#Infosec21: NCSC Outlines Biggest Cyber Threats During COVID19

#Infosec21: NCSC Outlines Biggest Cyber Threats During COVID19

The main cyber-threat trends during COVID-19 and how they will affect the UK going forward were discussed by Eleanor Fairford, head of incident management at the National Cyber Security Centre (NCSC), during the keynote session on day two of the Infosecurity Europe virtual conference.

Fairford began by describing the new opportunities that the COVID-19 pandemic has presented to cyber-criminals and nation-state actors. Cyber-criminals have been able to “make the most of people’s vulnerabilities during this period and the increased threat surface that was presented by everyone working from home.” And for hostile nation-states, the pandemic provided more chances to steal highly sensitive information from other governments to gain an advantage over them, such as vaccine development.

She outlined the three areas NCSC regard as the biggest cyber-attack trends of 2020: cyber and fraud during COVID-19, the SolarWinds supply chain attacks and the proliferating ransomware threat.

Cyber and Fraud During COVID-19

In terms of cyber and fraud, Fairford revealed that during 2020, the NCSC observed more online scams “than in the previous three years combined.” Unsurprisingly, many were related to the COVID-19 pandemic – prominent examples include fake celebrity endorsement scams, vaccine adverts and fake online shops purporting to sell medical equipment or even COVID-19 ‘cures’. She added: “These are the sorts of techniques that really preyed on people’s vulnerability.” This is because of the enormous toll the pandemic has had on areas like health and the economy, making people far more anxious than they would typically be, and therefore more liable to be tricked.

Fairford also highlighted new measures the NCSC has taken to mitigate these scams and protect individuals and businesses. These include updating its active cyber-defense tools and measures, “which are being rolled out as widely as possible to provide a baseline level of protection.”

According to Fairford, the NCSC has emphasized protecting the NHS, the vaccine supply chain, and research institutions in this period. This includes monitoring for attempts to harvest NHS credentials in order to spoof this institution via phishing. In total, the NCSC observed 122 phishing campaigns in 2020 that used NHS branding, making them appear genuine. This compared to just 36 in 2019.

Fairford outlined another key initiative introduced by the NCSC last year to tackle the threat of online scams. This is the Suspicious Email Reporting Service, “which enables members of the public to send into the NCSC emails they had received which looked like phishing emails.” This has proven highly successful so far, with over six million reports received as of May 31 2021, leading to the removal of more than 45,000 scams and 90,000 URLs.

Encouragingly, Fairford said the NCSC took down nearly 30,000 COVID-19-themed attack groups last year alone.

SolarWinds Attack

She then moved onto the SolarWinds attacks that took place at the end of 2020, which she described as “the key cyber-espionage act of the last decade.” This incident, believed to have been perpetrated by Russian state-backed actors, was particularly “unique and noteworthy,” according to Fairford. This was primarily due to the method used by the threat actors to compromise SolarWinds and subsequently enable them to access the systems of up to 180,000 of its customers.

This was achieved by interfering with SolarWinds software updates, meaning that “as you routinely updated your SolarWinds package, you would install a tampered update, and that provided a backdoor into your network.” She, therefore, noted that all customers that follow guidance on patching and installing updates “were more likely to be a victim of this particular attack.”

Part of the novelty of this method was that services remained unaffected, allowing attackers to go through affected organizations’ systems unnoticed for a very long time. In its subsequent analysis of the incident, she added that the NCSC observed “high levels of operational security techniques” being employed by the attackers, including wiping all traces of their activity.

Fairford believes the attack may well have remained undetected had it not been for FireEye’s initial discovery in December 2020.

“It directly interrupts people’s access to workplaces, learning and key services”

The Surge of Ransomware

Unlike SolarWinds, in which the perpetrators operated behind the scenes and caused no disruption to any services, ransomware attacks have been shown to have a huge impact on individuals and organizations, especially in the past year or so. Fairford commented: “It directly interrupts people’s access to workplaces, learning and key services so this really does create an impact on people’s lives.”

She outlined two major incidents on local authorities in the UK last year – Redcar & Cleveland and Hackney councils. Both led to severe consequences: in the Redcar case, online public services were unavailable to 135,000 local residents for over a week and total recovery costs exceeded £10m, while in the Hackney council case, sensitive personal data of staff and residents ended up being published on the dark web.

There has also been particularly heavy targeting of hospitals and other healthcare institutions since the start of COVID-19, including the recent attack on Ireland’s healthcare service. Fairford also cited a ransomware attack on a hospital in Germany last year, which potentially contributed to the death of a critically ill patient who had to be redirected to another hospital.

Finally, Fairford discussed the recent ransomware attack on the Colonial Pipeline company, which led to the US’ largest fuel pipeline being taken offline. This demonstrated the substantial threat that ransomware poses to countries’ critical national infrastructure. A ransom of $4.4m was paid to the attackers, but pleasingly, the majority of the money has reportedly been seized by the US Department of Justice.

Fairford also highlighted how ransomware groups are becoming increasingly professionalized in their approaches, with many even “behaving like a sophisticated business-type operation.” In one example she gave, a group even has its own list of FAQs, detailing how victims should behave in the event of an incident.

Fairford concluded by outlining how these trends are expected to impact the UK cyberspace over the coming year. Firstly, she believes “the health sector will continue to be a priority target for nation state operations, particularly as research continues into variants and vaccines,” while disinformation campaigns related to the pandemic are likely to still be heavily utilized by malicious actors. Additionally, it is predicted that ransomware will continue to proliferate, including the growth of the double extortion tactic.

Another area she believes will grow are supply chain attacks, with SolarWinds demonstrating just how effective these can be to compromise a large number of organizations globally. Finally, Fairford said she expects to see extensive targeting of “UK companies that are really at the forefront of things like emerging technologies.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

A Third of Execs Plan to Spy on Staff to Guard Trade Secrets

A Third of Execs Plan to Spy on Staff to Guard Trade Secrets

Most senior executives believe more money is needed to protect trade secrets from malicious third parties and insider threats, and many are prepared to spy on staff to do so, according to a new study from global law firm CMS.

The firm commissioned The Economist Intelligence Unit to interview over 300 senior corporate executives from various sectors in China, France, Germany, Singapore, the UK and the US.  

Three-quarters (75%) agreed that greater investment was needed to guard trade secrets, with cybersecurity (49%) and employee leaks (48%) viewed as the most serious threats.

Most pointed to lost business and competitive advantage as the main risk of not doing so.

Security controls (53%) were seen as the most important step, followed by confidentiality agreements and policies (46%) and restricted access (42%). Less than a third (31%) thought that creating a culture that incentivizes trade secret protection would be effective.

When it came to mitigating the insider threat, around a third of respondents are planning various measures over the next two years, including changes to company culture, avoiding cloud storage, new offboarding measures and encouraging the reporting of leaks.

Controversially, a similar number (33%) said they were planning surveillance of employees’ digital activity. Those in China, Singapore and the US were most likely to snoop on staff, with European respondents more reluctant, due to GDPR safeguards.

Hannah Netherton, employment partner at CMS, argued that employee leaks are driving a need for new strategies to guard key assets.

“Companies must find the right balance between perfecting their cybersecurity protections and creating a healthy company culture that incentivizes trade secret protection and encourages speaking up through appropriate channels — even the most rigorous of protocols won’t prevent every employee leak or a disgruntled whistleblower,” she added.

“The pandemic has opened doors to a digital workspace, where it’s easier for employees to accidentally or purposefully access and expose confidential information. It is impossible to protect trade secrets if employees are not aware of the sensitivities around these assets, so putting the right values and measures in place has never been more important to an organization’s success.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Fixes Seven Zero-Days This Patch Tuesday

Microsoft Fixes Seven Zero-Days This Patch Tuesday

Microsoft announced patches for a half-century of CVEs this month, including seven zero-day vulnerabilities, six of which are being actively exploited in the wild.

The six vulnerabilities in question start with CVE-2021-31955, an information disclosure bug in Windows kernel, and remote code execution flaw CVE-2021-33742.

The rest are elevation of privilege bugs in Windows NTFS (CVE-2021-31956), the Microsoft Enhanced Cryptographic Provider (CVE-2021-31199 and CVE-2021-31201) and the Microsoft DWM Core Library (CVE-2021-33739).

In addition, CVE-2021-31968 is a denial of service vulnerability in Windows Remote Desktop Services, which has been publicly disclosed but not yet seen in attacks.

Chris Goettl, Ivanti senior director of product management and security, said that CVE-2021-31199 and CVE-2021-28550 are related to a previously exploited Adobe flaw, CVE-2021-28550, released in the Adobe Security Bulletin ID APSB21-29.

“Customers running affected versions of Microsoft Windows should install the June security updates to be fully protected from these three vulnerabilities,” he added. “This vulnerability affects Windows 7, Server 2008 and later Windows OS versions and is rated as ‘important’ with a CVSSv3 base score of 5.2, which could be missed in some organizations’ prioritization.”

In fact, many of the zero-days published on Tuesday don’t at first glance appear to be particularly risky for organizations due to their low CVSS scores.

“This brings a very important prioritization challenge to the forefront this month. Vendor severity ratings and scoring systems like CVSS may not reflect the real-world risk in many cases,” warned Goettl.

“Adopting a risk-based vulnerability management approach and using additional risk indicators and telemetry on real-world attack trends is vital to stay ahead of threats like modern ransomware.”

Elsewhere this month, Recorded Future senior solution architect, Allan Liska, urged sysadmins to focus on CVE-2021-31963, a critical remote code execution vulnerability in Microsoft SharePoint Server.

Although not previously disclosed or exploited in the wild, similar bugs have been used to deliver payloads, including ransomware in the past, he warned.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Police Access Encrypted Devices in Major Global Crime Bust

Police Access Encrypted Devices in Major Global Crime Bust

Global law enforcers are celebrating today after a three-year operation across 16 countries led to the arrest of 800 and the seizure of over 30 tons of narcotics.

Europol described operation Greenlight/Trojan Shield as “one of the largest and most sophisticated law enforcement operations to date.”

According to The Economist, it was made possible after the developer of an encrypted device service known as Anom turned informant back in 2018.

This allowed the FBI and the Australian Federal Police to effectively take over the distribution of Anom-equipped hardened devices to the criminal underworld. One narcotics kingpin, Hakan Ayik, is reported to have unwittingly recommended Anom to others.

Anom eventually grew to support 12,000 devices and over 300 criminal syndicates in more than 100 countries, Europol claimed.

Thanks to their access to messages, global police recently searched 700 homes, made over 800 arrests and seized more than eight tons of cocaine, 22 tons of cannabis and cannabis resin, two tons of synthetic drugs, six tons of synthetic drugs precursors, 250 firearms, 55 luxury vehicles and over $48 million in fiat and cryptocurrencies.

Further “spin-off” operations will be launched over the coming weeks using evidence gathered from the 27 million Anom messages intercepted by the police, Europol added.

The willingness of criminals to sign-up for the service stemmed from previous disruption efforts, which led to the dismantling of the EncroChat platform in July 2020 and the takedown of Sky ECC in March this year.

“Encrypted criminal communications platforms have traditionally been a tool to evade law enforcement and facilitate transnational organized crime. The FBI and our international partners continue to push the envelope and develop innovative ways to overcome these challenges and bring criminals to justice,” said the FBI’s Criminal Investigative Division assistant director Calvin Shivers.

“We are grateful to Europol for their commitment to fighting transnational organized crime and their partnership with the FBI.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Information Flows and Democracy

Henry Farrell and I published a paper on fixing American democracy: “Rechanneling Beliefs: How Information Flows Hinder or Help Democracy.”

It’s much easier for democratic stability to break down than most people realize, but this doesn’t mean we must despair over the future. It’s possible, though very difficult, to back away from our current situation towards one of greater democratic stability. This wouldn’t entail a restoration of a previous status quo. Instead, it would recognize that the status quo was less stable than it seemed, and a major source of the tensions that have started to unravel it. What we need is a dynamic stability, one that incorporates new forces into American democracy rather than trying to deny or quash them.

This paper is our attempt to explain what this might mean in practice. We start by analyzing the problem and explaining more precisely why a breakdown in public consensus harms democracy. We then look at how these beliefs are being undermined by three feedback loops, in which anti-democratic actions and anti-democratic beliefs feed on each other. Finally, we explain how these feedback loops might be redirected so as to sustain democracy rather than undermining it.

To be clear: redirecting these and other energies in more constructive ways presents enormous challenges, and any plausible success will at best be untidy and provisional. But, almost by definition, that’s true of any successful democratic reforms where people of different beliefs and values need to figure out how to coexist. Even when it’s working well, democracy is messy. Solutions to democratic breakdowns are going to be messy as well.

This is part of our series of papers looking at democracy as an information system. The first paper was “Common-Knowledge Attacks on Democracy.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

How to Teach Kids About Online Safety: A Guide

Kids are online now more than ever, not just during free time, but also during school time. It is impossible to always peek over their shoulder, and depending on their age, they may grow tired of a POS (aka parent over shoulder). The internet can be a dangerous place, but with the right education, kids can navigate hazards and remain safe and calm while online. 

Check out this online safety guide on how to keep your children engaged while learning about cybersecurity and imparting lessons that stick. This guide will work for children ages 6 through 18 with variations. 

1. Keep Lessons Relatable

The first tip to teaching kids about online safety is making sure that your lessons are relatable. For example, if the day’s lesson is about phishing, do not illustrate it with an example of a major corporation’s folly. Instead, liken it to stranger danger. Just like kids know not to talk to strangers on the sidewalk and to distrust strangers who say they have candy, tell them that the same rule applies to online strangers: Walk right by and do not accept anything you are offered. That means not clicking on any links the online stranger sends you, especially when they say you have won a prize. Thirty-four percent of Canadians have encountered a phishing attack since the beginning of the pandemic, according to Statistics Canada. This prevalence means that it is likely someone in your family will receive a phishing message. Warn children that phishing and other social engineering attempts are likely to play with their emotions to make them feel happy, excited, mad, or scared. Encourage your children to always stay calm online and let an adult know when they are approached by strangers. 

2. Emphasize What is at Stake

Along the lines of keeping cybersecurity lessons relatable, make sure that children also know what is at stake if they are irresponsible online. In the case of clicking on suspicious links, tell children that this could make their device ill. When computers are infected with a virus, or are sick, they work slowly and could shut off when they are in the middle of a school assignment. Also, make note of the prevalence of viruses, and how children should stay on guard for them constantly. Over 800,000 Canadian devices had encounters with malware in the last 30 days, at the time this article was written. 

In extreme cases, children can have their identities stolen due to irresponsible online behavior. A stolen identity could affect their credit card eligibility and set them off on the wrong foot in adulthood. Stress the severity of identity theft and the specific consequences. Teenagers who have their sights set on financial freedom, buying a car, or setting up their own bank account could be severely affected. The best way to keep your identity safe is by keeping your Social Insurance Number completely private, never sharing your banking information, and not oversharing online. Canada’s Centre for Digital and Media Literacy explains that preteens especially have a hard time judging the accuracy of online information and are vulnerable to filling out forms that ask for their personal information. When possible, try to keep all internet-connected devices in communal areas of your home so you can periodically check in on your kids. 

When teaching children about online safety, make sure you don’t use fear tactics. Be firm about the potential consequences, but emphasize that kids have your support, the right online literacy skills, and the support of antivirus software and identity theft protection to catch any threats that fall through the cracks. 

3. Use Passphrases!

Passwords are a thing of the past. The hippest new way to protect your accounts is with complex, yet memorable, passphrases. The Government of Canada defines a passphrase as “a memorized phrase consisting of mixed words with or without spaces.” When kids are old enough to be responsible for their own accounts, such as a school login, email address, or social media profile, impart the lesson of passphrases. Thinking up passphrases can turn into a fun exercise. 

When it is time to create a passphrase, have your kids brainstorm some of their favorite things that loosely relate to the account the passphrase is for. For example, a social media site’s passphrase could be about friends, like “A$hleyIsMy#1Fr13nd!” and a school login could be along the lines of “$0cial$tud!esR0ck$!” A loose association may make the passphrase easier to remember. 

If they are gamers, kids may already be familiar with leet, or using symbols in place of letters. Encourage children to practice their leet fluency and substitute as many letters for symbols as they would like. The Government of Canada recommends that passphrases be at least 15 characters long. 

As hard as it might be, never write down passphrases on paper, do not share your password with other people, and do not reuse passphrases. Instead, leverage a password manager, like McAfee True Key, to keep them safe for you. If your child is old enough, encourage them to set up their own account and protect it with two-factor authentication. 

4. See Something, Say Something

Encourage kids to ask questions! Part of your cybersecurity lessons should be to alert an adult when they are not sure if something is quite right. For example, they received an email from grandma, but there is a weird link hidden inside it. Children should know that they can come to you for questions and caution is better than rolling the dice. Questions can then lead to advanced lessons, like how to hover over links to see where they redirect and if the links look fishy. 

Cybersecurity Is for Everyone 

The cybersecurity lessons you impart on children now will set a solid foundation for sound cyber literacy for a lifetime. No one is ever too old or too young to learn the basics and then put them into practice.    Who knows? Maybe you will learn something along the way. 

Stay Updated

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our newsletter, listen to our podcast Hackable?, and ‘Like’ us on Facebook.  

The post How to Teach Kids About Online Safety: A Guide appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk