More Biden Cybersecurity Nominations

News:

President Biden announced key cybersecurity leadership nominations Monday, proposing Jen Easterly as the next head of the Cybersecurity and Infrastructure Security Agency and John “Chris” Inglis as the first ever national cyber director (NCD).

I know them both, and think they’re both good choices.

More news.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

McAfee Labs Report Reveals Latest COVID-19 Threats and Malware Surges

The McAfee Advanced Threat Research team today published the McAfee Labs Threats Report: April 2021.

In this edition, we present new findings in our traditional threat statistical categories – as well as our usual malware, sectors, and vectors – imparted in a new, enhanced digital presentation that’s more easily consumed and interpreted.

Historically, our reports detailed the volume of key threats, such as “what is in the malware zoo.” The introduction of MVISION Insights in 2020 has since made it possible to track the prevalence of campaigns, as well as, their associated IoCs, and determine the in-field detections. This latest report incorporates not only the malware zoo but new analysis for what is being detected in the wild.

The Q3 and Q4 2020 findings include:

  • COVID-19-themed cyber-attack detections increased 114%
  • New malware samples averaging 648 new threats per minute
  • 1 million external attacks observed against MVISION Cloud user accounts
  • Powershell threats spiked 208%
  • Mobile malware surged 118%

Additional Q3 and Q4 2020 content includes:

  • Leading MITRE ATT&CK techniques
  • Prominent exploit vulnerabilities
  • McAfee research of the prolific SUNBURST/SolarWinds campaign

These new, insightful additions really make for a bumper report! We hope you find this new McAfee Labs threat report presentation and data valuable.

Don’t forget keep track of the latest campaigns and continuing threat coverage by visiting our McAfee COVID-19 Threats Dashboard and the MVISION Insights preview dashboard.

The post McAfee Labs Report Reveals Latest COVID-19 Threats and Malware Surges appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Patch Tuesday, April 2021 Edition

Microsoft today released updates to plug at least 110 security holes in its Windows operating systems and other products. The patches include four security fixes for Microsoft Exchange Server — the same systems that have been besieged by attacks on four separate (and zero-day) bugs in the email software over the past month. Redmond also patched a Windows flaw that is actively being exploited in the wild.

Nineteen of the vulnerabilities fixed this month earned Microsoft’s most-dire “Critical” label, meaning they could be used by malware or malcontents to seize remote control over vulnerable Windows systems without any help from users.

Microsoft released updates to fix four more flaws in Exchange Server versions 2013-2019 (CVE-2021-28480, CVE-2021-28481, CVE-2021-28482, CVE-2021-28483). Interestingly, all four were reported by the U.S. National Security Agency, although Microsoft says it also found two of the bugs internally. A Microsoft blog post published along with today’s patches urges Exchange Server users to make patching their systems a top priority.

Satnam Narang, staff research engineer at Tenable, said these vulnerabilities have been rated ‘Exploitation More Likely’ using Microsoft’s Exploitability Index.

“Two of the four vulnerabilities (CVE-2021-28480, CVE-2021-28481) are pre-authentication, meaning an attacker does not need to authenticate to the vulnerable Exchange server to exploit the flaw,” Narang said. “With the intense interest in Exchange Server since last month, it is crucial that organizations apply these Exchange Server patches immediately.”

Also patched today was a vulnerability in Windows (CVE-2021-28310) that’s being exploited in active attacks already. The flaw allows an attacker to elevate their privileges on a target system.

“This does mean that they will either need to log on to a system or trick a legitimate user into running the code on their behalf,” said Dustin Childs of Trend Micro. “Considering who is listed as discovering this bug, it is probably being used in malware. Bugs of this nature are typically combined with other bugs, such as browser bug of PDF exploit, to take over a system.”

In a technical writeup on what they’ve observed since finding and reporting attacks on CVE-2021-28310, researchers at Kaspersky Lab noted the exploit they saw was likely used together with other browser exploits to escape “sandbox” protections of the browser.

“Unfortunately, we weren’t able to capture a full chain, so we don’t know if the exploit is used with another browser zero-day, or coupled with known, patched vulnerabilities,” Kaspersky’s researchers wrote.

Allan Laska, senior security architect at Recorded Future, notes that there are several remote code execution vulnerabilities in Microsoft Office products released this month as well. CVE-2021-28454 and CVE-2021-28451 involve Excel, while CVE-2021-28453 is in Microsoft Word and CVE-2021-28449 is in Microsoft Office. All four vulnerabilities are labeled by Microsoft as “Important” (not quite as bad as “Critical”). These vulnerabilities impact all versions of their respective products, including Office 365.

Other Microsoft products that got security updates this month include Edge (Chromium-based), Azure and Azure DevOps Server, SharePoint Server, Hyper-V, Team Foundation Server, and Visual Studio.

Separately, Adobe has released security updates for Photoshop, Digital Editions, RoboHelp, and Bridge.

It’s a good idea for Windows users to get in the habit of updating at least once a month, but for regular users (read: not enterprises) it’s usually safe to wait a few days until after the patches are released, so that Microsoft has time to iron out any kinks in the new armor.

But before you update, please make sure you have backed up your system and/or important files. It’s not uncommon for a Windows update package to hose one’s system or prevent it from booting properly, and some updates have been known to erase or corrupt files.

So do yourself a favor and backup before installing any patches. Windows 10 even has some built-in tools to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once.

And if you wish to ensure Windows has been set to pause updating so you can back up your files and/or system before the operating system decides to reboot and install patches on its own schedule, see this guide.

As always, if you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a better-than-even chance other readers have experienced the same and may chime in here with some helpful tips.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Sports Teams Boycott Social Media

UK Sports Teams Boycott Social Media

Professional sports teams in the United Kingdom have stopped posting on social media in a bid to raise awareness of online abuse. 

Soccer clubs including Birmingham City, Swansea City, and Rangers are taking part in a week-long boycott of all their social media platforms. 

Swansea led the way, with the club’s official social media accounts falling silent at 17:00 on April 8. The club’s boycott has been supported and echoed by its staff and by the men and women who make up its teams. 

With Swansea City’s silence, captain of the first men’s team, Matt Grimes, said that the club hoped to encourage the operators of social media companies to take action against the discrimination and abuse taking place on their platforms. 

“We wanted to take this stance as we again call on those at the forefront of social media companies to implement the change that is needed now and in the future,” said Grimes.

Shortly after Swansea went dark on social media, soccer club Birmingham City posted that they stood “in solidarity with Swansea in the fight against abuse and discrimination of all forms across social media.”

Rangers, whose midfielder Glen Kamara and strikers Alfredo Morelos and Kemar Roofe have been subject to racist abuse online, joined the boycott soon after. The club said it wants social media platforms to make users verify their identity before being allowed to post content. 

Liverpool Football Club captain Jordan Henderson gave anti-cyberbullying charity The Cybersmile Foundation control of his social media accounts in the hope of “raising awareness of how seriously online abuse can affect people.”

In March, former French international footballer and Arsenal star Thierry Henry quit social media altogether, stating that the volume of racism was “too toxic to ignore.” 

English cricket team pacer Stuart Broad has said that the team management are prepared to boycott social media over the online abuse leveled at players. England cricketer Jofra Archer has been the target of racist comments on social media platforms including Instagram.

“It beggars my belief that someone could write some of the messages to my teammates that they have to Jofra,” Broad told PA Media. 

“If you said some of the stuff people say on social media on the street, it wouldn’t end well, would it?”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Biden Nominates More Ex-NSA Officials to Top Cybersecurity Roles

Biden Nominates More Ex-NSA Officials to Top Cybersecurity Roles

Four months after his inauguration, the president of the United States, Joe Biden, has named two former National Security Agency (NSA) officials to top cybersecurity roles in his administration.

On Monday, the White House announced the nomination of former NSA deputy director John C. “Chris” Inglis as the government’s first national cyber director. Ex-deputy director of the NSA’s counterterrorism center, Jen Easterly, was named to head up the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA).

In a statement announcing the nominees, national security adviser Jake Sullivan said: “I’m proud of what we are building across the U.S. government when it comes to cyber. If confirmed, Chris and Jen will add deep expertise, experience and leadership to our world-class cyber team.”

He added: “We are determined to protect America’s networks and to meet the growing challenge posed by our adversaries in cyberspace—and this is the team to do it.”

News of today’s nominations of Easterly and Inglis was leaked on April 11 by the Washington Post. It isn’t the first time that Biden has elected to fill a top cybersecurity position with a former NSA employee. 

Anne Neuberger, whom Biden appointed to the post of deputy national security adviser for cyber and emerging technology, worked at the NSA between 2013 and 2021.

Jen Easterly, who recently served as the cyber policy lead for the Biden-Harris Transition Team, is head of firm resilience and the Fusion Resilience Center at Morgan Stanley, where she is responsible for ensuring preparedness and response to operational risks to the firm. 

Inglis worked at the NSA for nearly 30 years, retiring in 2014 as deputy director after almost eight years in the post. 

Other key leadership roles announced by the Biden administration today were John Tien for deputy secretary, Ur Jaddou for director of United States Citizenship and Immigration Services, Chris Magnus for commissioner of US. Customs and Border Protection, Jonathan Meyer for general counsel, and Robert Silvers for under secretary for strategy, policy, and plans.

Silvers served as assistant secretary for cyber policy at the US Department of Homeland Security (DHS) under the Obama administration.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Iran Nuclear Facility Suffers Cyber-Attack

Iran Nuclear Facility Suffers Cyber-Attack

An Iranian nuclear facility south of Tehran has been hit by cyber-attackers, according to the country’s chief nuclear official. 

Ali Akbar Salehi said that the attack on the Natanz complex took place the day after Iran unveiled new equipment to enrich uranium. In a ceremony broadcast live on television on April 10, the country’s president, Hassan Rouhani, inaugurated new centrifuges at the Natanz site. 

According to the Federation of American Scientists, centrifuges can raise serious nuclear weapons proliferation concerns “because exactly the same machines that are used to enrich uranium for a nuclear reactor can enrich uranium for a nuclear bomb.”

Salehi described the strike as a “terrorist attack” carried out to “sabotage” Iran’s nuclear program. He did not state who was responsible for the incident, but intelligence sources cited in Israeli public media are attributing the attack to Israel.

Israeli public broadcaster Kan and the Haaretz newspaper painted the Natanz incident as a power cut brought about by Israeli cyber-operatives. 

The flow of warnings issued by Israel regarding the danger of Iran’s nuclear program has recently increased; however, Israel is yet to publicly comment on the Natanz attack.

On Iranian state television, Salehi was quoted as saying: “Condemning this despicable move, the Islamic Republic of Iran emphasizes the need for the international community and the International Atomic Energy Agency [IAEA] to deal with this nuclear terrorism.

“Iran reserves the right to take action against the perpetrators.”

Under the terms of a 2015 nuclear deal, Iran is permitted to produce and store only limited quantities of enriched uranium. The deal also restricts the country’s use of the heavy metal to the production of fuel for commercial power plants.

Behrouz Kamalvandi, a spokesperson for the Atomic Energy Organization of Iran (AEOI), said on Sunday that the Natanz facility’s power network have been impacted by an “incident” on the morning of April 11. 

He assured Iranian news agency Fars that “no casualties or leaks” had occurred at the complex. 

IAEA has not commented on the reported incident at Natanz.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-criminals Increasingly Leveraging Debates About Travel During #COVID19 to Launch Attacks

Cyber-criminals Increasingly Leveraging Debates About Travel During #COVID19 to Launch Attacks

A 93% increase in malicious COVID-related domains created using the word ‘Travel’ has been detected in the first three months of 2021 by threat intelligence firm Webroot.

Analysis from its real-time anti-phishing protection system demonstrated that cyber-criminals have increasingly sought to leverage the topic of international travel amid the rapid rollout of COVID-19 vaccines this year. Debates surrounding the resumption of foreign travel and the use of vaccine passports have been a major source of news headlines in the first few months of 2021, and malicious actors appear to have responded in kind.

Compared to the previous 30 rolling days, Webroot said there was a 79% increase in the word ‘Passport’ in malicious COVID-related domains in March 2021. This represents an enormous 3900% increase compared to June 2020.

Additionally, from February 22, which was the date the UK Prime Minister Boris Johnson announced the lockdown easing roadmap, a 169% rise in malicious domains using common travel/holiday search terms including ‘weekend break’, ‘cheap’ and ‘last minute’ was detected.

Interestingly, malicious domains created using the word ‘testing’ or ‘toolkits’ fell by 71% between January 1 and March 29 2021.

The findings further demonstrate how cyber-criminals have continuously adapted to new developments throughout the pandemic to launch phishing and domain spoofing attacks. Other examples include the sales of PPE equipment, government financial relief programs and vaccines.

Nick Emanuel, senior director of product at Webroot, commented: “The length and duration of the pandemic has allowed hackers an extended opportunity to hone and craft their domains. The language used in these malicious domain names is highly reflective of current trends, and key events like travel bans introduced globally have a direct impact on how hackers create resources to trick people.”

He added: “Similarly, the decrease in terminology related to ‘testing’ and ‘testkit’ correlates with the introduction of a comprehensive school testing regime in the UK and we believe the strong supply and ease of obtaining a test has cut down opportunities for scammers on this specific topic. Both examples demonstrate how cyber-criminals are carefully grooming news and creating domains that will have a higher percentage of hits.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Europol: “Virtually All” Crime Now Has a Digital Element

Europol: “Virtually All” Crime Now Has a Digital Element

“Virtually all” criminal activities have an online component to them, while many have fully migrated online, according to a new report by Europol.

The 2021 Serious and Organised Crime Threat Assessment (SOCTA) highlighted how criminals are increasingly incorporating digital technologies into their activities, a trend that has been exacerbated in the last year amid COVID-19 lockdowns. This includes in areas like communication and finances, making crimes harder for law enforcement agencies to detect and track down.

The growth of encrypted communication channels and social media has made it easier cyber-criminals to advertise their services to a wider range of people, while the shift to online shopping has “entailed a steep increase in the use of small parcels, via postal or express courier services, to distribute illicit goods.” The study additionally noted that new money laundering techniques involving cyptocurrencies have proliferated recently.

The analysis, which is published every four years, also found that cyber-attacks have both increased in prevalence and become more sophisticated since the previous SOCTA report in 2017. The authors also believe cyber-dependent crime is significantly underreported, meaning the picture is far worse than official figures show.

This trend has been exacerbated by the shift to digital services as a result of the COVID-19 pandemic. The report stated: “During 2020, the COVID-19 pandemic has seen a surge in connections from private to corporate systems as telework became the norm in many sectors and industries. This development has made many corporate networks more vulnerable to cyber-attacks.”

Europol added that the increasing availability of cybercrime services online has made it easier for criminals without technological expertise to use tools such as malware, ransomware and DDoS. As well as having the ability to purchase cybercrime services and tools, they can receive technical expertise and support via this crime-as-a-service model. 

Europol noted: “Criminals are digital natives. Virtually all criminal activities now feature some online component and many crimes have fully migrated online. Criminals exploit encrypted communications to network among each other, use social media and instant messaging services to reach a larger audience to advertise illegal goods, or spread disinformation.”

Commenting on the findings, Ilia Kolochenko CEO, founder and chief architect at ImmuniWeb said: “The insightful report emphasizes that both street and organized crime are gradually leveraging digital transformation to hinder police investigations, increase profits and expand criminal businesses globally.

“We are dealing with a mature, well-organized and international network of crime. Sadly, most law enforcement agencies are currently unequipped and understaffed to timely discover, intercept and decrypt digital communications from perpetrators.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Brits Still Confused by Multi-Factor Authentication

Brits Still Confused by Multi-Factor Authentication

The British public are still woefully underinformed and unaware of the security benefits of multi-factor authentication (MFA), a new study from the FIDO Alliance has revealed.

The industry association, founded in 2012 to promote authentication standards and reduce global reliance on passwords, recently polled over 4000 consumers in the UK, France, Germany and the US.

It revealed that half (49%) UK consumers have had their social media accounts compromised or know a friend or family member who has.

However, despite a continued number of high-profile account takeovers, 43% said this doesn’t make them enhance security on their accounts, even though they “feel like” they should.

Part of the problem seems to be a general lack of understanding about the benefits of MFA in protecting account holders from phishing, as well as credential stuffing and other brute force attack types.

Although such features are offered by all social media companies today, over a quarter (26%) of respondents said they weren’t using or didn’t know about them.

A further 15% said they would like to increase the security of their accounts but don’t know how, and two-fifths (39%) admitted they were unable to make a judgement either way as to whether their accounts are vulnerable or not.  

Of those that had taken action to improve account security, the most popular option (56%) was to create a stronger password, even though this still exposes them to the risks mentioned above.

Andrew Shikiar, executive director of the FIDO Alliance, warned that social media accounts are an attractive target for attackers as they contain plenty of personally identifiable information (PII).

“The research is showing us that there’s a general lack of awareness among consumers about how to assess their own risk of falling victim to social media hacks. They are also unsure as to what steps should be taken to best protect their accounts,” Shikiar continued.

“Social media platforms like Twitter and Facebook have made much stronger security options available. Consumers just need to know what they are, how easy they are to use and how to turn them on.”

If consumers are non-plussed over use of MFA for social media accounts, there’s also a strong possibility that their other online accounts will be similarly under-protected.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Over 90% of Organizations Hit by a Mobile Malware Attack in 2020

Over 90% of Organizations Hit by a Mobile Malware Attack in 2020

Almost every global organization suffered at least one mobile malware attack in 2020, according to a new report from Check Point.

The security vendor polled 1800 customers of its Harmony Mobile device threat protection product to compile its 2021 Mobile Security Report.

Of the near-total number that faced a mobile attack last year, 93% of incidents originated in a device network, and were either phishing attempts (52%), C&C communication with malware already on the device (25%) or involved infected websites/URLs (23%).

Check Point also warned that unsecured networks like public Wi-Fi could enable man-in-the-middle (MitM) attacks designed to compromise devices and data.

The study revealed that nearly half (46%) of responding organizations had at least one employee download a malicious mobile application that threatened networks and data last year. Banking Trojans, mobile Remote Access Trojans (MRATs), premium diallers, clickers and ad fraud were among the most common.

Some 97% of organizations faced mobile threats originating in multiple vectors, including applications, networks, devices and OS vulnerabilities. However, Check Point warned that mobile device management (MDM) is a potentially major new target for attackers.

In April last year, the security vendor claimed to have detected for the first time information stealing malware targeting the MDM server of a large multi-national, and in so doing compromising over 75% of its devices.

“Regrettably, the MDM’s most notable feature, and arguably the reason for its existence – a single, central control for the entire mobile network, is also its major weakness,” noted Check Point. “This malware [a Cerberus variant] is very damaging, for once installed, it can collect large amounts of sensitive data, including user credentials, and send it to a remote command and control (C&C) server.”

In the report, Check Point also repeated claims made last summer that around 40% of the world’s mobile devices are vulnerable to attacks, after it found hundreds of bugs in Qualcomm’s popular DSP chips.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk