Lessons We Can Learn From Airport Security

Most of us don’t have responsibility for airports, but thinking about airport security can teach us lessons about how we consider, design and execute IT security in our enterprise. Airports have to be constantly vigilant from a multitude of threats; terrorists, criminals, rogue employees and their security defenses need to combat major attacks, individual threats, stowaways, smuggling as well as considering the safety of passengers and none of this can stop the smooth flow of travelers as every delay has business knock on effects. Whew! And this is just the start.

The airport operators are a lesson in supply-chain and 3rd party communications. They cooperate with airlines, retailers and government agencies, and their threats can be catastrophic. They also need to consider mundane problems like how do you move a large number of people around quickly, what to do when someone leaves a bag to go shopping and how to balance risk reduction with traveler comfort – many needs to be considered, planned for and the execution when a risk is identified needs to be immediate. All this before thinking about IT-related issues, thefts from retailers, employee assessments and training, building safety, people tracking and … the list seems almost endless.

Our business IT security needs might not seem so complex; however every enterprise has its external and internal attackers; hackers, ransomware, DDoS attacks to take down your systems and rogue employees or inadvertent actions by good employees who don’t realize what link they are clicking on or data they are over-sharing. At the same time, the business needs to be able to enable the newest and most effective apps and systems and employees hate anything that appears to get in their way.

So, let’s see what airports can teach us about thinking about possible threats and appropriate safeguards to deploy a layered approach that protects your data, users and infrastructure.

If you take just one threat; terrorism as – this image shows that US airports have more than 20 layers of security – a mixture of human and technological measures.

There’s no silver bullet, there’s not one piece of security awareness or technology that will solve all problems – but if integrated, they can all build together to draw a picture of the possible threat.  Our defenses shouldn’t rely on just one technology either, but when we have multiple capabilities working together, we can evaluate, identify and address our security needs.

Here’s my table of some of the needs of an airport and equivalent areas in general IT security. Just as in an airport, individual pieces are of limited benefit unless they are brought together. Even though each item improves overall security, a single management console that can correlate all these pieces of knowledge and suggest or make policy decisions is crucial to ensure you get maximum benefit.

Airport Enterprise IT
Check ticket against passport Global SSO and multi-factor authentication for every app (including cloud)
X-ray baggage Scan attachments for malware
Security gates and handbaggage check DLP for confidential data loss control
Facial recognition comparing security gate and plane gate with ticket Zero trust – keep checking at all times
Baggage weight check Review email attachments – treat previously unseen executables as suspect
CCTV as passengers move around airport User behavior analytics for risky behavior
Database of travellers, prior travel, destination information Logging / analytics
Temperature tests for COVID Block surfing to high risk web sites
Visa requirements Access control to sensitive areas or sensitive data
Check expiry date on passport Reconfirm credentials after a period
History of prior travel User behavior analytics to understand “normal traffic” for each individual user and alert on unusual patterns.
Open Skies Initative – sharing data with destination – allowing arrest on landing Insights to check and implement defences before attacks based on other organization’s threats
Landing card (where staying, reason etc.) Employee justification for actions – feedback loops when challenged
Finger prints on landing – check against previous travel history Insights
Security guards, customs agents, check in staff, people monitoring CCTV The personal touch – the SOC team investigating threats and defining and implementing policies
Different security lines for additional checks Remote Browser Isolation
Overall SOC center to correlate all inputs Global management

 

What have we learned?

Firstly, the job of securing an airport is complex and involves a lot of planning, cooperation with 3rd parties and a vast mixture of people and technology-based security.

Secondly, we cannot rely on one defense, just like airports.

Thirdly, concepts like zero trust, MITRE ATT&CK framework, Cyber Kill Chain are all aiming to look at threats in the round – we need look at threats from every angle we can and implement the best technology we can.

The best solutions will be integrated, you need to be able to collate activity patterns to evaluate risks and define defenses.  McAfee’s Device to Cloud Suites are designed to bring together multiple systems all under one umbrella and let you accelerate cloud adoption, improve productivity and bring together more than ten different security technologies all managed by McAfee ePO.

 

Device to Cloud Suites

Easy, comprehensive protection that spans endpoints, web, and cloud

Learn more

 

The post Lessons We Can Learn From Airport Security appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Beware of BRATA: How to Avoid Android Malware Attack

Cybercriminals go to great lengths to hack personal devices to gather sensitive information about online usersTo be more effective, they make significant investments in their technology. Also, cybercriminals are relying on tactic called social engineering, where they capitalize upon fear and urgency to manipulate unsuspecting device users to hand over their passwords, banking information, or other critical credentials. 

One evolving mobile device threat that combines malware and social engineering tactics is called BRATA. BRATA has been recently upgraded by its malicious creators and several strains have already been downloaded thousands of times, according to a McAfee Mobile Research Team report 

Here’s how you can outsmart social engineering mind games and protect your devices and personal information from BRATA and other phishing and malware attacks. 

BRATA stands for Brazilian Remote Access Tool Android and is a member of an Android malware familyThe malware initially targeted users in Brazil via Google Play and is now making its way through Spain and the United States. BRATA masquerades as an app security scanner that urges users to install fake critical updates to other apps. The apps BRATA prompts the user to update depends on the device’s configured language: Chrome for English speakers, WhatsApp for Spanish speakers, and a non-existent PDF reader for Portuguese speakers. 

Once BRATA infects a mobile device, it combines full device control capabilities with the ability to capture screen lock credentials (PIN, password, or pattern), capture keystrokes (keylogger functionality), and record the screen of the compromised device to monitor a user’s actions without their consent. 

BRATA can take over certain controls on mobile phones, such as: 

  • Hiding and unhiding incoming calls by setting the ring volume to zero and blacking out the screen 
  • Discreetly granting permissions by clicking the “Allow” button when permission dialogs appear on the screen 
  • Disabling Google Play Store, and therefore, Google Play Protect 
  • Uninstalling itself 

BRATA is like a nosy eavesdropper that steals keystrokes and an invisible hand that presses buttons at will on affected devices. 

BRATA and Social Engineering Attacks 

BRATA’s latest update added new phishing and banking Trojan capabilities that make the malware even more dangerousOnce the malware is installed on a mobile device, it displays phishing URLs from financial institutions that trick users into divulging their sensitive financial information. What makes BRATA’s banking impersonations especially effective is that the phishing URLs do not open into a web browser, which makes it difficult for a mobile user to pinpoint it as fraudulent. The phishing URLs instead redirect to fake banking log-in pages that look legitimate. 

The choice to impersonate banks is a strategic one. Phishers often impersonate authoritative institutions, such as banks and credit card companies, because they instill fear and urgency. 

Social engineering methods work because they capitalize on the fact that people want to trust others. In successful phishing attacks, people hand cybercriminals the keys instead of the cybercriminal having to steal the keys themselves. 

How Can You Stay Safe from Social Engineering? 

Awareness is the best defense against social engineering hacks. When you’re on alert and know what to look for, you will be able to identify and avoid most attempts, and antivirus tools can catch the lures that fall through the cracks. 

Here are three tell-tale signs of a social engineering attack and what you should do to avoid it. 

1. Conduct app research 

Just because an app appears on Google Play or the App Store does not mean it is legitimate. Before downloading any app, check out the number of reviews it has and the quality of the reviews. If it only has a few reviews with vague comments, it could either be because the app is new or it is fake. Also, search the app’s developer and make sure they have a clean history.  

 2. Don’t trust links from people you don’t know 

Never click on links if you are not sure where they redirect or who sent it. Be especially wary if the message surrounding the link is riddled with typos and grammar mistakes. Phishing attempts often convey urgency and use fear to pressure recipients to panic and respond too quickly to properly inspect the sender’s address or request. If you receive an urgent email or text request concerning your financial or personal information, take a deep breath and investigate if the claim is legitimate. This may require calling the customer service phone number of the institution.  

3. Subscribe to a mobile antivirus program 

Just like computers, mobile devices can be infected with viruses and malware. Protect your mobile device by subscribing to a mobile antivirus product, such as McAfee Mobile Security. McAfee Mobile Security is an app that is compatible with Android devices and iPhones, and it protects you in various ways, including safe surfing, scanning for malicious apps, and locating your device if it is lost or stolen. 

Stay Updated 

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook. 

The post Beware of BRATA: How to Avoid Android Malware Attack appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Dating Service Suffers Data Breach

Dating Service Suffers Data Breach

Men’s social networking website and online dating application Manhunt has suffered a data breach. 

According to a security notice filed with the office of the Washington attorney general on April 1, the 20-year-old site was compromised in a cyber-attack that took place in February 2021.

An unauthorized third party downloaded personal information belonging to some Manhunt users after gaining access to the company’s account credential database.

The compromised database contained customers’ usernames, email addresses, and passwords. After discovering that a breach had occurred, Manhunt performed a forced reset of all users’ passwords.

Manhunt began notifying users of the security incident last month. The company did not say how many of the approximately 6 million men who use the site had been impacted by the attack.

In the notice of data breach, Manhunt revealed that the personal information of an estimated 7,714 Washington residents had been affected. 

The breach was discovered by Manhunt on March 2. An investigation into the incident revealed that the attacker(s) had downloaded customers’ data at the beginning of February. 

“On March 2, 2021, Manhunt discovered that an attack gained access to a database that stored account credentials for Manhunt users,” wrote the company in the notice. 

“The attacker downloaded the usernames, email addresses and passwords for a subset of our users. We immediately took steps to remediate the threat and reset the passwords of affected users.”

Following the breach, Manhunt retained a third-party forensics consultant “to assist us in investigating what happened and confirm that there is no ongoing unauthorized access to our systems.” 

The company said that no evidence had been found to suggest that users’ pictures, messages, or other information from their profiles had been accessed by the hacker. 

No payment card information was exposed because of the incident as Manhunt doesn’t transmit or store this type of information. 

The company warned users to be on the lookout for phishing messages from threat actors impersonating Manhunt or claiming to have information about users. Customers were reminded that the company would never ask them for their password or other sensitive information over email.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

School District’s Files Leaked in $40m Ransomware Attack

School District’s Files Leaked in $40m Ransomware Attack

A South Florida school district that refused to pay its cyber-attackers a $40m ransom has had thousands of its files leaked online. 

Broward County Public Schools was targeted by the Conti ransomware gang at the beginning of March in an attack that caused a shutdown of its computer system but left classes undisturbed. 

Conti demanded that the sixth-largest school district in the United States hand $40m of its annual $4bn budget over to them. 

In a transcript published by the gang, a negotiator for the district allegedly said that the ransom demand was impossibly large and countered with an offer to pay $500k. The ransomware gang turned the offer down but dropped their demand by three quarters to $10m. 

On March 31, the office of Broward’s chief communications officer, Kathy Koch, released a statement declaring that although the district “is aware of the recent actions taken by the criminals who breached our system,” it had no intention of paying those criminals a ransom. 

On April 19, Conti published nearly 26,000 files that had been exfiltrated from the school district. Reporters at the South Florida Sun Sentinel who reviewed the data found “a few isolated incidents where confidential student or employee information was released.”

The 25,971 files date from 2012 to March 2021 and chiefly contain financial records, including purchase orders, invoices, and travel expenses claim forms. 

While no Social Security information was found amongst the leaked data, it did include several employee phone lists. 

Personal information belonging to one nine-year-old student was exposed on an invoice from the state health department. 

The Sentinel reported that most of the Broward data published by Conti is already a matter of public record. Among the information are payments to local police departments and the Broward Sheriff’s Office for security, utility bills, 750 mileage reports, and over 700 invoices for spring water. 

In the hope of preventing another cyber-attack on Broward, the school district’s chief information officer, Phil Dunn, has requested $20m for cybersecurity enhancement. He warned the school board last week that another hit could be devastating.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Threat Actor Claims to Have Hacked Domino’s

Threat Actor Claims to Have Hacked Domino’s

A threat actor is claiming to have stolen the personal data of over a million customers of Domino’s Pizza.

In an advert placed on the dark web, the alleged hacker says that they are selling 13 terabytes of data that they claim was stolen from the Indian branch of the American multinational pizza restaurant. 

The illicit advertisement was discovered by Alon Gal, the co-founder and chief technology officer of Israel-based cybercrime intelligence firm Hudson Rock. Gal posted news of the alleged hack on social media on April 18.

In his post, the cybersecurity specialist said that the data appeared to include the details of as many as 180 million Domino’s orders. Among the allegedly leaked information was sensitive customer data, including phone numbers, addresses, email addresses, and the details of over one million credit cards.

Gal said that dark web users were being offered the opportunity to purchase the data for $550,000.

To enable the data to be selectively picked through, the threat actor said that they would be building a search portal. 

A spokesperson for Domino’s Pizza in India said that Jubilant FoodWorks Limited, which holds the master franchise for Domino’s Pizza in India, Nepal, Sri Lanka, and Bangladesh, had experienced an information security incident recently. 

“No data pertaining to financial information of any person was accessed and the incident has not resulted in any operational or business impact,” said the spokesperson.

They added that customers’ financial data was not vulnerable to hacking attacks because of the company’s data storage practices.

“As a policy, we do not store financial details or credit card data of our customers, thus, no such information has been compromised,” said the spokesperson. 

They added: “Our team of experts is investigating the matter and we have taken necessary actions to contain the incident.”

Cybersecurity researcher Rajshekhar Rajaharia said that he alerted the Indian government’s Computer Emergency Response Team (CERT-In) on March 5 that data belonging Domino’s may have been exposed on the dark web since February.

On Twitter, Rajaharia said that the threat actor claiming to have hacked the pizza restaurant may be the same person who allegedly hacked India’s largest independent mobile payments network, MobiKwik, in February.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

QR Code Malware Threat as Lockdown Ends

QR Code Malware Threat as Lockdown Ends

UK consumers are keen to embrace the use of QR codes as the country exits COVID-19 lockdown, but security experts have warned that low awareness levels could be exploited by cyber-criminals.

Security vendor Ivanti recently polled over 500 British consumers to better understand their attitudes to QR codes.

The technology is increasingly being used in hospitality settings like bars and restaurants to enable customers to access “touch-free” menus and other information in a more hygienic way.  

In fact, 96% of UK respondents to the Ivanti poll said they’d scanned a QR code on their mobile device in restaurants or retail stores in the past six months. Four in five (80%) agreed that QR codes make life easier.

However, Ivanti warned that they could also be booby-trapped to download malware and other threats to users’ devices.

“Hackers spent lockdown exploring new ways to exploit consumers, so we can expect hackers to get even more creative with QR codes now that the UK is reopening shops, bars and restaurants,” said Nigel Seddon, VP of EMEA West at Ivanti.

“For example, a malicious QR code can easily be pasted over the one provided by a restaurant or bar, to trick a user into paying for the bad actor’s next holiday instead of a round of drinks.”

The problem is compounded by a lack of awareness of such threats among the general public, the vendor claimed.

Almost half (48%) of respondents said they don’t know if they have mobile security software installed on their device. A majority also said they didn’t know that scanning these codes could also download an app, start a phone call or initiate a text message.

Nearly two-thirds (65%) believe QR codes only open links.

There’s also a potential risk to businesses, if BYOD devices allowed to connected to corporate networks have been compromised by QR code malware, Ivanti warned.

“By not knowing if their mobile devices are secure, people are directly putting businesses in jeopardy of cyber-attacks,” Seddon argued.

“With an increasing number of employees utilizing their mobile devices for business purposes, it is critical that organizations re-evaluate their security strategies to center on mobile devices.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Campus Still Closed as Portsmouth University Reels from Suspected Ransomware

Campus Still Closed as Portsmouth University Reels from Suspected Ransomware

Key IT systems at the University of Portsmouth continue to remain offline this week after a supposed ransomware attack, delaying the start of the new term.

A notice on the university’s homepage doesn’t explicitly name ransomware as the cause of the “cyber incident,” but the “ongoing technical disruption” it describes is a tell-tale sign of such attacks. However, The News has reported that it has seen an email from the university claiming it suffered a ransomware attack. 

“This has affected some of our IT systems, which remain offline whilst we work with expert support to investigate the issue and securely restore these systems,” the notice said.

“As part of this, we have taken the decision to close down many of our services in order to best protect our systems and information while the investigation is underway.”

Although it was due to open on Monday for the start of the summer term, the university campus will continue to remain closed to students until Wednesday, according to a BBC report.

It also claimed that police had been notified about the incident.

“We are working with an experienced cybersecurity forensic firm to address the issue and to investigate and remedy the incident as quickly as we can,” the homepage notice concluded. “This is a complex issue and we appreciate your patience while we resolve this matter.”

It is also an issue which has faced countless higher education institutions in the UK and abroad over recent months and years, as cyber-criminals have relentlessly targeted a sector they see as under-resourced and vulnerable to extortion.

Last week we reported how the University of Hertfordshire in southern England suffered a major ransomware-related outage taking down its network for days.

A report last year claimed that a third of UK universities have been hit with ransomware over the past decade.

Such attacks threaten to impact what was a thriving sector of the UK economy pre-COVID, with a market size of nearly £41 billion. Situated on Britain’s south coast, Portsmouth University has around 25,000 students.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Government Reviews Nvidia-Arm Deal on National Security Fears

UK Government Reviews Nvidia-Arm Deal on National Security Fears

The UK government has stepped in to review the sale of chip designer Arm to Nvidia on national security as well as competition grounds.

Digital Secretary Oliver Dowden yesterday issued a Public Interest Intervention Notice (PIIN), which will require regulator, the Competition and Markets Authority (CMA), to begin a “phase one” investigation.

“As a next step and to help me gather the relevant information, the UK’s independent competition authority will now prepare a report on the implications of the transaction, which will help inform any further decisions,” he said in a statement.

“We want to support our thriving UK tech industry and welcome foreign investment, but it is appropriate that we properly consider the national security implications of a transaction like this.”

Under the Enterprise Act 2002, the digital secretary has “quasi-judicial” powers to intervene in some mergers on public interest grounds.

The CMA now has until July 30 to complete and send its report to Dowden. After that time the secretary could clear the transaction, require remedies to the competition or public interest concerns, or refer it to a “phase two” investigation.

Depending on the outcome of that potential second phase of CMA work, the digital secretary could theoretically block the merger.

The CMA had already stated its intention to look into the proposed $40 billion deal on competition grounds after it was announced last September.

Despite Nvidia assurances that Arm’s HQ would not move from Cambridge and that it would maintain the chip designer’s neutrality, concerns have been raised not only in the UK but among many of Arm’s 500-odd customers about the deal.

The design and production of semiconductors are increasingly seen as strategically critical to countries’ national and financial security. Arm’s designs can be found in the vast majority of smartphones on the planet, including handsets from the likes of Apple and Samsung. Its chips also have uses in technologies related to defense.  

America’s FTC is also looking at the takeover on competition grounds.

SoftBank acquired Arm for $32bn (£23bn) back in 2016.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Government Unveils Plans to Speed Up Rollout of 5G Technology

UK Government Unveils Plans to Speed Up Rollout of 5G Technology

The UK government has announced plans to speed up the rollout of 5G technology, which could have major implications for cybersecurity as experts warn that it will expand the attack surface for cyber-criminals.

Under the proposals, mobile companies will be allowed to make new and existing masts up to five meters taller and two meters wider, allowing operators to fit more equipment so they can be shared easily.

This is expected to have a particularly big impact for countryside areas, as it will mean rural communities will need fewer masts to get a better signal as well as be able to more easily take advantage of 5G-connected technology. As a result, this will reduce the build time and cost of new telecom infrastructure as well as minimize the visual impact of masts.

Also included in the joint technical consultation between the Department for Digital, Culture, Media and Sport (DCMS) and the Ministry for Housing, Communities and Local Government (MHCLG) are reforms to allow greater flexibility for installing cabinets in existing compounds to support new 5G networks. The consultation will last for eight weeks, closing on June 14, 2021.

The proposals are part of the previously stated desire of the UK government to put the country at the forefront of 5G technology. While the growth in 5G offers opportunities for advancements in cybersecurity, experts have warned that it will expand the attack surface for cyber-criminals, as a result of the likely rise of IoT devices and the potential for the development of so-called “smart cities.”

The final report of the Telecoms Diversification Taskforce, set up to provide independent advice on how to boost competition and innovation in the UK telecoms market, has also been published today. This follows the decision last year by the UK government to remove Huawei equipment from Britain’s 5G network by 2027 due to national security concerns. Among its recommendations, the taskforce has advised policy interventions to support the entry of new vendors into the UK market and to identify opportunities to invest in long-term research and innovation to build UK capability for current and future generations of telecoms technology.

Matt Warman, Minister for Digital Infrastructure, commented: “Our £250 million strategy will unleash a wave of innovation across the UK and make sure companies have a wide range of revolutionary 5G technology to choose from that is trusted and secure.

“I welcome today’s report from the Telecoms Diversification Taskforce. It will be instrumental in helping us prepare our networks for next-generation mobile technologies. We will now consider its recommendations and respond in due course.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk