Connect with us

Technology

Tenable Research Uncovers Thousands of Vulnerable Cyber Assets Amongst Southeast Asia’s Financial Sector

Published

on

Over 26,500 internet-facing assets susceptible to potential exploitation

SINGAPORE, Aug. 29, 2024 /PRNewswire/ — New research conducted by Tenable®, Inc., the exposure management company, has uncovered more than 26,500 potential internet-facing assets among Southeast Asia’s top banking, financial services and insurance (BFSI) companies by market capitalisation across Indonesia, Malaysia, the Philippines, Singapore, Thailand and Vietnam. 

On July 15, 2024, Tenable examined the external attack surface of over 90 BFSI organisations with the largest market capitalisations across the region. The findings revealed that the average organisation possesses nearly 300 internet-facing assets susceptible to potential exploitation, resulting in a total of more than 26,500 assets across the study group.

Singapore ranked the highest among the six countries assessed, with over 11,000 internet-facing assets identified across its top 16 BFSI companies. Over 6,000 of those assets are hosted in the United States.  Next on the list is Thailand with over 5000 assets. The distribution of internet-accessible assets underscores the need for cybersecurity strategies that adapt to the rapidly evolving digital landscape.

Country

Number of internet-facing assets amongst top 90 BFSI
companies by market capitalisation

1. Singapore

11,000

2. Thailand

5,000

3. Indonesia

4,600

4. Malaysia

4,200

5. Vietnam

3,600

6. Philippines

2,600

“The results of our study reveal that many financial institutions are struggling to close the priority security gaps that put them at risk. Effective exposure management is key to closing these gaps,” said Nigel Ng, Senior Vice President, Tenable APJ. “By identifying and securing vulnerable assets before they can be exploited, organisations can better protect themselves against the growing tide of cyberattacks.”

Cyber Hygiene Gaps 
The Tenable study revealed many potential vulnerabilities and exposed several cyber hygiene issues among the study group, including outdated software, weak encryption, and misconfigurations. These vulnerabilities provide cybercriminals with easily exploitable potential entry points, posing potential risk to the integrity and security of financial data.

Weak SSL/TLS encryption
A notable finding is that among the total assets, organisations had nearly 2,500 still supporting TLS 1.0—a 25-year old security protocol introduced in 1999 and disabled by Microsoft in September 2022. This highlights the significant challenge organisations with extensive internet footprints face in identifying and updating outdated technologies.

Misconfiguration increases external exposure
Another concerning discovery was that over 4,000 assets, originally intended for internal use, were inadvertently exposed and are now accessible externally. Failing to secure these internal assets poses a significant risk to organisations, as it creates an opportunity for malicious actors to target sensitive information and critical systems.

Lack of encryption
There were over 900 assets with unencrypted final URLs, which can present a security weakness. When URLs are unencrypted, the data transmitted between the user’s browser and the server is not protected by encryption, making it vulnerable to interception, eavesdropping, and manipulation by malicious actors. This lack of encryption can lead to the exposure of sensitive information, such as login credentials, personal data, or payment details, and can compromise the integrity of the communication.

API vulnerabilities amplify risk
The identification of over 2,000 API v3 out of the total number of assets among organisations’ digital infrastructure poses a substantial risk to their security and operational integrity.

APIs serve as crucial connectors between software applications, facilitating seamless data exchange. However, inadequate authentication, insufficient input validation, weak access controls, and vulnerabilities in dependencies within API v3 implementations create a vulnerable attack surface.

Malicious actors can exploit such weaknesses to gain unauthorised access, compromise data integrity, and launch devastating cyber attacks.

“The cybersecurity landscape is evolving faster than ever, and financial institutions must evolve with it, so they can know where they are exposed and take action to close critical risk” Ng added. “By prioritising exposure management, these organisations can better protect their digital assets, safeguard customer trust, and ensure the resilience of their operations in an increasingly hostile digital environment.”

About Tenable
Tenable® is the exposure management company, exposing and closing the cybersecurity gaps that erode business value, reputation and trust. The company’s AI-powered exposure management platform radically unifies security visibility, insight and action across the attack surface, equipping modern organizations to protect against attacks from IT infrastructure to cloud environments to critical infrastructure and everywhere in between. By protecting enterprises from security exposure, Tenable reduces business risk for more than 44,000 customers around the globe. Learn more at tenable.com.

Notes to Editors:

Tenable examined the top 12-16 BFSI companies discoverable based on market cap.In the context of this alert:An asset is a domain name, subdomain, or IP addresses and/or combination thereof of a device connected to the Internet or internal network. An asset may include, but not limited to web servers, name servers, IoT devices, network printers, etc. Example: foo.tld, bar.foo.tld, x.x.x.xs.The Attack Surface is from the network perspective of an adversary, the complete asset inventory of an organisation including all actively listening services (open ports) on each asset.

 

View original content:https://www.prnewswire.com/apac/news-releases/tenable-research-uncovers-thousands-of-vulnerable-cyber-assets-amongst-southeast-asias-financial-sector-302232805.html

SOURCE Tenable

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Fitterfly Healthtech and Ascensia Diabetes Care Launch a 21-Day Diabetes Management Program on World Diabetes Day

Published

on

By

MUMBAI, India, Nov. 14, 2024 /PRNewswire/ — This World Diabetes Day, on 14th November, Fitterfly Healthtech and Ascensia Diabetes Care are joining hands to launch a complimentary 21-day Diabetes Management Program for Ascensia’s glucometer users. This initiative aims to make diabetes care simpler and more effective for people, offering them personalised support, expert guidance, and easy-to-use tools.

For many, managing diabetes can feel overwhelming. Even with the right tools, knowing where to start can be challenging and confusing. That’s why this 21-day program is designed to help users get started on a wellness journey and build lasting habits, as 21 days is the time it takes to set a habit. By simply scanning a QR code on the warranty page of Ascensia’s glucometer, users can join the Fitterfly program and access diet plans, a 24/7 AI wellness coach, group sessions with diabetes experts, glucose tracking and insights, food diary tracking, assessments, and more. With each step, this structured support brings confidence and clarity, helping users feel truly in control of their health.

Albertraj Balraj, Country Head and Director at Ascensia Diabetes Care India Pvt Ltd., commented, “Glucometers and Self-Monitoring Blood Glucose (SMBG) play an important role in effective blood sugar monitoring. Through this partnership, we aim to offer people a 360° solution by combining our world-class glucometer with Fitterfly’s advanced tools and expert support to make diabetes management truly simple for everyone. We want people to approach diabetes care with confidence and without fear.”

Dr Arbinder Singal, CEO & co-founder of Fitterfly Healthtech, added, “Lifestyle management remains the first line of therapy for type 2 diabetes. Our collaboration with Ascensia makes it easy for people to take control of their health and get started on a journey to lower their blood sugar sustainably. By linking their glucometer to our Fitterfly app, users can track their readings, gain insights, and learn to manage diabetes with ease.”

This partnership is a true example of two brands joining forces to reduce the diabetes burden in the country.

To know more about Fitterfly’s Diabetes Programs, visit Fitterfly.

About Fitterfly

Fitterfly is a leading Indian healthtech company specialising in digital therapeutic programs for managing diabetes, obesity, and heart disease. Co-founded in 2016 by Dr Arbinder Singal and Shailesh Gupta, the Mumbai-based company employs over 200 professionals, including doctors, nutritionists, fitness experts, and technologists. Fitterfly aims to improve metabolic health by focusing on conditions like prediabetes, diabetes, obesity, hypertension, and heart disease. Fitterfly has significantly contributed to health technology research, publishing over 80 papers and winning numerous awards, including the Economic Times Healthtech Startup of the Year 2022. Fitterfly has raised $16.6 million in funding, with its last round in June 2022 led by Amazon with support from Fireside Ventures, 9 Unicorns, and Venture Catalysts.

About Ascensia Diabetes Care

Ascensia Diabetes Care is a global company focused entirely on helping people with diabetes. Our mission is to empower those living with diabetes through innovative solutions that simplify and improve their lives. We are home to the world-renowned CONTOUR® portfolio of blood glucose monitoring systems and the exclusive global distribution partner for the Eversense® Continuous Glucose Monitoring Systems from Senseonics. Ascensia is a member of PHC Group and was established in 2016 through the acquisition of Bayer Diabetes Care by PHC Holdings Corporation. Ascensia products are sold in more than 100 countries. Ascensia has around 1,400 employees and operations in 29 countries. For further information, please visit the Ascensia Diabetes Care website at www.ascensia.com.

Photo: https://mma.prnewswire.com/media/2553921/Fitterfly_Ascensia_Launch.jpg

View original content to download multimedia:https://www.prnewswire.com/in/news-releases/fitterfly-healthtech-and-ascensia-diabetes-care-launch-a-21-day-diabetes-management-program-on-world-diabetes-day-302303822.html

Continue Reading

Technology

Eco-documentary A Chorus of Frogs officially launched

Published

on

By

NANJING, China, Nov. 14, 2024 /PRNewswire/ — Recently, the ecological documentary A Chorus of Frogs produced by Nanjing Newspaper Media Group was officially launched. The film told the story of Wang Ningjing, a post-95s Nanjing girl, who returned to the countryside to find the Chinese immaculate treefrog and shoot a documentary.

https://youtu.be/V8aI9PIFalA?si=Mcc6iP5FeAk3Y8OF

Wang Ningjing, the post-95s generation from Nanjing, is currently studying wildlife filmmaking in the UK. Professor Borzée Amaël from Nanjing Forestry University, who grew up in Madagascar, has been researching treefrogs over ten years.

Unlike most girls who like fairy tales, Wang has been passionate about creature and nature since childhood. Nanjing Hongshan Forest Zoo, not far from her home, was a place she often visited as a child.

“I see one. Is that it?……That one on the wheat. So beautiful!” The species’ breeding season is May and June. During this period, Professor Amaël conducted regular field surveys to locate populations of the treefrog, known for its unique calls that can be heard from a distance. The documentary began with Wang listening to the calls of the treefrog in the fields at night.

A Chorus of Frogs is positioned as an ecological and humanistic documentary. By following Wang Ningjing and Amer to explore the traces of the Chinese immaculate treefrog, it vividly tells the story of people and frogs.

Chinese path to modernization has the distinctive features of respecting nature, following its laws and protect it as well as promoting harmony between humans and nature. The harmonious coexistence between human and the environment is important not only to China but to the world as well.

Where does the Chinese immaculate treefrog go? I believe everyone will find their own answer after watching.

Nanjing Newspaper Media Group, a state-owned media group in Nanjing City, was established on December 17, 2002 with the approval from the National Press and Publication Administration. In recent years, the group has seized strategic opportunities for media convergence to develop a new type of mainstream media based on the Internet. Fully committed to mobile first, it has accelerated the establishment of all-media communication system. The group’s flagship brand, Zijinshan Video, focuses on short video creation, particularly the production of documentaries. It currently has more than 65 million followers across all platforms.

Video – https://www.youtube.com/watch?v=V8aI9PIFalA

View original content:https://www.prnewswire.co.uk/news-releases/eco-documentary-a-chorus-of-frogs-officially-launched-302305134.html

Continue Reading

Technology

Avathon Partners with CP PLUS, Largest CCTV Manufacturer in India, to Enhance Public Safety while Strengthening Community Bonds

Published

on

By

PLEASANTON, Calif., Nov. 13, 2024 /PRNewswire/ — Avathon, provider of the leading AI platform for industrial operations, has partnered with CP PLUS, one of the largest manufacturers of CCTV cameras, to create safer, more connected societies by bundling Avathon’s computer vision technology with each camera. The companies are bringing Avathon’s computer vision AI capabilities to small and medium-sized businesses (SMBs) across India, turning their cameras into intelligent assets that enable more secure workplaces, factories and facilities.           

In today’s fast-paced world, it’s hard to keep an eye on every single detail, every minute of the day. Computer vision AI technology gives users the freedom and control to go about their daily lives knowing they will receive proactive alerts identifying safety and security issues in real time.

“Increasing demand for advanced public safety tools, smart home devices and integrated AI-powered cameras is fueling massive industry growth,” said Aditya Khemka, Managing Director, CP PLUS, a subsidiary of Aditya Group. “Our partnership with Avathon will help us to better deliver state-of-the-art AI-powered solutions that feature advanced functions like real-time anomaly detection and intelligent monitoring.”

Avathon’s computer vision AI automatically detects and alerts unsafe conditions and incidents in real time, allowing users to proactively take the right actions. Avathon enables business owners using valuable resources to monitor CCTV camera feeds to get back to focusing on operations. The company partners with OEM camera manufacturers by providing AI technology that enables end customers to quickly and accurately address processes, behaviors, and conditions that cause unacceptable risk. Through its partnership with CP PLUS, Avathon has democratized this technology, giving access to large organizations and small businesses alike.

CP PLUS is India’s leading surveillance brand with the most extensive portfolio in the entire global industry. Representing a major share of the Indian CCTV market, CP PLUS offers a range of products and services to meet the varied needs of government, commercial, residential, and industrial customers and its products are successfully deployed in every nook and corner of India and many countries across verticals and industry.

“AI cameras are paving the path forward in India toward smart-city initiatives and enhanced public safety improvements. In this sometimes disconnected world, it’s comforting to rely on a technology that instantly alerts users to potential dangers and other anomalies,” said Pervinder Johar, CEO of Avathon. “We’re proud to partner with CP PLUS to provide the AI innovations needed to push India to the leading edge of technological advancement.”

About Avathon

Avathon, a leader in Industrial AI, extends the life of critical infrastructure while advancing the journey toward full autonomy. Avathon’s Industrial AI platform empowers commercial and government customers with scalable, secure, and value-driven solutions that enhance efficiency and resilience across heavy industry.

Media contact:

Jon Ross
Sr. PR & Communications Manager
Avathon
jross@avathon.com

View original content:https://www.prnewswire.com/news-releases/avathon-partners-with-cp-plus-largest-cctv-manufacturer-in-india-to-enhance-public-safety-while-strengthening-community-bonds-302304865.html

SOURCE Avathon

Continue Reading

Trending