Staff Bonus was “Crass” Phishing Simulation

Staff Bonus was “Crass” Phishing Simulation

A British train company has been criticized for running a cybersecurity test that made employees think they would receive a bonus for working hard during the pandemic.

West Midlands Trains sent an email purporting to be from the company’s managing director, Julian Edwards, out to its approximately 2,500 employees. The missive thanked staff for toiling through 2020 and told them that they would receive a one-off payment as a reward for their efforts. 

But what appeared to be a welcome bonus during difficult times was actually a phishing simulation. When workers clicked on a link that appeared to connect to a personal thank you from Edwards, they were greeted with a message stating that the email was a cybersecurity test.

“This was a test designed by our IT team to entice you to click the link and used both the promise of thanks and financial reward,” read the message, reported by The Guardian.

The leader of the trade union the Transport Salaried Staffs’ Association (TSSA) slammed the simulation as “crass and reprehensible” because many West Midlands Trains workers had been ill with the coronavirus and one had died after contracting COVID-19.

Manuel Cortes, general secretary of the TSSA, said: “This was a cynical and shocking stunt by West Midlands Trains, designed to trick employees who have been on the frontline throughout this terrible pandemic—ensuring essential workers were able to travel.

“The company must now account for their totally crass and reprehensible behavior. They could and should have used any other pretext to test their internet security. It’s almost beyond belief that they chose to falsely offer a bonus to workers who have done so much in the fight against this virus.”

A spokesperson for West Midlands Trains said that the simulation was an accurate representation of threat actors’ attack methods.

“We take cybersecurity very seriously. We run regular training and it’s important to test your resilience,” said the spokesperson.

“The design of the email was just the sort of thing a criminal organization would use—and thankfully it was an exercise without the consequences of a real attack.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

University Cancels Exams After Cyber-Attack

University Cancels Exams After Cyber-Attack

Final examinations at the oldest technological research university in America have been canceled following a cyber-attack.

Much of the computer network of Rensselaer Polytechnic Institute (RPI) was forced to shut down after unauthorized access was detected on Friday. Student assessments, research, and other academic activities have been impacted.

On May 8, the Institute took to Instagram to share news of the attack, stating: “Rensselaer is investigating a trespass into our university network.

“We have temporarily suspended access to the network as we work with law enforcement and cybersecurity experts to determine the extent of the trespass.”

Students whose online exams were impacted by the attack were told that they would be accommodated.

On May 9, the Institute announced that because of the security incident, all final examinations, term papers, and project reports that were due in today and tomorrow had been canceled.

In a social media post, RPI said: “As you are likely aware, suspension of access to the Rensselaer network has impacted final exams, research, and other academic activities. 

“We are writing to communicate that all final exams and submissions (e.g., term papers, project reports) scheduled or due for Monday (May 10th) and Tuesday (May 11th) are cancelled.”

Staff at RPI are taking steps to ensure that students’ futures are not negatively affected by the attack.

“Modifications to grading polices designed to accommodate this disruption are being developed and will be communicated in due time,” said the Institute.

RPI did not share any further details of the incident such as what information may have been accessed. The institute has not shared when its network will be up and running again but stated yesterday that “information about exams scheduled for Wednesday (May 12th) will be forthcoming.”

Jesse Madrid, a junior at RPI, told Chron: “We started looking around and we couldn’t access anything—LMS (the Student Information System), our RPI email, anything.

“People were making jokes at first, but now it’s day three.”

Rensselaer Polytechnic Institute, which has around 7,900 students, is a private university sited in the city of Troy, New York. Information Technology and Web Science are among the academic disciplines taught at the Institute.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Malicious UK Website Takedowns Surge 15-Fold in 2020

Malicious UK Website Takedowns Surge 15-Fold in 2020

The UK authorities took down over 700,000 malicious and phishing sites last year, a huge increase from 2019, according to the National Cyber Security Centre (NCSC).

The GCHQ body revealed the figures in its annual Active Cyber Defence (ACD) report. ACD is the NCSC’s four-year-old strategy to protect the public sector and, where possible, a broader audience.

It does so via a toolkit of around 14 initiatives, headed by the Takedown Service, which involves finding and removing malicious websites from the internet.

As well as 700,000+ websites, the service removed 1.4 million malicious URLs. Although COVID-19 scams surged in 2020, the NCSC said that the 15-fold increase in the volume of sites taken down was due to an expansion of the service, which saw it invest in a wider set of measures to address “different categories of campaigns.”

Among the institutions protected by the ACD last year was the NHS. The NCSC claimed to have detected and blocked 122 phishing campaigns spoofing the health service, up from just 36 in 2019. This included fake vaccine lures and over 40 malicious apps masquerading as official titles such as NHS Test and Trace in third-party app stores.

Also spoofed was the TV Licensing agency, which was hit by a surge of scam emails in July 2020 when entitlements for pensioners changed, and tax office the HMRC, which was the most phished brand last year.

Overall, more than 11,000 government-themed phishing campaigns were taken down — more than double the 2019 figure.

Meanwhile, the Suspicious Email Reporting Service, only launched in April 2020, received nearly four million reports by the end of the year, leading to the removal of over 26,000 scams not previously identified by the Takedown Service.

NCSC technical director, Ian Levy, said the ACD was made possible through partnerships at home and abroad.

“This has never been more important than in the last year, where it was vital for us to do everything we could to protect our most critical services and the wider public during the pandemic,” he added.

“The bold defensive approach taken by the ACD program continues to ensure our national resilience and so I urge public bodies, companies and the general public to sign up to the services available to help everyone stay safe online.”

The full ACD report is available to read here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK/US: Patch These 11 Bugs Now to Thwart Russian Spies

UK/US: Patch These 11 Bugs Now to Thwart Russian Spies

The US and UK governments have released new information on the current tactics of Russian cyber-spies, including 11 vulnerabilities dating back to 2018 that are being used for initial access.

The new report, Further TTPs associated with SVR cyber actors, was released by the UK’s National Cyber Security Agency (NCSC) and the US Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency and FBI.

It updates readers on the activities of the Russian Foreign Intelligence Service (SVR) — also known as APT29, Cozy Bear, and The Dukes — blamed for the recent SolarWinds attacks and many other espionage campaigns.

In a classic cat-and-mouse game, the SVR appears to have recently changed its tactics in response to a previous report issued by the US and UK, in an attempt to stay hidden.

This includes exploitation of widely reported Microsoft Exchange Server bugs, they claimed.

The report also listed 11 flaws in products from Fortinet, Cisco, Oracle, Zimbra, Pulse Secure, Citrix, Elasticsearch, VMware and F5 which are being exploited by the SVR to gain access to victim networks.

“This list should not be treated as exhaustive,” the report warned.

“The group will look to rapidly exploit recently released public vulnerabilities which are likely to enable initial access to their targets.”

The government report also flagged the SVR’s use of legitimate tool Cobalt Strike, as well as a custom backdoor (GoldMax), downloader (Sibot), HTTP tracer tool (GoldFinder), and open source Red Team command and control framework (Sliver), in post-compromise activity.

Organizations should be particularly careful to protect their administrator mailboxes as these are a common target for SVR attackers, who use access to better understand the victim’s network and to obtain further privileges and credentials for persistence and lateral movement.

Gurucul CEO, Saryu Nayyar, argued that as long as unpatched systems remain openly accessible, attacks will continue.

“The payloads may change depending on what the threat actor is after, but attackers will continue to leverage vulnerabilities in web servers, routers and virtualization software until there aren’t any vulnerable hosts to exploit,” she added.

“This series of attacks is a reminder of how important it is to patch security vulnerabilities, and to make sure the network is protected with an up-to-date security stack.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Takes Down East Coast Fuel Pipeline

Ransomware Takes Down East Coast Fuel Pipeline

The US government has been forced to issue emergency legislation after a ransomware attack knocked offline the country’s largest fuel pipeline.

Colonial Pipeline confirmed over the weekend that it had suffered a serious cyber-attack.

“Quickly after learning of the attack, Colonial proactively took certain systems offline to contain the threat. These actions temporarily halted all pipeline operations and affected some of our IT systems, which we are actively in the process of restoring,” it said in an update on Sunday.

“While our mainlines (Lines 1, 2, 3 and 4) remain offline, some smaller lateral lines between terminals and delivery points are now operational. We are in the process of restoring service to other laterals and will bring our full system back online only when we believe it is safe to do so, and in full compliance with the approval of all federal regulations.”

The government legislation is designed to relax rules restricting the transportation of fuel by road.

However, if the outage persists there are likely to be shortages and price rises across the 12 states the pipeline travels through and beyond. Reports suggest it carries 2.5 million barrels a day, representing nearly half of the East Coast’s supply of diesel, gasoline and jet fuel.

According to the BBC, the attack was launched by the Russian-speaking DarkSide group, who claim to have also stolen 100GB of data in a classic “double extortion” play.

“Being able to take systems offline and begin a process of restoration is undeniably important, but there is an additional threat if this data is exposed. It underlines the importance of international collaboration to bring down these highly coordinated groups early in their development if we want to protect our critical services,” argued Nominet government cybersecurity expert, Steve Forbes.

“As we watch the domino effect of this cyber-attack, it is very apparent that impact is not limited to systems and software — victims will come in all shapes and sizes, from industries to individuals.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Shuts Down US Pipeline

This is a major story: a probably Russian cybercrime group called DarkSide shut down the Colonial Pipeline in a ransomware attack. The pipeline supplies much of the East Coast. This is the new and improved ransomware attack: the hackers stole nearly 100 gig of data, and are threatening to publish it. The White House has declared a state of emergency and has created a task force to deal with the problem, but it’s unclear what they can do. This is bad; our supply chains are so tightly coupled that this kind of thing can have disproportionate effects.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Gartner names McAfee a Leader in 2021 Magic Quadrant for Endpoint Protection Platforms

At McAfee, we believe no one person, product or organization can combat cybercrime alone. That is why we continue to build our device-to-cloud security platform on the premise of working together – together with customers, partners and even other cybersecurity vendors. We continue this fight against the greatest challenges of our digital age: cybercrime. As part of our ongoing effort to protect what matters, we have developed breakthrough technologies over the past several years that enable customers to proactively respond to emerging threats and adversaries despite a constantly evolving threat landscape. So, today, we are extremely proud to announce that McAfee is positioned as a “Leader” in the 2021 Gartner Magic Quadrant for Endpoint Protection Platforms (EPP).   

This is a monumental development in so many ways, especially when you consider that we were not recognized in the Magic Quadrant a few years ago. This recognition speaks volumes about the innovations we are bringing to market that resonate both with our customers and industry experts. Let me review, from my perspective, why McAfee is recognized in the Leaders Quadrant.  

Here are some key innovations in our Endpoint Protection Platform that contributed to our Leader recognition: 

  • MVISION Endpoint Security (ENS) – to prevent ransomware, fileless attacks, and defend against other advanced persistent threats.  
  • MVISION Insights – to preempt and prevent attacks before they hit. 
  • MVISION EDR – to identify and stop sophisticated threat campaigns 
  • Unique capabilities to Auto-recover from ransomware attacks (Demo) 

Vision    

We set out with a vision, to create the most powerful endpoint protection platform and we are aggressively executing towards this vision. Over the past 12 months, we have made great strides in developing a market leading product, MVISION Insights, and our cloud delivered MVISION EDR. Looking ahead, our goal is to develop a unified and open eXtended Detection and Response (XDR) solution and strategy that further delivers on our device-to-cloud strategy 

We believe, McAfee’s position as a Leader further acknowledges some of our key differentiators, such as MVISION Insights, and our ability to eclipse the market with an innovative device-to-cloud strategy that spans the portfolio, including web gateway, cloud, and our network security offerings. 

Executing on Innovation 

We started by redefining our endpoint security offering with the release of MVISION Insights, a game-changing product that functions as the equivalent of an early warning system – effectively delivering preventative security. It’s hard to understate the significance of this innovation; we’re breaking the old paradigm of post-attack detection and analysis and enabling customers to stay ahead of threats. In parallel, we streamlined our EDR capabilities, which now provide AI-driven, guided investigations that ease the burden on already-stretched Security Operations Centers (SOCs) 

Increasing Value 

The bottom line is that we’re the only vendor taking a proactive risk management approach for safer cloud usage while reducing total cost of ownership. In addition, we have improved our licensing structure to fit customer needs and simplify consumption of our endpoint security solutions. We’ve made it easy to choose from a simplified licensing structure allowing customers to buy subscriptions for complete endpoint protection with no add-ons or extra costs. Our user-based licensing agreements provide for 5 devices, thus enabling frictionless expansion to incorporate additional device support in remote work environments 

Validation 

In just under a year, our latest release of McAfee Endpoint Security (ENS) 10.7 has emerged as our highest deployed version of any McAfee product worldwide and our fastest-ever single-year ramp. More than 15,000 customers comprising tens of millions of nodes are now on ENS 10.7 and are deploying its advanced defenses against escalating threats. Customers get added protected because ENS 10.7 is backed by our Global Threat Intelligence (GTI) service to provide adaptable, defense in-depth capabilities against the techniques used in targeted attacks, such as ransomware or fileless threats. It’s also easier to use and upgrade. All of this means your SOC can be assured that customers are protected with ENS 10.7 on their devices.  

Customer input guides our thinking about what to do next. Since the best critics are the people who use our products, let’s give them the last word here.  

“We are now positioned to block usage of personal instances of Sanctioned services while allowing the business to move forward with numerous cloud initiatives, without getting in the way. We also now have the visibility that was lacking to ensure that we can allow our user community to work safely from their homes without introducing risks to our corporate environment.” 

 Kenn JohnsonCybersecurity Consultant 

Commitment:  

Our continued commitment to our customers is to protect what matters. We believe that McAfee’s position in the Leaders  Quadrant validates that we are innovating at the pace and scale that meets the most stringent needs of our enterprise customers. We are proud of our product teams and threat researchers who continue to be driven by our singular mission, and who strive to stay ahead of adversaries with their focus on technological breakthroughs, and advancements in researching threats and vulnerabilities. 

What we have accomplished over the past several years, and our position as a Leader in the 2021 Gartner Magic Quadrant for EPP, is only the tip of the iceberg for what’s ahead.  

2021 Gartner Magic Quadrant for Endpoint Protection Platforms

McAfee named a Leader in the 2021 Gartner Magic Quadrant for Endpoint Protection Platforms. Download the Magic Quadrant report, which evaluates the 19 vendors based on ability to execute and completeness of vision.

Download Now

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. 

 

Gartner Magic Quadrant for Endpoint Protection Platforms Authored by: Analyst(s): Peter Firstbrook, Dionisio Zumerle, Prateek Bhajanka, Lawrence Pingree,Paul Webber. Published May 2021

The post Gartner names McAfee a Leader in 2021 Magic Quadrant for Endpoint Protection Platforms appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

More Apps for Younger Users Emerging. Here’s What Parents Need to Know.

More and more social platforms are coming up with safer ways for younger kids to access their apps. The most recent announcement comes from Facebook who is reportedly creating a version of Instagram for kids 13 and under.

It’s a family safety win to see so many companies (YouTube, TikTok, and Facebook have parental control channels) making changes. That’s because currently, kids under 13 have no problem getting around an app’s age restrictions, a decision that can expose them to risks such as cyberbullying, stranger connections, and inappropriate content.

With apps making an overall shift toward safer experiences, areas of concern for families still exist especially since kids are increasingly connecting with social media companies before they enter middle school. Here are just a few things to consider as your child moves into the world of social networking, regardless of his or her age.

Family Talking Points

  1. The emotional side of social. Not all social networks work the same. Instagram is photo-based, which means a child’s experience may impact self-esteem and mental health more so than a network that is solely text-based. Consider talking to your child about the risks often associated with Instagram such as body image, cyberbullying, mental health issues. Regardless of age, it’s important to keep close tabs on a child’s mental health if they spend time online.
  1. Talk about the risks. The years before kids begin using the trendier social networks, is a critical window to have honest, age-appropriate conversations. Consider discussing what kinds of things to look out for online, including bullying, predatory behavior, and inappropriate content.
  1. Explain monetization. While social networks are a way of life for teens today, there’s so much more going on behind the scenes. Consider discussing the concept of monetization with your kids so they are aware of the businesses churning behind social networks. Cultivating the next generation of untapped users is a huge piece of a tech company’s strategy. Creating safer avenues for younger kids is a win for parents. However, introducing kids to a platform as early as possible is a big win for tech companies as well.
  1. Discuss personal privacy. One of the biggest risks to kids online — and often the one kids care about the least — is privacy and how social networks collect and use kids’ data. It’s never too early to start talking about privacy and ways to reign in your family’s digital footprint.
  1. Start building digital skills. The tween years are critical to preparing your child to eventually spend more time on social platforms for kids over 13. In addition to privacy, consider other important topics such as digital literacy, cyberbullying, online scams, why parental controls matter, and other important digital skills.

The window between 9-12 is an important one when it comes to teaching kids digital skills and influencing their digital behavior. It’s never too early to begin these conversations. Remember, kids need aware, digitally savvy parents more than ever to prepare them for the challenges ahead.

Stay Updated

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our newsletter, listen to our podcast Hackable?, and ‘Like’ us on Facebook.

The post More Apps for Younger Users Emerging. Here’s What Parents Need to Know. appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk