Marvel Movie Malware Detected

Marvel Movie Malware Detected

Cyber-scammers are exploiting public interest in the latest Marvel movie to spread malware infections. 

The eagerly anticipated premiere of Disney’s Black Widow is scheduled to take place simultaneously offline in movie theaters and online via streaming services tomorrow. However, cyber-criminals have been illegally monetizing interest in the new flick for months, according to research by cybersecurity company Kaspersky.

To gauge the extent of scamming involving the release, Kaspersky experts analyzed malicious files impersonating the new Black Widow movie. They also investigated film-themed phishing websites that were designed to steal users’ credentials.

Researchers observed spikes in attempts to infect users that coincided with the dates on which the movie was announced and its launch dates. 

They found infection attempts increased significantly in the lead up to the film’s official announcement in May of 2020, as well as around its initial planned release dates of November 2020 and May 2021 that were pushed back by Covid-19 to July 2021. 

At two different points during the past year, infections attempts occurred on 13% of streams and downloads related to the Black Widow film.

Researchers found multiple phishing websites designed to steal movie lovers’ credentials. One site lured victims with the promise of an early preview of the film. Users were only shown a few minutes of the movie before being asked to register to watch the rest of it. 

During the registration process, users were asked to enter their bank card details to confirm their region of residence. Money was later debited from their card, and viewers were not given access to the full film. 

“Big movie releases have always been a source of entertainment but they are also an attractive lure for cyber-criminals to spread threats, phishing pages, and spam letters,” commented Kaspersky security expert Anton V. Ivanov. 

“Right now, we have observed intensified scamming activities around Black Widow, the release of which, fans all over the world have been eagerly anticipating for a long time. In their excitement to watch the long-awaited movie, viewers have become inattentive to the sources they use, and this is exactly what fraudsters benefit from.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Multi-Cloud Environments More Risky

Multi-Cloud Environments More Risky

A new study has revealed that nearly all security professionals operating in a multi-cloud environment believe it’s riskier than relying on a single cloud provider.

The research, published today by global security and compliance solutions provider Tripwire, is based on a June 2021 survey of 314 security professionals with direct responsibility for the security of public cloud infrastructure within their organization.

Nearly three quarters (73%) of those surveyed currently work in a multi-cloud environment. Of those, 98% said that depending on multiple cloud providers creates additional security challenges.

The findings follow the Biden administration’s recent cancellation of the single-provider JEDI Cloud contract in favor of the multi-cloud/multi-vendor Joint Warfighter Cloud Capability (JWCC).

More than half of security professional (59%) have configuration standards for their public cloud, and over three quarters (78%) use best practice security frameworks. However, just 38% of framework users apply those frameworks consistently across their cloud environment. 

Keeping track of events is tough for the majority of professionals, with only 21% saying that they have a centralized view of their organization’s security posture and policy compliance across all cloud accounts. 

Another thorny issue for professionals was knowing where their responsibilities end and where those of their cloud service providers and customers begin. The major said that shared responsibility models for security were not always clear, and three quarters said that they rely on third-party tools or expertise to secure their cloud environment.

“We’ve seen a massive shift to cloud in response to the growing business need to manage more data and have greater accessibility,” said Tim Erlin, vice president of product management and strategy at Tripwire. 

“Given the growing complexity of systems and threats that come with moving to a cloud environment, and security policies that are unique to each provider, it makes sense that organizations are finding it increasingly difficult to secure the perimeter.”

Another of the survey’s key findings was that most organizations follow a high-risk strategy regarding cloud environment management, relying on existing security teams to complete training or self-teach. Only 9% of those surveyed said they would categorize their internal teams as experts.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cybercrime Costs Organizations Nearly $1.79 Million Per Minute

Cybercrime Costs Organizations Nearly $1.79 Million Per Minute

Cybercrime costs organizations an incredible $1.79m every minute, according to RiskIQ’s 2021 Evil Internet Minute Report.

The study, which analyzed the volume of malicious activity on the internet, laid bare the scale and damage of cyber-attacks in the past year, finding that 648 cyber-threats occurred every minute.

The researchers calculated that the average cost of a breach is $7.2 per minute, while the overall predicted cybersecurity spend is $280,060 every minute.

E-commerce has been heavily hit by online payment fraud in the past year, with cyber-criminals taking advantage of the shift to online shopping during the COVID-19 pandemic. While the e-commerce industry saw a record $861.1bn in sales, it lost $38,052 to online payment fraud every minute.

Healthcare, another sector that has faced a surge in cyber-attacks since the start of COVID-19, lost $13 per minute on digital security breaches in the past year.

The report also looked at the impact of different forms of cybercrime. It showed that per minute, there was $3615 lost to cryptocurrency scams, 525,600 records compromised and six organizations victimized by ransomware.

The scale of cyber-attacks last year was further underlined by the fact that one Magecart host was detected every 31 minutes, one vulnerable Microsoft Exchange server was patched every 1.7 minutes and one malicious mobile app blocklisted every five minutes.

According to Lou Manousos, CEO of RiskIQ, cybercrime is easier than ever to participate in: “Better threat technology makes cyber-criminals more effective and wealthier than ever before. We have compiled the vast numbers associated with cybercrime over the past year with help from our Internet Intelligence Graph and third-party sources to help businesses and researchers better understand what they’re up against.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CTOs Keeping Quiet on Breaches to Avoid Cyber Blame Game

CTOs Keeping Quiet on Breaches to Avoid Cyber Blame Game

Nearly two-thirds (36%) of IT leaders are not disclosing breaches for fear that they may lose their job, complicating efforts to enhance security, according to new research.

Keeper Security polled 1000 UK IT decision-makers at businesses of between 100 and 5000 employees to compile its 2021 Cybersecurity Census Report.

It revealed that security breaches are widespread: 92% of respondents said their organization suffered one in the past year and over three-quarters (78%) feel unprepared to deal with cyber-threats.

The financial fallout of successful attacks is also significant, costing nearly one in 10 businesses over £1 million.

Worryingly, many IT leaders appear to be keeping quiet about breaches rather than actively taking steps to tackle their causes.

Nearly all (92%) respondents said they’re aware of gaps in their defenses, but less than half (40%) are addressing all of them. A third (32%) even admitted to using weak credentials such as “password” or “admin” to protect data.

Training and skills appear to be key weaknesses: 58% of IT pros said employees don’t understand the consequences of poor cyber-hygiene, while even more (61%) complained of cyber skills shortages.

This matters increasingly in the context of a current working environment in which remote employees may be more exposed to threats.

Two-thirds (66%) of UK organizations said they’d relaxed their cybersecurity policies to support productivity over the past 12 months.

“UK businesses are clearly worried about their cybersecurity and the challenges are manifold, affecting everything from budgets to productivity,” said Darren Guccione, CEO and co-founder of Keeper Security.

“Companies are facing many competing challenges right now and, understandably, might not always make cybersecurity investments a priority. Our report is an urgent reminder for organizations to proactively address their cybersecurity challenges as a priority, since deferring them will make the consequences far more severe.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Regulator Probes Former Health Secretary’s Use of Private Email

Regulator Probes Former Health Secretary’s Use of Private Email

The UK’s data protection regulator has launched an investigation into whether the former health secretary broke the law in using his private email account to conduct official departmental business.

Concerns were raised by the Labour Party late last month after Matt Hancock resigned following leaked CCTV footage showing the married Tory MP in a romantic embrace with an advisor.

They revolve around question marks over whether government contracts for PPE and other items were awarded fairly and transparently.

Information commissioner Elizabeth Denham said in a blog post that her investigation would focus on whether the use of private email for official government business may be a security risk. If there is a risk, the records won’t be available when freedom of information requests are made. It’s not technically illegal for ministers to use their private emails, as long as guidance from the ICO and government is being met.

“The suggestion of ministers and senior officials using private correspondence channels, such as private email accounts, to conduct sensitive official business is a concerning one. It concerns the public to feel there may be a loss of transparency about decisions affecting them and their loved ones. And as the regulator of data protection and freedom of information laws, it concerns me,” Denham argued.

“[My] investigation will establish if private correspondence channels have been used, and if their use led to breaches of freedom of information or data protection law. We will publish the results of that investigation in due course.”

The Information Commissioner’s Office (ICO) has already issued information notices on the Department for Health and Social Care in order to preserve evidence for the inquiry.

Its powers range from best practice recommendations and enforcement notices to criminal prosecution of individuals where information has been “deliberately destroyed, altered, or concealed” after being requested under the Freedom of Information Act.

Last year, The Guardian revealed that a former publican and friend of Hancock’s won a £50 million contract for test-and-trace supplies despite running a company that had no experience producing such equipment.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New PrintNightmare Patch Can Be Bypassed, Say Researchers

New PrintNightmare Patch Can Be Bypassed, Say Researchers

Microsoft has now released a patch for all Windows versions affected by the PrintNightmare zero-day, but researchers have already found a way to bypass the fix in attacks.

As predicted, Microsoft this week pushed an out-of-band patch for CVE-2021-34527, which now has a CVSS “high severity” score of 8.2.

The incomplete initial release on Tuesday was followed up a day later with a version which covered the remaining unpatched products: Windows Server 2012, Windows Server 2016 and Windows 10, Version 1607.

However, within hours of the release, researchers took to Twitter to show proof-of-concept attacks on patched systems which means they’re effectively still vulnerable to local privilege escalation and remote code execution.

Mimikatz creator Benjamin Delpy said the problem relates to the Point and Print function, which is designed to allow a Windows client to create a connection to a remote printer with first requiring installation media.

That effectively means an authenticated user could still gain administrator-level privileges on a machine running the Print Spooler service to run arbitrary code.

Most concerning is that this vulnerability could put servers running Windows domain controllers at risk, effectively giving attackers the keys to the kingdom to compromise enterprise networks with ransomware or other malicious code.

Microsoft acknowledged the issue at the bottom of its advisory.

“Point and Print is not directly related to this vulnerability, but the technology weakens the local security posture in such a way that exploitation will be possible,” it admitted. “To disallow Point and Print for non-administrators make sure that warning and elevation prompts are shown for printer installs and updates.”

The latest issue adds to a catalog of errors that began when Chinese researchers accidentally published a proof-of-concept exploit last month, believing it to have already been circulated by a researcher and patched by Microsoft.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk