SEC Probes SolarWinds Breach Disclosure Failures

SEC Probes SolarWinds Breach Disclosure Failures

The United States Securities and Exchange Commission (SEC) has launched a probe to determine whether some companies failed to disclose that they had been impacted by the 2020 hacking attack that compromised the SolarWinds Orion software supply chain.

The assault on SolarWinds was discovered and disclosed by researchers at FireEye in December. The advanced persistent threat (APT) group behind the attack was able to compromise nine government agencies, critical infrastructure, and hundreds of private-sector organizations.

Last month, SolarWinds CEO Sudhakar Ramakrishna revealed that the attackers may have accessed the company’s system as early as January 2019. The company has said that as many as 18,000 of its customers were affected by the breach. 

The United Kingdom and the US have laid the blame for the hack at the door of Russia’s Foreign Intelligence Service (SVR). Russia has denied any culpability for the attack.

Two people familiar with the SEC investigation told the news source Reuters that letters were sent out last week by the SEC to a number of investment firms and public issuers. In the missives, the Commission asked the entities to voluntarily state whether they had been victimized by the unprecedented SolarWinds hack and kept quiet about it. 

The anonymous sources also said that in addition to probing data breach disclosure failures, the SEC is seeking to determine whether the cybersecurity policies at certain companies were designed to protect customer data. 

A spokesperson for SolarWinds said in a statement: “Our top priority since learning of this unprecedented attack by a foreign government has been working closely with our customers to understand what occurred and remedy any issues.”

The company added that it is “collaborating with government agencies in a transparent way.”

Under United States securities law, companies are required to disclose material information that could affect their share prices, including data on breaches caused by cybersecurity incidents. 

If the entities that receive the SEC’s letters reply by disclosing information about the breaches, they will avoid any enforcement actions linked to internal accounting control failures and historical failures, the sources said. 

They added that the SEC was considering creating new policies regarding the effect of cybersecurity issues on investors and markets.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Tool Launched to Remove Nude Images of Children Online

New Tool Launched to Remove Nude Images of Children Online

A new online tool has been launched to help young people remove nude images of themselves that have been shared online.

The Report Remove tool, developed by Childline and the Internet Watch Foundation (IWF), enables any person under the age of 18 to report any nude image or video of them that has appeared on the internet. The IWF will assess the content, which will work to remove it if it is found to have broken the law. To do so, a digital fingerprint – a hash – will be created from the image and provided to tech platforms to enable them to prevent the image from being shared or uploaded online.

Any young person making a report should also receive feedback from the IWF via Childline within one working day.

The new tool has been created amid a surge in self-generated images this year, with the IWF revealing that reports of this nature have more than doubled from January to April 2021 compared to the same period last year, from 17,500 to 38,000. The sharing of sexual images online can have a particularly devastating impact on young people, leading to mental health issues and fears about how it may affect their future prospects.

There are a variety of reasons why young people self-generate sexual images or videos. Sometimes they are sent for fun to a boyfriend or girlfriend and are subsequently shared online without their consent. In other circumstances, young people are groomed online or blackmailed into generating this type of content.

Childline quoted a 14-year-old girl who had contacted them about her own experiences of this. She stated. “I don’t know what to do because this Instagram account keeps posting pictures of me and they keep saying they’re going to follow my friends so they can see them too. It all started after I shared naked pics with someone who I thought was a friend but it turned out to be a fake account. I just feel so hopeless and I don’t know how to make it stop.”

The Report Remove tool, which was first piloted in February 2020, provides an avenue for support for young people in this situation.

t has also been developed to ensure young people’s use of the tool remains confidential – they do not need to provide their real name, and they can verify their age without revealing any other details by using Yoti’s digital identity platform. Additionally, Childline and IWF have coordinated with law enforcement to ensure children will not be unnecessarily visited by the police when they make a report.

Cormac Nolan, service head of Childline Online, pointed out how damaging sharing explicit content can be to children: “The impact of having a nude image shared on the internet cannot be underestimated and for many young people, it can leave them feeling extremely worried and unsure on what to do or who to turn to for support.

“That’s why Childline and the IWF have developed Report Remove to provide young people a simple, safe tool that they can use to try and help them regain control over what is happening and get this content erased.

“At Childline we also want to remind all young people that if they discover that a nude image of themselves has been shared online that they do not need to deal with this situation alone and that our Childline counsellors are always here to listen and help provide support.”

Susie Hargreaves OBE, chief executive of the IWF, said: “When images of children and young people are taken and spread around the internet, they lose control. This is about giving them that control back.

“Once those images are out there, it can be an incredibly lonely place for victims, and it can seem hopeless. It can also be frightening, not knowing who may have access to these images.

“This tool is a world first. It will give young people the power, and the confidence, to reclaim these images and make sure they do not fall into the wrong hands online.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Fifth of Google Play Apps Violate Child Protection Law

Fifth of Google Play Apps Violate Child Protection Law

One in five apps on Google Play designed for children appear to be breaking federal law, according to new research from Comparitech.

The consumer rights and comparison site analyzed the top 300 free and top 200 paid apps on the marketplace under the children and family categories and reviewed each listed privacy policy.

It found that one in five contravened the Children’s Online Privacy Protection Act (COPPA), legislation which places a strict set of FTC-enforced requirements on websites and online services aimed specifically at the under-13s, or those that collect personal data on children.

Of the 20% of Google Play-listed apps found to be violating COPPA, half were collecting personal information from children without the required child-specific privacy policy in place, according to Comparitech.

A further 27% claimed not to be aimed at children, despite being listed under the “Everyone” age limit on Google Play. Two of these were explicitly aimed at those under 10, the report claimed.

Some 9% of the erring apps did not collect children’s data themselves but worked with third parties that might. Therefore, a child-specific policy section and parental consent are required.

The same number (9%) tried to place responsibility on children and parents, either by asking kids not to submit their personal info to the app or parents to monitor their child’s app usage. Both apparently violated COPPA.

The final 6% had crucial gaps in their policies, such as failing to explain how a parent can consent or access their child’s data or featuring a privacy policy lacking clarity in some areas.

Unfortunately, half of the apps listed in the research that violate COPPA have been awarded a Google Play “teacher approved” badge.

“Two hundred and seventy-four of the apps we reviewed had received this teacher-approved tick and 50 of these (18%) were found to be in violation of COPPA guidelines,” Comparitech explained in a blog post.

“This means the apps and their privacy policies have been through two layers of review and have still passed quality control despite being in breach of COPPA’s standards.”

Most of the info collected by the rogue apps came in the form of IP addresses (42%), followed by online contact information (16%), name (12%), address (7%), telephone number (7%) and other details.

Legally it remains unclear whether the app developers alone or Google would be liable under COPPA for any infractions.

Back in 2019, Google and YouTube agreed to pay the FTC $170 million to settle a case under COPPA that they collected personal information from viewers of child-oriented channels without asking parents first.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Payments Could Be Tax Deductible – Report

Ransomware Payments Could Be Tax Deductible – Report

US organizations that choose to pay a ransom to their online extorters may be eligible to claim the money back from the Internal Revenue Service (IRS), it has emerged.

A report from The Associated Press over the weekend cited tax lawyers and accountants who claimed the little-known clause could be a “silver lining” for ransomware victims.

However, the deduction could also be seen as a further corporate incentive to pay up, encouraging more affiliate groups to join the race to pilfer money from big-name multinationals.

It also flies in the face of official US government guidance, repeated many times by FBI boss Christopher Wray and others, that organizations should not pay any ransom.

Nikos Mantas, an incident response expert at Obrela Security Industries, argued that this tax oversight “will not last long.”

“Ransomware attacks are growing in severity and frequency today, so until now, it is unlikely the IRS had to specifically mention them in their guidance,” he told Infosecurity.

“However, as more and more companies fall victim, they will have to be taken into account. It seems unlikely the IRS will say payments will be tax-deductible as this could be seen as funding a criminal industry.”

IRS spokesperson Robyn Walker, told AP: “The IRS is aware of this and looking into it.”

The Biden administration has signaled its intent to take a hard line on ransomware actors in the wake of attacks on Colonial Pipeline and JBS USA that exposed the fragility of key supply chains.

However, aside from the creation of a DoJ Ransomware and Digital Extortion Task Force and a letter sent to corporate bosses from the National Security Council’s top cyber official, it’s unclear what this will entail.

Some criminal organizations like the infamous Evil Corp are on a US sanctions blacklist, which prevents victims from paying them. However, even here, there have been various attempts to skirt the laws.

Global organizations already have a major incentive to pay their ransomware extorters in the form of cyber-insurance policies that cover such losses or a large part of them. However, things may be changing here too: AXA recently declared it would no longer reimburse clients for these payments in France.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Three-Quarters of SMBs Can’t Repel Cyber-Attacks

Three-Quarters of SMBs Can’t Repel Cyber-Attacks

Millions of the UK’s small businesses aren’t confident they can withstand a cyber-attack, with resources frequently diverted to other areas, according to new research from Arctic Wolf.

The security operations vendor polled over 500 decision-makers in the UK working at firms with fewer than 250 employees to better understand their cyber challenges.

It found that three-quarters (73%) believe their organization lacks the in-house expertise and capabilities to defend against cyber-attacks. The figure could amount to as many as 4.5 million of the UK’s SMBs, the vendor claimed.

More than half (55%) of respondents said cybersecurity issues are regularly deprioritized in favor of other business goals.

This is having a major impact on security operations (SecOps): two-fifths (39%) of respondents said their teams are overwhelmed by security alerts and a similar number (34%) don’t have time to investigate every alert.

The findings chime with a recent Trend Micro study that revealed that over half of SecOps teams in global organizations are drowning in alerts and 55% aren’t confident in prioritizing and responding to them.

As a result, 70% admitted feeling emotionally distressed by the continuous pressure. This can impact both productivity and staff churn at a time when it’s already difficult to fill key security analyst positions.

Christina Richmond, program vice president, security services, at IDC, argued that SMBs should consider outsourcing such capabilities to cloud-hosted security service providers.

“Cyber-attacks, such as ransomware, are growing more advanced by the day, and organizations that fall victim are experiencing not only short-term financial and operational impacts, but also long-term impacts from customers and partners losing their trust,” she explained.

“Being able to identify and mitigate cybersecurity risk has become an essential function for all organizations, but finding the talent, tuning the tools, and developing the internal process is a significant challenge for even the largest, well-resourced organizations.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk