<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
                        <id>https://mail.onecovernepal.com/blogs.rss</id>
                                <link href="https://mail.onecovernepal.com/blogs.rss"></link>
                                <title><![CDATA[Blogs]]></title>
                                <updated>2021-11-21T17:50:52+00:00</updated>
                        <entry>
            <title><![CDATA[Training on Cyber Security - Securing Business in 21st Century]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/critical-sqlite-flaw-leaves-millions-of-apps-vulnerable-to-hackers" />
            <id>https://mail.onecovernepal.com/4</id>
            <author>
                <name> <![CDATA[Chiranjibi Adhikari]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p><span style="color: #222222; font-family: Verdana, Geneva, sans-serif; font-size: 15px; text-align: justify;">A training on &lsquo;Cyber Security &ndash; Securing Business in the 21st Century was organized by Annapurna Software Development in association with One Cover Private Limited at Hotel Barahi Pokhara on Friday, September 4th, 2019. Senior managers, managers, and offers from government agencies, businesses, banks, NGOs, INGOs, corporate houses, university faculty, and representatives from CAN Federation Kaski Chapter participated in the training. The training was presented by Dr. Pramod Parajuli, a well-known cybersecurity professional, and Mr. Chiranjibi Adhikari, a certified professional and an expert on cybersecurity implementation in Nepal. The training was coordinated by Mr. Navin Gautam, a well-known figure in IT products and services in Pokhara.</span></p>
<p><span style="color: #222222; font-family: Verdana, Geneva, sans-serif; font-size: 15px; text-align: justify;">For more details: </span><a title="Cybersecurity bootcamp" href="https://ictframe.com/cyber-security-bootcamp-and-training-conducted-successfully-at-pokhara/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-05-31T13:31:13+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Risk-Based Approach in Cyber Security In Nepal]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/risk-based-approach-in-cyber-security-in-nepal" />
            <id>https://mail.onecovernepal.com/6</id>
            <author>
                <name> <![CDATA[Chiranjibi Adhikari]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>Risk-Based Approach in Cyber Security In Nepal</p>
<p>Source:&nbsp;<a href="https://ictframe.com/wp-content/uploads/Risk-Based-Approach-in-Cyber-Security-In-Nepal.pdf">https://ictframe.com/wp-content/uploads/Risk-Based-Approach-in-Cyber-Security-In-Nepal.pdf</a></p>]]>
            </summary>
            <updated>2021-05-31T13:24:22+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Awarded Web Application Security Certificate To Mavorion Systems]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/awarded-web-application-security-certificate-to-mavorion-systems" />
            <id>https://mail.onecovernepal.com/8</id>
            <author>
                <name> <![CDATA[Chiranjibi Adhikari]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p><span style="color: #222222; font-family: Verdana, Geneva, sans-serif; font-size: 15px; text-align: justify;">Nepali healthcare sector is aggressively digitizing its information and service delivery channels. Whether it&rsquo;s hospitals or pharmacies or pathology labs or even the Ministry of Health, all are using information systems for automation and better customer satisfaction.</span></p>
<p><span style="color: #222222; font-family: Verdana, Geneva, sans-serif; font-size: 15px; text-align: justify;">For more details:&nbsp;</span><a href="https://ictframe.com/one-cover-awarded-web-application-security-certificate-to-mavorion-systems/">https://ictframe.com/one-cover-awarded-web-application-security-certificate-to-mavorion-systems/</a></p>]]>
            </summary>
            <updated>2021-05-30T21:36:37+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Experts Urge All To Be Digitally Secure As Phishing Up 3 Times]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/experts-urge-all-to-be-digitally-secure-as-phishing-up-3-times" />
            <id>https://mail.onecovernepal.com/9</id>
            <author>
                <name> <![CDATA[The Himalayan Times]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p><span style="font-family: georgia, sans-serif; font-size: 16px;">The whole world&rsquo;s prime focus now is on the pandemic coronavirus with news and posts about the virus being updated every minute across the world. With the widespread use of digital media and the Internet, people now have the luxury to stay updated as well as share news instantly.</span></p>
<p><span style="font-family: georgia, sans-serif; font-size: 16px;">For more details:&nbsp;</span><a href="https://thehimalayantimes.com/lifestyle/experts-urge-all-to-be-digitally-secure-as-phishing-up-3-times/">https://thehimalayantimes.com/lifestyle/experts-urge-all-to-be-digitally-secure-as-phishing-up-3-times/</a></p>]]>
            </summary>
            <updated>2021-05-31T13:24:58+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[One Cover Signs MOU With TechCERT]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/one-cover-signs-mou-with-techcert" />
            <id>https://mail.onecovernepal.com/10</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p class="MsoNormal">A Memorandum of Understanding (MOU) was signed between two parties - One Cover Pvt. Ltd. and TechCERT to collectively work as consultants for carrying on the business of providing cybersecurity assessments, consultancy, and managed security services.</p>
<p class="MsoNormal">One Cover Pvt. Ltd. is a security company based in Kathmandu that provides dependable security solutions. In fact, it places itself at the frontier of the cybersecurity needs of organizations. Its expertise is in the domain of risk management, security solutions, IT audit, and security research &amp; innovation.</p>
<p class="MsoNormal">TechCERT is Sri Lanka&rsquo;s finest and largest Computer Emergency Readiness Team (CERT). It provides fully integrated information security services to organizations across the globe. Furthermore, it works in collaboration with several national and global information or cybersecurity organizations.</p>
<p class="MsoNormal">What does it mean for One Cover?</p>
<p class="MsoNormal">One Cover has expertise in domains that cover a complete cybersecurity framework required for an organization. Collaboration with TechCERT will enable the company to offer enhanced solutions to its clients.</p>
<p class="MsoNormal">Moreover, it will help to sustain a global standard that One Cover promises to provide. It also ensures reliable and consistent services as per the need of organizations.</p>
<p class="MsoNormal">Mutual Benefit for TechCERT</p>
<p class="MsoNormal">TechCERT, as an industry leader, will make resources and expertise available to projects with One Cover. Likewise, an active partnership with One Cover to provide Cyber Security services are on the table.</p>
<p class="MsoNormal">How this Collaboration Benefits Cybersecurity in Nepal?</p>
<p class="MsoNormal">One Cover provides state-of-the-art security solutions with experts on deck. This collaboration brings along a complete solution to help prepare, protect, and secure network and IT infrastructure in Nepal.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">TechCERT will work collaboratively with One Cover in projects as an opportunity to provide Cyber Security services in Nepal.</p>
<p class="MsoNormal">Insight and technical assistance from an industry leader will help take the necessary steps to improve security processes and operations at every step.</p>
<p class="MsoNormal"><a href="https://technologykhabar.com/2020/06/17/35958/">https://technologykhabar.com/2020/06/17/35958/</a></p>
<p class="MsoNormal"><a href="https://ictbyte.com/news/one-cover-signs-mou-with-techcert/">https://ictbyte.com/news/one-cover-signs-mou-with-techcert/</a></p>
<p class="MsoNormal"><a href="https://csrinepal.org/onecover-signs-mou-with-techcert/">https://csrinepal.org/onecover-signs-mou-with-techcert/</a></p>
<p class="MsoNormal"><a href="https://himalsanchar.com/23399/">https://himalsanchar.com/23399/</a></p>
<p class="MsoNormal"><a href="https://ictframe.com/onecover-signs-mou-with-techcert/">https://ictframe.com/onecover-signs-mou-with-techcert/</a></p>
<p class="MsoNormal"><a href="https://banksnepal.com/posts/2020-06-24-02-46-31">https://banksnepal.com/posts/2020-06-24-02-46-31?</a></p>]]>
            </summary>
            <updated>2021-05-31T13:24:10+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Pandemics, Digital Transformation and Cybersecurity]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/pandemics-digital-transformation-and-cybersecurity" />
            <id>https://mail.onecovernepal.com/11</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p class="normal" style="text-align: justify;">The recent COVID-19 pandemic has forced many businesses, agencies, and individuals to adopt digital services for communication, work production, and collaboration. Digital transformation of workflows, communication, financial transactions, and so on was expected, but due to the pandemic, the change occurred unexpectedly very fast.</p>
<p class="normal" style="text-align: justify;"><span lang="EN">Many have experienced a lack of preparedness for such a digital transformation. Due to such a surge in digital services, cybersecurity attackers and scammers are leaving no stones unturned to capitalize on vulnerabilities of digital services.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Cybersecurity has become the most critical challenge in the present context, with many works shifting to digital platforms.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">The digital transformation has become an urgency to maintain social distancing and, at the same time, keep the work going.&nbsp;<em>Social Distancing</em>&nbsp;and&nbsp;<em>Work from Home</em>&nbsp;have become the new normal.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">However, the rush to produce work has opened windows for attackers, compromising the privacy of many.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">The primary reason behind this is the lack of digital literacy and preparedness as well as cybersecurity awareness at the individual level and cybersecurity preparedness at the organizational level.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">In this article, we will review some of the most common cybersecurity attacks reported during the pandemic and provide recommendations to protect from such attacks.</span></p>
<h2 style="text-align: justify;"><a style="background-image: url('img/anchor.gif');" name="_4lfg13nsku0"></a><span lang="EN">Cyber Attacks During the Pandemic</span></h2>
<p class="normal" style="text-align: justify;"><span lang="EN">During the pandemic, every country has published reports of at least one or two cases of COVID-19 themed cyberattacks. Let's look at some threats that we are exposed to in the wake of the pandemic.</span></p>
<h3 style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"><a style="background-image: url('img/anchor.gif');" name="_xi0y4jewc9a1"></a><span lang="EN">1.<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-weight: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;</span></span><span lang="EN">SMS &amp; Email Phishing</span></h3>
<p class="normal" style="text-align: justify;"><span lang="EN">Since employees are working from home, phishing has become a go-to attack for threat actors.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">This type of attack tricks email or SMS recipients into believing that the email/SMS is from a reliable source.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">These emails can be disguised as health advice from WHO and UNICEF.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">When users open such messages, it can either compromise users'' sensitive data by asking to fill a form or install malicious applications on their device.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">The worst part is that this all happens without the user's knowledge or consent.</span></p>
<h3 style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"><a style="background-image: url('img/anchor.gif');" name="_n7qbhc4ya03o"></a><span lang="EN">2.<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-weight: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;</span></span><span lang="EN">Malware</span></h3>
<p class="normal" style="text-align: justify;"><span lang="EN">The trend of attacking devices through malware hidden in mobile apps has increased recently.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">The app developers use coronavirus-related keywords to bring these apps to the top search results in app stores.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">According to a&nbsp;<a href="https://research.checkpoint.com/2020/covid-19-goes-mobile-coronavirus-malicious-applications-discovered/"><span style="color: #1155cc;">report</span></a>&nbsp;from CheckPoint Research, 16 such apps that claimed to offer information on the virus outbreak, contained malware.</span></p>
<h3 style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"><a style="background-image: url('img/anchor.gif');" name="_6xg89xhbfw79"></a><span lang="EN">3.<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-weight: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;</span></span><span lang="EN">Promotional Code Malware</span></h3>
<p class="normal" style="text-align: justify;"><span lang="EN">Online shopping has also surged during the pandemic, and who doesn't love to get discounts while shopping online?</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">While most online shopping platforms are malware-proof, attackers are exploiting this opportunity by promoting tools on the darknet with ''COVID19'' or ''coronavirus'' as discount codes.</span></p>
<h3 style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"><a style="background-image: url('img/anchor.gif');" name="_vzflrkef3rvi"></a><span lang="EN">4.<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-weight: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;</span></span><span lang="EN">Safety Equipment Scams</span></h3>
<p class="normal" style="text-align: justify;"><span lang="EN">Some hackers were advertising the sales of sanitizers, face masks, and PPE kits online. It was part of a desperate attempt to launder cash from email scams.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">In Europe, the pharmaceutical company got away with &euro;6.64 million, and the buyers never received their deliveries.</span></p>
<h3 style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"><a style="background-image: url('img/anchor.gif');" name="_bq35e6e2avj2"></a><span lang="EN">5.<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-weight: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;</span></span><span lang="EN">Ransomware Attacks</span></h3>
<p class="normal" style="text-align: justify;"><span lang="EN">Every individual's data is a gold mine for attackers and data brokers.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">There are cases of hospital record system breach where attackers got access to vital information of patients.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">By holding such digital information hostage, cybercriminals ask for ransom in exchange for not releasing the data.</span></p>
<h2 style="text-align: justify;"><a style="background-image: url('img/anchor.gif');" name="_oaw60jg5x28y"></a><span lang="EN">What Needs to be done?</span></h2>
<p class="normal" style="text-align: justify;"><span lang="EN">According to a survey from 2017, a total of 756 ".np" websites were defaced. Out of these sites, 332 were commercial websites (.com.np) and 160 were government websites (.gov.np).</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">The first step on the to-do-list to prevent cyberattacks should be assessing the vulnerabilities of digital platforms. It's better to understand first-hand that software or applications are never risk-free.&nbsp;</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Most of the version updates and patches should include a security assessment and fix. The more people use applications, the more issues are identified.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Therefore, testing and maintenance of digital platforms shall never be stopped.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Organizations need to have the capability to eliminate vulnerabilities immediately after their discovery.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Moreover, users and organizations also need to assess if the applications are being used wrong. There may be a more secure way to use them, which is usually valid for most applications that offer premium versions.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">The premium versions are always more secure, but again, most users would prefer the free versions of software and digital platforms. An individual's choice of using a free version of a software/tool may not necessarily meet the security requirements of an organization.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Individuals and organizations that are not able to&nbsp;<a href="http://onecovernepal.com/blog/risk-based-approach-in-cyber-security-in-nepal"><span style="color: #1155cc;">assess risks of cybersecurity</span></a>&nbsp;attacks may follow best practices and take expert advice in protecting themselves from cybersecurity attacks.</span></p>
<h2 style="text-align: justify;"><a style="background-image: url('img/anchor.gif');" name="_58qcs638emzz"></a><span lang="EN">Best Practices to Stay Away from the Harm's's Way</span></h2>
<h3 style="text-align: justify;"><a style="background-image: url('img/anchor.gif');" name="_tfai4scvic84"></a><span lang="EN">Accelerate System Patching</span></h3>
<p class="normal" style="text-align: justify;"><span lang="EN">Critical systems or applications such as Virtual Private Networks (VPNs), cloud interfaces, firewalls, meeting tools, collaboration systems, and email servers need constant updates. This can help eliminate vulnerabilities soon after their discovery.</span></p>
<h3 style="text-align: justify;"><a style="background-image: url('img/anchor.gif');" name="_syieyml2o1cw"></a><span lang="EN">Strong Password and Multifactor Authentication</span></h3>
<p class="normal" style="text-align: justify;"><span lang="EN">Most users tend to use passwords that are easier to remember, and in doing so, they don't realize that it makes attackers easy to guess the passwords.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Therefore, the use of complex passwords reduces the risk of unauthorized access attacks.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Also, employees working remotely need to use multifactor authentication (MFA) to access network connections and critical applications.</span></p>
<h3 style="text-align: justify;"><a style="background-image: url('img/anchor.gif');" name="_qg7796ekn8g4"></a><span lang="EN">Avoid Mixing Personal and Professional Digital Contents</span></h3>
<p class="normal" style="text-align: justify;"><span lang="EN">Mixing personal and professional aspects have never been appropriate - either it's's in life in general or at work.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Saving office work on personal storage or cloud is not a good idea. Users need to establish good cyber hygiene to use official email accounts or cloud storage to store official work.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">&nbsp;</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">It prevents the risk of information leak if one of the personal or work services gets compromised, another can remain protected.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">&nbsp;</span></p>
<h3 style="text-align: justify;"><a style="background-image: url('img/anchor.gif');" name="_9eusdziu4714"></a><span lang="EN">Promote &amp; Use Resilient Platforms</span></h3>
<p class="normal" style="text-align: justify;"><span lang="EN">There are a few digital platforms that support extensive remote work, while others lack the basic features and security.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">&nbsp;</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">For example, an employee without prior experience in extensive remote work using VPN may find it difficult even to set up a client VPN in their devices.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Therefore, it would be better to provide support to the employees in setting up minimum security requirements such as MFA and VPN on their devices.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Similarly, the use of verified tools and services from trusted vendors will have a lesser risk of data breach and cyberattacks.</span></p>
<h3 style="text-align: justify;"><a style="background-image: url('img/anchor.gif');" name="_bp19qb4k79x1"></a><span lang="EN">Awareness is the Key</span></h3>
<p class="normal" style="text-align: justify;"><span lang="EN">In&nbsp;<a href="http://onecovernepal.com/blog/experts-urge-all-to-be-digitally-secure-as-phishing-up-3-times"><span style="color: #1155cc;">phishing scams</span></a>, the attacker poses as someone or something to steal credentials. This can happen while opening an attachment or clicking a malicious link in an email.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">&nbsp;</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">It is of utmost importance for the users to understand and identify such threats.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">90%&nbsp;of ransomware attacks originate from phishing attempts.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Therefore, here are<strong>&nbsp;some tips to follow</strong>&nbsp;to protect from such scams or threats.</span></p>
<p class="normal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"><span lang="EN">●<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></span><span lang="EN">Avoid opening emails from people you don't know or from senders that seem suspicious in any way.</span></p>
<p class="normal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"><span lang="EN">●<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></span><span lang="EN">Know which links are safe to click and which are not. To do so, hover over the link to know where it redirects to.</span></p>
<p class="normal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"><span lang="EN">●<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;There's</span></span><span lang="EN"> a high chance that malicious links or attachments may come from friends whose mail may have been compromised as well. Therefore, make sure to verify if you were not expecting such emails.</span></p>
<p class="normal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"><span lang="EN">●<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></span><span lang="EN">Pay a closer look at the email details. Make sure to check grammatical errors, senders detail, and subject.</span></p>
<h3 style="text-align: justify;"><a style="background-image: url('img/anchor.gif');" name="_w24jkilqtvuk"></a><span lang="EN">Avoid Public WiFi</span></h3>
<p class="normal" style="text-align: justify;"><span lang="EN">Everybody loves free services. Public WiFi, although open, poses a higher level of security risk. Working from home over the public WiFi should be prohibited.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Public WiFi should be the last resort but is not recommended if users don't have a client VPN setup.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Enabling VPN ensures an encrypted connection between the user's device and the server making it difficult for cybercriminals to access the transmitted data.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Similarly, mobile networks can also be used if client VPN is unavailable.</span></p>
<h3 style="text-align: justify;"><a style="background-image: url('img/anchor.gif');" name="_exmeykg5olyw"></a><span lang="EN">Monitoring of Accounts/Sensitive Data</span></h3>
<p class="normal" style="text-align: justify;"><span lang="EN">It is a top priority to safeguard online accounts and monitor them. Employees'', customers'', and users'' online accounts may be compromised, and sensitive data such as personal details, credit/debit card information, and health information get leaked.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Such a breach of privacy may happen at any time. Therefore, it's better to monitor for suspicious activities and unauthorized access regularly.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Reminding employees, customers, and users about their role in keeping a secure password, using MFA, updating PINs, etc. would help reduce data breach due to cybersecurity attacks.</span></p>
<h2 style="text-align: justify;"><a style="background-image: url('img/anchor.gif');" name="_7uxn36ta31dy"></a><span lang="EN">Conclusion</span></h2>
<p class="normal" style="text-align: justify;"><span lang="EN">COVID-19 pandemic has allowed innovative ways of working from home and is bringing digital transformations in many organizations.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">However, for attackers, it has created opportunities for security and privacy breach.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Organizations that use digital platforms need to be aware of the risks of adopting digital platforms beforehand, build cybersecurity preparedness, and monitor the platforms for any suspicious activities to provide a safe and secure digital online experience to employees, customers, and users.</span></p>
<p class="normal" style="text-align: justify;"><span lang="EN">Image Source:&nbsp;</span><span lang="EN" style="text-align: center; color: red;">Source: </span><span lang="EN" style="text-align: center; color: red;"><span style="color: #1155cc;">Threat Report 2017</span></span><span lang="EN" style="text-align: center;"><span style="color: red;"> Nepal From ThreatNix</span></span></p>]]>
            </summary>
            <updated>2020-06-22T04:08:43+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Tender Notice - Supply/Delivery of Security Operation Centre (SOC)/SIEM/FIM]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/tender-notice-supplydelivery-of-security-operation-centre-socsiemfim" />
            <id>https://mail.onecovernepal.com/14</id>
            <author>
                <name> <![CDATA[ONECOVER]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p><a style="box-sizing: border-box; margin: 0px; padding: 0px; color: #42a5f5; transition: all 0.4s ease-in-out 0s; outline: 0px; outline-offset: -2px; font-family: 'Open Sans', Arial, Helvetica, sans-serif;" href="https://neps.com.np/images/Neps_Nepal__Tender_Notice_FH11.pdf">Tender Notice - Supply/Delivery of Security Operation Centre (SOC)/SIEM/FIM</a></p>
<p>&nbsp;</p>
<p>Download the RFP: https://drive.google.com/file/d/1gHH2PIgcnjMtTFMCF7Q5MFyhk6k_SOpF/view?usp=sharing</p>
<p>&nbsp;</p>]]>
            </summary>
            <updated>2020-08-27T09:51:52+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[NTA Lauched Cyber Security Byelaw 2077]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/nta-lauched-cyber-security-byelaw-2077" />
            <id>https://mail.onecovernepal.com/15</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;"><span style="color: #14171a; font-family: system-ui, -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Ubuntu, 'Helvetica Neue', sans-serif; font-size: 15px; text-align: start; white-space: pre-wrap; background-color: #f5f8fa;">नेपाल दूरसञ्&zwj;चार प्राधिकरणबाट अनुमतिपत्र प्राप्त सबै दूरसञ्&zwj;चार सेवा प्रदायकहरु (आधारभूत दूरसञ्&zwj;चार/टेलिफोन, मोबाईल, नेटवर्क, इन्टर्नेट लगायत) को लागि जारी गरिएको Cyber Security Byelaw, 2077 (2020) सम्बन्धी अत्यन्त जरूरी सुचना</span></p>
<p style="text-align: justify;">For more&nbsp; details:&nbsp;<a href="https://nta.gov.np/wp-content/uploads/2020/08/Cyber-Security-Bylaw-2077-2020.pdf">https://nta.gov.np/wp-content/uploads/2020/08/Cyber-Security-Bylaw-2077-2020.pdf</a></p>]]>
            </summary>
            <updated>2021-05-31T13:24:45+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Chief Technical Officer Jobs in Nepal]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/chief-technical-officer-jobs-in-nepal" />
            <id>https://mail.onecovernepal.com/16</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<div class="gs" style="margin: 0px; padding: 0px 0px 20px; width: 950px; color: #222222; font-family: Roboto, RobotoDraft, Helvetica, Arial, sans-serif; font-size: medium;">
<div class="">
<div id=":ni" class="ii gt" style="font-size: 0.875rem; direction: ltr; margin: 8px 0px 0px; padding: 0px; position: relative;">
<div id=":nh" class="a3s aXjCH " style="overflow: hidden; font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: small; line-height: 1.5; font-family: Arial, Helvetica, sans-serif;">
<div dir="ltr">
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Job Category: IT and IS Audit Firm</span></p>
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Job Level: Top Level</span></p>
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">No.of Vacancy: 1</span></p>
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Employment Type: Full Time</span></p>
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Job Location: New Baneshwor</span></p>
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Offered Salary: Negotiable</span></p>
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Apply Before: 30<sup>th</sup>&nbsp;Nov 2020</span></p>
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Education Level: Bachelor</span></p>
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Experience Required: More than or equals to 5 years</span></p>
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Age: More than 25 years</span></p>
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Professional Skill Required: CEH, LPT, CPTE, OWASP, CSP, CISSP</span></p>
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Other Specification:</span></p>
<p style="text-align: justify; margin: 0in 0in 0.0001pt 0.5in; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></span><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">5+ Years of IS Lead Audit</span></p>
<p style="text-align: justify; margin: 0in 0in 0.0001pt 0.5in; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></span><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">VAPT</span></p>
<p style="text-align: justify; margin: 0in 0in 0.0001pt 0.5in; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></span><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Experience Using Tools for Testing</span></p>
<p style="text-align: justify; margin: 0in 0in 0.0001pt 0.5in; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></span><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Strong English speaking and writing skills</span></p>
<p style="text-align: justify; margin: 0in 0in 0.0001pt 0.5in; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></span><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Experience with different frameworks like COBIT 5</span></p>
<p style="text-align: justify; margin: 0in 0in 0.0001pt 0.5in; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></span><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Experience with CBS and their system</span></p>
<p style="text-align: justify; margin: 0in 0in 8pt 0.5in; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><span style="font-size: 12pt; line-height: 17.12px; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></span><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">Experience with Networking Technologies</span></p>
<p class="MsoNormal" style="margin: 0in 0in 8pt; text-align: justify; line-height: 15.6933px; font-size: 11pt; font-family: Calibri, sans-serif;"><strong><span style="font-size: 12pt; line-height: 17.12px; font-family: 'Times New Roman', serif;">About the Company</span></strong></p>
<p style="margin: 0in 0in 0.0001pt; text-align: justify; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-origin: initial; background-clip: initial; font-size: 12pt; font-family: 'Times New Roman', serif;"><span style="color: black;">One Cover Pvt. Ltd. is a security company providing dependable security services and state-of-the-art security solutions to a diverse set of industries in Nepal and abroad. OneCover places itself at the frontier of the cybersecurity needs of every organization by providing bespoke security and risk management services and solutions.</span><span id="m_3670448373260768300gmail-docs-internal-guid-f542ba69-7fff-24ba-6515-afeea60091ca" style="box-sizing: border-box;"></span></p>
<p style="margin: 0in 0in 0.0001pt; text-align: justify; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-origin: initial; background-clip: initial; box-sizing: border-box; max-width: 850px; font-size: 12pt; font-family: 'Times New Roman', serif;"><span style="box-sizing: border-box; white-space: pre-wrap;"><span style="color: black;">One Cover has put the best expertise with the right knowledge and skills to provide security services and solutions in the domain of risk management, IT audit, security solutions, and security research &amp; innovation.</span></span></p>
</div>
<div class="yj6qo">&nbsp;</div>
<div class="adL">&nbsp;</div>
</div>
</div>
<div class="hi" style="border-bottom-left-radius: 1px; border-bottom-right-radius: 1px; padding: 0px; width: auto; background: #f2f2f2; margin: 0px;">&nbsp;</div>
</div>
</div>]]>
            </summary>
            <updated>2021-05-31T13:26:19+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Cyber Security Awareness Model by EC-Council]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/cyber-security-awareness-model-by-ec-council" />
            <id>https://mail.onecovernepal.com/17</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>One Cover Pvt. Ltd, Cybersecurity practitioners from Nepal and Ec-Council team interaction on Cyber Security Awareness Model developed by Ec-Council.&nbsp;</p>
<p>&nbsp;</p>
<p>Many IT pros don&rsquo;t exactly know where to start when it comes to creating a security awareness program that will work for their organization. The program is complete with actionable tasks, helpful tips, courseware suggestions and a management calendar. You also have the ability to export the full program as a detailed or executive summary version in PDF format.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>]]>
            </summary>
            <updated>2021-05-31T13:23:46+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[One Cover Private Limited Appointed Information Security Consultant, Chandra Bilash Bhurtel]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/one-cover-private-limited-appointed-information-security-consultant-chandra-bilash-bhurtel" />
            <id>https://mail.onecovernepal.com/19</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>One Cover Private Limited Appointed Information Security Consultant, Chandra Bilash Bhurtel. A huge congratulation to Chandra Bilash Bhurtel for being the Information Security Consultant of Onecover Pvt. Ltd.</p>
<p>&nbsp;It's a matter of pride to have you on our team. We will perform many cybersecurity activities in superb cooperation.&nbsp;</p>
<p>Wish you the best of luck for the journey ahead.</p>
<p>&nbsp;</p>
<p>Regards</p>
<p>Chiranjibi Adhikari</p>
<p>Managing Director</p>
<p>&nbsp;</p>
<p>#onecover #cybersecurity #informationsecurity</p>]]>
            </summary>
            <updated>2021-05-25T13:02:04+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Dipendra Poudel Appointed Information Security Consultant of One Cover Private Limited.]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/dipendra-poudel-appointed-information-security-consultant-of-one-cover-private-limited" />
            <id>https://mail.onecovernepal.com/20</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">&ldquo;We are fortunate to welcome Dipendra Poudel as a member of onecover Private Limited,&rdquo; said Chiranjibi Adhikari, Managing Director of Onecover Private Limited.</p>
<p style="text-align: justify;">&ldquo;Given his extensive leadership experience in the information security area.</p>
<p style="text-align: justify;">Dipendra Poudel, a renowned industry veteran brings over one decade of information security and technology management leadership experience.</p>
<p style="text-align: justify;">He most recently served as Managing Director at Kamakhya Trade Pvt. Ltd.</p>]]>
            </summary>
            <updated>2021-05-26T12:09:44+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Shree Paudel Appointed Cyber Security Consultant of One Cover Private Limited.]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/shree-paudel-appointed-cyber-security-consultant-of-one-cover-private-limited" />
            <id>https://mail.onecovernepal.com/21</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>Shree Paudel is a professional and technology enthusiastic. He has completed a Master Degree in Information</p>
<p>Technology. He has 15+ years of hands-on experience in the IT industry.</p>
<p>&nbsp;He is closely involved with the world's leading technology companies like gPayments (Australia), Thales e-Security (UK), Hitachi - Payment switch (Colombo), IBM, Dell, Hp, Cisco, Microsoft, VMware.</p>
<p>&ldquo;We are lucky to welcome Shree Paudel as a member of onecover Private Limited,&rdquo; said Chiranjibi Adhikari, Managing Director of Onecover Private Limited.</p>
<p>&nbsp;</p>]]>
            </summary>
            <updated>2021-05-26T19:25:50+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Cyber Security Interns in Nepal, Opportunity For Cyber Security Jobs]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/cyber-security-interns-in-nepal-opportunity-for-cyber-security-jobs" />
            <id>https://mail.onecovernepal.com/22</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">One cover Pvt. Ltd. provides dependable security services. It is a security company.&nbsp; It meets cybersecurity needs by providing bespoke security and risk management services and solutions.</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">One cover puts its best knowledge and skills to provide security services and solutions in the domain of risk management, IT audit, security solutions, and security research &amp; innovation.</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;"><a href="https://pixel.facebook.com/jobs/job-opening/253812852853451/?source=post" target="_blank" rel="noopener">Cybersecurity</a> is the process of protecting internet-connected systems from cyber threats. These systems can be hardware, software, or data.&nbsp;</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">It is used to prevent cyberattacks. Cyber threats or attacks aim for accessing, changing, or destroying sensitive information. Cyberattacks extract money from users or interrupt normal business processes.&nbsp;</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><a href="https://ictframe.com/career-path-in-cyber-security-successfully-conducted/" target="_blank" rel="noopener"><strong><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">Job Type- Internship (Full-Time / Part-Time)</span></span></strong></a></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">Qualifications: Bachelor's degree completed or running in Computer Engineering or BSc. CSIT or BIT or BCA</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">Passion in Cybersecurity</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">Freshers are highly encouraged</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">Fluent in the English language</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">working Experience less than a year can also apply</span></span></p>
<p class="MsoNormal" style="line-height: normal; text-align: left;"><strong><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">Requirements:</span></span></strong></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">Basic knowledge about cybersecurity</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">Excellent problem-solving skills</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">Good attitude towards learning and sharing</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">good communication and interpersonal skills</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-outline-level: 1;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 16px;">Time management skills</span></span></p>]]>
            </summary>
            <updated>2021-06-01T10:01:35+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[10 things you should know about cybersecurity in Nepal]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/10%20things%20you%20should%20know%20about%20cybersecurity%20in%20Nepal" />
            <id>https://mail.onecovernepal.com/27</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<h1><em style="mso-bidi-font-style: normal;"><span style="font-size: 12.0pt; font-weight: normal; mso-bidi-font-weight: bold;">Youths are finding difficulty in understanding cybersecurity. Here you will find some interesting facts about this field.</span></em></h1>
<p>Cybersecurity protects systems, networks, and programs from cyberattacks. It focuses on securing the environment for various organizations. Criminals usually access, change or destroy sensitive data. They also use that information to extort money from users.&nbsp;</p>
<p>Security is in high demand in cyberspace. Most of the institutions now adopt digital systems. Nepal is also growing its digital footprint. Even in Nepal, we have been facing lots of cybercrime incidents.&nbsp;&nbsp;</p>
<p>Around 2013, Cybersecurity came into the spotlight in Nepal. There's no fixed when the term was first discussed or realized.&nbsp;The Crime Investigation Department of Nepal Police reported 19 cases of social media crimes during that time. Finally, the private sector started efforts to defend and secure cyberspace.</p>
<p>Confused about cybersecurity? Here are 10 interesting facts you need to know.</p>
<p style="margin-left: .5in; text-indent: -.25in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><!-- [if !supportLists]--><span style="mso-list: Ignore;">1.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]-->&nbsp;<strong>Pioneers in Nepali cyberspace</strong></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in;"><span style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman',serif;">LogPoint Nepal Pvt Ltd, the first company that introduced security information. It also used event management (SIEM) products to secure cyberspace. The first ones to start working in the field and give services were Eminence Ways and Rigo Technology.&nbsp;</span></p>
<p style="margin-left: .5in; text-indent: -.25in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><!-- [if !supportLists]--><span style="mso-list: Ignore;">2.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]-->&nbsp;<strong>Early reported cases in Nepal</strong></p>
<p style="margin-left: .5in;">Many of the incidents that occurred went unnoticed.&nbsp; Due to which the exact first incident is difficult to detect. However, some of the reported earlier cases include:</p>
<ol start="2" type="1">
<ul type="circle">
<li class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-list: l2 level2 lfo1; tab-stops: list 1.0in;"><span style="font-size: 12.0pt; font-family: 'Times New Roman',serif;">In July 2013, a young woman ended up transferring money for an online airline ticket booking. In fact, she fall victim to online swindling.&nbsp; Out of a total of Rs. 110,000&nbsp;she got back Rs. 15,000 only. She transferred the money with the help of the district court.&nbsp;</span></li>
<li class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-list: l2 level2 lfo1; tab-stops: list 1.0in;"><span style="font-size: 12.0pt; font-family: 'Times New Roman',serif;">In Kathmandu School of Law, the first known case of cyberbullying was&nbsp;</span><a href="https://web.archive.org/web/20141009124537/https:/ekantipur.com/np/2071/6/12/full-story/396698.html"><span style="font-size: 12.0pt; font-family: 'Times New Roman',serif;">reported</span></a><span style="font-size: 12.0pt; font-family: 'Times New Roman',serif;">&nbsp;on October 7, 2014.</span></li>
<li class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-list: l2 level2 lfo1; tab-stops: list 1.0in;"><span style="font-size: 12.0pt; font-family: 'Times New Roman',serif;">In 2016, Nepal Police&nbsp;</span><a href="https://english.onlinekhabar.com/police-arrest-18-year-old-hacker-say-reports-claiming-hacking-nepal-telecom-website-false.html"><span style="font-size: 12.0pt; font-family: 'Times New Roman',serif;">caught</span></a><span style="font-size: 12.0pt; font-family: 'Times New Roman',serif;">&nbsp;an 18-year-old who operated Anonymous #Opnep. Government websites including Nepal Telecom, National Tuberculosis Centre were hacked. </span></li>
</ul>
</ol>
<h4 style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-indent: -.25in; line-height: normal; mso-pagination: widow-orphan; page-break-after: auto; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><!-- [if !supportLists]--><strong><span style="font-family: 'Cambria',serif; mso-ascii-theme-font: major-latin; mso-fareast-font-family: Cambria; mso-fareast-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-font-family: Cambria; mso-bidi-theme-font: major-latin; color: black; mso-themecolor: text1; font-style: normal; mso-bidi-font-style: italic;"><span style="mso-list: Ignore;">3.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span></strong><!--[endif]--><span style="color: black; mso-themecolor: text1; font-weight: normal; mso-bidi-font-weight: bold; font-style: normal; mso-bidi-font-style: italic;">&nbsp;</span><strong><span style="font-family: 'Cambria',serif; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: major-bidi; color: black; mso-themecolor: text1; font-weight: normal; font-style: normal; mso-bidi-font-style: italic;">Common incidents reported in Nepal </span></strong></h4>
<h4 style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; line-height: normal; mso-pagination: widow-orphan; page-break-after: auto;"><span style="font-size: 12.0pt; font-family: 'Times New Roman',serif; color: black; mso-themecolor: text1; font-weight: normal; mso-bidi-font-weight: bold; font-style: normal; mso-bidi-font-style: italic;">Some of the usually reported incidents included </span><a href="https://english.onlinekhabar.com/tag/atm-hacking"><span style="font-size: 12.0pt; font-family: 'Times New Roman',serif; color: black; mso-themecolor: text1; font-style: normal; mso-bidi-font-style: italic;">ATM attacks</span></a><span style="font-size: 12.0pt; font-family: 'Times New Roman',serif; color: black; mso-themecolor: text1; font-weight: normal; mso-bidi-font-weight: bold; font-style: normal; mso-bidi-font-style: italic;">, ransomware, spear phishing, privacy leaks. Also, social media-related crimes were reported such as harassment; identity theft, </span><a href="https://english.onlinekhabar.com/some-nepali-children-are-getting-addicted-to-porn-experts-warn-of-grave-consequences.html"><span style="font-size: 12.0pt; font-family: 'Times New Roman',serif; color: black; mso-themecolor: text1; font-style: normal; mso-bidi-font-style: italic;">child pornography</span></a><span style="font-size: 12.0pt; font-family: 'Times New Roman',serif; color: black; mso-themecolor: text1; font-weight: normal; mso-bidi-font-weight: bold; font-style: normal; mso-bidi-font-style: italic;">,&nbsp;and dissemination of false information.</span></h4>
<p class="MsoNormal">&nbsp;</p>
<p style="margin-left: .5in; text-indent: -.25in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><!-- [if !supportLists]--><strong><span style="font-weight: normal;"><span style="mso-list: Ignore;">4.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span></strong><!--[endif]--><strong>Common mistakes that make you a victim </strong></p>
<p style="margin-left: .5in;">The digital transformation leaves behind some obvious factors that lead to cybercrime in Nepal.&nbsp; Some of the typical mistakes include the use of easy and repeated passwords on many platforms. Also, Poor knowledge and lack of awareness also lead them to phish and scams. Furthermore, the use of outdated and pirated software, application, and hardware also lead to cyberattack.&nbsp;</p>
<p style="margin-left: .5in; text-indent: -.25in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><!-- [if !supportLists]--><span style="mso-list: Ignore;">5.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><strong>2017 was a bad year</strong></p>
<ul type="disc">
<li class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;">&nbsp;On June 27, 2017, a group of Turkish&nbsp;<a href="https://myrepublica.nagariknetwork.com/mycity/news/nepal-vulnerable-to-cyber-attacks">hackers </a>hacked the official website of the Department of Passport. They&nbsp;faced threatening notes to reveal the government&rsquo;s data.</li>
<li class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;">Paradox Cyber Ghost hacked 58 government websites On July 25, 2017, thus making it one of the biggest breaches of all times in Nepal.&nbsp;</li>
<li class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;">An unidentified hacker hacked the&nbsp;<a href="https://www.onlinekhabar.com/2017/11/642528">SWIFT</a>&nbsp;system of NIC Asia Bank on October 23. From the user accounts to six different countries, the hackers caught USD 4.4 million. Yet, the bank&nbsp;<a href="https://www.reuters.com/article/us-cyber-heist-nepal-idUSKBN1D72JP">claimed</a>&nbsp;to recover about USD 4 million.</li>
<li class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;">Onlinekhabar, known as one of the popular online news portals of Nepal, was&nbsp;<a href="https://techlekh.com/onlinekhabar-mining-monero-coins/">accessed by a third party</a> On November 28, 2017.&nbsp; In addition, a JavaScript mining application to mine cryptocurrency called Monero was asked to install.&nbsp;&nbsp;</li>
</ul>
<p style="margin-left: .5in; text-indent: -.25in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><!-- [if !supportLists]--><span style="mso-list: Ignore;">6.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><strong><span style="mso-spacerun: yes;">&nbsp;</span>Data breach is a serious issue</strong></p>
<ul type="disc">
<li class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-list: l0 level1 lfo3; tab-stops: list .5in;">On April 8, 2020, a hacker using the Twitter handle, Narpichas @paapi_kto_mah leaked the customer data of more than 160,000 customers of Vianet Communication. They made public data that included customers&rsquo; emails, phone numbers, and addresses.&nbsp;</li>
<li class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: normal; mso-list: l0 level1 lfo3; tab-stops: list .5in;">A hacker using the Twitter handle, Mr. Mugger,<a href="https://english.onlinekhabar.com/foodmandu-survives-cyber-attack-details-of-around-30000-customers-stolen.html">&nbsp;hacked and dumped data of 50,000 users of Foodmandu</a> on March 8, 2020. Data included names, mailing addresses, email addresses, and phone numbers.</li>
</ul>
<p style="margin-left: .5in; text-indent: -.25in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><!-- [if !supportLists]--><span style="mso-list: Ignore;">7.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><strong>Nepal Police has a dedicated bureau</strong></p>
<p style="margin-left: .5in;">Cybercrimes were constantly increasing in Nepal. Therefore, the Nepal Police established a dedicated <a href="https://www.nepalpolice.gov.np/index.php/cyber-bureau">cyber bureau</a> on June 10, 2018. Its head office lies in Bhotahiti of Kathmandu.&nbsp;</p>
<p style="margin-left: .5in; text-indent: -.25in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><!-- [if !supportLists]--><span style="mso-list: Ignore;">8.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><strong><span style="mso-spacerun: yes;">&nbsp;</span>Number of people working&nbsp;</strong></p>
<p style="margin-left: .5in;">About 60 men and about 10 women work professionally in the field. Meanwhile, over 120 people include the students and junior workforce associated with the field.&nbsp;</p>
<p style="margin-left: .5in; text-indent: -.25in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><!-- [if !supportLists]--><span style="mso-list: Ignore;">9.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><strong><span style="mso-spacerun: yes;">&nbsp;</span>Private organizations working today</strong></p>
<p style="margin-left: .5in;">Eminence Ways, Vairav Tech, CryptoGen Nepal, ThreatNix, One Cover Pvt Ltd., Reanda Biz Serve, and Cynical Technology actively work in the field of cybersecurity.&nbsp;</p>
<h4 style="margin-left: .5in; text-indent: -.25in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><!-- [if !supportLists]--><span style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black; mso-themecolor: text1; font-style: normal; mso-bidi-font-style: italic;"><span style="mso-list: Ignore;">10.<span style="font: 7.0pt 'Times New Roman';">&nbsp; </span></span></span><!--[endif]--><span style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman',serif; color: black; mso-themecolor: text1; font-style: normal; mso-bidi-font-style: italic;"><span style="mso-spacerun: yes;">&nbsp;</span>Nepali&rsquo;s in the international scenario</span></h4>
<h4 style="margin-left: .5in;"><span style="font-family: 'Times New Roman',serif; color: black; mso-themecolor: text1; font-weight: normal; mso-bidi-font-weight: bold; font-style: normal; mso-bidi-font-style: italic;">Many Nepali's have created and left their mark on the international&nbsp;</span><a href="https://www.facebook.com/whitehat/thanks"><span style="font-family: 'Times New Roman',serif; color: black; mso-themecolor: text1; font-style: normal; mso-bidi-font-style: italic;">hall of fame</span></a><span style="font-family: 'Times New Roman',serif; color: black; mso-themecolor: text1; font-weight: normal; mso-bidi-font-weight: bold; font-style: normal; mso-bidi-font-style: italic;">.&nbsp;In 2015, Sachin Thakuri and Prakash Sharma were included in Facebook&rsquo;s hall of fame. They reported bugs on the social media platform. Similarly, Hall of fame of Facebook, Google, Sony, Microsoft, HackerOne, and Bugcrowd enlist ethical hackers like Nirmal Dahal, Santosh Bhandari, Nirmal Thapa, Ajay Gautam, Saugat Pokhrel, Aaditya Khati, Bishal Shrestha, etc&nbsp;</span></h4>
<p class="MsoNormal">&nbsp;</p>]]>
            </summary>
            <updated>2021-06-08T12:55:05+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Cyber Incidents in Nepal]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/Cyber-Incidents-in-Nepal" />
            <id>https://mail.onecovernepal.com/29</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;"><br />Internet users have reached 20 million in Nepal.&nbsp;Cybercrimes rise more and more every year and it's not slowing down. With the pandemic, it's even growing more rapidly globally. Cyber incidents try to expose, modify, delete or steal valuable information. They attack everyone from low to high business companies. These are the type of incidents that usually occurs:</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-align: justify; text-indent: -.25in; line-height: normal;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">1.</span><span style="font-size: 7.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">&nbsp;&nbsp;&nbsp;&nbsp;</span><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">To gain unauthorized access to a system</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-align: justify; text-indent: -.25in; line-height: normal;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">2.</span><span style="font-size: 7.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">&nbsp;&nbsp;&nbsp;&nbsp;</span><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">For the processing or storing of data unauthorized use of systems</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-align: justify; text-indent: -.25in; line-height: normal;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">3.</span><span style="font-size: 7.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">&nbsp;&nbsp;&nbsp;&nbsp;</span><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">Modifying systems firmware, software, or hardware without the system owner's consent.</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-align: justify; text-indent: -.25in; line-height: normal;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">4.</span><span style="font-size: 7.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">&nbsp;&nbsp;&nbsp;&nbsp;</span><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">Either Malicious disruption or denial of service.&nbsp;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal;"><strong><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">It is said that cybercrime came into the spotlight in 2013. Even though the exact first cyber incident of Nepal is unknown, here are some of the early crimes that took place in Nepal:</span></strong></p>
<ul type="disc">
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">In July 2013, a young woman fell victim to online swindling. She transferred Rs. 110,000 for an online air booking. She got back only Rs. 15,000.</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Reported first Cyberbullying case on Kathmandu School of law on October 7, 2014</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">In 2016, an 18-year old boy operated Anonymous #Opnep to hack government websites&nbsp;</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">A group of Turkish&nbsp;<span style="color: blue;">hackers&nbsp;</span>breached the official website of the Department of Passport On June 27, 2017.</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Biggest breaches of all times in Nepal, when Paradox Cyber Ghost hacked 58 government websites On July 25, 2017.&nbsp;</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">An unidentified hacker hacked the&nbsp;<a href="https://www.onlinekhabar.com/2017/11/642528"><span style="color: blue;">SWIFT</span></a>&nbsp;system of NIC Asia Bank on October 23, 2017. Hacker caught USD 4.4 million but the bank recovered USD 4 million.</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Onlinekhabar news portal was&nbsp;<a href="https://techlekh.com/onlinekhabar-mining-monero-coins/"><span style="color: blue;">accessed by a third party</span></a>&nbsp;on November 28, 2017.</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Narpichas @paapi_kto_mah, Twitter handler leaked the customer data of more than 160,000 customers of Vianet Communication on April 8, 2020,&nbsp;</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Similarly from Twitter Mr. Mugger,&nbsp;<a href="https://english.onlinekhabar.com/foodmandu-survives-cyber-attack-details-of-around-30000-customers-stolen.html"><span style="color: blue;">hacked and dumped data of 50,000 users of Foodmandu</span></a>&nbsp;on March 8, 2020.</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">In September 2020, Five Chinese nationals hacked <a href="https://neps.com.np/"><span style="color: blue;">NEPS (Nepal Electronic Payment System)</span></a>. Nepal police arrested them trying to withdraw cash with cloned debit cards.</span></li>
</ul>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">Likewise, many incidents have been reported. From famous Celebrity facebook hack to websites and ATM hacks. While many of them still unreported and out of the media reach. According to official statistics from 2018-2019, Recorded cases of cybercrime are 180 were 125 from Kathmandu and 55 from outside the valley.</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal;"><strong><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">Cyber incidents Prevention</span></strong></p>
<ul type="disc">
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Train your staff: ask them to check links, email addresses and double-check before granting requests</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Keep your software and systems fully up to date: don't give a hacker a chance to exploit weakness&nbsp;</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Ensure Endpoint Protection: Protect your remotely working devices</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Install a Firewall: to block brute force attacks</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Backup your data: to avoid downtime</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Control access to your systems: secure your office environment</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Wi-Fi Security: Hide your Wi-Fi&nbsp;</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Employee personal accounts have a separate login for each staff member.&nbsp;</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Access Management: block staffs from accessing or installing network&nbsp;</span></li>
<li class="MsoNormal" style="color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman';">Passwords: have different passwords for every application</span></li>
</ul>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal;"><strong><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">Cybersecurity Organizations and Companies in Nepal</span></strong></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">The demand of cybersecurity increases with an increase in internet usage in almost all the business. Before investing in cybercrime was considered a waste of money. Currently, there's a cyber bureau to investigate these crimes. About 60 men and about 10 women work professionally in the field. Meanwhile, over 120 people include the students and junior workforce associated with the field.&nbsp;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">Though some reported incidents included&nbsp;<a href="https://english.onlinekhabar.com/tag/atm-hacking"><span style="color: blue;">ATM attacks</span></a>, ransomware, spear phishing, privacy leaks. Furthermore, social media-related crimes were reported such as harassment; identity theft,&nbsp;<a href="https://english.onlinekhabar.com/some-nepali-children-are-getting-addicted-to-porn-experts-warn-of-grave-consequences.html"><span style="color: blue;">child pornography</span></a>,&nbsp;and dissemination of false information.</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; text-align: justify; line-height: normal;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">Some of the private organizations working in cybersecurity</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-align: justify; text-indent: -.25in; line-height: normal;"><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">1.</span><span style="font-size: 7.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;">&nbsp;&nbsp;&nbsp;&nbsp;</span><span style="font-size: 14.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; color: black;"><a title="One Cover Pvt Ltd" href="../" target="_blank" rel="noopener"><span style="color: blue;">One Cover Pvt Ltd</span></a>. It provides services like Security Consulting, Incident Response, Security Assessment, and Managed Security.</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-align: justify; text-indent: -.25in; line-height: normal;"><a href="https://npcert.org/" target="_blank" rel="noopener"><span style="font-family: Times New Roman, serif;"><span style="font-size: 18.6667px;">2. npCert: Information Security Response Team Nepal</span></span></a></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-align: justify; text-indent: -.25in; line-height: normal;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 18.6667px;">Cyber Security in Nepal</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-align: justify; text-indent: -.25in; line-height: normal;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 18.6667px;">Promote security awareness across industry, academia &amp; public sector</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-align: justify; text-indent: -.25in; line-height: normal;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 18.6667px;">Research and analysis of cybersecurity incidents</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-align: justify; text-indent: -.25in; line-height: normal;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 18.6667px;">Gather and disseminate technical information on cybersecurity</span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-align: justify; text-indent: -.25in; line-height: normal;"><a href="https://csrinepal.org/" target="_blank" rel="noopener"><span style="font-family: Times New Roman, serif;"><span style="font-size: 18.6667px;">3. Center For Cybersecurity Research and Innovation</span></span></a></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; margin-left: .5in; text-align: justify; text-indent: -.25in; line-height: normal;"><span style="font-family: Times New Roman, serif;"><span style="font-size: 18.6667px;">CSRI can clearly determine cybersecurity issues and turn out applicable solutions and justify those solutions during an approach that everybody will perceive.</span></span></p>]]>
            </summary>
            <updated>2021-06-10T21:31:42+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[राष्ट्रिय सुरक्षाका लागि साइबर सुरक्षा]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/Cybersecurity:%20A%20National%20Security%20Issue" />
            <id>https://mail.onecovernepal.com/30</id>
            <author>
                <name> <![CDATA[Onlinekhabar]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;"><span style="color: #404040; font-family: mukta, sans-serif;"><span style="font-size: 20px;">सूचना तथा संचारप्रविधिको विकाससँगै मानव सभ्यताले ठूलो फड्को मारेको छ । महीनौं लगाएर पुग्ने चिठ्ठी इमेल मार्फत तुरुन्तै पुग्छ । शहरमा बस्ने डाक्टरले &lsquo;टेली मेडिसिन&rsquo; मार्फत दुर्गमका बासिन्दाको स्वास्थ्य परीक्षण गर्न सक्छन् । ताप्लेजुङका कृषकहरूले संसारभरि &lsquo;इ&ndash;कमर्स&rsquo; मार्फत आफ्नो उत्पादन बेच्न सक्छन् । सुर्खेतमा पढ्ने छोरीको स्कूल शुल्क हुम्लामा बस्ने आमाले आफ्नो मोबाइल मार्फत सजिलै तिर्न सक्छिन् ।</span></span></p>
<p><span style="color: #404040; font-family: mukta, sans-serif; font-size: 20px; text-align: justify;">For more details: <a href="https://www.onlinekhabar.com/2021/06/966944" target="_blank" rel="noopener">Click Here</a></span></p>]]>
            </summary>
            <updated>2021-06-09T09:18:13+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Cybersecurity Boot Camp]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/cybersecurity-boot-camp" />
            <id>https://mail.onecovernepal.com/31</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p class="MsoNormal" style="text-align: justify;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Cybersecurity Boot Camp</span></strong></p>
<p class="MsoNormal" style="text-align: justify;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Background </span></strong></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Boot camp is usually defined as a training program. It is an intense training session designed to prepare students for the practical reality of developments. Similarly, boot camp is also taken as a program or a situation that helps people become much better at doing something quickly.</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">In short, <strong>it&rsquo;s a short intensive course of training there are different types of boot camps with different functions</strong>. However, cybersecurity boot camps are one of them. Let&rsquo;s have a quick discussion on the topic of cybersecurity boot camp.</span></p>
<p class="MsoNormal" style="text-align: justify;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">&nbsp;</span></strong></p>
<p class="MsoNormal" style="text-align: justify;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Introduction</span></strong></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Cybersecurity boot camp is a special course that teaches students all the necessary technical skills or certifications needed to land cyber securities employment. These boot camps are usually certain intense often competed within 12 to 14 weeks. Cybersecurity boot camp focuses on hands-on learning with a priority on skills over theory. There are several cybersecurity boot camps all over the world. Some of them are listed below:</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Flatiron school</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Divergence academy</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Full-stack academy</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Georgia tech boot camp</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Secure set academy</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Tech launch</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Claim academy etc.</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">All these academics and institutions teach students the skill to become a cyber-security analyst or cybersecurity engineer by teaching skills like networking, system administration, threat management, etc.</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">&nbsp;</span></p>
<p class="MsoNormal" style="text-align: justify;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Objective </span></strong></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">1. For increase knowledge and to upskill </span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">2. To generate ideas </span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">3. Develop concrete implementation strategies for ideas</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">4. To expose to resources </span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">5. Build networking </span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">6. To prevent or mitigate harm or destruction of a computer, networks, application and, data&rsquo;s</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">7. Ensure that you are equipped with the focus and practical knowledge and skills that you need to meet your career goals</span></p>
<p class="MsoNormal" style="text-align: justify;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Important of cybersecurity boot camp</span></strong></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Though boot camps are more expensive, you&rsquo;ll learn the skilled employee is looking for. You&rsquo;ll be held accountable for your work and progress .these boot camp classes embrace collaboration and working with others. Advisors and instructions are always available to help you where you&rsquo;re stuck in case of participating in the boot camps. You&rsquo;ll be on a strict schedule to ensure you stay on target. Moreover, Career services are available at the best boot camps so you execute a smart job search. Cybersecurity boot camps play a vital role in graduating you with a full portfolio to show employers. As well as many boot camp focus on learning how to learn so you&rsquo;ll continue to improve as your career progress.</span></p>
<p class="MsoNormal" style="text-align: justify;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Roles of cybersecurity boot camps on career enhancement:</span></strong></p>
<p style="text-align: justify; vertical-align: baseline;"><strong><span style="font-size: 16.0pt; font-family: 'Arial',sans-serif; color: #2b2b2b; border: none windowtext 1.0pt; mso-border-alt: none windowtext 0in; padding: 0in; font-weight: normal; mso-bidi-font-weight: bold;">Cybersecurity boot camps are worth it if you want to change your career and are willing to work hard.&nbsp;</span></strong><span style="font-size: 16.0pt; font-family: 'Arial',sans-serif; color: #2b2b2b;">Boot camps are expensive, however, many of the best boot camps offer tuition flexibility and different payment options.&nbsp;</span></p>
<p style="text-align: justify; vertical-align: baseline;"><span style="font-size: 16.0pt; font-family: 'Arial',sans-serif; color: #2b2b2b;">As we mentioned earlier, you get out of a cyber-security boot camp what you put into it. Diligence, confidence, and perseverance are all important in a boot camp because boot camps are tough. But if you do commit to learning and keep your eye on the prize, there is no better and more efficient way to start a cyber-security career than to attend a cyber-security boot camp.</span></p>
<p style="text-align: justify; vertical-align: baseline;"><span style="font-size: 16.0pt; font-family: 'Arial',sans-serif; color: #2b2b2b;">All in all, cybersecurity boot camps are worth it if it is the right choice for your career goals and development. This industry is rapidly growing so the investment is worth it when you land that first job following completion of the program. Cybersecurity professionals are paid very well and average higher salaries than most tech roles throughout the US.</span></p>
<p style="text-align: justify; vertical-align: baseline;"><span style="font-size: 16.0pt; font-family: 'Arial',sans-serif; color: #2b2b2b;">Being a Cyber Security professional requires a strong mix of hard and soft skills as these folks are often tasked with implementing techniques to keep their company safe from threats as well as educating the rest of the company on how to comply with best practices that are taught in cybersecurity boot camp.</span></p>]]>
            </summary>
            <updated>2021-06-09T15:22:21+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Cybersecurity Workshop Nepal]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/cybersecurity-workshop-nepal" />
            <id>https://mail.onecovernepal.com/32</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p class="MsoNormal"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 18.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Cybersecurity workshop Nepal</span></strong></p>
<p class="MsoNormal"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Background </span></strong></p>
<p class="MsoNormal"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">The Workshop is usually a brief intensive education program for a relatively small group of people that focuses especially on technique and skills in a particular field. Similarly, a workshop is also taken as a program or a situation that helps people to become much better at doing something in a short period of time.</span></p>
<p class="MsoNormal"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">In short, it&rsquo;s a short intensive course of training there are different types of workshops with different functions. However, a cybersecurity workshop is one of them. Let&rsquo;s have a discussion on the topic of the cybersecurity workshop.</span></p>
<p class="MsoNormal"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Introduction </span></strong></p>
<p class="MsoNormal"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Cybersecurity workshop based on to secure your personal information, conduct online activities use of webcams and public WI FI. This workshop tasks participants through the main feature of online scams, social engineering techniques, and phishing activities. In cybersecurity workshop, participants will learn about common cyber threats and counter defense tools on how to keep accounts and credentials safe. Also how to avoid the common, yet dangerous threats and malicious scams. List of organization of the world that conduct cybersecurity workshop:</span></p>
<p class="MsoNormal" style="text-indent: -.25in; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in; background: white; margin: 0in 0in 3.0pt 0in;"><!-- [if !supportLists]--><span style="font-size: 10.0pt; mso-bidi-font-size: 16.0pt; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; color: #202124;"><span style="mso-list: Ignore;">&middot;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; font-family: 'Arial',sans-serif; mso-fareast-font-family: 'Times New Roman'; color: #202124;">Peter Kiewit Institute</span></p>
<p class="MsoNormal" style="text-indent: -.25in; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in; background: white; margin: 0in 0in 3.0pt 0in;"><!-- [if !supportLists]--><span style="font-size: 10.0pt; mso-bidi-font-size: 16.0pt; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; color: #202124;"><span style="mso-list: Ignore;">&middot;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; font-family: 'Arial',sans-serif; mso-fareast-font-family: 'Times New Roman'; color: #202124;">The SANS Institute</span></p>
<p class="MsoNormal" style="text-indent: -.25in; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in; background: white; margin: 0in 0in 3.0pt 0in;"><!-- [if !supportLists]--><span style="font-size: 10.0pt; mso-bidi-font-size: 16.0pt; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; color: #202124;"><span style="mso-list: Ignore;">&middot;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; font-family: 'Arial',sans-serif; mso-fareast-font-family: 'Times New Roman'; color: #202124;">Computer Operations, Audit, and&nbsp;<span style="mso-bidi-font-weight: bold;">Security</span>&nbsp;Technology (COAST)</span></p>
<p class="MsoNormal" style="text-indent: -.25in; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in; background: white; margin: 0in 0in 3.0pt 0in;"><!-- [if !supportLists]--><span style="font-size: 10.0pt; mso-bidi-font-size: 16.0pt; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; color: #202124;"><span style="mso-list: Ignore;">&middot;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; font-family: 'Arial',sans-serif; mso-fareast-font-family: 'Times New Roman'; color: #202124;">CERT Program</span></p>
<p class="MsoNormal" style="text-indent: -.25in; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in; background: white; margin: 0in 0in 3.0pt 0in;"><!-- [if !supportLists]--><span style="font-size: 10.0pt; mso-bidi-font-size: 16.0pt; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; color: #202124;"><span style="mso-list: Ignore;">&middot;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; font-family: 'Arial',sans-serif; mso-fareast-font-family: 'Times New Roman'; color: #202124;">The Computer&nbsp;<span style="mso-bidi-font-weight: bold;">Security</span>&nbsp;Institute</span></p>
<p class="MsoNormal" style="text-indent: -.25in; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in; background: white; margin: 0in 0in 3.0pt 0in;"><!-- [if !supportLists]--><span style="font-size: 10.0pt; mso-bidi-font-size: 16.0pt; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; color: #202124;"><span style="mso-list: Ignore;">&middot;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; font-family: 'Arial',sans-serif; mso-fareast-font-family: 'Times New Roman'; color: #202124;">The Institute for&nbsp;<span style="mso-bidi-font-weight: bold;">Security</span>&nbsp;Technology Studies (ISTS)</span></p>
<p class="MsoNormal" style="text-indent: -.25in; line-height: normal; mso-list: l1 level1 lfo2; tab-stops: list .5in; background: white; margin: 0in 0in 3.0pt 0in;"><!-- [if !supportLists]--><span style="font-size: 10.0pt; mso-bidi-font-size: 16.0pt; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; color: #202124;"><span style="mso-list: Ignore;">&middot;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; font-family: 'Arial',sans-serif; mso-fareast-font-family: 'Times New Roman'; color: #202124;">National&nbsp;<span style="mso-bidi-font-weight: bold;">Security</span>&nbsp;Agency Science of&nbsp;<span style="mso-bidi-font-weight: bold;">Security</span>&nbsp;Initiative</span></p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif;">Objective </span></strong></p>
<p class="MsoListParagraphCxSpFirst" style="text-indent: -.25in; mso-list: l0 level1 lfo1;"><!-- [if !supportLists]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial; color: black;"><span style="mso-list: Ignore;">1.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">Exchange information and experiences related to the development and implementation of criteria</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -.25in; mso-list: l0 level1 lfo1;"><!-- [if !supportLists]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial; color: black;"><span style="mso-list: Ignore;">2.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">To bring together research, practitioners, the private sector, and donors that have been working on efforts to promote cybersecurity.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -.25in; mso-list: l0 level1 lfo1;"><!-- [if !supportLists]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial; color: black;"><span style="mso-list: Ignore;">3.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">For network</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -.25in; mso-list: l0 level1 lfo1;"><!-- [if !supportLists]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial; color: black;"><span style="mso-list: Ignore;">4.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">Expose to resources</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -.25in; mso-list: l0 level1 lfo1;"><!-- [if !supportLists]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial; color: black;"><span style="mso-list: Ignore;">5.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">Increase skills </span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -.25in; mso-list: l0 level1 lfo1;"><!-- [if !supportLists]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial; color: black;"><span style="mso-list: Ignore;">6.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">ensure that you are equipped with the focus and practical knowledge and skills that you need to meet your career goals<span style="mso-spacerun: yes;">&nbsp; </span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -.25in; mso-list: l0 level1 lfo1;"><!-- [if !supportLists]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial; color: black;"><span style="mso-list: Ignore;">7.<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">to build a culture of security</span></p>
<p class="MsoListParagraphCxSpLast"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">&nbsp;</span></p>
<p class="MsoNormal"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">Important of cybersecurity workshop</span></strong></p>
<p class="MsoListParagraphCxSpFirst"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">Though previous knowledge in cybersecurity would be helpful but not essential that&rsquo;s why workshops makes clear and essential. You&rsquo;ll learn about the challenging objectives that you may come across in your role.</span> <span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">Advisors and instructions are always available to help you where you&rsquo;re stuck in case of participating in the workshop. You&rsquo;ll be on a strict schedule to ensure you stay on target. Moreover, Career services are available at the best workshop so you execute a smart job search. As well as individuals will be able to enhance their capability and knowledge during this career.</span></p>
<p class="MsoListParagraphCxSpLast"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">These workshop classes embrace collaboration and working with others.</span></p>
<p class="MsoNormal"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 18.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">&nbsp;</span></strong></p>
<p class="MsoNormal"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 18.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">&nbsp;</span></strong></p>
<p class="MsoNormal"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 18.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">Roles of cybersecurity workshop</span></strong></p>
<p class="MsoNormal"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">A Cybersecurity workshop is worth it if it is the right choice for your career goals and development. This industry is rapidly growing so the investment is worth it when you land that first job following completion of the program. Cybersecurity professionals are paid very well , and average higher salaries than most tech roles throughout the US.</span></p>
<p class="MsoNormal"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">As well as Cyber Security professional requires a strong mix of hard and soft skills as these folks are often tasked with implementing techniques to keep their company safe from threats as well as educating the rest of the company on how to comply with best practices which are taught in cybersecurity workshop.</span></p>
<p class="MsoNormal"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">&nbsp;</span></strong></p>
<p class="MsoNormal"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 18.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">Conclusion </span></strong></p>
<p class="MsoNormal"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">Cybersecurity is a complex subject whose understanding requires knowledge and expertise from multiple disciplines. But not limited to computer science and information technology, psychology, economics, organizational behavior, political science, engineering, sociology, decision sciences, international relations, and law. In practice, although technical measures are an important element, cybersecurity is not primarily a technical matter, although it is easy for policy analysts and others to get lost in the technical details. </span><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: #3c3b3b; background: white;">During the program of the workshop, the trainees were able to have a piece of good knowledge about the core security techniques, Monitoring and detection, incident response and threat hunting, and security management. At the end of the program, the trainees were honored and handed over knowledge to attendance</span><span style="font-size: 16.0pt; line-height: 107%; font-family: 'asd',serif; color: #3c3b3b; background: white;">.</span></p>
<p class="MsoListParagraph"><span style="font-size: 16.0pt; line-height: 107%; font-family: 'Arial',sans-serif; color: black; background: white;">&nbsp;</span></p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">&nbsp;</p>]]>
            </summary>
            <updated>2021-06-09T15:58:22+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Join LogPoint ThinkIn Conference]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/join-logpoint-thinkin-conference" />
            <id>https://mail.onecovernepal.com/33</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p><span style="color: #050505; font-family: 'Segoe UI Historic', 'Segoe UI', Helvetica, Arial, sans-serif; font-size: 15px; white-space: pre-wrap;">Join LogPoint ThinkIn Conference starting from 4:45 PM local time where Mr. Basudev Raut will be speaking on Advanced Correlation Features in LogPoint with Machine Learning Capabilities @ 6:55 PM Nepal local time.</span></p>
<p><span style="color: #050505; font-family: 'Segoe UI Historic', 'Segoe UI', Helvetica, Arial, sans-serif; font-size: 15px; white-space: pre-wrap;">Here is the link: <a href="https://vimeo.com/event/935974/e5a2c0281d?fbclid=IwAR1OzKrhUD3auMVZpO9MDNbWK8vTvHpoAthQDj8u9HF5L44ua028Lc7OIFk" target="_blank" rel="noopener">Click Here</a></span></p>]]>
            </summary>
            <updated>2021-06-09T16:57:01+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Download the National Cybersecurity Policy 2078 Draft]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/download-the-national-cybersecurity-policy-2078-draft" />
            <id>https://mail.onecovernepal.com/34</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p><span style="color: #202124; font-family: Google Sans, Roboto, RobotoDraft, Helvetica, Arial, sans-serif;"><span style="font-size: 22px; font-variant-ligatures: no-contextual;">Download the National Cybersecurity Policy 2078 Draft. राष्ट्रिय साइबर सुरक्षा नीति,२०७८-मस्यौदा उपर राय, सुझाव, पृष्ठपोषण उपलब्ध गराउने बारे.</span></span></p>
<p>Download: <a href="https://drive.google.com/file/d/1SMEWNVJyI-rWbjb2fWAcj2xAFnG11XEx/view?usp=sharing" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-06-10T08:24:15+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Public Notice for Selection of Cyber Security Consulting Firms]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/public-notice-for-selection-of-cyber-security-consulting-firms" />
            <id>https://mail.onecovernepal.com/35</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>Public Notice for Selection of Cyber Security Consulting Firms.</p>
<p>Download the Notice: <a href="https://nta.gov.np/en/public-notice-20210505/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-06-10T16:04:20+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Cyber Insurance in Nepal]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/cyber-insurance-in-nepal" />
            <id>https://mail.onecovernepal.com/36</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p class="MsoNormal" style="text-align: justify;">Generally, the term Insurance is a contract, represented by a policy in which an individual or entity receives financial protection or reimbursement against losses from an insurance company. The company pools client&rsquo;s risk making payments more affordable for the insured.</p>
<p class="MsoNormal" style="text-align: justify;">Insurance is a legal agreement between two parties i.e. the insurance company and individual.in this, the insurance company promises to make good the losses of the insured on happening of the insured accidents. An accident is an event that causes a loss.it can be the death of the policyholder or damage of the property. It&rsquo;s called an accident because there&rsquo;s uncertainty regarding the happening of the event.</p>
<h3>Objective of insurance</h3>
<p class="MsoNormal" style="text-align: justify;">1.&nbsp; &nbsp;Granting security to people</p>
<p class="MsoNormal" style="text-align: justify;">2.&nbsp; &nbsp;Minimization of losses</p>
<p class="MsoNormal" style="text-align: justify;">3.&nbsp; &nbsp;Diversifying the risk</p>
<p class="MsoNormal" style="text-align: justify;">4.&nbsp; &nbsp;Reduces the anxiety and fear</p>
<p class="MsoNormal" style="text-align: justify;">5.&nbsp; &nbsp;Generation capital</p>
<h3 class="MsoNormal" style="text-align: justify;">Types of insurances</h3>
<p class="MsoNormal" style="text-align: justify;">1. Life insurance</p>
<p class="MsoNormal" style="text-align: justify;">2. Health insurance</p>
<p class="MsoNormal" style="text-align: justify;">3. Car insurance</p>
<p class="MsoNormal" style="text-align: justify;">4. Education insurance</p>
<p class="MsoNormal" style="text-align: justify;">5. Home insurance, etc.</p>
<h3>Cyber insurance</h3>
<p class="MsoNormal" style="text-align: justify;">Every business requires a special type of insurance, policies that insure against a specific type of harm or risk faced by a particular business. There are several types of insurance, among all cyber insurance is one of them. Cyber insurance basically covers your business &lsquo;liability for a data breach involving sensitive customer information, such as social security number credit card number account number driver&rsquo;s license number, and health record.</p>
<p class="MsoNormal" style="text-align: justify;">Cyber insurance help in notifying the customer about a data breach, restoring the personal identities of the affected customer. Similarly, cyber insurance recovers compromised data as well as repairs damaged computer systems.</p>
<p class="MsoNormal" style="text-align: justify;">Moreover, cyber insurance is also known as cyber liability insurance or policy that helps protect organizations from fallout from cyber-attacks and hacking threats. Having a cyber-insurance policy can help minimize business disruption during the cyber incidents and their aftermath. Meanwhile it also potentially cover the financial cost of some element of dealing with the attack and recovering from it.</p>
<h3>Important of cyber insurance</h3>
<p class="MsoNormal" style="text-align: justify;">Cyber-insurance is a risk management technique by which network user risks are transferred to an insurance company, in return for a fee, i.e., the insurance premium. Examples of potential cyber-insurers might include ISP, the cloud provider, traditional insurance organizations. Promoters of cyber-insurance believe that cyber-insurance would lead to the design of insurance contracts that would shift appropriate amounts of self-defense liability to the clients, thereby making cyberspace more powerful. Here the term &lsquo;self-defense' implies the efforts by a network user to secure their system through technical solutions such as anti-virus and anti-spam software, firewalls, using secure operating systems, etc.</p>
<h3>Conclusion</h3>
<p class="MsoNormal" style="text-align: justify;">Hence, Cyber insurance is a form of insurance for businesses and individuals against internet-based risks. The most common risk that is insured against is data breaches. Cyber insurance typically includes losses from network security breaches, theft of intellectual property, and loss of privacy.</p>
<p class="MsoNormal" style="text-align: justify;">&nbsp;</p>]]>
            </summary>
            <updated>2021-06-10T21:26:43+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Bid Document – Cyber Security Simulation Lab for Telecom Industry]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/bid-document-cyber-security-simulation-lab-for-telecom-industry" />
            <id>https://mail.onecovernepal.com/37</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>Bid Document &ndash; Cyber Security Simulation Lab for Telecom Industry (CERT for Telecom Industry)</p>
<p>Download link: <a href="https://nta.gov.np/wp-content/uploads/2021/03/BID-DOCUMENT-Cyber-Security-Lab.pdf" target="_blank" rel="noopener">Click Here</a></p>
<p>&nbsp;</p>]]>
            </summary>
            <updated>2021-06-11T05:24:30+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Panel Formed to Study Cyber Security Policy in Nepal]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/panel-formed-to-study-cyber-security-policy-in-nepal" />
            <id>https://mail.onecovernepal.com/38</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>Panel Formed to Study Cyber Security Policy in Nepal. Newly-appointed Minister of Communications and Technology Nainakala Thapa has formed a task force to study Cyber Security Policy, 2021, under the leadership of Communications and Technology <a href="https://ictframe.com/first-decision-of-the-newly-appointed-minister-of-mocit/" target="_blank" rel="noopener">Secretary Hari Prasad Basyal.</a></p>
<p>Source: <a href="https://thehimalayantimes.com/nepal/panel-formed-to-study-cyber-security-policy" target="_blank" rel="noopener">The Himalayan Times</a></p>
<p>&nbsp;</p>]]>
            </summary>
            <updated>2021-06-11T09:14:49+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[North Atlantic Treaty Organization - Cyber Defence]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/north-atlantic-treaty-organization-cyber-defence" />
            <id>https://mail.onecovernepal.com/39</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>Cyber threats to the security of the Alliance are becoming more frequent, complex, destructive, and coercive. NATO will continue to adapt to the evolving cyber threat landscape</p>
<p>Here is the link: <a href="https://www.nato.int/cps/en/natohq/topics_78170.htm" target="_blank" rel="noopener">NATO Cyber Defence</a></p>]]>
            </summary>
            <updated>2021-06-12T14:52:20+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Cyber Security Initiative of NTA - Cybersecurity Policy Draft]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/cyber-security-initiative-of-nta-cybersecurity-policy-draft" />
            <id>https://mail.onecovernepal.com/40</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>Cyber Security Initiative of NTA - Cybersecurity Policy Draft</p>
<p>&nbsp;</p>
<p>Download the link: <a href="https://nta.gov.np/wp-content/uploads/2018/05/Nepal-Cybersecurity-Policy-Draft.pdf" target="_blank" rel="noopener">National Cybersecurity Policy 2016</a></p>]]>
            </summary>
            <updated>2021-06-12T16:54:32+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Information Security Awareness Training Program]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/information-security-awareness-training-program" />
            <id>https://mail.onecovernepal.com/41</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p class="font_5" style="margin: 0px; padding: 0px; border: 0px; outline: 0px; vertical-align: baseline; background: transparent; pointer-events: auto; font-size: 28px; line-height: normal; color: rgb(var(--color_24)); text-align: justify;"><strong><em><span style="font-family: roboto-bold, roboto, sans-serif;"><span style="font-size: 26px;">Information security Awareness Training Platform that Reduces phishing and ransomware attacks by educating and</span></span><span style="font-family: roboto-bold, roboto, sans-serif;"><span style="font-size: 26px;"> awarene</span></span><span style="font-family: roboto-bold, roboto, sans-serif;"><span style="font-size: 26px;">ss</span></span><span style="font-family: roboto-bold, roboto, sans-serif;"><span style="font-size: 26px;"> of your employees on cyber threats.</span></span></em></strong></p>
<p class="font_5" style="margin: 0px; padding: 0px; border: 0px; outline: 0px; vertical-align: baseline; background: transparent; pointer-events: auto; font-size: 28px; line-height: normal; color: rgb(var(--color_24)); text-align: justify;"><strong><span style="font-family: roboto-bold, roboto, sans-serif;"><span style="font-size: 26px;"><em>Are you looking for a security awareness training solution for your company?</em>&nbsp;</span></span></strong></p>
<p><span style="font-family: roboto-bold, roboto, sans-serif;"><span style="font-size: 26px;">Email us: onecovernepal@gmail.com</span></span></p>]]>
            </summary>
            <updated>2021-06-15T09:17:46+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Reduce Business Risk by Fixing 3 Critical Endpoint-to-Cloud Security Requirements]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/reduce-business-risk-by-fixing-3-critical-endpoint-to-cloud-security-requirements" />
            <id>https://mail.onecovernepal.com/42</id>
            <author>
                <name> <![CDATA[Onecover nepal]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: 33.75pt; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; vertical-align: baseline; text-align: justify;"><span style="font-size: 18.0pt; mso-bidi-font-size: 22.5pt; font-family: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman'; color: #2b2d41; letter-spacing: -.25pt; mso-font-kerning: 18.0pt; mso-bidi-font-weight: bold;">Since last year, every businesses and organization has to adapt remote work system due to covid-19.But, working in the internet can put us on cybersecurity related risk. lookout recommends considering these three factors to minimize risk:</span></p>
<p class="MsoListParagraphCxSpFirst" style="margin-bottom: 0.0001pt; line-height: 33.75pt; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; vertical-align: baseline; text-align: justify;"><span style="font-size: 18.0pt; mso-bidi-font-size: 22.5pt; font-family: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman'; color: #2b2d41; letter-spacing: -.25pt; mso-font-kerning: 18.0pt; mso-bidi-font-weight: bold;">Complete visibility</span></p>
<p class="MsoListParagraphCxSpLast" style="margin-bottom: 0.0001pt; line-height: 33.75pt; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; vertical-align: baseline; text-align: justify;"><span style="font-size: 18.0pt; mso-bidi-font-size: 22.5pt; font-family: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman'; color: #2b2d41; letter-spacing: -.25pt; mso-font-kerning: 18.0pt; mso-bidi-font-weight: bold;">Unified insights&nbsp;</span></p>
<p class="MsoListParagraphCxSpLast" style="margin-bottom: 0.0001pt; text-indent: -0.25in; line-height: 33.75pt; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; vertical-align: baseline; text-align: justify;"><span style="font-size: 18.0pt; mso-bidi-font-size: 22.5pt; line-height: 115%; font-family: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman'; color: #2b2d41; letter-spacing: -.25pt; mso-font-kerning: 18.0pt; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-bidi-font-weight: bold;">&nbsp; &nbsp; Secure access to empower productivity</span></p>
<p style="text-align: justify;">&nbsp;</p>
<p style="text-align: justify;"><span style="font-size: 18.0pt; mso-bidi-font-size: 22.5pt; line-height: 115%; font-family: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman'; color: #2b2d41; letter-spacing: -.25pt; mso-font-kerning: 18.0pt; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-bidi-font-weight: bold;">Read more: <a href="https://thehackernews.com/2021/06/reduce-business-risk-by-fixing-3.html" target="_blank" rel="noopener">thehackernews</a></span></p>]]>
            </summary>
            <updated>2021-06-25T06:19:19+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Data breach at US eye clinic impacting 500,000 patients potentially exposed private medical information]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/data-breach-at-us-eye-clinic-impacting-500000-patients-potentially-exposed-private-medical-information" />
            <id>https://mail.onecovernepal.com/43</id>
            <author>
                <name> <![CDATA[Onecover nepal]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;"><span style="color: #324d5c; font-family: Arial, Helvetica, sans-serif; font-size: 16px;">US healthcare provider Wolfe Eye Clinic is affected by data breach&nbsp;</span><span style="color: #324d5c; font-family: Arial, Helvetica, sans-serif; font-size: 16px;">happened on February 8, 2021.</span><span style="color: #324d5c; font-family: Arial, Helvetica, sans-serif; font-size: 16px;">The advisory reads:</span><span style="color: #324d5c; font-family: Arial, Helvetica, sans-serif; font-size: 16px;">&ldquo;Out of an abundance of caution, we are also notifying all potentially affected individuals and have begun mailing letters to everyone whose information may have been compromised because of this incident.&rdquo;</span></p>
<p style="text-align: justify;"><span style="color: #324d5c; font-family: Arial, Helvetica, sans-serif; font-size: 16px;">Read more: <a href="https://portswigger.net/daily-swig/data-breach-at-us-eye-clinic-impacting-500-000-patients-potentially-exposed-private-medical-information" target="_blank" rel="noopener">Click here</a></span></p>]]>
            </summary>
            <updated>2021-06-25T05:59:49+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Malicious Cryptominers Target Software Repositories to Burn a Hole in Your Wallet]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/malicious-cryptominers-target-software-repositories-to-burn-a-hole-in-your-wallet" />
            <id>https://mail.onecovernepal.com/44</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>25 June 2021, Kathmandu&nbsp;</p>
<p>Are you a Developer? Do you use open-source code repositories?</p>
<p>If you use PyPI, GitHub, RubyGems or any other open-source code repositories, then you have to be aware of the threads and malicious package those could trigger a supply-chain attack jeopardizing your information.</p>
<p>For more Information:&nbsp;<a href="https://cyware.com/news/malicious-cryptominers-target-software-repositories-to-burn-a-hole-in-your-wallet-0b9b0c8c" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-06-25T17:26:49+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[EU wants emergency team for &#039;nightmare&#039; cyber-attacks]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/eu-wants-emergency-team-for-nightmare-cyber-attacks" />
            <id>https://mail.onecovernepal.com/45</id>
            <author>
                <name> <![CDATA[Onecover nepal]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>&nbsp;</p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 13.5pt; line-height: 115%; font-family: 'Georgia','serif'; color: #222222; background: white;">The Colonial Pipeline Company reported on May 7 that it was the victim of a &ldquo;cybersecurity attack&rdquo; that &ldquo;involves ransomware,&rdquo; forcing the company to take some systems offline and disabling the pipeline. After the incident The US government has also recently formed a Ransomware Task Force, while the UK's National Cyber Security Centre warns that ransomware is the biggest cyber-threat to UK. That&rsquo;s why<span style="mso-bidi-font-weight: bold;"> the European Commission has announced plans to build a Joint Cyber Unit to tackle large scale cyber-attacks. European Commission vice-president Margaritis Schinas said last month's hack on US fuel supplies was 'the nightmare&rsquo; scenario that we have to prepare against.</span></span></p>
<p class="MsoNormal" style="text-align: justify;">&nbsp;</p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 13.5pt; line-height: 115%; font-family: 'Georgia','serif'; color: #222222; background: white;"><span style="mso-bidi-font-weight: bold;">Read more: <a href="https://www.bbc.com/news/technology-57583158" target="_blank" rel="noopener">Click here</a></span></span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 13.5pt; line-height: 115%; font-family: 'Georgia','serif'; color: #222222; background: white;"><span style="mso-spacerun: yes;">&nbsp;</span><span style="mso-spacerun: yes;">&nbsp;</span></span></p>
<p>&nbsp;</p>]]>
            </summary>
            <updated>2021-06-25T17:10:02+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Crackonosh malware abuses Windows Safe mode to quietly mine for cryptocurrency]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/crackonosh-malware-abuses-windows-safe-mode-to-quietly-mine-for-cryptocurrency" />
            <id>https://mail.onecovernepal.com/46</id>
            <author>
                <name> <![CDATA[One Cover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 14.0pt; mso-bidi-font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman','serif';">Crypto mining malware &ldquo;dubbed Crackonosh&rdquo; is abusing window&rsquo;s safe mode quietly to mine cryptocurrency. The malware is circulated since 2018 especially from torrent sites.</span> <span style="font-size: 14.0pt; mso-bidi-font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman','serif';">The infection chain begins with the drop of an installer and a script that modifies the Windows registry to allow the main malware executable to run in Safe mode.</span></p>
<p class="MsoNormal" style="text-align: justify;">&nbsp;</p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-family: 'Times New Roman','serif';">Read more :&nbsp;<a href="https://www.zdnet.com/article/crackonosh-malware-abuses-windows-safe-mode-to-quietly-mine-for-cryptocurrency/" target="_blank" rel="noopener">Click here</a></span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-family: 'Times New Roman','serif';">&nbsp;</span></p>]]>
            </summary>
            <updated>2021-06-26T20:49:02+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[A New Attack on AI-driven Facial Recognition System]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/a-new-attack-on-ai-driven-facial-recognition-system" />
            <id>https://mail.onecovernepal.com/47</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>26 June 20201, Kathmandu</p>
<p style="text-align: justify;">No matter what security measure we are using, there always be a new way to penetrate through that system. And its good to know that researchers are helping to find vulnerability in these type of systems. This will help to deal with problems existing in security systems.</p>
<p>For more Information:<a href="https://cyware.com/news/a-new-attack-on-ai-driven-facial-recognition-systems-4ece656a" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-06-26T20:47:16+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[An Unusual File Attachment Is Being Used in Phishing Attacks]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/an-unusual-file-attachment-is-being-used-in-phishing-attacks" />
            <id>https://mail.onecovernepal.com/48</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">The awareness of cybersecurity is growing day by day. All the organizations and people are implementing advanced security majors. Even so, attackers adapt to the new security system. And WIM attachment file is one of its examples. WIM contains Agent Tesla malware that can bypass detection from security software, and it can take full control over compromised systems and exfiltrate data.</p>
<p>Read more: <a href="https://heimdalsecurity.com/blog/an-unusual-file-attachment-is-being-used-in-phishing-attacks/?web_view=true" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-06-26T20:49:20+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Dutch Group Launches Data Harvesting Claim Against TikTok]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/dutch-group-launches-data-harvesting-claim-against-tiktok" />
            <id>https://mail.onecovernepal.com/49</id>
            <author>
                <name> <![CDATA[One Cover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;"><span style="font-size: 14.0pt; line-height: 115%; font-family: 'Trebuchet MS','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;">A Dutch consumer organization is launching a 1.5 billion euro ($1.8 billion) claim against TikTok over what it alleges is unlawful harvesting of personal data of users of the popular video sharing platform.</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 14.0pt; line-height: 115%; font-family: 'Trebuchet MS','sans-serif'; mso-bidi-font-family: 'Times New Roman';">The consumer organization and privacy foundation are demanding that TikTok pay damages to Dutch children and delete what they call unlawfully collected personal data. They say if TikTok does not comply, they will take the company to court.</span></p>
<p style="text-align: justify;"><span style="color: #111111; font-family: Roboto, 'Helvetica Neue', Helvetica, sans-serif; font-size: 18px;">Read more : <a href="https://www.securityweek.com/dutch-group-launches-data-harvesting-claim-against-tiktok" target="_blank" rel="noopener">Click here</a></span></p>]]>
            </summary>
            <updated>2021-06-27T05:57:52+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Crypto-Mining Malware in Cracked Games]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/crypto-mining-malware-in-cracked-games" />
            <id>https://mail.onecovernepal.com/50</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Malware known as Crackonosh is distributed by scammers through the pirated title of cracked versions of popular games. This malware secretly mines cryptocurrency using the infected systems.</p>
<p style="text-align: justify;">According to the Avast security company, it&rsquo;s already on tens of thousands of devices around the world and spreading to roughly 800 more systems a day.</p>
<p style="text-align: justify;">For more Information: <a href="https://www.pcmag.com/news/scammers-distribute-crypto-mining-malware-via-cracked-games" target="_blank" rel="noopener">Click here</a></p>]]>
            </summary>
            <updated>2021-06-27T11:33:08+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Two New IcedID Campaigns Discovered]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/two-new-icedid-campaigns-discovered" />
            <id>https://mail.onecovernepal.com/51</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">IcedID is a modular banking trojan that targets user financial information and is capable of acting as a dropper for other malware.</p>
<p style="text-align: justify;">Recently, Kaspersky researchers discovered two new spam campaigns. The first campaign (DotDat) spread ZIP attachments and in the second campaign, spam emails included links to hacked websites with malicious archives named documents[.]zip0, doc-XX[.]zip, document-XX[.]zip.</p>
<p style="text-align: justify;">Read more:&nbsp;<a href="https://cyware.com/news/two-new-icedid-campaigns-making-rounds-in-the-wild-93868644" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-06-28T15:00:17+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Improvements in windows 11 security features]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/improvements-in-windows-11-security-features" />
            <id>https://mail.onecovernepal.com/52</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Microsoft has officially announced Windows 11. This new OS will be a free upgrade for Windows 10 users and will start rolling out as early as October 20. Microsoft has assured windows 11 will come with new user-friendly design, features, and security improvements.</p>
<p style="text-align: justify;">Cybersecurity experts reacted to the sneak peek of Windows 11 security measures and offered preliminary feedbacks. Security experts pointed out some smart decisions and some security flaws made by Microsoft on its security majors. Hopefully, this will help to improve the Windows 11 security even more.</p>
<p>Read More:&nbsp;<a href="https://www.bankinfosecurity.com/sizing-up-security-features-slated-for-windows-11-a-16943?&amp;web_view=true" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-06-29T16:15:15+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[The Coronavirus Scams]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/the-coronavirus-scams" />
            <id>https://mail.onecovernepal.com/53</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">The COVID-19 pandemic made a great acceleration towards digital transformation, with technology at the forefront of countries&rsquo; response to the crisis. Sametime scammers are coming with a new way to take advantage of this pandemic situation. They use text or e-mail, and in most cases, a URL pointed to a fake institutional website that requests debit/credit card details.</p>
<p style="text-align: justify;">Since the outbreak of the pandemic in 2019 there have been reports of scams impersonating public authorities such as the World Health Organisation, and organizations such as supermarkets and airlines targeting support platforms such as PPE and offering COVID-19 cures. They often target the public, who are now socializing and spending more time online in general, as well as the increased population of people who are working from home.</p>
<p>Read More:&nbsp;<a href="https://www.goodhousekeeping.com/uk/consumer-advice/a31702083/coronavirus-scams-fraud/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-06-30T07:37:56+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Unofficial Facebook Page Of Nepal Rastra Bank (NRB)]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/unofficial-facebook-page-of-nepal-rastra-bank-nrb" />
            <id>https://mail.onecovernepal.com/54</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Nepal Rastra Bank (NRB), the Central Bank of Nepal, was established in 1956. NRB is actively regulating and supervising all commercial banks, development banks, financial institutions, and microfinance companies. With the number of deposit accounts over 70% of the total population of Nepal, NRB is providing financial services all over the country.</p>
<p style="text-align: justify;">Facebook is a very popular social media platform. It would be very beneficial for both banks and customers with an official Facebook page of the bank to engage in the banking relationship. But there is no official Facebook Page of NRB. However, there is an unofficial page named 'Nepal Rastra Bank' on Facebook. The public can be easily be confused by this page. The post and contains can create delusion information about the NRB in the general public.</p>
<p style="text-align: justify;">The Nepal Rastra Bank has nothing to do with this page. The Bank has issued a notice not to believe in any content on that page. Also, the bank has notified that the action will be taken against the responsible person or group following prevailing cybersecurity law.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://www.nrb.org.np/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-01T21:47:05+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[GitHub Copilot]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/github-copilot" />
            <id>https://mail.onecovernepal.com/55</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Developed in collaboration with OpenAI, powered by OpenAI Codex, GitHub is launching a technical preview of GitHub Copilot. It a new AI pair programmer that helps you write better code. GitHub Copilot draws context from the code you are working on and suggests whole lines or entire functions. It helps you quickly discover alternative ways to solve problems, write tests, and explore new APIs without having to tediously tailor a search for answers on the internet. As you type, it adapts to the way you write code to help you complete your work faster.</p>
<p style="text-align: justify;">GitHub Copilot understands significantly more context than most code assistants. It converts comments to code, autofill for repetitive code, tests without the toil, and many more. GitHub Copilot works with a broad set of frameworks and languages, but this technical preview works especially well for Python, JavaScript, TypeScript, Ruby and Go.</p>
<p>For more Information:&nbsp;<a href="https://copilot.github.com/?fbclid=IwAR3DTr_0-bbjD6OxllQFAu-TgV4NF_vY9Xc8aljQP2H1FQnTPGTewofnRuo" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-02T10:31:01+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Official Website Of Purbanchal University Got hacked]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/official-website-of-purbanchal-university-got-hacked" />
            <id>https://mail.onecovernepal.com/56</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p>Friday, July 2, 2021</p>
<p>Today the official website of Purbanchal University, Biratnagar, Nepal, has been hacked by Hunter Umer.</p>
<p>The hacker has left a Facebook account with a message that says,</p>
<p>"Website Hacked By Hunter Umer (Click Me For Proof)</p>
<p>Students Don't Worry For Change Your Results Just Contact With Me...</p>
<p>https:///www.facebook.com/hunter.umar786"</p>
<p>Currently, the hacked website has been taken down. You can not reach the Purbanchal University webpage right now.</p>
<p>Hacker's Facebook account:&nbsp;<a href="https://www.facebook.com/hunter.umar786">Click here</a></p>]]>
            </summary>
            <updated>2021-07-02T19:20:28+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Indian Military Targeted With Spyware By Hackers]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/indian-military-targeted-with-spyware-by-hackers" />
            <id>https://mail.onecovernepal.com/57</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Cyber and 360 Core Security Lab discovered active spyware campaign that is mainly targeting Indian military personnel. The spyware campaign has been active since January and detected in dating and instant messaging apps. According to researchers, the recent version of PJobRAT spyware was first observed in December 2019.</p>
<p style="text-align: justify;">Researchers detected that this recent variant is disguising as a dating app known as Trendbanter, as well as the Signal app, for non-resident Indians. The spyware mimics other apps to fool unsuspecting users. Moreover, through third-party app stores and other mediums, including malicious URLs and SMS, the attackers had accomplished their propagation goals in which they distributed multiple spyware.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://cybleinc.com/2021/06/22/android-application-disguised-as-dating-app-targets-indian-military-personnel/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-03T12:13:57+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Vulnerable Code In Windows]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/vulnerable-code-in-windows" />
            <id>https://mail.onecovernepal.com/58</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Microsoft has assigned CVE-2021-34527 to the print spooler remote code execution vulnerability known as "PrintNightmare" and confirmed that the offending code is lurking in all versions of Windows.</p>
<p style="text-align: justify;">Microsoft also confirmed that this nasty was distinct from CVE-2021-1675, which was all about a different attack vector and a different vulnerability in RpcAddPrinterDriverEx(). The June 2021 Security update dealt with that, according to Microsoft, and did not introduce the new badness. That had existed prior to the update.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://www.theregister.com/2021/07/02/printnightmare_cve/?&amp;web_view=true" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-04T06:32:05+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Cybersecurity Is Everyone&#039;s Responsibility]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/cybersecurity-is-everyones-responsibility" />
            <id>https://mail.onecovernepal.com/59</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">One of the most common misconceptions about cybersecurity is that the responsibility and ownership sits solely on the shoulders of the CISO and the security team.</p>
<p style="text-align: justify;">Common assumptions are anything related to cybersecurity, a security issue or security initiative resides with the security team and the Chief Information Security Officer (CISO). Phishing attacks? That&rsquo;s a problem for the security department. Vetting vendors and third parties? That belongs to the vendor management team. Data regulation compliance issues? That&rsquo;s the cybersecurity team&rsquo;s problem.</p>
<p style="text-align: justify;">The reality, however, is that security is a team sport and we all have a role to play and a responsibility.Every company needs to build a risk portfolio, have incident response plans for every line of business and automate the risk management process as much as possible. Cybersecurity visibility is at the core of all of this.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://securityscorecard.com/blog/security-is-everyones-job" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-05T14:12:45+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[GitLab Bug Bounty]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/gitlab-bug-bounty" />
            <id>https://mail.onecovernepal.com/60</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">GitLab has resolved a raft of vulnerabilities including two high-impact web security flaws with an update to its software development platform. A cross-site request forgery (CSRF) vulnerability in GitLab&rsquo;s GraphQL API created a means for an attacker to call mutations while posing as their victim. A second high severity vulnerability meant that the GitLab Webhook feature could be abused to perform denial-of-service (DoS) attacks.</p>
<p style="text-align: justify;">The DoS vulnerability was discovered by researcher &lsquo;afewgoats&rsquo; and disclosed through a GitLab bug bounty program run by HackerOne. CVE trackers have been requested for both high impact vulnerabilities, but identifiers are yet to be assigned. Ethical hacker &lsquo;afewgoats&rsquo; told The Daily Swig that they've been working on a way to attack services that offer webhooks.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://portswigger.net/daily-swig/gitlab-triages-bug-bounty-reported-flaws-with-latest-release?&amp;web_view=true" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-07T07:39:24+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[PrintNightmare RCE Vulnerability]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/printnightmare-rce-vulnerability" />
            <id>https://mail.onecovernepal.com/61</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Even as Microsoft expanded patches for the so-called PrintNightmare vulnerability for Windows 10 version 1607, Windows Server 2012, and Windows Server 2016, it has come to light that the fix for the remote code execution exploit in the Windows Print Spooler service can be bypassed in certain scenarios, effectively defeating the security protections and permitting attackers to run arbitrary code on infected systems.</p>
<p style="text-align: justify;">On Tuesday, the Windows maker issued an emergency out-of-band update to address CVE-2021-34527 (CVSS score: 8.8) after the flaw was accidentally disclosed by researchers from Hong Kong-based cybersecurity firm Sangfor late last month, at which point it emerged that the issue was different from another bug tracked as CVE-2021-1675 that was patched by Microsoft on June 8.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://thehackernews.com/2021/07/microsofts-emergency-patch-fails-to.html?&amp;web_view=true" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-08T17:29:00+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Apps on Google Play Found Harvesting Facebook Credentials]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/apps-on-google-play-found-harvesting-facebook-credentials" />
            <id>https://mail.onecovernepal.com/62</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Google singled out nine apps with over 5.8 million combined downloads&mdash;masqueraded as genuine apps such as Horoscope Daily and Rubbish Cleaner to steal Facebook login details. However, the victims were unaware of the fact that they are downloading a malicious app on their devices.</p>
<p style="text-align: justify;">These malicious apps have been removed by Google from the Play Store. However, this is not the first instance of malicious apps making their way into the Google Play Store. Malicious apps are getting detected regularly on legitimate app stores, which shows that users can not entirely rely on app stores for ensuring their security. Before and after installing any app, users must stay vigilant for unusual activity and permissions required by the apps.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://news.drweb.com/show/?i=14244&amp;lng=en" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-10T08:52:50+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Malware Dropper]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/malware-dropper" />
            <id>https://mail.onecovernepal.com/63</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Organizations are being hammered by malware droppers offering threat actors with a multitude of options for multi-stage attacks. This leaves the firms at higher risks of malware threats, data theft, and compromised systems, among others.Organizations are being hammered by malware droppers offering threat actors with a multitude of options for multi-stage attacks. This leaves the firms at higher risks of malware threats, data theft, and compromised systems, among others. Proofpoint researchers dissected a new variant of JSSLoader malware that offered threat actors to evade detections and load additional payloads.</p>
<p style="text-align: justify;">Droppers are a well-known type of malware that has been around since the early days of trojans. Besides downloading and installing malware, droppers have been observed exhibiting different behaviors that set it apart from other malware. These include searching for available security controls, connecting to suspicious websites, and attempting to hide connections with sites. Moreover, with the increased ransomware and ongoing malicious emails threats, it is expected that the growing presence of loaders is likely to witness a rise.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://unit42.paloaltonetworks.com/matanbuchus-malware-as-a-service/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-11T15:12:55+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[PDF Phishing Campaign]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/pdf-phishing-campaign" />
            <id>https://mail.onecovernepal.com/64</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Stealing corporate credentials is a lucrative business in the underground markets. Threat actors have been found to go to various lengths to obtain those. Now, another group of cybercriminals has been observed impersonating Adobe online services and using fake notifications to lure their victims. According to Kaspersky researchers, messages inside the phishing emails claim that a file has been shared using Adobe PDF online service. However, this service name does not exist. It is suspected to be impersonating genuine services, such as Acrobat online or Document Cloud.</p>
<p style="text-align: justify;">The use of malicious PDF files in phishing emails is prominently displayed in several recently observed attacks. A lot of incidents have witnessed attackers using PDF files to target unsuspecting users. Phishing emails spoofing the names of well-known software to fool recipients is a common yet effective threat. A common set of security hygiene measures can greatly reduce the risk of infection from this threat. Companies can protect themselves by providing training to their employees about spotting phishing attacks. Moreover, they can use anti-phishing solutions and use security products with anti-phishing components.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://www.kaspersky.co.uk/blog/adobe-online-imitation/22990/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-12T13:31:31+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Nepal Telecom Call Details Stolen By Chinese Hackers?]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/nepal-telecom-call-details-stolen-by-chinese-hackers" />
            <id>https://mail.onecovernepal.com/65</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Nepal Telecom has been subjected to a terrible "cyber attack" from China. Chinese hackers have attacked Nepal Telecom and stolen the call details of all Nepali users. By hacking the Oracle Glass Fish Server used by the telecom company, the Chinese hackers have stolen all the call details of Nepalis. According to technical experts, the hackers used 41 Tactics of Advanced Persistent Threat (APT) and 71 Tactics of Advanced Persistent Threat (APT) and backdoor weapons.</p>
<p style="text-align: justify;">Hackers have been seen taking CDR data from telecom servers to APT 41 and APT 71. It has also been found that the data stolen from the telecom server has been kept on the dark web for sale. The CDR call data record of the telco was put for selling on June 29.</p>
<p style="text-align: justify;">NTC Managing Director Dilli Ram Adhikari says the company's main server is secure. Speaking to reputed outlets, he said: "Hackers might have breached into a dated server of CDMA. The company's team of expert technicians are looking into the matter to trace the culprits. Our main server is protected by a highly secure firewall and remains safe."</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://ciso.economictimes.indiatimes.com/news/nepal-telecom-call-details-stolen-by-chinese-hackers/84366159" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-13T19:02:27+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Spreading Malware With Marvel’s Black Widow Movie]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/marvels-black-widow-movie-to-spread-malware" />
            <id>https://mail.onecovernepal.com/66</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">After getting delayed for nearly a year due to the COVID-19 pandemic, Marvel&rsquo;s Black Widow movie is finally released in movie theatres and online streaming platforms, which has got the attention of scammers and cybercrooks alike. They are looking to use this opportunity to the best of their abilities and using the movie&rsquo;s digital premier to spread malware infections.After getting delayed for nearly a year due to the COVID-19 pandemic, Marvel&rsquo;s Black Widow movie is finally released in movie theatres and online streaming platforms, which has got the attention of scammers and cybercrooks alike. They are looking to use this opportunity to the best of their abilities and using the movie&rsquo;s digital premier to spread malware infections.</p>
<p style="text-align: justify;">Kaspersky alerts of Black Widow movie-themed malware. The movie was released in the United Kingdom on July 9th while it is yet to be released in several other countries. However, researchers have identified malicious files under the guise of the new Black Widow movie that are already circulating across the web.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://www.hackread.com/cybercriminals-marvel-black-widow-movie-malware/?web_view=true" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-14T18:16:41+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Is REvil Shutting Down?]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/is-revil-shutting-down" />
            <id>https://mail.onecovernepal.com/67</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">After creating havoc across the globe in the past several months, the payment site, public site, helpdesk chat, and negotiation portal of the REvil ransomware gang are now offline, according to researchers. Experts believe it could be due to internal disputes or fear of law enforcement action. Or, maybe the group is actually heading toward a shutdown. The sudden takedown of the REvil&rsquo;s infrastructure appears to be the group&rsquo;s own conscientious decision. If not that, it can be an outcome of the recent dialogue between the U.S. and the Russian governments, and pressure from law enforcement agencies after the Kaseya attack.</p>
<p style="text-align: justify;">It&rsquo;s not the first incident that happened in the past few months where a well-established ransomware group had shut down its operations. There have been multiple ransomware gangs shutting their shops. It is not clear why all of a sudden these websites went offline. If the group has decided to no more engage in encryption-based extortion, the news of shutdown for a prominent gang like REvil is indeed a positive development for the security community. Nevertheless, it will be too early to feel relieved. If the gang happens to sell its attack infrastructure to other cybercrime groups, you may want to stay alert and informed.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://www.zdnet.com/article/revil-websites-down-after-governments-pressured-to-take-action-following-kaseya-attack/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-17T15:41:28+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[New Backdoor Obfuscation Tricks Challenging Security]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/new-backdoor-obfuscation-tricks-challenging-security" />
            <id>https://mail.onecovernepal.com/68</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">A new phishing campaign has been discovered delivering the BazarBackdoor malware. The campaign is using the multi-compression method to hide the malware as an image file. This method can trick Secure Email Gateways (SEGs) into detecting malicious attachments as clean files.According to researchers from Cofense, the multi-compression method can bypass some SEGs as they have limits on thoroughly checking or scanning a compressed file.</p>
<p style="text-align: justify;">As the year commenced, BazarBackdoor got a makeover. Now, the threat actors behind it are getting more sophisticated and using new ways of disseminating the malware. This makes it a worrisome threat and requires continuous monitoring from security agencies.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://cofense.com/blog/nested-files-evade-segs/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-19T07:29:38+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Microsoft takes down domains used to scam Office 365 users]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/microsoft-takes-down-domains-used-to-scam-office-365-users" />
            <id>https://mail.onecovernepal.com/69</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Microsoft's Digital Crimes Unit (DCU) has seized 17 malicious domains used by scammers in a business email compromise (BEC) campaign targeting the company's customers. The domains taken down by Microsoft were so-called "homoglyph" domains registered to resemble those of legitimate business. This technique allowed the threat actors to impersonate companies when communicating with their clients.</p>
<p style="text-align: justify;">According to the complaint filed by Microsoft last week (more details available in the court order), they used the domains registered via NameSilo LLC and KS Domains Ltd./Key-Systems GmbH as malicious infrastructure in BEC attacks against Office 365 customers and services.</p>
<p>For more Information:&nbsp;<a href="https://www.bleepingcomputer.com/news/security/microsoft-takes-down-domains-used-to-scam-office-365-users/?&amp;web_view=true" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-21T07:54:56+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[15 Popular Banks of Nepal Received Email Threatening To Hack Banking System]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/15-popular-banks-of-nepal-received-email-threatening-to-hack-banking-system" />
            <id>https://mail.onecovernepal.com/70</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">On Wednesday, 21 July 2021, Including Nepal Rastra Bank fifteen banks in Nepal recieved a warning email threatening to hack their banking System. This message was sent to the spokesman Of Nepal Rastra Bank, Mr. Dev Kumar Dhakal. He also recieved a phone call on thursday morning from america, warning to hack the system of Nepal Rastra Bank and Nabil Bank. Same mail was forwarded to deputy spokesperson of Nepal Rastra Bank (NRB), the central bank of Nepal, and high-ranking officials of various domestic banks.</p>
<p style="text-align: justify;">According to Mr. Dhakal, the suspect threatened to hack the system of Rastra Bank, Nepal Bank, &amp; Nabil Bank in english. He added,"We are aware about this threat. All banks are requested to check their system and imply measures to avoid possible threat &amp; attacks." The group behind this message are still unknown and further investigation on this case are underway.</p>
<p style="text-align: justify;">In the message the hackers stated that all banking process system had been completely compromised. They warned of withdrawing money by hacking the banking systems of Nepal Rastra Bank, Kumari Bank, Nepal Bank, Nabil Bank, Rastriya Banijya Bank, Machhapuchchhre Bank, NMB Bank, NIC Asia Bank, Bank of Kathmandu, Citizens Bank International, Sanima Bank, Nepal SBI Bank, Everest Bank, Nepal Investment Bank, and Himalayan Bank. The hackers had warned not to take this message lightly.</p>]]>
            </summary>
            <updated>2021-07-22T16:29:10+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Twitter with Two-Factor Auth (2FA) Adoption Rate]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/twitter-with-two-factor-auth-adoption-rate" />
            <id>https://mail.onecovernepal.com/71</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Twitter has revealed in its latest transparency report that only 2.3% of all active accounts have enabled at least one method of two-factor authentication (2FA) between July and December 2020. 2FA is an extra security layer for Twitter accounts that requires users to use a security key or enter a code together with their passwords to log into their accounts.</p>
<p style="text-align: justify;">This ensures that only the account owner can sign in and blocks malicious takeover attempts which try to guess, use stolen credentials, or reset the password.While some high-profile Twitter accounts were successfully hijacked last year despite having 2FA enabled after attackers gained access to internal admin systems, you should still toggle on 2FA to be protected against less-sophisticated hacking attempts.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://www.bleepingcomputer.com/news/security/twitter-reveals-surprisingly-low-two-factor-auth-2fa-adoption-rate/?&amp;web_view=true" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-26T07:06:41+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Ujjwal Gautam Identified &quot;Sub Domain Takeover&quot; Vulnerability In The Asset Of United Nation]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/ujjwal-gautam-identified-sub-domain-takeover-vulnerability-in-the-asset-of-united-nation" />
            <id>https://mail.onecovernepal.com/72</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">When a subdomain has a canonical name (CNAME) in Domain Name System (DNS), with no host providing content for it, attackers can control over the subdomain. This situation can occur if virtual host hasn&rsquo;t been published yet or a virtual host has been removed. An attacker can take over that subdomain by providing their own virtual host and then hosting their own content for it. Then they can potentially read cookies set from the main domain, perform cross-site scripting, or circumvent content security policies, thereby enabling them to capture protected information (including logins) or send malicious content to unsuspecting users.</p>
<p style="text-align: justify;">We are very pleased to share that Ujjwal Gautam has identified "Sub domain takeover" vulnerability in the asset of United Nation. Currently intern at One Cover Pvt. Ltd. Ujjwal Gautam is a self-motivated, confident, and highly energetic individual with a passion for information technology and cybersecurity. He is a team player with a positive attitude and high dedication. He is currently pursuing a BSc(Hons) Computing degree from Islington College (affiliated to London Metropolitan University).</p>
<p style="text-align: justify;">If you want to learn more about Subdomain takeovers, <a href="https://developer.mozilla.org/en-US/docs/Web/Security/Subdomain_takeovers" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-28T08:55:27+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Huge Increase Detection Of Discord Malware]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/huge-increase-detection-of-discord-malware" />
            <id>https://mail.onecovernepal.com/73</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Researchers have observed a huge increase in the number of Discord malware detections in comparison to last year. A recent report claims that malware incidents have increased 140 times from the last year due to CDN and API abuse. According to Sophos researchers, Discord&rsquo;s CDN is often exploited by attackers for hosting malware, and the API is abused to exfiltrate stolen data.</p>
<p style="text-align: justify;">Discord&rsquo;s CDN and API provide a flexible architecture that is frequently abused by cybercriminals. Further, attacks are not just limited to gamers anymore as the messaging app is being used by other groups and online communities as well. Therefore, all users are recommended to take caution and not follow any suspicious links or download any file shared on Discord servers or chats.</p>
<p>For more Information:&nbsp;<a href="https://news.sophos.com/en-us/2021/07/22/malware-increasingly-targets-discord-for-abuse/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-28T16:36:37+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Scammers Using Fake Windows 11 Installers To Spread Malwares]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/scammers-using-fake-windows-11-installers-to-spread-malwares" />
            <id>https://mail.onecovernepal.com/74</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Whenever some new software product, specifically when a new major OS version is about to be unveiled, attackers try to take advantage of the event. Lately, announcements about the launch of Windows 11 are making the rounds all over the world. This has created an opportunity for hackers to exploit eager users by launching new attacks. Microsoft hasn&rsquo;t yet released Windows 11, but the new operating system is already available for download and preview. Cybercriminals, of course, are exploiting that, slipping malware to users who think they&rsquo;re downloading Microsoft&rsquo;s new operating system.</p>
<p style="text-align: justify;">The enthusiasm for Windows 11 is expected to stay until it is officially released (in early 2022) and attackers are suspected to take full advantage of it. Microsoft is running the Windows Insider program through which interested people can register for the upcoming OS version. Therefore, it is recommended that users avoid downloading installations from third-party websites.</p>
<p>For more Information:&nbsp;<a href="https://www.kaspersky.com/blog/fake-windows-11-installers/40718/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-07-30T07:26:23+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Vulnerabilities in Android Apps on Your Phone]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/vulnerabilities-in-android-apps-on-your-phone" />
            <id>https://mail.onecovernepal.com/75</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Over 60% of Android apps contain security vulnerabilities, with the average number of bugs per-app totaling a whopping 39 vulnerabilities. These figures are based on data presented by Atlas VPN, and data based on a report by CyRC, which analyzed the security of open-source software components of 3,335 free and paid mobile applications on the Google Play store as of Q1 2021.</p>
<p style="text-align: justify;">The report makes sobering reading because it highlights the huge problems that Android users face when it comes to securing their smartphones. And it's not just free apps and games. The problems are across the board and affect apps such as banking and payment apps. Predictably, the category of top-free games was the worst, where 96% were found to contain vulnerable components. Following closely behind were top-grossing games and top-paid games.</p>
<p>For more Information:&nbsp;<a href="https://www.zdnet.com/article/the-android-apps-on-your-phone-each-have-39-security-vulnerabilities-on-average/?&amp;web_view=true" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-08-01T07:16:41+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Top Exploited Vulnerabilities in 2020 vs 2021]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/top-exploited-vulnerabilities-in-2020-vs-2021" />
            <id>https://mail.onecovernepal.com/76</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">A joint report has been published by several global cybersecurity agencies alerting about top exploited vulnerabilities in 2020 and 2021. This joint cybersecurity advisory is issued by the CISA, NCSC, and ACSC. It provides technical details for each vulnerability, indicators of compromise, and mitigations. The advisory warns about cyberattacks abusing flaws in VPN appliances, network equipment, and enterprise cloud applications, such as MobileIron, Atlassian, Fortinet, F5, Citrix, and Telerik.</p>
<p style="text-align: justify;">Cybercriminals are always eager to exploit vulnerabilities for their malicious intentions. Therefore, security agencies recommend organizations patch and update their systems. Following a proper patch management policy can reduce the attack surface.</p>
<p style="text-align: justify;">Reed more:&nbsp;<a href="https://securityaffairs.co/wordpress/120644/hacking/top-routinely-flaws-exploited.html" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-08-03T07:48:42+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Android Banking Trojan Vultur]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/android-banking-trojan-vultur" />
            <id>https://mail.onecovernepal.com/77</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Researchers have discovered new waves of banking trojans targeting Android smartphone users. The latest ones identified are Vultur and Oscorp trojans. Both the Trojans are targeting banking apps to steal login credentials and other information. According to ThreatFabric researchers, the majority of apps targeted by the Vultur trojan are related to banks based in Italy, Spain, and Australia. In addition to this, Vultur is suspected to be connected with a dropper framework known as Brunhilda.</p>
<p style="text-align: justify;">Vultur and Oscorp attempt to gain full remote access to the infected device and perform unauthorized bank transfers. Both the malware abuse Android Accessibility Services to stay undetected and perform malicious tasks, indicating malware developers are getting advanced in developing new malware as well as updating existing ones.</p>]]>
            </summary>
            <updated>2021-08-08T07:26:05+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Apple&#039;s Defenses Fails Against Updated AdLoad Malware]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/apples-defenses-fails-against-updated-adload-malware" />
            <id>https://mail.onecovernepal.com/78</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">As reported by SentinelOne researchers, multiple ongoing attacks started in November last year and a rise in activity was detected from early July to early August. Researchers have observed more than 220 samples, of which 150 were not detected by XProtect, the built-in antivirus of Apple. Now, it is updated with around a dozen AdLoad signatures. Many of the samples spotted by SentinelOne are signed with genuine Developer ID certificates issued by Apple, while others are created to run at default Gatekeeper settings.</p>
<p style="text-align: justify;">During the attack, once the adware infects a Mac, it installs a Man-in-the-Middle (MITM) web proxy to hijack search engine results. Ads are later injected into web pages for financial gain. Following infection, it gains persistence on compromised Macs by installing LaunchDaemons and LaunchAgents. In some instances, user cron jobs are executed every two and a half hours.</p>
<p style="text-align: justify;">Hundreds of unique samples of well-known AdLoad adware were circulating in the wild undetected for almost ten months, which calls for immediate attention. It indicates that attackers are getting smarter with every passing day and emphasizes the need for additional layers of security to protect Mac devices.</p>
<p style="text-align: justify;">For Detail:&nbsp;<a href="https://www.bleepingcomputer.com/news/apple/new-adload-malware-variant-slips-through-apples-xprotect-defenses/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-08-18T07:23:40+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Google Docs Scams Still Pose a Threat]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/google-docs-scams-still-pose-a-threat" />
            <id>https://mail.onecovernepal.com/79</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">In May 2017, a phishing attack now known as &ldquo;the Google Docs worm&rdquo; spread across the internet. It used special web applications to impersonate Google Docs and request deep access to the emails and contact lists in Gmail accounts. The scam was so effective because the requests appeared to come from people the target knew. If they granted access, the app would automatically distribute the same scam email to the victim's contacts, thus perpetuating the worm. The incident ultimately affected more than a million accounts before Google successfully contained it. New research indicates, though, that the company's fixes don't go far enough. Another viral Google Docs scam could happen anytime.</p>
<p style="text-align: justify;">Google Workspace phishing and scams derive much of their power from manipulating legitimate features and services to abusive ends, says independent security researcher Matthew Bryant. Targets are more likely to fall for the attacks because they trust Google's offerings. The tactic also largely puts the activity outside the purview of antivirus tools or other security scanners, since it's web-based and manipulates legitimate infrastructure.&nbsp;</p>
<p>For more information:&nbsp;<a href="https://www.wired.com/story/google-docs-scams-threat-phishing/?&amp;web_view=true" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-08-21T08:35:17+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Optical Adversarial Attack’ uses low-cost projector to trick AI]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/optical-adversarial-attack-uses-low-cost-projector-to-trick-ai" />
            <id>https://mail.onecovernepal.com/80</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Researchers have discovered a new adversarial attack that can fool AI technologies. This new attack&mdash;OPtical ADversarial attack (OPAD)&mdash;is based on three main objects - a camera, a low-cost projector, and a computer - that are used to perform the attack. OPAD is based on a low-cost projector-camera system in which researchers have projected calculated patterns to modify the appearance of the 3D objects.</p>
<p style="text-align: justify;">One of the critical factors of such an attack is that no physical access is required for the objects. OPAD attacks can transform any known digital results into real 3D objects. OPAD showed that organizations developing AI technologies should stay alert regarding potential security problems from within the AI models. Also, they should invest more in the security and testing of AI technology before real-world use.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://www.hackread.com/optical-adversarial-attack-low-cost-projector-trick-ai/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-08-23T15:16:42+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Increasing Phishing and Crypto Attacks in 2021]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/increasing-phishing-and-crypto-attacks-in-2021" />
            <id>https://mail.onecovernepal.com/82</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Phishing attacks have always been one of the most popular attacks for cybercriminals. As of lately, attackers have also set their eyes on cryptocurrency theft for greater revenue. According to a report published by PhishLabs, these two attacks have witnessed a huge rise in H1 2021.</p>
<p style="text-align: justify;">Phishing is one of the most basic methods employed by threat actors to steal credentials, compromise organizational networks, and hijack accounts. Furthermore, the rising popularity of cryptocurrencies and subsequent attacks on them, drive home the need for stronger and proactive cybersecurity defenses. The threat landscape is evolving way too quickly and enterprises need to plan appropriately.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://www.phishlabs.com/blog/new-quarterly-threat-trends-intelligence-report-now-available/" target="_blank" rel="noopener">Click Here</a></p>
<p>&nbsp;</p>]]>
            </summary>
            <updated>2021-08-25T07:22:51+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Botnet targets hundreds of thousands of devices using Realtek SDK]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/botnet-targets-hundreds-of-thousands-of-devices-using-realtek-sdk" />
            <id>https://mail.onecovernepal.com/83</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Researchers from SAM Seamless Network have identified that within 48 hours of disclosure, the vulnerabilities in Realtek devices were being exploited in the wild. These serious security flaws exist in Software Development Kits (SDK) of devices. One of the critical security flaws tracked as CVE-2021-35395 impacts smart lightning gateways, IP cameras, travel routers, Wi-Fi repeaters, and smart toys. The bug impacts the management web interface of the devices giving attacks remotely access to scan and run an arbitrary code on flawed devices. The most common network devices using faulty Realtek SDK targeted by Mirai-based botnets are found to be Edimax N150, Netis E1+ extender, N300 Wi-Fi routers, and Repotec RP-WR5444 router.&nbsp;</p>
<p style="text-align: justify;">Recent developments show how quickly and actively cybercriminals attempt to cash in on any opportunity that arises. Moreover, such vulnerabilities are easy to abuse and can be embedded inside malware code. Therefore, vulnerable device users are recommended to apply patches as soon as possible.</p>]]>
            </summary>
            <updated>2021-08-28T00:01:03+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Online Scams Gaining Traction in the Crypto and Financial Space]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/online-scams-gaining-traction-in-the-crypto-and-financial-space" />
            <id>https://mail.onecovernepal.com/84</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">The COVID-19 pandemic hit last year and things have never been the same since. Since then, scammers have come up with various lures and tricks up their sleeves to dupe individuals and organizations of their hard-earned money. Lately, these scams have gained huge momentum and have become a constant source of pain.</p>
<p style="text-align: justify;">The likelihood of scammers being successful is a game of numbers - the more targets they get, the higher the chances of being successful. Security specialists need to strengthen their defenses to combat all these frauds. Because of their inexorability, scams and frauds have become a serious issue. Every quarter, the number of reported cases keeps rising. Since these are here to stay, it goes without saying that users should stay vigilant.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://cyware.com/news/various-online-scams-are-gaining-traction-in-the-crypto-and-financial-space-83ff90f2" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-08-31T05:55:31+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[DEV-0322 Behind the SolarWinds Zero-Day Attacks]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/dev-0322-behind-the-solarwinds-zero-day-attacks" />
            <id>https://mail.onecovernepal.com/85</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">A few weeks ago, experts identified a severe zero-day remote code execution exploit aimed at SolarWinds Serv-U FTP software. Researchers have now disclosed details about the attacker.</p>
<p style="text-align: justify;">Recently, Microsoft linked a limited and highly targeted attack on SolarWinds with a Chinese threat actor &ndash; DEV-0322. It begins abusing Serv-U servers by connecting to the open SSH port and then, sends a malicious pre-auth connection request to run its malicious code and take control of exposed devices. Some Serv-U binaries were not protected by the ASLR (Address Space Layout Randomization) feature, thus allowing attackers to exploit them. Microsoft did not provide information regarding post-infiltration activities of the actor, such as cyberespionage, intelligence collection, or cryptomining. But, it provided technical details regarding the zero-day flaw exploitation by the attackers. The flaw, whose patch is out now, was tracked as CVE-2021-35211.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://www.microsoft.com/security/blog/2021/09/02/a-deep-dive-into-the-solarwinds-serv-u-ssh-vulnerability/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-09-12T17:47:31+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Golden SAML Attack]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/golden-saml-attack" />
            <id>https://mail.onecovernepal.com/86</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">Researchers found out that the threat group targeted the Office 365 environment that is believed to be having a hybrid authentication model set up or fully operating on a cloud network. The threat actor hijacked the AD FS server probably using stolen credentials and gained access to the server exploiting the SAML token. The attackers specifically targeted token-signing certificates and private keys used to signify SAML tokens, within the servers. This certificate is by default valid for a year.&nbsp; It allows cybercriminals to log into Azure or Office365 as any existing user within AD, regardless of any password resets or MFA requirement.</p>
<p style="text-align: justify;">The recent attack is complicated and carried out with the aim of achieving the token-signing certificate to gain entry to a specific target network. Therefore, experts suggest implementing additional layers of protection for SAML certificates, and in case of compromise, re-issue certificates on the ADFS twice and force re-authentication for all users.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://gbhackers.com/golden-saml-attack/" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-09-15T06:47:46+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[India reported an 11.8% rise in cybercrime in 2020]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/india-reported-an-118-rise-in-cybercrime-in-2020" />
            <id>https://mail.onecovernepal.com/87</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">The rate of cyber crime (incidents per lakh population) also increased from 3.3 percent in 2019 to 3.7 percent in 2020 in the country, according to the National Crime Records Bureau (NCRB) data.</p>
<p style="text-align: justify;">India recorded 50,035 cases of cyber crime in 2020, with aa 11.8 per cent surge in such offences over the previous year, as 578 incidents of "fake news on social media" were also reported, official data showed on Wednesday.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://timesofindia.indiatimes.com/india/india-reported-11-8-rise-in-cyber-crime-in-2020-578-incidents-of-fake-news-on-social-media-data/articleshow/86230597.cms?&amp;web_view=true" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-09-17T10:14:23+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[Threats Targeting Financial Services]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/threats-targeting-financial-services" />
            <id>https://mail.onecovernepal.com/88</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p style="text-align: justify;">In a new phishing campaign, the customers of European and South American banks are reportedly on the target of a new banking trojan. Brazilian hackers have released a trojan dubbed maxtrilha via customized phishing templates to infiltrate banking systems across the world.&nbsp; As of now, its instances have been traced in Latin America, extended Europe, and Portugal. Encrypted victims&rsquo; data is being sent to the C2 server geolocated in Russia.</p>
<p style="text-align: justify;">Financial industry leaders, along with their security teams, need to find a workaround to mitigate threats and minimize attack surfaces by addressing flaws in systems. Besides adopting newer technologies to offer a seamless banking service, it is imperative that organizations dole out funds to upgrade and fortify their security posture as these threats will only grow in the coming times.</p>
<p style="text-align: justify;">For more Information:&nbsp;<a href="https://securityaffairs.co/wordpress/122134/malware/maxtrilha-banking-trojan.html" target="_blank" rel="noopener">Click Here</a></p>]]>
            </summary>
            <updated>2021-09-25T07:45:49+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[SOC Analyst Jobs In Nepal]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/soc-analyst-jobs-in-nepal" />
            <id>https://mail.onecovernepal.com/89</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<h3 style="text-align: justify;"><span style="font-size: 16px;">One Cover announces job vacancy for the post of SOC Analyst. Here are the requirements that are required for the job:</span></h3>
<h4 style="text-align: justify;"><strong><span style="font-size: 16px;">Education Qualification to Be a SOC Analyst</span></strong></h4>
<p style="text-align: justify;"><span style="font-size: 16px;">To start your career in this domain, you should have a bachelor&rsquo;s degree in the field of computer science or other similar sectors. Further, you must also go through proper training from a well-reputed institute, gain certification, and become a Certified SOC Analyst (CSA). This is the first step that you need to take to become a member of the SOC team in any company.</span></p>
<h4 style="text-align: justify;"><strong><span style="font-size: 16px;">Skills to Be a SOC Analyst</span></strong></h4>
<p style="text-align: justify;"><span style="font-size: 16px;">You need to have some specific skills to land your job in this field and move ahead in your career. Following are the skills that you need to acquire to become a CSA:</span></p>
<h5 style="padding-left: 40px; text-align: justify;"><strong><span style="font-size: 16px;">1. Network defenders: </span></strong></h5>
<p style="padding-left: 40px; text-align: justify;"><span style="font-size: 16px;">You need to be able to defend the network as it is one of the primary responsibilities of CSA in any company. It will allow you to monitor, discover, and analyze any possible threats through the Internet that can disturb the network. It is easy for hackers to attack the network as they are connected to the Internet actively and can easily explore vulnerabilities. You should have the skills to keep the network traffic in check and respond to any skeptical activities.</span></p>
<h5 style="padding-left: 40px; text-align: justify;"><strong><span style="font-size: 16px;">2. Ethical Hacking:</span></strong></h5>
<p style="padding-left: 40px; text-align: justify;"><span style="font-size: 16px;">SOC professionals with expert skills in Ethical Hacking have the required knowledge to find probable threats and report the vulnerabilities so that the company stays protected from attacks. Moreover, they have an understanding of perpetration testing to test systems, networks, web applications, and more and find vulnerabilities.</span></p>
<h5 style="padding-left: 40px; text-align: justify;"><strong><span style="font-size: 16px;">3. Response to incidents:</span></strong></h5>
<p style="padding-left: 40px; text-align: justify;"><span style="font-size: 16px;">You must have the skills to manage various effects of breaches to reduce their impact and suggest changes in the security controls to prevent the company from any future security breaches.</span></p>
<h5 style="padding-left: 40px; text-align: justify;"><strong><span style="font-size: 16px;">4. Computer forensics:</span></strong></h5>
<p style="padding-left: 40px; text-align: justify;"><span style="font-size: 16px;">As a SOC professional, you should be familiar with computer forensics to successfully prevent any form of cybercrime in your organization. With an understanding of this module, you will be skilled enough to collect, analyze, and report security data. Besides, you must also find and analyze evidence to prevent any future possible security breaches.</span></p>
<h5 style="padding-left: 40px; text-align: justify;"><strong><span style="font-size: 16px;">5. Reverse engineering:</span></strong></h5>
<p style="padding-left: 40px; text-align: justify;"><span style="font-size: 16px;">With skills in reverse engineering, you will be able to understand and read the performance of given software program such that you will be capable of patching a bug.</span></p>
<p style="text-align: justify;"><span style="font-size: 16px;">For more details: info@onecovernepal.com</span></p>
<p>&nbsp;</p>]]>
            </summary>
            <updated>2021-11-21T17:50:52+00:00</updated>
        </entry>
            <entry>
            <title><![CDATA[IBM Security QRadar SOC Solutions in Nepal]]></title>
            <link rel="alternate" href="https://mail.onecovernepal.com/blog/ibm-security-qradar-soc-solutions-in-nepal" />
            <id>https://mail.onecovernepal.com/90</id>
            <author>
                <name> <![CDATA[Onecover]]></name>
            </author>
            <summary type="html">
                <![CDATA[<p class="MsoNormal" style="text-align: justify;"><strong><span style="font-size: 12.0pt; line-height: 107%; font-family: 'Times New Roman',serif;">OneCover Pvt. Ltd is all set to provide QRadar SOC (Security Operation Center) Solutions in Nepal and South Asia in association with IBM USA for the first time. </span></strong><span style="font-size: 12.0pt; line-height: 107%; font-family: 'Times New Roman',serif;">IBM QRadar SOC is a part of security team of an organization that is designed to analyze and protect the organization from cyberattacks. &nbsp;<span style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;">IBM has QRadar SOC&nbsp;analysts and QRadar SOC engineers ready to provide services.</span><span style="color: #181c21; letter-spacing: 0.05pt; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;">SOCs are centralized units within buildings or facilities that have the ability to monitor employees on and off site and access information and data from multiple sources.</span></span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 12.0pt; line-height: 107%; font-family: 'Times New Roman',serif;">The IBM QRadar SOC responsibilities are at the operational aspects of an organization to ensure the continued operations of the organization&rsquo;s information security protection.</span> <span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;">IBM QRadar SOC Offerings are provided through experienced professionals and from Cloud infrastructure that is certified for various Security Standards. IBM QRadar SOC services make it possible for companies to focus on doing what companies do best &mdash; focusing on promoting their own products and services and offloading security to trained professionals, From small to enterprise businesses.</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;">IBM SOC primary goal is to ensure any potential security incidents are identified correctly, analyzed accordingly through a thorough investigation, with any steps to reduce any immediate impact if possible implemented. The reporting of incidents is vitally important as incorrect reporting could end up making a security incident worse.</span></p>
<p class="MsoNormal" style="text-align: justify;"><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;">IBM has developed complete SOC processes like Monitoring procedure, Notification, escalation process, Compliance monitoring procedure, Incident investigation procedure, and strictly follow the process in the SOC operation.</span></p>
<p class="MsoNormal" style="text-align: justify;"><strong><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;">SOC Services:</span></strong></p>
<p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; padding-left: 40px; text-align: justify;"><!-- [if !supportLists]--><span style="font-size: 12pt; line-height: 107%; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">24/7 Security Monitoring, Data aggregation, Correlation and Analytics</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; padding-left: 40px; text-align: justify;"><!-- [if !supportLists]--><span style="font-size: 12pt; line-height: 107%; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">SOC Analysts</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; padding-left: 40px; text-align: justify;"><!-- [if !supportLists]--><span style="font-size: 12pt; line-height: 107%; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">Automated analysis</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; padding-left: 40px; text-align: justify;"><!-- [if !supportLists]--><span style="font-size: 12pt; line-height: 107%; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">User and Entity Behavior Analytics with Real-Time Threat Hunting and Detection</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; padding-left: 40px; text-align: justify;"><!-- [if !supportLists]--><span style="font-size: 12pt; line-height: 107%; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">On-demand/Scheduled reporting as per various industry standards to ensure regulatory compliances </span><span style="font-size: 12pt; line-height: 107%; font-family: Symbol;"><span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp; </span></span><!--[endif]--><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">&nbsp;</span></p>
<p class="MsoNormal" style="text-align: justify;"><strong><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">SOC provides:</span></strong></p>
<p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; padding-left: 40px; text-align: justify;"><!-- [if !supportLists]--><span style="font-size: 12pt; line-height: 107%; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><strong><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">SOC Monitoring</span></strong></p>
<p class="MsoListParagraphCxSpMiddle" style="padding-left: 40px; text-align: justify;"><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">Monitoring involves checking system for cyber security threats and involves using specialized cybersecurity tools to pick up suspicious patterns. These cyber security tools link into a centralized management system with dashboards that provide any alerts to suspicious activities and patterns. </span></p>
<p class="MsoListParagraphCxSpMiddle" style="padding-left: 40px; text-align: justify;"><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">SOC monitoring is watching and analyzing an organization&rsquo;s systems and environments for security events and organization&rsquo;s network service databases to its websites endpoints like computers and more are in scope for security monitoring specialist security tools like breach detection tools are used to protect systems.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="padding-left: 40px; text-align: justify;"><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">With some tools providing immediate responses that is in real-time to breaches such as intrusion prevention systems (IPS) and intrusion detection system (IDS). With other tools providing delayed responses like the SIEM tool. As these tools work by ingesting logs and analyzing these logs with the delay in getting these logs being responsible for these tools not to be able to work in real-time.</span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; padding-left: 40px; text-align: justify;"><!-- [if !supportLists]--><span style="font-size: 12pt; line-height: 107%; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><strong><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">Analysis:</span></strong></p>
<p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">The analysis will determine how systems were breached by trying to find out the entry point where hackers managed to get in.</span></p>
<p class="MsoListParagraphCxSpFirst" style="margin-left: 0.75in; text-indent: -0.25in; text-align: justify;"><!-- [if !supportLists]--><span style="font-size: 12pt; line-height: 107%; font-family: Wingdings;">&Oslash;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp; </span></span><!--[endif]--><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">Check if SIEM alerts are real or just false positives</span></p>
<p class="MsoListParagraphCxSpMiddle" style="margin-left: 0.75in; text-indent: -0.25in; text-align: justify;"><!-- [if !supportLists]--><span style="font-size: 12pt; line-height: 107%; font-family: Wingdings;">&Oslash;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp; </span></span><!--[endif]--><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">Rate the SIEM alerts as; High, Medium to Low Risk</span></p>
<p class="MsoListParagraphCxSpLast" style="margin-left: 0.75in; text-indent: -0.25in; text-align: justify;"><!-- [if !supportLists]--><span style="font-size: 12pt; line-height: 107%; font-family: Wingdings;">&Oslash;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp; </span></span><!--[endif]--><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">Raise incidents as P1, P2, P3, etc.</span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; padding-left: 40px; text-align: justify;"><!-- [if !supportLists]--><span style="font-size: 12pt; line-height: 107%; font-family: Symbol;">&middot;<span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]--><strong><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">SOC Incident Management</span></strong></p>
<p class="MsoListParagraphCxSpLast" style="padding-left: 40px; text-align: justify;"><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">Incident Management is dealing with alerts to suspicious activities and patterns involving trying to determine firstly the criticality of the threat and then running through various incident management processes to try to neuter the threat. The processes generally involve people to manage them and technology to help pinpoint more information about the threats and try to stop it.</span></p>
<p style="padding-left: 40px; text-align: justify;"><span style="font-size: 12pt; line-height: 107%; font-family: 'Times New Roman', serif;">The goal of the SOC team is to analyze and respond to anomalies and potential cyber security incidents through a combination of technologies and processes. Employees work closely with the organizing team to ensure that security issues are resolved quickly after they are detected.</span></p>]]>
            </summary>
            <updated>2021-11-21T17:33:46+00:00</updated>
        </entry>
    </feed>
