign likely began sometime in April this year.

Credit card skimming has become a popular activity for cybercriminals over the past few years, and the increase in online shopping during the pandemic means additional business for them, too, Malwarebytes said in a blog post, adding that attackers do not need to limit themselves to the most popular e-commerce platforms.

Researchers from global cybersecurity and anti-virus brand Kaspersky had warned in December last year that more cybercriminal groups will target online payment processing systems in 2020. 

It said that over the past couple of years, so-called JS-skimming (the method of stealing of payment card data from online stores), has gained immense popularity among attackers. 

Kaspersky researchers in their report said they are currently aware of at least 10 different actors involved in these type of attacks.

Their number will continue to grow during the next year, the report said, adding that the most dangerous attacks will be on companies that provide services such as e-commerce as-a-service, which will lead to the compromise of thousands of companies.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
July 3,2020

Mumbai, Jul 3: In yet another move to keep Chinese technologies companies at bay, the Centre has cancelled the 4G upgradation tender for BSNL as it has decided to come up with fresh specifications for the upgrade process, sources said.

The Department of Telecommunications (DoT) is likely to issue a fresh tender in the next two weeks.

People in the know said that the fresh tender may not allow Chinese companies to participate and that the new tenders that will be floated in the next two weeks will emphasise on Make in India.

As the border tussle with China escalated last month and around 20 soldiers lost their lives, the government had last month asked both BSNL and MTNL not to use equipment of Chinese makers in their upgrading process to 4G facilities.

Huawei and ZTE are the major Chinese telecom equipment makers working with Indian telecom companies and they would be the hardest hit by the decision.

The impact may be felt in terms of the much-awaited 5G trials in the country. After much deliberation, the Centre last December decided to allow Huawei to take part in the 5G trials.

The cancellation of tender for BSNL's 4G upgradation comes after the Centre on Monday banned 59 Chinese apps including TikTok, WeChat and UC Browser.

A statement by the Ministry of Electronics and IT said that the decision was taken since "there is credible information that these apps are engaged in activities which are prejudicial to sovereignty and integrity of India, defence of India, security of state and public order".

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.