<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>hacker Archives - International Finance</title>
	<atom:link href="https://internationalfinance.com/tag/hacker/feed/" rel="self" type="application/rss+xml" />
	<link>https://internationalfinance.com/tag/hacker/</link>
	<description>International Finance - Financial News, Magazine and Awards</description>
	<lastBuildDate>Mon, 17 Nov 2025 13:50:38 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.7</generator>

<image>
	<url>https://internationalfinance.com/wp-content/uploads/2020/08/favicon-1-75x75.png</url>
	<title>hacker Archives - International Finance</title>
	<link>https://internationalfinance.com/tag/hacker/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cyberattack on healthcare firm Doctor Alliance: All you need to know</title>
		<link>https://internationalfinance.com/technology/cyberattack-healthcare-firm-doctor-alliance-all-you-need-know/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cyberattack-healthcare-firm-doctor-alliance-all-you-need-know</link>
					<comments>https://internationalfinance.com/technology/cyberattack-healthcare-firm-doctor-alliance-all-you-need-know/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Mon, 17 Nov 2025 13:50:38 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Cyberattack]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Doctor Alliance]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[health insurance]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=53844</guid>

					<description><![CDATA[<p>Recently, Cybernews confirmed a post on a popular hacker forum, likely made by the alleged perpetrators, claiming 353 gigabytes of data were stolen during a breach of Doctor Alliance’s network</p>
<p>The post <a href="https://internationalfinance.com/technology/cyberattack-healthcare-firm-doctor-alliance-all-you-need-know/">Cyberattack on healthcare firm Doctor Alliance: All you need to know</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A cybersecurity research firm has now found a new data trove on the <a href="https://internationalfinance.com/magazine/opinion-magazine/erosion-of-trust-dark-webs-financial-fallout/"><strong>dark web</strong></a>, said to contain 1.24 million files, many related to direct patient care, that allegedly belong to Doctor Alliance, a health IT platform that provides automated billing services. This is a serious development, given the fact that the Texas-based venture has clients (healthcare providers) including Intrepid, AccentCare, Carter and Interim across the United States, representing millions of patients.</p>
<p>Recently, Cybernews confirmed a post on a popular hacker forum, likely made by the alleged perpetrators, claiming 353 gigabytes of data were stolen during a breach of Doctor Alliance’s network. For now, the data has not been leaked, with the user going by the alias “GOD” threatening to either post or sell the information on November 21, 2025, in case a ransom of USD 200,000 is not paid.</p>
<p>Alias &#8220;GOD,&#8221; who likely represents a group of individuals, released a small 200 MB sample to prove they have the files. As per Cybernews, the revealed files include “various medical records, riddled with sensitive personal data,” specifically details on patient prescriptions, treatment plans, names, health insurance numbers, phone numbers, home addresses, hospital orders and more.</p>
<p>In the United States, such data access would constitute a reportable breach under the terms of the Health Insurance Portability and Privacy Act (HIPAA). <a href="https://internationalfinance.com/technology/start-up-week-armed-with-fresh-funding-chainguard-eyes-become-major-cybersecurity-player/"><strong>Cybersecurity</strong></a> researchers now believe the trove, if determined to be legitimate, poses a serious risk to patients and employees, as it could all be used for identity theft, blackmail or other nefarious purposes. This includes not only medical identity theft but also insurance fraud.</p>
<p>&#8220;This data leak poses a huge risk of identity theft and medical fraud for the patients involved, such as obtaining medical services or prescription drugs in the victim&#8217;s name. Both doctors and patients can fall victim to social engineering attacks,&#8221; remarked the researchers.</p>
<p>While promising that the data would be deleted if the ransom is paid, the alleged cybercriminals in a post refused to divulge details like when the attack took place and what vector was used. No known hacker outfit has claimed credit for the attack.</p>
<p>The post <a href="https://internationalfinance.com/technology/cyberattack-healthcare-firm-doctor-alliance-all-you-need-know/">Cyberattack on healthcare firm Doctor Alliance: All you need to know</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/cyberattack-healthcare-firm-doctor-alliance-all-you-need-know/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>EU AI Act: A struggle to keep up with tech</title>
		<link>https://internationalfinance.com/magazine/technology-magazine/eu-ai-act-a-struggle-to-keep-up-with-tech/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=eu-ai-act-a-struggle-to-keep-up-with-tech</link>
					<comments>https://internationalfinance.com/magazine/technology-magazine/eu-ai-act-a-struggle-to-keep-up-with-tech/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Tue, 25 Feb 2025 05:59:52 +0000</pubDate>
				<category><![CDATA[Magazine]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[ChatGPT]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[EU AI Act]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Generative AI]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[investment]]></category>
		<category><![CDATA[Startups]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=52435</guid>

					<description><![CDATA[<p>While the EU has implemented the AI Act to set global standards, its broad and stringent regulations have raised concerns among startups and investors</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/eu-ai-act-a-struggle-to-keep-up-with-tech/">EU AI Act: A struggle to keep up with tech</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Regulators worldwide face a rapidly growing technology with enormous economic and geopolitical effects. European Union (EU) negotiations often result in deals made after midnight due to fatigue and horse-trading. The one the European Council and EU Parliament agreed upon on December 8–9, 2023, was similar.</p>
<p>Its outcome, the EU AI Act, is the first major piece of legislation controlling AI, including ‘generative AI’ chatbots, which have become the Internet&#8217;s new craze since ChatGPT&#8217;s inception in late 2022.</p>
<p>Two days later, French startup Mistral AI unveiled Mixtral 8x7B, a new large language model (LLM) for generative AI. Its unique setup of eight expert models makes it better than proprietary alternatives despite being smaller. Worse, the Act&#8217;s harsher regulations do not apply to its open-source code, presenting regulators with new issues.</p>
<p>Mixtral&#8217;s disruptive potential exemplifies policymakers&#8217; struggles to rein in AI. Tech companies believe self-regulation is the answer. Given their inclination to prematurely enforce restrictive laws, former Google CEO Eric Schmidt believes governments should leave AI regulation to tech corporations.</p>
<p>How to control something that changes so fast is a question for most policymakers.</p>
<p><strong>Setting EU law</strong></p>
<p>The first attempt to answer that question is the AI Act, which will take effect in May 2025. Given the bloc&#8217;s regulatory powerhouse status, it intends to develop a European and possibly worldwide regulatory framework by encompassing practically all AI applications.</p>
<p>RPC partner Helen Armstrong said, &#8220;Large, multi-jurisdictional businesses may find it more efficient to comply with EU standards across their global operations on the assumption that they will probably substantially meet other countries’ standards.&#8221;</p>
<p>It is also the first attempt to handle foundation models, or General Purpose AI models (GPAI), which power AI systems.</p>
<p>All models must be horizontally compliant, including detecting AI-generated content, or face fines of up to 7% of the miscreant&#8217;s global revenue. How do you control rapid change? The Act tiers risk and responsibility for activities and AI models.</p>
<p>GPAIs with systemic risk must undergo rigorous reviews, incident reporting, and advanced cybersecurity procedures, including ‘red teaming,’ a simulated hacker attack. It&#8217;s called &#8220;systemic risk&#8221; because of two main factors: the amount of computation used to train the model (more than 10^25 &#8220;floating point operations&#8221;), which shows how big the industry is; and the model having more than 10,000 business users in the EU.</p>
<p>It appears only ChatGPT-4 and probably Google&#8217;s Gemini fit these criteria. Not everyone finds these criteria effective. Nigel Cannings, the founder of Intelligent Voice, stated that some high-capacity models may be relatively benign, while others may use lower-capacity models in high-risk contexts. The computing criterion may encourage developers to find workarounds that technically meet the threshold without reducing risks.</p>
<p>Cutting data requirements to achieve favourable outcomes is the goal of current AI research. Patrick Bangert, a data and AI expert at Searce, a technology consulting firm, said, “Classifying models by the amount of compute they require is only a short-term solution. These efforts are likely to break the compute barrier in the medium term, thus making this regulation void.”</p>
<p>The Act&#8217;s final draft was fiercely negotiated. France, Germany, and Italy initially resisted binding foundation model legislation, fearing it would hurt their startups. The Commission proposed horizontal regulations for all models and codes of practice for the most powerful as a compromise.</p>
<p>“There was a feeling that a lower threshold could hinder foundation model development by European companies, which were training smaller models at the time,” said Philipp Hacker, an AI regulation expert at the European New School of Digital Studies.</p>
<p>Hacker argued that this was entirely incorrect, as the rules only codify the bare minimum of industry practices—even falling short by some measures. Domino Data Lab AI expert Kjell Carlsson said, &#8220;We chose the threshold after extensive lobbying, resulting in an imperfect outcome. Others think the Act is too broad. It&#8217;s far more effective to regulate use cases instead of the general technologies that underpin them.&#8221;</p>
<p>Many European startups and SMEs say the limitations could hurt them compared to competitors.</p>
<p>The Future Society, an AI governance think tank, discovered that foundation model suppliers that invest much in training data—1% of their development costs—find compliance easier. Sceptics argue that this solution serves as an additional barrier to the EU&#8217;s regulatory framework, hindering innovation in an area where Europe desperately needs success stories.</p>
<p>Compared to the United States and China, the EU has created few AI unicorns and lagged in research. Nicolai Tangen, head of Norway&#8217;s $1.6 trillion sovereign wealth fund, which uses AI in its investment decision-making, has publicly criticised the EU&#8217;s approach: &#8220;He said, &#8220;I am not saying it is good, but in America, you have a lot of AI and no regulation; in Europe, you have no AI and a lot of regulation.&#8221;</p>
<p>European firms face a fragmented market, stricter data protection regulations, and difficulty retaining AI professionals. Hacker says the Act&#8217;s unjustified &#8220;bad reputation&#8221; may make things worse.</p>
<p>“It is not particularly stringent, but there has been a lot of negative coverage, and many investors, especially from the international venture capital (VC) scene, treat the Act as an additional risk. This will hinder European unicorns&#8217; fundraising,” he said.</p>
<p>Some disagree with this assessment. The Act&#8217;s rules require VCs to add a new criterion to their scorecard: Is the company building a model or product that is and will remain EU compliant?</p>
<p>Dan Shellard, partner at Paris-based venture finance firm Breega, said regulation might offer regtech opportunities. Some believe it will boost innovation.</p>
<p>Chris Pedder, Chief Data Scientist at AI-powered edtech firm Obrizum, said forcing corporations to be more open and responsible will certainly spur innovation.</p>
<p>The special installation of fans&#8217; recreations of Johannes Vermeer&#8217;s &#8216;Girl with a Pearl Earring&#8217; includes Julian van Dieken&#8217;s AI-powered piece. Another issue is that technology is evolving faster than legislation. The Act doesn&#8217;t regulate open-source models like Mixtral 8x7B unless they pose a systemic risk. Making them public aims to increase transparency and accessibility, but it also poses significant safety risks.</p>
<p>Open-source models offer a broader range of computational capabilities, allowing many users to utilise local computing resources instead of expensive cloud-based ones.</p>
<p>Iain Swaine of BioCatch, a digital fraud detection startup, noted that in a decentralised system, it becomes easier to create malware, phishing sites, and deepfakes.</p>
<p><strong>America is divided</strong></p>
<p>The United States is behind in regulation despite its commercial AI dominance. Multiple federal agencies regulate AI, creating a fragmented regulatory framework. An executive order requires federal agencies to investigate AI usage, require AI system developers to assure ‘safe, secure, and trustworthy’ systems and share safety test results with the US government.</p>
<p>Donald Trump has vowed to reverse it, but it may fail without Republican support in Congress. Congress&#8217; bipartisan AI task force has yielded little. Due to partisanship, any compromise before the November elections is improbable. Since American governments value innovation and economic progress, we project US regulation to be less severe than European regulation. Europe has no AI and lots of regulation, while America has lots of AI and little regulation.</p>
<p>Morgan, Lewis &amp; Bockius partner David Plotinsky said, &#8220;AI will be an area in which both Congress and the executive branch take a very incremental approach to regulating AI—including by first applying existing regulatory frameworks to AI rather than developing entirely new frameworks.&#8221;</p>
<p>States could potentially fill this void. He said the risk is a “patchwork of regulations that may overlap in some areas and also conflict in others.” Apocalyptic predictions that an omnipotent AI may threaten humanity inform the debate. Some, like Elon Musk, want AI development stopped. However, mundane matters seem more urgent. The advent of monopolies, especially in generative AI, is a serious concern, but multiple ChatGPT competitors have allayed concerns that OpenAI, the business behind ChatGPT, will monopolise.</p>
<p>&#8216;Our Planet Powered by AI&#8217; author Mark Minevich said, &#8220;The industry&#8217;s high barriers to entry, such as the need for enormous data and computational power, mean that only a few huge incumbents, such as top big tech companies, could dominate.&#8221;</p>
<p>As AI becomes a flashpoint in the United States-China relationship, policymakers are also concerned about how legislation affects US competitiveness. In another executive order, US President Joe Biden ordered the Treasury to prohibit outbound AI investment in countries of concern and to review AI technologies for security vulnerabilities.</p>
<p>Plotinsky, acting chief of the US Department of Justice&#8217;s Foreign Investment Review Section, predicted that Washington would need to adopt a risk-based approach to foundation models. He also said that any risk-based approach would have to consider whether the foundation model was created in the United States or another trusted country, as well as what controls and other safety measures might be needed to keep China&#8217;s potentially powerful goals from causing concerns. National AI leadership is the government&#8217;s goal for 2030, with substantial funding.</p>
<p><strong>China produces most AI research</strong></p>
<p>Its Global AI Governance Initiative, which includes creating a new international AI governance organisation, shows its desire to influence global regulation. The initiative also urges “opposing drawing ideological lines or forming exclusive groups to obstruct other countries from developing AI,” a reference to US legislation restricting US investment in China&#8217;s AI business.</p>
<p>According to Wendy Chang, a technology analyst at the Mercator Institute for China Studies, China aspires to participate in international forums and influence the global development of AI regulation.</p>
<p>Domestically, Beijing&#8217;s tightly managed censorship regime needs to be maintained, often openly, by requiring generated text content to ‘reflect communist basic values.’ The EU launched a global AI standards race. Although the government encourages Chinese enterprises to build Gen AI tools to compete internationally, these beliefs may hinder China&#8217;s AI leadership. Baidu and Alibaba unveiled their AI-powered chatbots last year.</p>
<p>The country&#8217;s early generative AI standards required developers to verify the ‘truth, correctness, objectivity, and diversity’ of training data, a high standard for models trained on online content. Recent regulatory changes allow Chinese enterprises to ‘elevate the quality’ and ‘strengthen truthfulness’ instead of ensuring training data honesty, but hurdles remain.</p>
<p>One working group suggested a proportion of model-rejectable answers. Given chatbots&#8217; potential to spread falsehoods, such regulations may require Chinese corporations to develop their models with restricted firewalled data. Chinese companies and citizens cannot use ChatGPT. After an AI tool criticised Mao Zedong, iFlytek&#8217;s founder apologised publicly. Chang said Beijing&#8217;s domestic information regulation is a major issue for AI developers.</p>
<p>Compliance would be difficult for tech companies, especially smaller ones, and may deter many from entering the field. We already see tech companies focusing on corporate solutions rather than public products, which the government desires.</p>
<p>A full AI law is due from the Chinese government, which has published specific AI regulations. The 2021 recommendation algorithm regulation was driven by concerns over their role in information dissemination, a perceived threat to political stability, and China&#8217;s concept of ‘cyber sovereignty.’ Importantly, the rule created a list of algorithms with &#8220;public opinion properties,&#8221; which means developers had to explain how their algorithms were trained and how they were used. It now covers AI models and training data, with the first LLMs passing these reviews released in August.</p>
<p>China&#8217;s internet authority recently issued guidelines for AI-produced deepfakes, and its deep synthesis regulation, finalised five days before ChatGPT&#8217;s debut, requires synthetically generated content to be labelled. Who owns this photo? Another rising battleground is foundation model data IP ownership.</p>
<p>Generative AI has stunned creative workers, prompting legal action and strikes in industries like Hollywood that were previously impervious to technological innovation. Many artists have sued generative AI platforms for creating unlicensed derivative works.</p>
<p>Stock image seller Getty Images sued image generation platform Stable Diffusion for copyright and trademark infringement. Financial authorities face new AI problems. Risk modelling, claims management, anti-money laundering, and fraud detection in finance increasingly use AI, posing serious hazards.</p>
<p><strong>Trouble in the EU</strong></p>
<p>In 2022, the Bank of England and FCA reported that 79% of UK financial services organisations used machine learning, with 14% deeming it essential. The &#8220;black box&#8221; problem, which involves algorithmic decision-making without transparency or accountability, is a major issue.</p>
<p>According to regulators, AI may increase systemic risks, including flash crashes, market manipulation by deepfakes, and convergent models causing digital cooperation. The industry has promised improved ‘explainability’ in how AI is used for decision-making, but this remains elusive, and regulators may fall victim to automation bias when overusing AI systems.</p>
<p>Scott Dawson from DECTA, a payment solutions provider, suggests that while transparency appears advantageous in theory, financial institutions often hide certain elements of their processes for legitimate reasons.</p>
<p>He cited fraud prevention as an example where more transparency about how financial services firms use AI systems could be counterproductive: “Telling the world what they are looking for would only make them less effective, leading to fraud.”</p>
<p>Another issue is algorithmic prejudice. AI in credit risk management can make loans harder to get or worsen their terms for marginalised groups. The EU&#8217;s planned Financial Data Access law, which allows financial institutions to exchange consumer data with third parties, may hurt vulnerable borrowers.</p>
<p>The EU AI Act classifies banks&#8217; AI-based creditworthiness operations and life and health insurance pricing and risk assessments as high-risk activities, requiring them to comply with stricter regulations.</p>
<p>“New ethical challenges are triggering unintended biases, forcing the industry to reflect on the ethics of new models and think about evolving towards a new, common code of conduct for all financial institutions,” said Dun &amp; Bradstreet head of banking and financial services, Sara de la Torre.</p>
<p>The platform&#8217;s proprietors responded by allowing artists to opt out and protect their IP.</p>
<p>Such legal action has raised the question of who owns AI-generated material—AI platforms, downstream providers, content creators, or users. Solutions include paying content creators, sharing revenue, and using open-source data.</p>
<p>EIP counsel Ellen Keenan-O&#8217;Malley said, &#8220;In the short term, I expect organisations to place greater reliance on contractual provisions, such as a broad intellectual property indemnity against third-party claims for infringement.&#8221;</p>
<p>Only the European Union has adopted a clear position; the AI Act requires model providers to take ‘adequate measures’ to safeguard copyright, including releasing full training data summaries and copyright rules. Synopsys data specialist Curtis Wilson said banning copyrighted photos for AI training will prevent AIs from mass-producing custom art.</p>
<p>However, the expert commented, “But it would also ban image classification AI that detects cancerous tumours.”</p>
<p>Europe and China want a piece of America&#8217;s tech superiority, making AI deployment geopolitical. Because AI models are growing so quickly and different approaches are used in different major economies, only bilateral agreements can work. For this reason, the tech industry thinks that global regulatory frameworks are too optimistic.</p>
<p>A recent Biden-Xi conference agreed to begin talks without specifics. Following a similar US-UK agreement to reduce regulatory divergence, the EU and US have agreed to strengthen AI-based technology cooperation, focusing on safety and governance.</p>
<p>Delivered during the first global AI summit in November at the United Kingdom&#8217;s Bletchley Park, the Bletchley Declaration called for international cooperation to mitigate AI concerns. Action has not yet followed. As politicians and tech businesses face the same headwinds that are fragmenting the global economy in an era of increasing deglobalization, unified AI regulation seems unlikely.</p>
<p>The EU has set the global AI standards with horizontal, and some say overly strict, rules for AI systems; the US, hampered by pre-election polarisation and the success of its AI firms, has taken a ‘wait-and-see’ approach that gives the tech industry a free hand; and China, as usual, censors domestically while trying to influence the global regulatory framework.</p>
<p>Morgan Wright, Chief Security Advisor at SentinelOne, an AI-powered cybersecurity platform, said, “The challenge going forward is not allowing China to dictate what standards are or promote policies regulating AI that favour them over everyone else.&#8221;</p>
<p>However, keeping up with technology is harder. If talkative chatbots surprised the world in 2022, the next waves of AI-powered innovation have left experts dumbfounded by their disruptive potential.</p>
<p>“The field is moving so fast, I am not sure that even venture capital firms not deeply immersed in the field for the last decade fully understand AI and its implications,” said Fluent Ventures founder Alexandre Lazarow.</p>
<p>According to Plotinsky from Morgan, Lewis &amp; Bockius, regulators may be at a disadvantage.</p>
<p>He said, “The technology has evolved too rapidly for lawmakers and their staff to fully comprehend both the underlying technology and the related policy issues.”</p>
<p>The rapid growth of AI technology has created a complex challenge for regulators worldwide, with varying approaches emerging in the EU, US, and China. While the EU has implemented the AI Act to set global standards, its broad and stringent regulations have raised concerns among startups and investors. In contrast, the US takes a more cautious, innovation-driven stance, creating regulatory uncertainty. China, balancing innovation with tight censorship, seeks to influence global AI governance.</p>
<p>As AI technology advances quickly, international cooperation and adaptable regulatory frameworks are crucial. The future of AI regulation will likely hinge on finding a balance between fostering innovation and addressing the emerging risks of AI, with each region contributing its own approach to the global conversation.</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/eu-ai-act-a-struggle-to-keep-up-with-tech/">EU AI Act: A struggle to keep up with tech</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/technology-magazine/eu-ai-act-a-struggle-to-keep-up-with-tech/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Tool-assisted Speedruns stir debate in esports</title>
		<link>https://internationalfinance.com/magazine/technology-magazine/tool-assisted-speedruns-stir-debate-in-esports/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=tool-assisted-speedruns-stir-debate-in-esports</link>
					<comments>https://internationalfinance.com/magazine/technology-magazine/tool-assisted-speedruns-stir-debate-in-esports/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Mon, 09 Dec 2024 06:56:30 +0000</pubDate>
				<category><![CDATA[Magazine]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[gaming]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[PCGamesN]]></category>
		<category><![CDATA[Speedrunning]]></category>
		<category><![CDATA[Speedruns]]></category>
		<category><![CDATA[Super Mario Maker]]></category>
		<category><![CDATA[TASBot]]></category>
		<category><![CDATA[Video Game]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=51571</guid>

					<description><![CDATA[<p>Hacker Allan Cecil hopes that by holding speedrunners accountable, he will contribute to the growth of both conventional speedrunning and the tool-assisted sort of speedrunning that he has helped pioneer</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/tool-assisted-speedruns-stir-debate-in-esports/">Tool-assisted Speedruns stir debate in esports</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The competitive sport of speedrunning video games, which involves moving through them as quickly as possible, has evolved in recent years into a hybrid of highly sophisticated science and virtuoso finger-and-thumb sports. The greatest speedruns combine uncanny ability with glitch-enabled shortcuts to finish big games that should take dozens of hours in a matter of minutes.</p>
<p>Sometimes a bit too inhumane. It turns out that cheaters who splice together video footage to fabricate proof or employ software that violates rules to obtain unfair advantages are the ones who create bogus records in speedrunning. Allan Cecil, a speedrunner and hacker, has made it his duty to find them.</p>
<p><strong>Bans in the past</strong></p>
<p>After admitting to cheating during the 2022 marathon, Done Quick has banned a speedrunner from participating in any future competitions. Additionally, it appears that the Russian player Mekarazium set a world record by completing the Metal Gear Rising: Revengeance expansion.</p>
<p>Mekarazium, on the other hand, presented a pre-recorded film that was assembled utilising segments of different runs rather than live gameplay. To promote the hoax, they responded to the video in real time.</p>
<p>While Summer Games Done Quick returned to an in-person setting for the first time since 2019, some speedrunners took part virtually. According to PCGamesN, Mekazarium was one of them that let them cheat. After reaching a charitable donation target, the player tackled the Blade Wolf DLC after first dominating MGR: Revengeance&#8217;s main campaign in a legal run.</p>
<p>On the other hand, spectators observed differences in the Blade Wolf gameplay. Some pointed out that while Mekarazium was playing the primary game, there were hardly any audible moments when he pressed keys on the keyboard. Mekarazium raises their right hand briefly while their persona is surveying their surroundings, despite their assertion that they were manipulating the mouse with their left hand.</p>
<p>Mekarazium later played down the fact that their run broke records as well. One would assume that a speedrunner who beat their own world record by 25 seconds would be ecstatic.</p>
<p>Mekarazium sent a message to the GDQ enforcement team that PCGamesN was able to receive.</p>
<p>&#8220;The Blade Wolf DLC run reward people paid for is a pre-recorded, segmented run. After switching the saves, I&#8217;ve decided to change my decision at the last minute from a real-time run,&#8221; he said.</p>
<p>Mekarazium stated that they wished to showcase the Blade Wolf run&#8217;s potential. They did, however, apologise and admit that they had done &#8220;an real awful thing.&#8221; They also feared what would happen to other fast runners. They went on, &#8220;I didn&#8217;t spend more time thinking about others and I acted selfishly.&#8221;</p>
<p>&#8220;GDQ informed Engadget in a statement that they learned yesterday that Mekazarium performed a segmented video for his DLC run at Summer Games Done Quick 2022,&#8221; he added.</p>
<p>Since then, Mekazarium has acknowledged this to GDQ employees as well as to certain community members. He got in touch with us and provided a paper that showed he had been planning this for more than a month, proving it was deliberate and planned.</p>
<p>&#8220;This is a blatant attempt to compromise the integrity of the speedrunning community, which we adore and encourage. It&#8217;s unclear from the document what precise outcome they were hoping for, but it&#8217;s obvious that they thought we wouldn&#8217;t be ready to call them out on their actions. Nonetheless, we think it is essential for the community to understand why GDQ withdrew this run. Mekazarium will not be able to run in the future, and we have removed his runs from our YouTube collection,” GDQ continued.</p>
<p>Unfortunately, the incident tarnished another GDQ event that was otherwise quite successful. For Doctors Without Borders, spectators and speedrunners raised just over $3 million. Still, there were a few more difficulties. The organisers had to remove a few games from the schedule because certain runs took longer than anticipated. On the last day, though, they managed to squeeze in one more Pokémon game in an attempt to maximise donations.</p>
<p><strong>The diable hack of 1996</strong></p>
<p>During a speech at the recent Defcon hacker conference in Las Vegas, Cecil intended to provide what he claims is proof that a speedrunning record for the 1996 Personal Computer game Diablo, which has been in the Guinness Book of World Records for over 15 years, was, in fact, the product of rule-breaking methods that ought to disqualify it.</p>
<p>Cecil will have assisted in disproving three high-profile speedruns in 2023 alone if he and the group of investigators he has been working with are successful in shattering the ostensibly unbreakable standard.</p>
<p>Cecil, better known in the gaming community as dwangoAC, started an equally obscure pastime that led him into this peculiar role as a speedrun debunker: Using emulator software to run a game in a controlled environment and discover the limits of that game&#8217;s speedrun, he is renowned for being an adept practitioner of so-called &#8220;tool-assisted speedruns&#8221;—a subset of speedrunning that some purists formerly thought to be a form of cheating.</p>
<p>Cecil contends that speed runs using tools, where competitors painstakingly rewind, replay, refine, and polish their runs frame by frame, can be their legitimate kind of competition or even art.</p>
<p>DwangoAC claims that part of the reason he became obsessed with apprehending cheaters was his desire to safeguard the little-known sport of speedrunning from people who would use the same tools covertly and misleadingly, thereby transforming tool-assisted speedruns into a form of speedrun doping rather than a legitimate pastime.</p>
<p>Cecil has established himself as a mainstay in the speedrunning community. He works as a staff member at the tool-assisted speedrun website TASvideos.org and has organised numerous epic speedrunning feats, including one that rewrote the game&#8217;s conclusion in Ocarina of Time using coding errors.</p>
<p>In addition, he is the inventor of TASBot, a robot that attaches to video game console controller ports to mimic controller inputs. This allows players to watch and validate recorded speed runs on actual gaming hardware. The robot is such a hit that, according to Cecil&#8217;s count, live streams of it have generated $1.5 million in donations for charitable organisations.</p>
<p>But the gamer has recently pushed his fixation with tool-assisted speedrunning in a new direction, using it to track down cheaters who jeopardise the credibility of his hobby. As he has done in all three of the records he has tried to disprove, if he can demonstrate that even a well-honed tool-assisted speedrun in a particular game isn&#8217;t faster than a supposed human record, then demonstration can act as a precursor to a suggestion that a record was probably fabricated. Additionally, he has discovered that the process of designing that tool-assisted run frequently yields fresh insights into the bounds of what is feasible or impractical for an unaided human endeavour.</p>
<p>Cecil may have embarked on his most contentious project yet with his latest record-breaking endeavour. He plans to showcase proof at Defcon that he believes should nullify the record of Maciej &#8220;groobo&#8221; Maselewski, a Polish speedrunner who currently owns the Guinness record for the fastest role-playing game speedrun of all time in addition to the fastest Diablo speedrun. Since 2009, Maselewski&#8217;s 3-minute and 12-second Diablo run has defeated all opponents.</p>
<p>Cecil claims that when he and another speedrunner, Matthew &#8220;funkmastermp&#8221; Petroff, attempted to complete a tool-assisted speed run for Diablo in January 2024, he became suspicious that Maselewski had broken the norms of speedrunning. They soon realised that no matter how good they became at running or how fortunate they were with the randomly generated dungeon layouts in the game, they would never be able to beat Maselewski&#8217;s time of 3 minutes and 12 seconds.</p>
<p>This prompted them to put together a team of investigators who eventually discovered what they believed to be a lengthy list of discrepancies in the items and software versions, missing frames, and other indications of possible tampering in the video of Maselewski&#8217;s run. They have compiled all of this information into a comprehensive document that has been uploaded to Cecil&#8217;s website.</p>
<p>When Maselewski was contacted for comment, he promptly refuted any such foul conduct. He mentioned in an email that his run was always regarded as &#8220;segmented,&#8221; edited together level by level, which is a widely recognized classification for speedrunning.</p>
<p>It was never mistaken for anything else, according to Maselewski.</p>
<p>It&#8217;s amazing to learn that a group of researchers has been working on this. Cecil shared a later text discussion between Maselewski and his associates, in which Maselewski called the effort to disprove his record a &#8220;witch hunt.&#8221;</p>
<p>Cecil counters that Maselewski&#8217;s straightforward explanation, that the speedrun was divided, is insufficient. He alleges that a piece of performance-enhancing software known as a &#8220;trainer&#8221; must have been used and that some dungeon layouts in Maselewski&#8217;s run could not have been generated even in a single segment of a run without changing the game&#8217;s data.</p>
<p>In a farewell email to WIRED the evening before Cecil&#8217;s Defcon talk, Maselewski stated that he thought individuals who were accusing him of cheating were employing inaccurate instruments and a partial understanding of Diablo&#8217;s intricacies. Dwango wants to share a narrative. Have I cheated? No, writes Maselewski.</p>
<p>&#8220;But the wonder of discovery has already overstayed its welcome for a select few, and the script has already been written, so it doesn&#8217;t matter what is true or not at this point,&#8221; he noted.</p>
<p>Cecil&#8217;s proof seems to have more of an impact on an administrator of Speed Demos Archive, or SDA, another speedrun record-keeping website where Maselewski owns a comparable Diablo record. The administrator, who goes under the pseudonym &#8220;ktwo,&#8221; claims that SDA hasn&#8217;t formally taken a decision and is still awaiting Maselewski&#8217;s explanation.</p>
<p>Ktwo states, &#8220;To be clear, we have reached a preliminary conclusion, based on the information provided.&#8221;</p>
<p>The staff is in agreement that the analysis presents issues regarding the legitimacy of the run, which must be resolved to prevent SDA from publishing the run. The runners and the administrative staff are currently debating these issues.</p>
<p>Speedrunner Eric &#8220;Omnigamer&#8221; Koziel started re-examining a record set by Todd Rogers for the Atari 2600 racing game Dragster in 2017 while doing research for a book about speedrunning. This is how Cecil got involved in the investigation of gaming records. Rogers has maintained his record time of 5.51 seconds for an astounding 35 years.</p>
<p>However, upon deconstructing Dragster&#8217;s code to attempt to decipher Rogers&#8217;s time-stamp, Koziel discovered that the strategies Rogers claimed to have employed, like shifting into second gear at the beginning of the game, wouldn&#8217;t have yielded the desired benefit.</p>
<p>Knowing Koziel from the speedrunning community, Cecil offered to aid in creating a tool-assisted speedrun that they could replay on a real Atari 2600 via TASBot, demonstrating that Rogers&#8217; record was unattainable even on that original hardware. They discovered that TASBot performed theoretically flawlessly in 5.57 seconds, which was less than Rogers&#8217; claimed time. Despite Rogers&#8217; protests, his three-and-a-half-decade-old record was removed from Twin Galaxies&#8217; records, along with all of his other records on the website, and Guinness removed his title for the &#8220;longest-standing video game record&#8221; worldwide.</p>
<p>A group of players set out to defeat every level of Super Mario Maker, and Cecil became involved in the investigation of another renowned speedrun early 2024, after taking a seven-year break to work on TASBot projects. When that Wii U game was published in 2015, players could post their levels for other players to play, that is, assuming they could upload a video of themselves beating the level. However, &#8220;Trimming the Herbs,&#8221; one of these levels, seemed unachievable. Only its inventor had been able to finish it for years.</p>
<p>Cecil offered to create a tool-assisted speedrun for the level in an attempt to assist this group of Super Mario Maker devotees. He discovered that, partly because of differences in the Bluetooth communications between the Wii U and its controllers, it was almost hard to clear it consistently.</p>
<p>In that instance, the level&#8217;s developer came forward during the investigation to admit he&#8217;d defeated the level by tampering with the internal components of his Wii U gamepad, a move he had always meant to be amusing but had never before disclosed to the public.</p>
<p>Cecil is not anticipating a confession or any kind of cordial agreement on the facts in his latest attempt to refute Maselewski&#8217;s Diablo record. However, he is sure that he and the researchers he has collaborated with will be able to overthrow Maselewski&#8217;s record and allow speedrunners to resume their approach to the game.</p>
<p>He was shocked to learn that, thanks to new Diablo strategies they discovered during their investigation, they could beat Maselewski&#8217;s record with a tool-assisted speedrun, finishing the game in 2 minutes and 45 seconds without using any of his purported rule-breaking modifications.</p>
<p>Cecil reports that Diablo speedrunner &#8220;xavier_sb&#8221; has finished a run of the game in less than four minutes and 40 seconds, setting a new record should Maselewski&#8217;s be wiped out.</p>
<p>He claims that this already demonstrates how the alleged unachievable record&#8217;s &#8220;chilling effect&#8221; is wearing off. Cecil claims that people had just given up since there was no point. The Diablo speedrunning competition has resumed.</p>
<p>Cecil hopes that by holding speedrunners accountable, he will contribute to the growth of both conventional speedrunning and the tool-assisted sort of speedrunning that he has helped pioneer.</p>
<p>According to him, the secret is to distinguish between people who utilise software tools to play games with superhuman accuracy as an honest kind of art and others who use them for dishonest purposes.</p>
<p><strong>Preserving the art of speedrunning</strong></p>
<p>As Cecil continues to fight for honesty in the speedrunning community, his efforts highlight a larger issue in competitive gaming: the fine line between legitimate optimisation and outright cheating. While tool-assisted speedruns push the limits of what is possible in games, they should not be confused with human achievement. Cecil believes that speedrunning, whether tool-assisted or not, should remain a space for creativity, innovation, and fairness.</p>
<p>The distinction between art and fraud in speedrunning comes down to transparency. Tool-assisted runs are a legitimate form of competition as long as they are presented as such. But when players use similar tools covertly to gain an unfair advantage, it threatens the credibility of the entire sport.</p>
<p>Cecil hopes to ensure that speedrunning continues to evolve as a thriving, legitimate sport, one that celebrates skill, creativity, and integrity.</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/tool-assisted-speedruns-stir-debate-in-esports/">Tool-assisted Speedruns stir debate in esports</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/technology-magazine/tool-assisted-speedruns-stir-debate-in-esports/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Malware LuaDream targeting telecom across three continents</title>
		<link>https://internationalfinance.com/technology/malware-luadream-targeting-telecom-across-three-continents/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=malware-luadream-targeting-telecom-across-three-continents</link>
					<comments>https://internationalfinance.com/technology/malware-luadream-targeting-telecom-across-three-continents/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Thu, 28 Sep 2023 03:37:01 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[LuaDream]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Middle East]]></category>
		<category><![CDATA[South Asia]]></category>
		<category><![CDATA[telecom]]></category>
		<category><![CDATA[telecommunications]]></category>
		<category><![CDATA[Western Europe]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=48039</guid>

					<description><![CDATA[<p>It's been noted that Lua is not exactly a popular choice among hackers, with malware written in this language having only been discovered three times in the previous ten years</p>
<p>The post <a href="https://internationalfinance.com/technology/malware-luadream-targeting-telecom-across-three-continents/">Malware LuaDream targeting telecom across three continents</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A rare piece of malware has been targeting telecommunications providers across three continents.</p>
<p>SentinelOne&#8217;s cybersecurity researchers have detected a fresh piece of malware called LuaDream on telecom infrastructure in the Middle East, Western Europe, and South Asia.</p>
<p>This malware is distinct because it makes use of the LuaJIT just-in-time (JIT) compiler for the Lua programming language. The Hacker News, a news website, notes that Lua is not exactly a popular choice among hackers, with malware written in this language having only been discovered three times in the previous ten years. That includes Project Sauron, Animal Farm (also known as SNOWGLOBE), and Flame. </p>
<p>The researchers added that LuaDream is a modular, multi-protocol backdoor with 13 core and 21 support components. Its primary objectives are to steal user and system data and to launch new plugins, including command execution.</p>
<p>The researchers hypothesize that the work is a &#8220;well-executed, maintained, and actively developed project of a considerable scale&#8221; in light of the victim organizations, the endpoints on which the malware had been discovered, the unusual choice of programming language, and the type of data LuaDream looks to exfiltrate. The attackers, who were unknown at the time, reportedly went to great measures to remain undetected.</p>
<p>The source code specifies a date in June 2022, but the malware was discovered in August 2023, giving the researchers the impression that it had been developed for more than a year.</p>
<p>Despite being inconclusive, some evidence regarding the assailants&#8217; identities pointed to Chinese actors. The &#8220;strategic&#8221; Chinese intrusions into Africa, some of which targeted telecom companies, are covered in a different SentinelOne study. These were a component of the Backdoor Diplomacy, Earth Estries, and Operation Tainted Love activity clusters. Operation Tainted Love, the latter, is said to use the same threat actor as LuaDream activities. </p>
<p>&#8220;Targeted intrusions by the BackdoorDiplomacy APT and the threat group orchestrating Operation Tainted Love indicate a level intention directed at supporting [China in its efforts to] shape policies and narratives aligned with its geostrategic ambitions, establishing itself as a pivotal and defining force in Africa&#8217;s digital evolution,&#8221; security researcher Tom Hegel said, TechRadar reported.</p>
<p>The post <a href="https://internationalfinance.com/technology/malware-luadream-targeting-telecom-across-three-continents/">Malware LuaDream targeting telecom across three continents</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/malware-luadream-targeting-telecom-across-three-continents/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>‘10 million banking app users at risk’</title>
		<link>https://internationalfinance.com/banking/10-million-banking-app-users-risk/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=10-million-banking-app-users-risk</link>
					<comments>https://internationalfinance.com/banking/10-million-banking-app-users-risk/#respond</comments>
		
		<dc:creator><![CDATA[Bharath Kumar]]></dc:creator>
		<pubDate>Mon, 11 Dec 2017 06:24:45 +0000</pubDate>
				<category><![CDATA[Banking]]></category>
		<category><![CDATA[attacks]]></category>
		<category><![CDATA[Certificate pinning]]></category>
		<category><![CDATA[Entersekt]]></category>
		<category><![CDATA[Gerhard Oosthuizen]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[MiTM]]></category>
		<category><![CDATA[University of Birmingham]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://www.internationalfinance.com/?p=12561</guid>

					<description><![CDATA[<p>Researchers at UK university find security flaw while testing samples of 400 mobile phone apps</p>
<p>The post <a href="https://internationalfinance.com/banking/10-million-banking-app-users-risk/">‘10 million banking app users at risk’</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Research conducted at the University of Birmingham has pointed out a security flaw that potentially puts around 10 million users of banking apps at risk. While performing security testing on samples of 400 mobile phone apps used in banking, researchers found a vulnerability that allows hackers to perform Man-In-the-Middle (MiTM) attacks.</p>
<p>An attacker connected to the same network as the victim, such as a public or corporate wifi, was able to carry out a MiTM attack, allowing them to see users’ sensitive data, like usernames and passwords or PIN codes.</p>
<p>This discovery will certainly be cause for alarm for many banks whose customers rely on these apps for safe and secure banking on the go.</p>
<p>Banks have a number of responsibilities to ensure that their customers are secure when using the bank’s mobile app:</p>
<p><strong>Regular updates and testing<br />
</strong>The bank has to ensure that its app security stack is up to date and aligned with the latest industry standards, typically by ensuring that it complies with the guidelines provided by industry best practice frameworks such as OWASP; and regularly update and test its security stack against this. Another approach is to disallow older applications from connecting to their systems.</p>
<p><strong>Security testing<br />
</strong>Banks should always aim to use external penetration testing (White-hat hackers) to externally validate applications have the correct security posture. Internal development teams are often under a lot of pressure to deliver before adequate quality assurance has been done, and they do not always have the latest skills or knowledge of new hacker exploits. Not only should the mobile be secured but also the API that it uses.</p>
<p><strong>Communications to customers about updates<br />
</strong>Banks should regularly release app updates to users via the relevant app stores and use their websites and other channels to educate users on the importance of always using the latest version of the app.</p>
<p><strong>Strategic partnerships to prioritise security<br />
</strong>In addition, banks can partner with vendors whose core business it is to look at security trends and work with them to ensure that the business unit responsible for security remains up-to-date with trends and has access to the latest digital fraud mitigation technologies.</p>
<p>From a user’s perspective, the top ways to minimise vulnerabilities include:</p>
<p>*   Always make sure to use the latest version of banking apps available.</p>
<p>*   Always aim to update mobile phones to the latest versions of the mobile operating system.</p>
<p>*   Avoid banking on public networks; this is usually a bad idea. If banking must be done in a public place, use the mobile data rather than public wifi network.</p>
<p>*   Be aware that several usernames and passwords have probably already been stolen in one or more mass data breaches. Aside from changing login credentials, press service providers to offer decent two-factor authentication (strong authentication) and use it as a second line of defence.</p>
<p><strong>Certificate pinning</strong></p>
<p>The University of Birmingham researchers pointed out that in the current case, certificate pinning – technology that would normally improve security – allowed standard security tests to fail in detecting a serious flaw that could let attackers decrypt, view and modify network traffic and take control of a victim&#8217;s online or mobile banking.</p>
<p>Certificate pinning is a technique used to ensure the identity of the website you are talking to by comparing the digital certificate presented against a set list of trusted certificates. Most browsers indicate that users are connecting to a legitimate website by showing a lock icon. This identification is provided by third-party authorities using digital certificates.</p>
<p>While the approach is generally sound, there have been cases where attackers were able to issue fake certificates and thus set up counterfeit bank websites that still register as legitimate in the browser.</p>
<p>Certificate pinning addresses this problem by disallowing the acceptance of any certificate that isn’t specifically listed by the bank as theirs.</p>
<p>Apps using certificate pinning do not allow a connection to be made to the ‘bank’ if it isn’t validated by a set list of trusted certificates. One could, of course, go further and create a certificate on the mobile side too, meaning that the bank will not connect to the app if it cannot recognise the certificate it presents. Connection between the client and the server is now mutually validated, meaning that both parties know exactly who they are talking to.</p>
<p>If a connection is validated and legitimated in this way, and it has been ensured that the integrity of the app is sound, the attack described by the researchers would not be feasible.</p>
<p><strong><em>Gerhard Oosthuizen is CIO at Entersekt</em></strong></p>
<p>The post <a href="https://internationalfinance.com/banking/10-million-banking-app-users-risk/">‘10 million banking app users at risk’</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/banking/10-million-banking-app-users-risk/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Industry is not ready for robot hack threat</title>
		<link>https://internationalfinance.com/technology/industry-not-ready-robot-hack-threat-2/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=industry-not-ready-robot-hack-threat-2</link>
					<comments>https://internationalfinance.com/technology/industry-not-ready-robot-hack-threat-2/#respond</comments>
		
		<dc:creator><![CDATA[Bharath Kumar]]></dc:creator>
		<pubDate>Wed, 20 Sep 2017 11:01:22 +0000</pubDate>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Amethyst Risk Management]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Principal Consultant]]></category>
		<category><![CDATA[Robots]]></category>
		<category><![CDATA[Ross Thomson]]></category>
		<guid isPermaLink="false">https://www.internationalfinance.com/?p=9774</guid>

					<description><![CDATA[<p>Lack of awareness is the reason most operators haven’t tackled the threat</p>
<p>The post <a href="https://internationalfinance.com/technology/industry-not-ready-robot-hack-threat-2/">Industry is not ready for robot hack threat</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Users of industrial robots from manufacturing to healthcare are unprepared for the real risk of a hacking attack. With the number of robots in smart factories worldwide now topping a million, lack of awareness is the reason most operators haven’t tackled the threat.</p>
<p>Many firms believe hackers only want personal or financial data, but there is a credible risk to industrial robots.</p>
<p>The risk is growing as robots, like other devices, are increasingly connected to wider networks and the internet. That gives hackers more ways in, and the consequences are potentially disastrous.</p>
<p>In one example, attackers locked up a robotic assembly plant in Mexico and demanded a ransom from the operators.</p>
<p>There is also the safety risk for human factory operatives if a robot were to be hacked.</p>
<p>Lack of awareness and preparedness for a cyber-attack extends to robot makers. In one experiment, researchers hacked a robotic arm and forced it to mis-perform, compelling its manufacturer to plug the security hole.</p>
<p><strong>Nightmare scenarios</strong><br />
The threat might come from disgruntled employees, criminals, recreational hackers or nation states.<br />
One kind of attack would inject faults or defects in the production process, or lock it down completely as in the Mexican incident, leading to loss of production and revenue. If defective products make it to the market, they can cause reputational damage, a potential advantage that could motivate an attack by unscrupulous competitors.</p>
<p>By manipulating safety protocols, hackers could cause the robot to injure human operators, or to damage itself or the factory environment. Alternatively, attackers might attempt to steal sensitive data from the machines themselves or the wider company network through remote access.</p>
<p><strong>How easy is it to hack a robot?</strong><br />
Ease of access to the software varies, making an inside job more likely in some scenarios. Firmware may be freely available online or retrievable from used robot CPUs, and some manufacturers allow programmers to access code in a simulation environment, creating a potential practice ground for would-be robot hackers.<br />
Hackers have other ways to infiltrate, other than via the internet. They may attack from within the factory, for example connecting to the robot directly through a USB port, or physically accessing its computer controller directly or via remote service.</p>
<p>Once they have penetrated the system, they can potentially alter the controller’s parameters, tamper with calibration programmes or production logic and alter the robot’s perceived state, for example to show it is idle when it is not, or its actual state causing loss of control.</p>
<p><strong>How big is the risk?</strong><br />
The scale of the threat could be enormous. It’s estimated there will be 1.3 million robots in factories worldwide by next year (2018) and that 12% of jobs will have been taken over by automated systems within a decade and a half. Robots are operating across almost all industrial sectors from car manufacturing to aviation and food processing.</p>
<p>The UK’s National Cyber Security Centre has highlighted hacking of robotic, unmanned and autonomous systems as a subject for attention, both by itself and by the intelligence organisation GCHQ.</p>
<p>A survey of robotic engineers by Italian academics found three quarters had never properly checked cybersecurity in their infrastructure, a third of robots were internet accessible and half of respondents didn’t see a realistic cyber security threat. To make matters worse, industrial robots often have weak authentication protocols and outdated software running on vulnerable operating systems Operators need to take the necessary precautions.</p>
<figure id="attachment_9776" aria-describedby="caption-attachment-9776" style="width: 227px" class="wp-caption alignleft"><a href="https://internationalfinance.com/wp-content/uploads/2017/09/Ross-Thomson-is-Principal-Consultant-at-Amethyst-Risk-Management.jpg"><img fetchpriority="high" decoding="async" class="size-medium wp-image-9776" src="https://www.internationalfinance.com/wp-content/uploads/2017/09/Ross-Thomson-is-Principal-Consultant-at-Amethyst-Risk-Management-227x300.jpg" alt="" width="227" height="300" srcset="https://internationalfinance.com/wp-content/uploads/2017/09/Ross-Thomson-is-Principal-Consultant-at-Amethyst-Risk-Management-227x300.jpg 227w, https://internationalfinance.com/wp-content/uploads/2017/09/Ross-Thomson-is-Principal-Consultant-at-Amethyst-Risk-Management.jpg 300w" sizes="(max-width: 227px) 100vw, 227px" /></a><figcaption id="caption-attachment-9776" class="wp-caption-text"><strong>Ross Thomson</strong> is Principal Consultant at Amethyst Risk Management</figcaption></figure>
<p>Operators of industrial robots must conduct a professional review of cybersecurity risks, have an incident response plan in place in case of a security breach and ensure that software is regularly updated, especially with security patches. The security review should look at what data robots hold and how they are potentially connected to sensitive data elsewhere on the network.</p>
<p>Considering the risk to production, people and facilities, it must be taken seriously from board level to operational level. An internet-connected robot should be treated with the same security precautions as any computer on the network, including setting long, complex passwords rather than relying on manufacturers’ default. There is a temptation to neglect updates because they may cause production downtime, but it needs to be given a higher priority.</p>
<p>Operators must make security a key factor when sourcing new industrial robots, selecting a manufacturer that shows commitment to the issue and provides frequent software updates with security patches.</p>
<p>Limiting who has access to robots and segmenting machines from networks where possible can also reduce risk.</p>
<p>Ultimately, one of the most effective precautions is also one of the most prosaic, and may comfort those who fear their jobs will be stolen by robots. It’s hard to imagine a time when we dare leave robots to get on with it, so until and unless that day comes, we need humans to keep watch on robots at work.</p>
<p><em><strong>Ross Thomson is Principal Consultant at Amethyst Risk Management</strong></em></p>
<p>The post <a href="https://internationalfinance.com/technology/industry-not-ready-robot-hack-threat-2/">Industry is not ready for robot hack threat</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/industry-not-ready-robot-hack-threat-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Morgan &#038; Morgan files lawsuit on behalf of millions of Equifax data breach victims</title>
		<link>https://internationalfinance.com/banking/morgan-morgan-files-lawsuit-behalf-millions-equifax-data-breach-victims/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=morgan-morgan-files-lawsuit-behalf-millions-equifax-data-breach-victims</link>
					<comments>https://internationalfinance.com/banking/morgan-morgan-files-lawsuit-behalf-millions-equifax-data-breach-victims/#respond</comments>
		
		<dc:creator><![CDATA[Bharath Kumar]]></dc:creator>
		<pubDate>Sat, 09 Sep 2017 13:35:55 +0000</pubDate>
				<category><![CDATA[Banking]]></category>
		<category><![CDATA[credit card fraud]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[equifax]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Morgan & Morgan]]></category>
		<guid isPermaLink="false">https://www.internationalfinance.com/?p=9271</guid>

					<description><![CDATA[<p>Equifax also admitted that credit card numbers for approximately 209,000 US consumers were accessed.</p>
<p>The post <a href="https://internationalfinance.com/banking/morgan-morgan-files-lawsuit-behalf-millions-equifax-data-breach-victims/">Morgan &#038; Morgan files lawsuit on behalf of millions of Equifax data breach victims</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Attorney John Yanchunis of Morgan &amp; Morgan filed a class action lawsuit yesterday against Equifax, one of the three largest credit reporting agencies in the US, for the data breach that potentially compromised 143 million consumer records. The complaint was filed in the Northern District of Georgia.</p>
<p>Equifax announced on September 7, 2017 that unauthorized users accessed the names, Social Security numbers, birth dates, addresses and, in some instances, driver&#8217;s license numbers of consumers from mid-may through July 2017. Equifax also admitted that credit card numbers for approximately 209,000 US consumers were accessed.</p>
<p>Lead plaintiffs Jamie McGonnigal and Brian Spector accuse Equifax of failing to properly secure and safeguard consumers&#8217; personally identifiable information which resulted in criminals obtaining their personal and financial information.</p>
<p>The complaint alleges that not only could Equifax have prevented this data breach—especially considering the warnings raised by the recent data breach of their competitor Experian—but that once discovered, they failed to notify consumers in a timely manner. Equifax acknowledged they discovered a breach had occurred on July 29, 2017, but they failed to announce it to the public until more than a month later.</p>
<p>As a result of the company&#8217;s negligence and failure to properly safeguard consumers&#8217; records, Mr. McGonnigal and Mr. Spector allege their personal and financial information was stolen and they incurred out-of-pocket costs for identity theft protection and unauthorized use of their financial accounts. In addition, they allege the likelihood of impending injuries in the future since criminals have access to their personal and financial information.</p>
<p>Leading Data Breach Attorney Says Equifax Breach is &#8220;Shocking&#8221;</p>
<p>Class action members are represented by one of the leading data breach attorneys in the country: John Yanchunis. He currently serves as lead counsel in the Yahoo data breach case, one of the largest class actions in history. Previously, he represented consumers in the Home Depot Inc. and Target Corp. data breach cases which settled for $13 million and $10 million respectively.</p>
<p>He has litigated some of the largest data breaches in history, yet when asked about the Equifax breach, John Yanchunis described it as &#8220;shocking.&#8221;</p>
<p>&#8220;Equifax contains one of the largest databases of consumer information and they should have been better prepared for any attempt to penetrate its systems,&#8221; he said.</p>
<p>Three Equifax Managers Sold Stock Prior to Data Breach Announcement</p>
<p>Coinciding with news of the data breach is information that three managers sold their stock in Equifax just prior to the announcement. After learning of these events, Attorney John Yanchunis said the data breach may justify punitive damages.</p>
<p>&#8220;Equifax has acknowledged that it discovered the breach on July 29th. What it hasn&#8217;t explained is why it waited so long to make an announcement that the breach had occurred,&#8221; he stated.</p>
<p>&#8220;The profiteering before the company&#8217;s announcement is astounding.&#8221;</p>
<p>Plaintiffs seek statutory damages under the Fair Credit Reporting Act (&#8220;FCRA&#8221;) and state consumer protection statutes, reimbursement of out-of-pocket losses and other compensatory damages, credit monitoring services beyond Equifax&#8217;s current two-year offer, and an order requiring Equifax to improve their data security measures.</p>
<p>The post <a href="https://internationalfinance.com/banking/morgan-morgan-files-lawsuit-behalf-millions-equifax-data-breach-victims/">Morgan &#038; Morgan files lawsuit on behalf of millions of Equifax data breach victims</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/banking/morgan-morgan-files-lawsuit-behalf-millions-equifax-data-breach-victims/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
