Archive for March 20, 2024

Vans Provides Further Information On Data Breach With Bad News For Their Customers

Posted in Commentary with tags on March 20, 2024 by itnerd

Earlier this year, Vans parent group VF Group disclosed a cyber incident. At the time, I said this:

The filing did not say specifically what kinds of personal data was taken or if any corporate data was stolen but VF Corp said it does not retain consumer Social Security numbers, bank account information, or payment card information for its consumer businesses.

Now Vans has put out a statement. And here’s the key part that you should pay attention to:

Our investigation revealed that the incident has affected some personal information of our customers, that we normally store and process in order to manage online purchases, such as email address, full name, phone number, billing address, shipping address. In certain cases, the affected data may also include order history, total order value, information about what payment method was used for the purchases.

Please note that, in any event, we never collect or retain in our IT systems any detailed payment/financial information, such as, for example, bank account or credit card information, so there is no chance that any detailed financial information was exposed to the threat actors. The information we hold is only what payment method was used for the purchases (for example “credit card”, “Paypal”, or “bank account payment”), with no additional details attached.

We can also confirm that no consumers’ passwords were exposed to the threat actors, so you can rest assured that the security of your online accounts was not affected as a result of this incident.

The evidence collected indicates that the affected data set may include one or more of the above personal data categories relating to you, since you previously interacted online with Vans, and possibly with other Brands belonging to the VF Group.

Darren Williams, CEO and Founder, BlackFog:

     “The attack on VF Group is a clear example that securing data must be at the forefront of retailers’ minds. The safety of customers must be of the utmost priority, otherwise, as we can see, loyal customers can quickly turn to victims. VF Group now risks not only financial but reputational damage which can last for years. To avoid becoming the next example, companies must invest in the latest anti data exfiltration technology to prevent any unauthorized data from leaving their systems.”

That’s not exactly reassuring if you are a customer of Vans. And it took way too long to get to this point. That really doesn’t make me want to buy from Vans going forward.

Guest Post: Announcing the Launch of StorageMAP 6.7

Posted in Commentary with tags on March 20, 2024 by itnerd

Enabling Customers To Master Data Management And Reach Business Objectives

By Carl D’Halluin, CTO, Datadobi

March 20, 2024 

We are delighted to introduce StorageMAP 6.7, with key capabilities designed to further enhance automation and unify data management capabilities.

REST API Improvements for Large or Complex Unstructured Data Environments

In response to the growing demand for increased capabilities around seamless integration and automation, we have extended our REST API with improvements tailored for large or complex environments.

With StorageMAP 6.7, users can now leverage REST API calls to:

– Add or configure file or object servers, streamlining the setup process for large data management projects

– Dynamically adjust server throttling, allowing for precise control over performance and resource utilization

– Retrieve real-time status updates of ongoing data management jobs, including critical information such as status and error counts.

These enhancements are particularly beneficial for organizations managing extensive data lifecycle or migration projects, such as our recent work with a well-known global luxury car manufacturer. With almost real-time automatic control over storage impact, and detailed progress insights, StorageMAP empowers users to accelerate and simplify operations, while maximizing efficiency. The end result? Greater use of automation to reduce both cost and risk for your business.

Replication Capability Now included in StorageMAP Act

In addition to REST API improvements, StorageMAP 6.7 brings about significant product unification by integrating replication functionality into StorageMAP. This means that StorageMAP now encompasses both N2N (NAS-to-NAS) and O2O (Object-to-Object) replication capabilities, consolidating all replication functionalities under a single, comprehensive solution.

Bottom line… whether juggling the complexities of managing existing (and growing) data created by the business or dealing with next-generation projects requiring the preparation of data for AI or Machine Learning applications, StorageMAP delivers all the capabilities needed to achieve your business goals in a single scalable solution.

StorageMAP has been and continues to be engineered from the ground up to empower its users to understand, harness, and protect their data in order to meet today’s business objectives while positioning themselves to meet the opportunities of tomorrow.

ServiceNow Accelerates Enterprise Transformation With Washington, D.C. Platform Release 

Posted in Commentary with tags on March 20, 2024 by itnerd

ServiceNow today announced its first platform release of 2024, designed to accelerate enterprise transformation with smarter, faster, simpler experiences. The Now Platform Washington, D.C. release includes new features that boost intelligent automation and deliver fast time to value, critical elements of a business’s digital transformation roadmap. 

According to Gartner, global spending on technology is forecast to rebound from 4.8% in 2023 to 7% in 2024, reaching $5 trillion. As CEOs seek to transform their businesses and work smarter, leaders are concentrating their digital investments into proven, strategic platforms that deliver net‑new innovation and maximize digitization across the enterprise. ServiceNow’s Washington, D.C. release makes it easier than ever for customers to put the power of the Now Platform to work, connecting and orchestrating processes to build seamless experiences that increase productivity and reduce costs.

Simplifying experiences to drive productivity and business efficiency

The Now Platform drives seamless, intelligent experiences among businesses, customers, and employees to propel growth. With a focus on enhancing efficiency, satisfaction, and productivity, the Washington, D.C. release includes new tools to optimize crucial interactions, fueling business growth and helping organizations adapt to ever‑shifting customer and employee needs.

Sales and Order Management (SOM) helps organizations increase revenue by uniting the sales and order lifecycles across front, middle, and back‑office teams on the ServiceNow platform. Sales and fulfillment agents can easily manage opportunities, configure and price quotes, and capture and fulfill orders. SOM empowers customer service agents to complete post‑sale commercial changes, helping drive upsell and cross‑sell opportunities – all in the same platform they use to manage customer service requests. Service agents can create opportunities, quotes, and orders just like sales staff. Improving the sales experience is a core need for businesses in industries like telecommunications, manufacturing, and technology—SOM helps companies orchestrate a more connected sales experience on a single platform to simplify processes, improve customer experiences, and accelerate results.

Platform Analytics offers a secure, simple, unified experience for reporting and analytics across the entire Now Platform. Customers can now seamlessly create data visualizations and dashboards that incorporate multiple data inputs into one, easy to understand experience to power faster, smarter decision making. Platform Analytics also surfaces meaningful, personalized, and timely information directly within Next Experience workspaces effortlessly connects to Workflow Studio, so customers can easily create condition‑based workflow triggers based on analytics thresholds out‑of‑the‑box to seamlessly go from insight to action. 

New AIOps experiences in Service Operations Workspace for ITOM allows AIOps users and administrators to speed issue resolution and achieve faster time to value with enhancements to Express List and alert automation. Express List helps operators work and address issues quickly and effectively—bringing historical alert trends and automated root cause analysis into a single, digestible screen view. Alert automation provides helpful context for operators to more easily understand and action events with alert simplification and grouping, so they can onboard more quickly and speed up resolution times.

A single intuitive interface for end‑to‑end workflow automation

Automating workflows not only simplifies experiences, but improves productivity, freeing up time for employees to focus on more complex tasks rather than manual and menial ones. The Washington, D.C. release includes new features to unlock end‑to‑end workflow automation across the enterprise, powering innovation and creating new efficiencies.

The new Workflow Studio allows creators to create workflow automations quickly and easily from start to finish. Users simply describe the process they’d like to automate, and Workflow Studio will visualize and create the workflows. The solution integrates capabilities like Flow Designer, Automation Engine, Process Automation Designer, and Decision Builder into one view, so employees can collaborate and easily create, configure, and monitor automated workflows. 

The Washington, D.C. release also updates the ServiceNow Operational Technology (OT) solution portfolio to serve industrial environments and smart factories. Operational Technology (OT) Knowledge Management adds to existing OT Visibility, Service Management, and Vulnerability products by accelerating the resolution of shop floor issues, further breaking down organizational barriers by capturing and sharing known resolutions for OT incidents and process deviations across sites. With upgraded asset inventory and amplified security, ServiceNow does for OT what it did for IT over the past two decades – accelerating digital transformation, specifically for industrial environments and smart factories.

Security Posture Control (SPC) is a new solution in the Security Operations portfolio that helps organizations gain visibility into critical security tool coverage gaps, identify assets with high‑risk combinations, and automate response workflows across the enterprise. This solution builds on customers’ existing investments in ITOM Visibility and Service Graph Connector programs. With Security Posture Control, customers will have a better understanding of their security posture, improving cybersecurity strength and resilience.


Driving consistency and efficiency with one extensible data model

Poor or inconsistent data can create risk, cost organizations time and resources, and lead to mistakes. The latest Now Platform release includes new pre‑built, cross‑functional workflows developed with our Common Services Data Model (CSDM), so companies can harness the power of their operational data and drive efficiencies at scale. Through automation, CSDM allows organizations to collect data across hardware or software, cloud or data center, into a trusted, auditable data model that can be used across multiple workflows and follows compliance guidelines.

These solutions can be applied across use cases in security incident management, human resources, and governance, by helping IT teams retain accurate, audit‑ready data for executive and regulatory reporting, decreasing time spent on maintaining applications.

Availability

Innovations announced today are generally available to all customers in the ServiceNow Store on March 20. In addition to the above, new, generative AI‑focused innovations were also announced. More details can be found here

Additional information:

  • Watch a demo on innovations from the Now Platform Washington, D.C. release.
  • Learn more about the Now Platform Washington, D.C. release from Jon Sigler, senior vice president of Platform and AI.

GuidePoint Security Details RaaS Recruitment Efforts Following Law Enforcement Disruption Of Other RaaS Groups

Posted in Commentary with tags on March 20, 2024 by itnerd

GuidePoint Security has revealed that it has discovered three RaaS groups attempting to recruit new members through advertisements on illicit forums on the dark web following Alphv and LockBit law enforcement disruptions, identifying Cloak on UFO Labs and Medusa and RansomHub on the Russian-language RAMP forum for posting ads. 

Each ad had a boilerplate with a short group description, ransom split rates, and contact for TOX. Cloak’s ad was the least remarkable, with few unique features that entice a potential affiliate with options. Medusa was particularly appealing with a sliding payout scale and affiliate/core split dependent on the size of the ransom payment obtained, incentivizing the appearance of high ransom demands. RansomHub was less materialistic, implicitly addressing the crisis of confidence in RaaS groups by declaring that its affiliates could collect ransom payments directly before paying the core group a 10% fee.

GuidePoint Security’s analysis observations include signs of distrust and discontent among RaaS groups and affiliates, indicating that the model is increasingly scrutinized.

You can read the report here.