Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
‘Privateer’ Threat Actors Emerge from Cybercrime Swamp
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
A Peek Inside the Underground Ransomware Economy
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
New Disk Wiping Malware Targets Israel
Apostle seems to be a new strain of malware that destroys data.
In a post published Tuesday, SentinelOne researchers said they assessed with high confidence that based on the code and the servers Apostle reported to, the malware was being used by a newly discovered group with ties to the Iranian government. While a ransomware note the researchers recovered suggested that Apostle had been used against a critical facility in the United Arab Emirates, the primary target was Israel.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Cyber Cyber, Burning Bright: Can XDR Frame Thy Fearful Asymmetry?
The security industry is engulfed in the most asymmetric cyberwarfare we have ever seen.
The outcome of an Attacker’s mission may depend entirely upon a single misplaced charge on a single memory chip on a single server, perhaps the difference between a vulnerable and secure setting in a registry key, and the difference between success and failure to gain access to infrastructure, information, and identities (I3) to subsequently wreak havoc, disable critical operations or infrastructure, and put lives at risk.
The outcome of a Defender’s day depends entirely upon how well they secure trillions of charges across chips, computers, containers, clouds, and even cars against potentially thousands of simultaneous Attackers running millions of attacks, each scouring the Defender’s kingdom for the crown jewels of control and information.
This ridiculously uneven war between Attacker and Defender has been a well-known challenge in cybersecurity for some time, and a few fear-inducing statistics always find their way into the first few slides of PowerPoint presentations. However, this asymmetric dynamic remains perhaps the single most fundamental truth that should guide us to innovate and to design solutions to give our Defenders better outcomes every day. From this lens, first, we must discuss how to shape and prioritize the protection, detection, and response capabilities with which we will arm Defenders.
Tyger, ‘Tis But a Flesh Wound: The Defender’s Déjà Vu
We must face some harsh and humbling truths that history has taught us about our asymmetric war:
A. Better incident response (IR) programs and better IR training will not solve this problem. Best practices and tool upgrades will win a few battles for the Defender. Still, research suggests a full investment in SOAR and other automation tools will at most reduce costs by roughly 60% for leaders over laggards, all while the cost of breaches continues to rise across all organizations. Investment in IR programs is unquestionably justified from a financial perspective, but that investment is equivalent to sharpening our spears around the campfire while waiting for the tigers to pounce in the long view of the asymmetric war.
B. Continued entrepreneurship and innovation in novel but transient security controls and frameworks will not solve this problem. Simson Garfinkel, currently Senior Data Scientist at the U.S. Department of Homeland Security, spoke of “The Cybersecurity Mess” and how “cybersecurity is a wicked problem that can’t be solved” almost a decade ago, which was arguably a much simpler and more manageable time for Defenders. Gartner’s Hype Cycle is an excellent value-lifecycle tracker for categories of inventions, and few categories have a faster ride on the Hype Cycle rollercoaster than cybersecurity. At best, security controls rapidly transition from revolutionary standalone products to line-item features on a data sheet as Attackers adapt to and overcome their main value proposition. Perhaps the next ten tigers are caught in camouflaged traps, but we soon notice that they have adapted to avoid them and even set their own.
So, do we accept our fate and ultimate defeat of the Defender at the hands of the Attackers? Or is there a Mars Shot initiative that could dwarf anything we have accomplished in the past, bringing symmetry to the war and erasing millions of person-years of Attacker experience and superiority in a flash? And what the heck does this have to do with eXtended Detection and Response (XDR)?
Go and The Great Equalizer: Cybersecurity and Not-your-everyday AI
Almost 25 years ago, IBM’s Deep Blue overcame 1500 years of cumulative chess knowledge to defeat Garry Kasparov. Five years ago, Google DeepMind’s AlphaGo destroyed over 3000 years of accumulated techniques and strategy to supplant Lee Sedol as the greatest go player ever. Shortly after, Google’s next-gen AlphaZero rendered its own AlphaGo mentor obsolete, having learned chess and go without any human interaction. It seems unfathomable that human beings will even attempt to win these titles back, and we have deep reinforcement learning (Deep RL) to thank.
We have the same massively disruptive opportunity to give hope to the Defender by looking to embed self-learning automated AI systems into our prevention, detection, and response controls, as outlined by the MIT Technology Review discussing security uses for AIOps. Less a point on the Gartner Hype Cycle, and more an entirely new dimension of innovation, this cybersecurity AI system, like all AI systems, requires two major components to feed its hunger to learn: (a) large amounts of data related to the inputs and outputs of the I3 systems across the attack surface, and (b) reliable feedback mechanisms and workflows to train the algorithms. The precursors of these needs map readily to (a) the well-established SIEM and Security Analytics markets and (b) the newer EDR and emerging XDR markets.
Source: Sutton, R.S., Barto, A.G. (2015). Reinforcement Learning: An Introduction, pp. 54.
EDR and Security Analytics: The Starter Fluid for This Promethean Fire
Allie Mellen, an analyst with Forrester Research who covers SecOps, has already written an excellent research report succinctly describing key strengths and weaknesses of these markets and the dynamics likely to unfold in the near term:
A. A convergence of critical technologies and capabilities from the SIEM, SOAR, and XDR markets is inevitable; and,
B. EDR and EDR platforms are the natural evolutionary precursors to XDR, given that endpoints have become pivotal nodes in attack chains.
EDR technology on computers, notebooks, and phones has proven to give us the most detailed and robust knowledge about end-user behavior and risk. EDR provides a natural data-rich progression to XDR on the Gartner 2020 Hype Cycle for Endpoint Security as the “next tech up” to provide meaningful and prescriptive training feedback to emerging AI platforms (e.g., IR Analyst A carried out Steps X, Y, and Z across Controls 1, 2 and 3 to negate Threat A). Through research such as Google’s multi-task machine learning exercise and Zhamak Dehghani’s groundbreaking rethinking of data architectures, we have also come to understand that future I3 datasets for AI consumption will likely reside in globally distributed data meshes and not monstrous and monolithic data lakes. The evolution from SIEM to Security Analytics and from EDR to XDR offer the preliminary steps to bring us to a fully integrated “DeepSecOps” platform that has the potential to turn the Attacker-Defender asymmetry on its head. For this blog, let’s define DeepSecOps as a platform or system that seamlessly and automatically integrates the components and processes described in the diagram above (and potentially more), with self-fueled learning and effective automated response as the fundamental goals.
There also exists a more foreboding reason to invest in XDR as a precursor to DeepSecOps. Tomorrow’s Attacker is honing their craft today: They will casually launch thousands of containers across a hybrid multi-cloud infrastructure designed to morph into multiple target infrastructure profiles with various off-the-shelf security controls already in place, and then unleash thousands of simulated attacks while their own Deep RL engine watches and measures its success.
To the Defender: Find Allies who are Building Towards that Winnable Future
Defenders should look to cybersecurity partners who offer them a clear path to build the foundation for a DeepSecOps future. What does this look like today? Some key considerations:
- Prioritize working with a security vendor who has a strong foundation in EDR that will inform them as to the best approach to XDR and AI/ML guidance,
- Ensure that your security vendor has experience providing Security Analytics solutions that integrate into their portfolio and with other vendors and partners to maximize I3 data collection,
- Consider security vendors who prioritize the integration of third-party APIs and components into a shared ecosystem to increase the amount and types of data available to the DeepSecOps system,
- At the same time, ensure that your security vendor supports enough organic security controls on their platform to train AI systems on the best path forward without relying on partners (i.e., a native-capable XDR vendor that still encourages hybridization per Mellen’s article). These technologies could include CASB, DLP, SWG, and more, both as raw data sources and as controls upon which to train outcomes. Ideally, the vendor should have native visibility end-to-end, from end user to cloud, from app user to app coder,
- Ensure your security vendor has a platform, strategy, and roadmap well-suited to delivering a data mesh architecture,
- Look for opportunities to work with vendors who already leverage AI/ML to preemptively reduce attack surfaces and provide guided investigations that indicate early adoption of DeepSecOps principles and architectures.
Make these considerations the tactical precursors to unleashing the DeepSecOps technology that will reframe and contain the Attacker-Defender asymmetry.
On what wings dare [they] aspire?
What the hand, dare seize the fire?
Capture that Promethean Fire with MVISION XDR
Whether you are building a SOC function with limited resources or maturing a well-established SOC, McAfee is here to help you simplify and strengthen your security operations with MVISION XDR. With MVISION XDR, you can proactively identify, investigate and mitigate threat actors targeting your organization before they can gain a foothold in the network. By combining the latest machine-learning techniques with human analysis, XDR connects and amplifies the early warning signals from your sensors at the network, endpoint, and cloud to improve situational awareness, drive better and faster decisions, and elevate your SOC.
To learn more about what MVISION XDR can do for you watch the video below.
* With apologies to William Blake for dragging his brilliant metaphor into the world of cybersecurity and with a nod to that early Wolverine comic.
The post Cyber Cyber, Burning Bright: Can XDR Frame Thy Fearful Asymmetry? appeared first on McAfee Blogs.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Private browsing vs VPN – Which one is more private?
As people turn to the Internet for news and answers to tough questions, it only makes sense that it would come to know you better than your closest friends and family. When we go online for answers to personal questions, we’re sharing our deepest secrets with search engines. While some people are happy to share that level of personal information with strangers, some turn to private browsing, or incognito mode, to help protect their personal data.
The thing is, incognito mode doesn’t work the way people think it does. When you open an incognito window, you’re told that “You’ve gone incognito.” The explanation underneath says that your browsing history, website visits, cookies, and information you put in forms, won’t be saved. This is where the confusion starts.
What the incognito explanation doesn’t tell you is that your browsing information isn’t blocked or hidden from advertisers while in incognito mode. So even though your browsing information “won’t be saved” on your device or available after you close the window, that doesn’t stop the internet from seeing everything you’ve been up to while in that session. Incognito mode That’s why more and more people use virtual private networks, or VPN, to protect their browsing history from prying eyes. If you’re new to VPN, this might be the perfect time to learn about what they are, how they work and why you might choose a VPN over private browsing.
What do virtual private networks do?
VPN protects your devices by wrapping your internet connection in a secure tunnel that only you can access. This stops people —like those nosey advertisers—from seeing what sites you visit. With a secure connection to the Internet, every search request, every website you browse, is hidden from sight. It’s important to point out that VPN don’t make you anonymous; they make it so only you can see what you’re doing online. You can learn more about VPN in this blog post I wrote late last year.
What does incognito mode do?
Incognito modes work by opening an isolated browser window. It stays separate from the rest of your browser tabs or windows, as if it’s on another device. Using incognito mode deletes cookies—the things advertisers use to follow you around the internet—and browsing history, but that’s about it.
If you check your browser’s cookies while in incognito mode, you’ll see that you’re still picking up cookies as you browse, just like you would with a normal browsing window. While it’s great that incognito mode deletes those cookies when you close the window, that doesn’t help you while you browse. Advertisers are still able to see what sites you’re browsing and target you with ads accordingly.
What’s the difference between VPN and private browsing?
VPN:
- Encrypt your internet connection
- Help hide your browsing from snoops
- Help hide your search requests
- Help protect your personal information
- Can protect multiple devices
- Block some types of online tracking
Private browsing:
- Deletes personal data when you stop browsing
- Only active in one browser window
- Hides Internet activity from other users on shared devices
Why use private browsing over VPN?
We wouldn’t recommend using incognito mode instead of a VPN, ever. Incognito mode has its place in your online security toolkit, but it’s not a replacement for other types of protection. If you share a device with other people, like family members or at a library, then you might want to use incognito mode to make sure your partner doesn’t accidentally find out how much you spent on that new TV in the den.
If you’re concerned with advertisers tracking you and watching what you do online, then you should consider using a VPN to protect your privacy.
Way’s to get VPN protection
If you’re already a McAfee Total Protection subscriber, you have access to unlimited VPN usage. Protect your personal information, like your banking information and credit cards, from prying eyes with McAfee Total Protection’s Secure VPN. If you haven’t already signed up, now’s the perfect time. McAfee Total Protection provides security for all your devices, giving you peace of mind while you shop, bank and browse online.
Stay updated
To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our newsletter, listen to our podcast Hackable?, and ‘Like’ us on Facebook.
The post Private browsing vs VPN – Which one is more private? appeared first on McAfee Blogs.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US to Regulate Pipeline Cybersecurity
US to Regulate Pipeline Cybersecurity

The United States Department of Homeland Security (DHS) is to issue its first ever set of cybersecurity regulations for pipelines, according to The Washington Post.
The news comes in the wake of a recent ransomware attack on the Colonial Pipeline that knocked operational systems offline for five days, triggering panic buying that led to fuel shortages in the Southeast.
Last week, Colonial Pipeline paid a ransom of $4.4m to cyber-criminal gang DarkSide to regain control of its systems and data.
According to the Post, a senior DHS official has said that a security directive will be issued this week requiring pipeline companies to report cybersecurity incidents to federal authorities. The directive will come from the Transportation Security Administration, a DHS unit.
This directive will be followed by a meatier set of regulations in a couple of weeks’ time. These rules are expected to lay out in more detail what pipeline operators must do to protect their systems from cyber-attacks.
Post-breach behavior will also be regulated, with companies who succumb to a cyber-attack ordered to adhere to a set of best practices.
These mandatory regulations will replace the voluntary cybersecurity guidelines issued previously by the DHS.
John Bambenek, threat intelligence advisor at Netenrich, said that the US government’s “shutting the stable door after the horse has bolted” approach to cybersecurity regulation may not be the best way to protect critical infrastructure.
“Notification to the federal government of cyber-attacks is less significant than whatever protective regulations they issue, but the facts are, we have thousands of pages of policies, regulations, and studies on security for the federal government and they still get breached. A regulatory approach based on preventing the last incident is always going to be lacking in terms of preventing the future incidents,” he told Infosecurity Magazine.
Lookout‘s Hank Schless took a more positive view of the regulations’ potential impact.
He told Infosecurity Magazine: “Implementing new regulations could be very effective in the battle against cyber-criminals so long as organizations actually take action to align with them. It takes time and resources to align with new regulations, but this should at least serve as motivation for similar companies to get the ball rolling.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
E-tailers See Surge in Automated Fraud
E-tailers See Surge in Automated Fraud

Automated fraud attacks against e-commerce retailers have increased in volume, frequency and sophistication, according to new research published today.
The Automated Fraud Benchmark Report: E-commerce Edition by PerimeterX is a new comprehensive annual report based on e-commerce cyber-attack activity over the past year.
Findings draw upon anonymous data collected during live online interactions by millions of consumers and hundreds of millions of bots in 2020. Analysis of the data revealed traffic and threat patterns across hundreds of the world’s largest websites, mobile apps and application programming interfaces (APIs).
Researchers determined that considerable growth occurred across all major types of automated fraud, including gift card cracking, account takeover (ATO), scraping and checkout attacks in 2020.
“The ongoing daily level of attacks was the same as during the most recent Cyber 5 period — the traditional Black Friday through Cyber Monday shopping timeframe,” said a PerimeterX spokesperson.
Key findings of the report were that checkout attacks rose 69% in April 2020, and scalper bots drove more than 40% of total shopping cart requests during peak limited-edition sneaker sales.
In September, 85% of all login attempts were ATO attempts, while peak levels of blocked traffic were over 95% in four months.
Researchers also observed that every major US holiday in 2020 saw increases in gift card fraud.
The report reveals that a broader range of online merchants faced automated fraud attacks last year as cyber-criminals expanded into new industries and started to target smaller businesses with greater frequency.
“What’s clear is that automated fraud has no season. The ‘new normal’ rate of automated attacks far outpaces previous seasonal peaks, and retailers should plan for elevated volumes throughout the year,” said Kim DeCarlis, CMO, PerimeterX.
“Retailers will need to adapt to this new environment of higher automated fraud activity in order to continue to grow their sales and profits, increase efficiency and protect their brands.”
DeCarlis added that last year, cyber-criminals were observed trialing their Cyber 5 attack plans in September, a month earlier than usual.
“This compressed the time that development and digital teams had to react and respond to shifting trends in automated attacks and application security,” explained DeCarlis.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Coast Guard to Create Red Team
Coast Guard to Create Red Team

The United States Coast Guard is to establish a Cyber Operational Assessments Branch this summer and create its first ever red team.
The planned restructuring, first reported by Federal News Network, will support the cybersecurity work currently being undertaken by the Coast Guard’s blue team.
Acting as a cyber adversary, the red team will emulate the behavior of threat actors and perform penetration tests to identify any weaknesses in the Coast Guard’s cyber-defenses.
Cyber blue team branch chief, Lt. Kenneth Miltenberger, said his team will continue to fulfill its existing duties, which include performing cooperative vulnerability assessments, security consulting for acquisition operations, and endpoint scanning.
Speaking at a webinar hosted last week by the Advanced Technology Academic Research Center (ATARC), Miltenberger said: “We’re excited to see that kind of fusion — of cooperative assessments, plus [the] red team for some kind of holistic assessments.”
Among the tasks assigned to the new Cyber Operational Assessments Branch will be an in-depth analysis of the challenges and opportunities associated with 5G infrastructure.
Dan Massey, the program lead of the Department of Defense’s 5G to NextG Initiative, said 5G infrastructure will help to reduce latency in augmented reality and virtual reality training.
“If I tried to do my AR/VR training by pushing everything back to a data center from Joint Base Lewis-McChord in Washington State back to a data center in the Pentagon, I’m stuck with a number of challenges just in terms of bandwidth, in terms of latency. It’s just not going to work well.
“But if I can distribute some of those key aspects out closer to the edge, almost all the way to the edge itself and combine that with back-end processing that might be happening back at that data center, I think I have the most powerful infrastructure,” said Massey.
Another recent technological development that saw the Coast Guard make the headlines was the military service’s decision to establish a UxS Cross Functional Working Group. The group’s mission will be to help the Coast Guard exploit the capabilities of existing and future unmanned systems.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Three-Quarters of CISOs Predict Another SolarWinds-Style Attack
Three-Quarters of CISOs Predict Another SolarWinds-Style Attack

Some 84% of global organizations have suffered a serious security incident over the past two years and a majority are expecting another SolarWinds-style supply chain attack, according to a new Splunk report.
The IT data platform provider interviewed 535 security leaders in nine leading economies across multiple industries, to compile its latest report, The State of Security 2021.
Of those that were successfully attacked, email compromise (42%) was the most common incident, followed by data breaches (39%), mobile malware (37%) and DDoS (36%).
However, over three-quarters (78%) expressed concern about more sophisticated supply chain attacks coming in the future.
Cloud complexity is emerging as a major threat to global organizations, with three-quarters (75%) of respondents already using multiple providers. Over half (53%) claimed attacks had increased in this area during the pandemic and 76% that remote workers are harder to secure.
Nearly 90% already run a substantial number of their business-critical applications in the public cloud.
Two of the key challenges of securing cloud environments highlighted by respondents were: maintaining and enforcing consistent policies (50%); and the complexity of using multiple security controls (42%).
Splunk urged organizations to modernize their Security Operations Centers (SOCs) with new SIEM platforms and more automation, such as in user and entity behavior analytics (UEBA) and security orchestration, automation and response (SOAR) tools.
It also advocated a zero trust approach, enhanced staff training and improved insight into network behavior to spot lateral movement more effectively.
“That modernized SOC will include an arsenal of the best tools and customization available. But that can create its own headaches, in terms of training and the ability to understand an incident with data from multiple sources,” the report concluded.
“In a complex, multi-cloud, multi-service environment, it’s essential to be able to see across all that data, not just traditional security data. This highest-level, end-to-end perspective is vital not only to security and compliance efforts, but to successful development and operations as well. A consolidated view of the data creates a single source of truth for security and IT teams.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk