Three-Quarters of Infosec Pros Concerned About Next SolarWinds

Three-Quarters of Infosec Pros Concerned About Next SolarWinds

Nearly three-quarters (72%) of cybersecurity professionals are concerned about supply chain risks to their organization following high-profile incidents like the SolarWinds campaign, according to a new poll.

Run by the Infosecurity Europe trade show, which is owned by the same company as Infosecurity Magazine, the poll received over 2500 responses on Twitter last week.

Nearly two-fifths (38%) said they were “very” concerned about the potential risks from third parties, whilst 34% claimed they were “somewhat” concerned.

They’re right to be: 28% admitted to having no processes in place to control data flows to and from third parties and a fifth (20%) didn’t even know if such measures had been implemented.

Even though more than half (52%) of respondents claimed to have processes in place, only a third (35%) said they actually enforce policy in this area.

Separate research from earlier this month revealed that almost half (44%) of North American organizations have suffered a breach via a third party over the past 12 months.

Even more (51%) said their organization is not assessing the security and privacy practices of suppliers before allowing them to access sensitive data.

Maxine Holt, senior research director at Omdia, argued that discovery must be the first step in assessing supplier risk.

“Which organizations do you have relationships with? What’s the nature of the relationship; do they handle PII on your behalf? Then prioritize accordingly,” she explained.

“Request compliance information, and details of cyber-risk insurance and accreditations. You also need to know where your data is and what it’s doing, and third-parties must be able to ensure that data transfers are consistent with what has been agreed.” 

Experts have argued in the past that accurate risk assessments are often out of reach for organizations as there’s too much reliance on trust and manual, spreadsheet-based approaches to provide assurance.


Infosecurity Europe 2021 will run 13-15 July 2021 at London Olympia, with selected talks and discussions to be made available online. The show will also be running a virtual conference from 8-10 June 2021.


Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

The Misaligned Incentives for Cloud Security

Russia’s Sunburst cyberespionage campaign, discovered late last year, impacted more than 100 large companies and US federal agencies, including the Treasury, Energy, Justice, and Homeland Security departments. A crucial part of the Russians’ success was their ability to move through these organizations by compromising cloud and local network identity systems to then access cloud accounts and pilfer emails and files.

Hackers said by the US government to have been working for the Kremlin targeted a widely used Microsoft cloud service that synchronizes user identities. The hackers stole security certificates to create their own identities, which allowed them to bypass safeguards such as multifactor authentication and gain access to Office 365 accounts, impacting thousands of users at the affected companies and government agencies.

It wasn’t the first time cloud services were the focus of a cyberattack, and it certainly won’t be the last. Cloud weaknesses were also critical in a 2019 breach at Capital One. There, an Amazon Web Services cloud vulnerability, compounded by Capital One’s own struggle to properly configure a complex cloud service, led to the disclosure of tens of millions of customer records, including credit card applications, Social Security numbers, and bank account information.

This trend of attacks on cloud services by criminals, hackers, and nation states is growing as cloud computing takes over worldwide as the default model for information technologies. Leaked data is bad enough, but disruption to the cloud, even an outage at a single provider, could quickly cost the global economy billions of dollars a day.

Cloud computing is an important source of risk both because it has quickly supplanted traditional IT and because it concentrates ownership of design choices at a very small number of companies. First, cloud is increasingly the default mode of computing for organizations, meaning ever more users and critical data from national intelligence and defense agencies ride on these technologies. Second, cloud computing services, especially those supplied by the world’s four largest providers — Amazon, Microsoft, Alibaba, and Google — concentrate key security and technology design choices inside a small number of organizations. The consequences of bad decisions or poorly made trade-offs can quickly scale to hundreds of millions of users.

The cloud is everywhere. Some cloud companies provide software as a service, support your Netflix habit, or carry your Slack chats. Others provide computing infrastructure like business databases and storage space. The largest cloud companies provide both.

The cloud can be deployed in several different ways, each of which shift the balance of responsibility for the security of this technology. But the cloud provider plays an important role in every case. Choices the provider makes in how these technologies are designed, built, and deployed influence the user’s security — yet the user has very little influence over them. Then, if Google or Amazon has a vulnerability in their servers — which you are unlikely to know about and have no control over — you suffer the consequences.

The problem is one of economics. On the surface, it might seem that competition between cloud companies gives them an incentive to invest in their users’ security. But several market failures get in the way of that ideal. First, security is largely an externality for these cloud companies, because the losses due to data breaches are largely borne by their users. As long as a cloud provider isn’t losing customers by the droves — which generally doesn’t happen after a security incident — it is incentivized to underinvest in security. Additionally, data shows that investors don’t punish the cloud service companies either: Stock price dips after a public security breach are both small and temporary.

Second, public information about cloud security generally doesn’t share the design trade-offs involved in building these cloud services or provide much transparency about the resulting risks. While cloud companies have to publicly disclose copious amounts of security design and operational information, it can be impossible for consumers to understand which threats the cloud services are taking into account, and how. This lack of understanding makes it hard to assess a cloud service’s overall security. As a result, customers and users aren’t able to differentiate between secure and insecure services, so they don’t base their buying and use decisions on it.

Third, cybersecurity is complex — and even more complex when the cloud is involved. For a customer like a company or government agency, the security dependencies of various cloud and on-premises network systems and services can be subtle and hard to map out. This means that users can’t adequately assess the security of cloud services or how they will interact with their own networks. This is a classic “lemons market” in economics, and the result is that cloud providers provide variable levels of security, as documented by Dan Geer, the chief information security officer for In-Q-Tel, and Wade Baker, a professor at Virginia Tech’s College of Business, when they looked at the prevalence of severe security findings at the top 10 largest cloud providers. Yet most consumers are none the wiser.

The result is a market failure where cloud service providers don’t compete to provide the best security for their customers and users at the lowest cost. Instead, cloud companies take the chance that they won’t get hacked, and past experience tells them they can weather the storm if they do. This kind of decision-making and priority-setting takes place at the executive level, of course, and doesn’t reflect the dedication and technical skill of product engineers and security specialists. The effect of this underinvestment is pernicious, however, by piling on risk that’s largely hidden from users. Widespread adoption of cloud computing carries that risk to an organization’s network, to its customers and users, and, in turn, to the wider internet.

This aggregation of cybersecurity risk creates a national security challenge. Policymakers can help address the challenge by setting clear expectations for the security of cloud services — and for making decisions and design trade-offs about that security transparent. The Biden administration, including newly nominated National Cyber Director Chris Inglis, should lead an interagency effort to work with cloud providers to review their threat models and evaluate the security architecture of their various offerings. This effort to require greater transparency from cloud providers and exert more scrutiny of their security engineering efforts should be accompanied by a push to modernize cybersecurity regulations for the cloud era.

The Federal Risk and Authorization Management Program (FedRAMP), which is the principal US government program for assessing the risk of cloud services and authorizing them for use by government agencies, would be a prime vehicle for these efforts. A recent executive order outlines several steps to make FedRAMP faster and more responsive. But the program is still focused largely on the security of individual services rather than the cloud vendors’ deeper architectural choices and threat models. Congressional action should reinforce and extend the executive order by adding new obligations for vendors to provide transparency about design trade-offs, threat models, and resulting risks. These changes could help transform FedRAMP into a more effective tool of security governance even as it becomes faster and more efficient.

Cloud providers have become important national infrastructure. Not since the heights of the mainframe era between the 1960s and early 1980s has the world witnessed computing systems of such complexity used by so many but designed and created by so few. The security of this infrastructure demands greater transparency and public accountability — if only to match the consequences of its failure.

This essay was written with Trey Herr, and previously appeared in Foreign Policy.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hacker Who Targeted Cops Gets Jail Time

Hacker Who Targeted Cops Gets Jail Time

A hacker who launched a long-running cyber-attack against a New Hampshire police department has been sent to prison for a year and a day.

Wayne Kenney Jr. broke into the computer systems of the Farnum Center, the Auburn Police Department (APD) and several department employees in 2015 after receiving a suspended sentence for heroin possession.

The Farnum Center is an addiction treatment center based in Manchester, New Hampshire, and it is where 31-year-old Hooksett resident Kenney was sent for drug treatment in early 2015. 

After gaining access to the Center’s systems on July 1, Kenney re-routed a drug helpline 1-800 telephone number to an adult entertainment business. He also doctored the Center’s portal so that users who logged in were greeted with a link to a video that showed heroin being injected.  

“The defendant’s reprehensible actions caused significant harm to entities that seek to help the public,” said Acting US Attorney John Farley in a statement. 

“By disabling access to drug and alcohol treatment information, the defendant cruelly impeded innocent people from getting help for their substance abuse problems. His actions also harmed innocent public servants in Auburn.”

After hacking into the APD’s computer system, Kenney deleted some files and installed malware that prompted pop-up messages to appear on the department’s computers. The messages prayed for the death of Kenney’s arresting officer.

He also took over email and social media accounts belonging to APD employees and defaced them with pornography. 

The attacks against the APD were carried out from February to July 2015 using a keyboard stroke logger, computer viruses and phishing emails. Kenney’s lawyer said that the hacker was going through personal problems when the crimes took place.

On November 18, 2020, Kenney pleaded guilty to unauthorized access to a computer and causing damage to protected computers. He was sentenced on Tuesday in US District Court in Concord.

“You can’t hide in the shadows of the internet and hack into computers and impede others from accessing emergency substance abuse treatment services and get away with it,” said Joseph Bonavolonta, special agent in charge of the FBI Boston Division.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Feds Warn DarkSide May Not Stay Dark

Feds Warn DarkSide May Not Stay Dark

The cyber-criminal gang DarkSide, which allegedly disbanded after carrying out the Colonial Pipeline ransomware attack, may not stay dark for long, according to a report by CNBC.

Key government cybersecurity and counterintelligence officials told the news source that if the gang has actually stopped operating, it could soon be back to its old and highly lucrative tricks under a different alias.

Research published last week by London-based blockchain analytics firm Elliptic appears to show that DarkSide extorted more than $90m in Bitcoin before supposedly halting its illegal activities. 

Federal experts also warned that certain countries were turning a blind eye to the cyber-criminal activity emanating from within their borders.  

In an interview with CNBC’s Eamon Javers on Wednesday, Assistant Attorney General of the Department of Justice’s National Security Division John Demers said that the Colonial Pipeline attack highlighted the issue of “nation-states serving as safe havens for criminal cyber-actors.” 

Demers said that “nation-states aren’t doing their part to investigate and root out hacking activity happening within their borders.” He went on to suggest that DarkSide, far from going dark, could be “just off renaming themselves.”

“Groups like that will come back,” he added. “Probably DarkSide itself, those actors that comprise that group, will be back if they’re not already out there in other forms operating as we’re talking.”

Acting Director of the National Counterintelligence and Security Center Michael Orlando concurred with Demers’ viewpoint. 

Speaking in the same interview, Orlando said: “We do know that countries like Russia and China, Iran and others certainly create safe havens for criminal hackers as long as they don’t conduct attacks against them.

“But that’s a challenge for us that we’re going to have to work through as we figure out how to counter ransomware attacks.”

KnowBe4‘s James McQuiggan told Infosecurity Magazine: “With the recent DarkSide group going dark after what appears to be a loss of their electronic infrastructure, it seems they are working on regrouping their efforts.”

He added: “Individually, cyber-criminals still need to live and make money, so they take their skills and expertise to another group and give themselves a new name and start all over.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Data Breach at Canada Post

Data Breach at Canada Post

Canada’s primary postal operator, Canada Post, confirmed Wednesday that it has suffered a data breach. 

The security incident occurred following a cyber-attack on one of the Crown corporation’s suppliers, Commport Communications, which provides electronic data interchange solutions. 

Commport Communications was hired by the postal service to manage the shipping manifest data of its large parcel business’ customers.

Following the cyber-attack, Canada Post has informed 44 of its commercial customers that data belonging to more than 950,000 customers has been compromised. 

Commport Communications notified Canada Post that manifest data stored in its systems had been exposed in a malware attack on May 19. 

“Shipping manifests are used to fulfill customer orders. They typically include sender and receiver contact information that you would find on shipping labels, such as the names and addresses of the business sending the item and the customer receiving it,” said Canada Post on Wednesday in a press release.

The corporation said that exposed information dates from July 2016 to March 2019 and that most of it (97%) contains the name and address of the receiving customer. The customer’s email address and/or phone number were included in 3% of the compromised data.

Canada Post said that a detailed forensic investigation into the data breach had not turned up any evidence of financial information’s being compromised. 

“We are now working closely with Commport Communications and have engaged external cybersecurity experts to fully investigate and take action,” Canada Post said.

Though the breach hit Canada Post customers via an attack on a supplier, the corporation said they “sincerely regret the inconvenience this will cause our valued customers” and have notified the Office of the Privacy Commissioner.

“Canada Post respects customer privacy and takes matters of cybersecurity very seriously,” said the corporation.

The postal operator added that it will “incorporate any learnings into our efforts, including the involvement of suppliers, to enhance our cybersecurity approach which is becoming an increasingly sophisticated issue.”

Last November, Commport Communications notified Innovapost, the IT subsidiary of Canada Post, of a potential ransomware issue. An investigation found no evidence to suggest any customer data had been compromised.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk