Risk

9/28/2017
12:45 PM
50%
50%

Central Banks Propose Better Inter-Bank Security

Institutions from the world's largest economies want to improve security following abuse of inter-bank messaging and payment systems.

CORRECTED: Central banks from major economies have suggested steps to advance security of inter-bank messaging and payment systems, Reuters reports. The Committee on Payments and Market Infrastructures (CPMI) has called for banks to improve security to protect the financial system.

Last year, attackers tried to steal almost $1 billion from the Bangladesh central bank's account at the Federal Reserve Bank of New York. About $80 million was taken before the hackers were detected. Bangladesh blamed the incident on poor security around the Bangladesh Bank's SWIFT terminal. SWIFT is used among banks to send payment instructions to transfer trillions of dollars every day.

CPMI made suggestions to secure messaging services like SWIFT and Britain's CHAPS system. These include ensuring quick reporting of fraud and attempted fraud, risk audits, user education, and monitoring system access points, where hackers often enter the system.

The security proposals will be published in early 2018.

Read more details here.

Editor's note: Original story said “SWIFT is used among banks to send payment instructions and until last year was used to transfer trillions of dollars every day.” 

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Google Engineering Lead on Lessons Learned From Chrome's HTTPS Push
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
White Hat to Black Hat: What Motivates the Switch to Cybercrime
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
PGA of America Struck By Ransomware
Dark Reading Staff 8/9/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Now about that mortgage refinance offer from Wells Fargo .....
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-2446
PUBLISHED: 2018-08-14
Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure.
CVE-2018-2447
PUBLISHED: 2018-08-14
SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute crafted InfoObject queries, exposing the CMS InfoObjects database.
CVE-2018-2448
PUBLISHED: 2018-08-14
Admin tools in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, allows an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure.
CVE-2018-2449
PUBLISHED: 2018-08-14
SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.
CVE-2018-2450
PUBLISHED: 2018-08-14
SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore read, modify or delete sensitive data from database.