Wednesday, February 27, 2019

Over $ 12 Billion Investment Likely at ASEAN Summit in Bengaluru




The three-day ASEAN Chambers of Commerce and Industry Business Meet opened in Bengaluru on Monday has already lined up investment proposals worth more than US $12 billion in various sectors including infrastructure, aerospace, defence, artificial intelligence, machine intelligence and robotics.

Sudhakar S Shetty, president of Federation of Karnataka Chambers of Commerce and Industry (FKCCI), which is hosting the conference for the first time in the south, said, “We have received a number of investment proposals from ASEAN, ASEAN Plus and Special Invitee countries. Two major ones on our table are: from a business council in the United States and the Indian subsidiary of a prominent Chinese construction company. The details will be announced at the conference.”

He said will sign memoranda of understanding with the Government of Karnataka during the ASEAN summit, and follow them up with letters of interest from the investors in specific sectors.

The conference was inaugurated on Monday by Governor VajubhaiVala at the banquet hall, VidhanaSoudha, in the presence of distinguished guests including Union ministers Suresh Prabhu and Sadananda Gowda, Chief Minister HD Kumaraswamy and Deputy Chief Minister G Parameshwara.

Shetty said the next two days of the conference, February 26 and 27, is being held at Lalit Ashok, which include panel discussions on 18 different sectors, a session on ‘Look East, Act West’ with the ambassadors from ASEAN countries and a special event with a focus on investment opportunities in Karnataka.

Over 1,200 delegates, including about 300 from abroad, have confirmed their participation in the business meet. Around 30 foreign delegations, including ministers and diplomats, like Shamsul Iskandar, deputy minister of primary industries, Malaysia, Pham SanhChau, ambassador of Vietnam, Savankhone Razmountry, vice minister, information & tourism, Laos, Paduka Sidek Ali, high commissioner of Brunei, Milan Hovorka, ambassador of Czech Republic are among those attending the conference.

The FKCCI President said large business delegations from Malaysia, Singapore, Philippines, Indonesia, Thailand, Myanmar, Laos, the US and the UAE. Indian billionaire businessman BR Shetty, who is settled in the Emirates, is leading a team of 25 business leaders.

One of the highlights of the international conference is that both the days will begin with one-hour yoga and meditation session led by the Art of Living team and one more hour of cultural programme.

The founder of Art of Living, Sri Sri Ravi Shankar made a special address on Day 2.

Many interesting panel sessions have been lined up on artificial intelligence, innovation in healthcare, renewable energy, opportunities for SMEs in aerospace and defence, global trends in fin-tech, digital transformation in the supply chain and the future of mass transportation, besides delegation-level B2B, B2G and B2C meetings.

Union Defence Minister Nirmala Sitaraman will be the chief guest at the valedictory on Feb 27, along with state ministers G Parameshwara, KJ George, UT Khader and Shobha Karandlaje, MP.

A large exhibition has been planned, with around 150 exhibitors participating, to explore new business avenues and look for outsourcing collaboration with other ASEAN countries.

Accenture Launches Applied Intelligence Platform to Help Clients Use AI Without Need for Deep Data Science Expertise


Accenture has launched its Applied Intelligence Platform today at Mobile World Congress, Barcelona, to make it easier for clients to transform the enterprise through artificial intelligence (AI). The new platform allows organizations to apply pre-configured self-learning industry solutions, as well as develop new solutions, without the need for deep data science expertise – which is becoming an increasingly scarce resource.

Applied Intelligence Platform builds on the proven Accenture Insight Platform through which Accenture has been offering analytics applications using machine learning and deep learning to clients. It will integrate these capabilities with edge analytics and Internet of Things (IoT) services, as well as access to more than 350 data sources – all made accessible via an on-demand, low-code platform. As a result, clients are less dependent on specific technologies as the platform leverages solutions and tools from leading technology providers, to enable creation of the proper solutions across industries and functions.

“The Applied Intelligence Platform enables AI-powered transformation at scale as clients will be able to systematically embed AI across their operations – from the edge right through to the cloud,” said Mike Sutcliff, group chief executive, Accenture Digital. “Thanks to the platform, the power to leverage AI to drive unprecedented new growth and efficiencies and unlock new insights, business models and experiences is within reach of every organization.”

Applied Intelligence Platform can deliver numerous benefits to clients including:

Scaling impact not investment. The platforms pre-configured services won’t require clients to build and maintain costly custom infrastructure and services from scratch.

Increased speed and agility. The platform uses open, standards-based platform services, APIs, and tools, which clients can use to rapidly build and move from prototype to production.

Chance for new growth opportunities. The Applied Intelligence Platform ecosystem fosters intelligent applications that run models on continuously updated enterprise and device data, which can drive network effects and new business models.

Edge analytics and IoT integration. The platform allows businesses to run machine learning and deep learning applications at the edge, and also better source data from IoT devices to power real-time applications and automated processes – enhancing efficiency and providing more data to fuel operational insights.

Enhanced security. Recommended, end-to-end security and privacy services are enhanced through the localization of sensitive data processing at the edge.

Accenture, with its team of industry specialists and more than 3,000 data scientists, has already developed a range of use cases and more than 40 intelligent industry solutions for Applied Intelligence Platform to help bridge the gap between information technology and operational technology. Use cases include asset and fleet management solutions expected to unlock efficiencies across manufacturing, transportation & logistics and energy. Examples from the platform’s suite of intelligent industry solutions include:

Remote monitoring – a global asset monitoring solution based on device data from installed industrial equipment. It is designed to reduce warranty repair costs through diagnostics to calculate mean-time before failure, as well as enhance equipment knowledge and supply chain efficiencies for spare parts.

Fleet management – an IoT-enabled telematics solution to improve operational efficiencies and reduce cost with embedded analytics and AI. It provides fleet operators better insights including vehicle tracking, diagnostics, critical event alerts, driver behavior monitoring, reporting, and route management.

“Data science to date has largely been decoupled from operations and application development, and models are often created and deployed only to be orphaned as there is a limited feedback on their effectiveness,” said Athina Kanioura, chief analytics officer and global lead of Accenture Applied Intelligence. “Our new Applied Intelligence Platform provides non-data scientist with the tools and access to the data they need to rapidly assemble and apply applications while the platform ensures the effectiveness of the underlying advanced analytics.”

PerkFinance Launches App in Indian languages to Enable Blue-Collar Workers Access Affordable Loans


India’s leading salary-linked personal loan company, PerkFinance, has launched its app in four Indian languages. PerkFinance enables employees of partnering companies to apply for a loan easily. The app is now available in Hindi, Kannada, Tamil, and Telugu and is primarily targeted at blue-collar workers.

Blue-collar workers, who are traditionally not part of the formal banking ecosystem, find it hard to obtain loans from mainstream financial institutions due to the complex documentation involved and their lack of credit history. They also form a large part of the Indian language internet users who are estimated to account for 75% of India’s total internet user base. A study by KPMG and Google found that the Indian language internet user base is growing at a CAGR of 18% and will reach 536 million by 2021.

“We believe that having our app in multiple Indian languages makes our financial products accessible to a larger section of the Indian population including blue-collar workers. Our aim is to make affordable loans available to anyone who has a smartphone. We have partnered with 50+ companies, which together employ more than two lakh people. With the launch of our multilingual app we hope to scale our reach to 15 lakh people by the end of the second quarter of 2019,” said Vivek Kandkur, Co-founder, PerkFinance. 

With easy access to loans, blue-collar workers will no longer need to turn to informal moneylenders who often charge exorbitant interest rates. Since PerkFinance uses the employee-employer relationship for risk assessment, it is able to offer better interest rates and faster processing times.

PerkFinance partners with companies to provide financial wellbeing products like affordable personal loans to their employees at no cost and no risk to the company.  Its financial products improve employee well-being, thereby boosting productivity and reducing attrition. The loans are reported to the credit bureau and improve the borrowers’ credit score. Borrowers can get approval for higher loan amounts and longer tenures at reduced rates of interest, with improved credit. 

About 65% People in South India not Prepared for Home Threats says Godrej Locks Report

Around 65% people in South India are not prepared to handle home safety threats such as burglaries, robberies, among others, highlights Godrej LocksS ‘Har Ghar Surakshit 2018 Report: India’s Safety Paradox – Home Safety Vs Digital Safety’, conducted by Research Now. While the Southern region seems unprepared for home safety threats, 57% people are also not ready to upgrade to high-tech safety solutions for homes. This is a startling fact, as Southern India is perceived to be a step ahead than other regions in adoption of technology.

While 82% people in South India are aware of home safety technologies such as digital locks, they have not felt the strong need of adopting it for their homes. South region is swift in adopting technologies, for convenience, comfort and productivity.  In this tech savvy region, 25% change their computer passwords and 19% change banking PIN’s every 2-5 months. Over 51% use fingerprint sensor on smart phones. Most of the safety options that people in South India use, like the fingerprint and PIN, are also available in home locking solutions, but they lag behind in embracing such technologies for home safety.

Commenting on Godrej LocksS ‘Har Ghar Surakshit 2018 Report’ and its findings, Mr. Shyam Motwani, Executive Vice-President and Business Head, Godrej Locking Solutions and Systems, said, “As a brand that is synonymous with trust and safety, Godrej LocksS purpose is to make people aware of the importance of home safety. Har Ghar Surakshit report suggests that Indians, although feel safe at home, are unprepared to deal with home safety issues. Moreover, home safety has become secondary in this digital age. We want to encourage people to prioritize home safety just like how they secure their digital assets. In line with this vision, #HarGharSurakshit campaign will promote the larger cause of enhancing safety across homes of people in urban and rural India.”

‘Har Ghar Surakshit 2018 Report’ is released as part of #HarGharSurakshit, a nationwide awareness campaign by Godrej LocksS, to promote home safety across Indian homes.  The report states 64% Indians are not equipped to handle home safety threats. Surprisingly, 70% of all thefts in India are home thefts while only 30% are digital thefts. This emphasizes that at a national level, home safety requires equal or more attention that is enjoyed by digital safety as 61% people don’t want to upgrade to high tech safety for homes. While speaking of the South, home safety needs greater attention as more than half of the population in the region are unprepared to deal with home safety threats. The report presents this interesting behavior pattern of people from across India towards home and digital safety.

Indian homes have a lot to protect like important documents and credentials, money, jewellery, and other valuables. However, Indians seem to be lagging behind in upgrading even the primary source of protection of their homes i.e. locks as only 40% Indians change their locks in 2-3 years and 20% have never changed it.

Indians enhance their digital safety actively due to regular updates of digital risks through information across platforms. They also receive reminders to change their passwords or upgrade their digital security level to the next advanced versions. Similarly, people are willing to enhance their home safety if they are made more aware and provided with information, which will bring about a behavioural change amongst citizens towards the perception of home safety. Through #HarGharSurakshit campaign, Godrej LocksS intends to bridge this awareness gap. The company has pledged an investment of INR 100 crore over the next 3 years towards #HarGharSurakshit and will be undertaking multiple initiatives through various platforms across India.

Grab Recognized as a Top Innovative Company in the World

Grab, the leading super app in Southeast Asia with a global R&D centre in Bangalore, has been ranked as a top transportation company and second overall on Fast Company’s “Most Innovative Companies” list for 2019. The list honors the businesses making the most profound impact on both industry and culture around the world. Grab in Bangalore currently employs almost 200 and has plans to double this workforce in the next 12-18 months. In giving Grab the No 2 rank, Fast Company described it as a “transactional super app” that brings together various lifestyle services that connect hundreds of millions of customers to local businesses in South East Asia.

Grab’s Bangalore based employees are an integral part of the company’s most innovative and exciting projects across the region and play a critical role in developing the company’s next generation technologies. “We are proud to be recognized as a top innovator by Fast Company. These are exciting times for Grab employees in Bangalore who are currently working on some of our most innovative and cutting-edge initiatives in the region” said Vikas Agrawal, Chief Technology Officer and Head of Engineering, Grab Financial Group. “Our teams here are focused on using state of the art technologies to solve the biggest everyday challenges for millions of people across the South-east Asian region - whether its safe and affordable transport or financial inclusion and access to the cashless economy. It is a huge opportunity and responsibility, and one that we take seriously” added Agrawal.

Grab set up its Bangalore R&D centre in 2017 and today employs almost 200 engineers. The company has grown its India workforce by 300% in the past year and has further plans to ramp-up its hiring in the next 12-18 months.

Grab is the leading provider of ride-hailing, fintech and marketplace services in Southeast Asia, operating in 336 cities across 8 countries, supported by 7 global R&D centers located in Singapore, Beijing, Bangalore, Seattle, Jakarta, Ho Chi Minh City and Kuala Lumpur. From advancing its leadership in transportation technology, to expanding its delivery, digital payments and financial services offerings, to launching an open platform “GrabPlatform” to support other local developers and services, Grab is providing solutions for Southeast Asians’ everyday needs in one convenient app. Leading the digitization of Southeast Asia’s economy, to date, Grab has served over 3 billion rides, the Grab app has been downloaded over 138 million times, and the Grab platform empowers over 9 million micro-entrepreneurs. 

McAfee Mobile Threat Report Unveils 550% Increase in Consumer Security Risks in Second Half of 2018

Today McAfee announced its extended relationships with Samsung and Turk Telekom to further protect what matters by expanding its presence in the consumer cybersecurity industry. McAfee is committed to expanding these partnerships to champion security that is built-in across devices and networks, as it is crucial that the entire ecosystem works together to protect consumers from attacks. McAfee also unveiled its latest Mobile Threat Report, reporting backdoors, malicious cryptomining, fake apps and banking Trojans all increased substantially in 2018, propelled by cybercriminals quest for illicit profits. Most notably, the number of fake app detections by McAfee’s Global Threat Intelligence increased from around 10,000 in June 2018 to nearly 65,000 in December 2018.

According to McAfee Labs 2019 predictions, cybercriminals are looking for ways to use trusted devices to gain control of Internet of Things (IoT) devices via password cracking and exploiting other vulnerabilities, such as through the exploitation via voice assistants. With over 25 million voice assistants in use across the world, these devices are often connected to other things in the home- controlling lights, thermostats, door locks and more. More devices mean greater connectivity and convenience for their owners, but connectivity also means more opportunities for malicious deeds.

“Most IoT devices are being compromised by exploiting rudimentary vulnerabilities, such as easily guessable passwords and insecure default settings” said Raj Samani, McAfee fellow and chief scientist at McAfee. “From building botnets, to stealing banking credentials, perpetrating click fraud, or threatening reputation damage unless a ransom is paid, money is the ultimate goal for criminals.”

“The rapid growth and broad access to connected IoT devices push us to deliver innovations with our partners that go beyond traditional AV, and we are creating solutions that address real world digital security challenges,” said Gary Davis, chief consumer security evangelist at McAfee. “From securing the gaming experience to safeguarding the connected home to protecting against cryptojacking, we are enabling our customers to protect what matters most to them.”

McAfee and Samsung Extend Partnership to Secure Galaxy S10 Smartphones

For the fifth year, Samsung and McAfee have worked to protect what matters for consumers around the world. McAfee extended its long-standing partnership with Samsung to safeguard consumers from cybersecurity threats on Samsung Galaxy S10 smartphones which come pre-installed with anti-malware protection powered by McAfee VirusScan. It will also support Samsung Secure Wi-Fi service that McAfee provided backend infrastructure to protect consumers against risky Wi-Fi. In addition to mobile, the partnership expands to better protect Samsung smart TVs, as well as PCs and laptops.

Türk Telekom and McAfee Offer Customers Digital Parenting Solution to Protect Families Online

McAfee strengthened its partnership with Türk Telekom, the leading information and communication technologies company in Turkey, to provide a security solution to help parents protect their family’s digital lives. Powered by McAfee’s Safe Family, fixed and mobile broadband customers will have the option to benefit from robust parental controls that will help provide parents with the confidence they need to better manage their children’s online experience.

“As the threat landscape continues to evolve in both speed and sophistication, we understand that consumers can feel at a loss when navigating the online security space. That’s why we are working diligently with our partners to create solutions for more than half a billion customers to address real world digital security challenges. From safeguarding the connected home to protecting against contemporary attacks such as cryptojacking, we’re enabling our customers to protect what matters to them by delivering the peace of mind needed to connect with confidence. Our partners share our belief that security must be built in from the start and prioritized to canvass all devices and networks,” said Terry Hicks, McAfee’s executive vice president, consumer business group.

McAfee’s Mobile Threat Report 2019

McAfee’s Mobile Threat Report 2019 reveals that while 2018 was the year of mobile malware, 2019 is shaping up to be the year of everywhere malware. Cybercriminals are looking for ways to maximize their income, and shift tactics in response to changes in the market. As the value of cryptocurrencies drops, they shift away from cryptomining. App stores are getting better at finding and deleting malicious apps, so cybercriminals bypass the stores and go directly to consumers. As the mobile platform remains a key target for ransomware developers, identity thieves and nation states, it is imperative to maintain diligence when considering which apps to install or following any link.

The McAfee Mobile Threat Report 2019 highlights the following mobile trends:

Increase in popularity of fake apps – Fake apps are and will be one of the most effective methods to trick users into installing suspicious and malicious applications on Android devices. With more than 200 million players globally, Fortnite has taken the world by storm and over 60 million people have downloaded the app, leading to several fake apps pretending to be various versions of the game.

Letting them inside with mobile backdoors – With smartphones connected to and controlling multiple items in people’s homes, cybercriminals are looking for new ways to trick users into letting them inside. While not new, in 2018 we saw the impact that TimpDoor, becoming the leading mobile backdoor family by more than 2x and showing how phishing over SMS is still effective to trick users into installing unknown applications.

Continued financial threats spike globally - A global spike in banking Trojans on mobile devices has continued, targeting account holders of large multinational and small regional banks. Cybercriminals continue to innovate in different distribution vectors for this threat, from phishing SMS messages to applications with real functionality that gets its malicious payload to bypass security checks on app marketplaces.

Mobile cryptomining – Cyber criminals are looking to find ways to add value to their digital wallets without the cost of doing their own mining. The popularity of Android-based devices not only makes them a prime target, but the latest cryptomining technique can jump from phone or tablet to smart TV to infect your entire environment.
Spyware attacks spike on mobile. From Operation RedDawn, targeting North Korean defectors, and FoulGoal, possibly targeting Israeli FIFA World Cup fans, mobile devices remain an attractive target of nation state actors to gather intelligence and track victims.

Increased risk of IoT attacks at home – The increasing proliferation of IoT devices are bringing conveniences that we could have never imagined, but they are also increasing the number of possible points of attack in our homes.

Prevent Data Leaks Caused by Web Applications - eScan


Security Researcher Elliot Alderson has discovered a huge leak of Aadhaar numbers from Indane's website as well as app. The leak has not just put Aadhaar number of 6.7 million people at stake but also their personal details.

Data breaches like these do not necessarily translate into a complicated attack by hackers, they may be simple attacks attributed to configuration errors or unpatched systems or coding error. However, when the same issues are discovered by Security Researchers, who put in efforts to find a way into the system and following the processes laid down for responsible disclosure, then these are termed as bugs / vulnerabilities.

Organizations lately have been hiring researchers to find vulnerabilities in their networks / systems with the objective to ensure that their systems are protected and decrease the footprint of the attack surface that may otherwise allow easy access to the hackers.

Existence of vulnerabilities in Web Applications, pose a greater risk to the integrity of the entire system, while mobility being the new mantra, we are embracing web-application and are moving towards cloud based systems at a much greater pace than ever before. Web-Applications viz, ERP, CRM, Emails are a conduit to the data which is essential for the functioning of an organization and unlike their stand-alone / networked counterparts, have a much larger attack surface.

Search engine caching paradigm
According to eScan, there have been instances when confidential datasets have been cached by Google, which otherwise shouldn't have been left exposed for general public to view and for hackers to gain foothold into the system.

Caching of datasets by search engine is an excellent example to the non-existence / therein lack of Authentication and Access Management, which is an inherent requirement when data is being served. The recent leak which was exposed by the French Researcher "Elliot Alderson" was cached by Google's Search Engine, furthermore, this cached dataset was devoid of authentication would have allowed anyone with scripting knowledge to automate the data-mining tasks on the actual urls. Presently, as per our observation, the erring URIs has been taken down by Indane.

Could this have been averted?
Dynamic Application Security Testing facilitates organizations to test their web-based applications / web-sites for existence of vulnerabilities viz. XSS, CSRF, SQLi, LFI / RFI, furthermore, pages which are supposed to be accessible after authentication are also tested for vulnerabilities which may allow users to gain access to the other resources served by the application.

In this case Unauthenticated API Endpoints were solely responsible for allowing anyone with the knowledge of using Google Search Engine to gain access to the datasets, which otherwise should have been protected.

DAST Solutions also facilitate organizations to discover such vulnerable end-points not just by crawling the web-application by also by querying and analyzing the results of the search engines.

The need of the hour for all organizations which handle sensitive data should conduct regular DAST audits of their web-applications.

Total Pageviews