Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Wi-Fi Devices as Physical Object Sensors
The new 802.11bf standard will turn Wi-Fi devices into object sensors:
In three years or so, the Wi-Fi specification is scheduled to get an upgrade that will turn wireless devices into sensors capable of gathering data about the people and objects bathed in their signals.
“When 802.11bf will be finalized and introduced as an IEEE standard in September 2024, Wi-Fi will cease to be a communication-only standard and will legitimately become a full-fledged sensing paradigm,” explains Francesco Restuccia, assistant professor of electrical and computer engineering at Northeastern University, in a paper summarizing the state of the Wi-Fi Sensing project (SENS) currently being developed by the Institute of Electrical and Electronics Engineers (IEEE).
SENS is envisioned as a way for devices capable of sending and receiving wireless data to use Wi-Fi signal interference differences to measure the range, velocity, direction, motion, presence, and proximity of people and objects.
More detail in the article. Security and privacy controls are still to be worked out, which means that there probably won’t be any.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
More Money, Less Problems: XDR Investment Can Protect the Financial Services Industry
The connection between cybersecurity and poet Ralph Waldo Emerson is not directly evident, however he once said, “money often costs too much.”
This statement rings true across the financial services industry, as money is a key driver for cybercriminals acting with malicious intent. The always-on eye of Sauron on the financial services industry means there are greater implications to keep this industry safe as a top target – and to keep money where it belongs.
IT teams across these organizations have historically invested heavily in technology stacks to combat fraud and decrease the likelihood of an attack or breach, but attacks keep getting more sophisticated and frequent. This Sisyphean task of keeping up with modern-day breaches is complex, and protecting the money is costly, as Ralph’s quote woefully reminds us.
McAfee’s “Hidden Costs of Cybercrime” report supports this current state of the financial services industry, indicating that these organizations spend up to $3,000 per employee on cybersecurity. Another survey from the Financial Services Information Sharing and Analysis Center (FS-ISAC) found that, depending on company size, financial institutions spend between 6% and 14% of IT budgets for defense.
This spending shows no sign of stopping as organizations will always have the onus to protect data, employees, and their own bottom lines. As long as cybercriminals exist, the need for cybersecurity will be omnipresent. However, there is a major change the financial services industry can implement to manage threats faster with higher efficacy and become more proactive instead of reactive: Extended Detection and Response (XDR).
Couldn’t Stop Past Breaches? Time to Stop Future Ones
It’s been less than 10 years since JPMorgan Chase & Co. fell victim to the largest known cyberattack at the time – one that occurred two months after it had vowed to spend a quarter-billion dollars a year on cybersecurity. Due to the breach, they increased the planned spend to half a billion dollars, per Forbes. Similarly, Capital One Financial Corp. more recently agreed to pay an $80 million dollar fine, pledging also to increase its cybersecurity efforts as a result of a breach that disclosed more than 100 million customer records.
Both of these financial institutions present examples where XDR could have provided a benefit and perhaps thwarted these major breaches. With its ability to coordinate systems and processes as well as automatically aggregate threat analysis and remove manual hunting and analysis, XDR acts as a modern-day catalyst for security operations center (SOC) success. This combination of prevention, detection, analysis, and response across the SOC and enterprise allows for better decisions that are made faster.
Taking a closer look at the JPMorgan breach, it was only uncovered due to a routine and typical scan conducted by the SOC team. Hackers were able to infiltrate using custom malware and a previously unknown flaw, entering via a website owned by JPMorgan to then stealthily extract data over the course of months – all without being caught by SOC teams. This is not uncommon, as recent Ernst & Young research cited that only 26% of the SOCs polled identified a threat event.
XDR’s ability to control access across an organization’s entire infrastructure from a unified and coordinated interface, coupled with more interconnected visualization across the SOC, provides the context needed to look at cybersecurity in a holistic manner. This is critical given the erratic lateral movements of advanced threats. This means all vectors are protected together, from endpoint, network, and the cloud; therefore, providing better context and overall awareness of security posture across an entire organization.
Breaches are a Promise, Losses Don’t Have to Be
This gift of proactivity empowering the SOC to act quicker cannot come at a better time as threat actors are still leveraging the upheaval COVID-19 wrought to take advantage of vulnerabilities created due to the pandemic. Not to mention, companies and employees are not clamoring to return to the office where endpoints are easier to track and manage.
The National Association for Business Economics found that only about 1 in 10 companies expect all employees to return to their pre-pandemic work arrangements. With employees apt to use personal devices, causing an ever-increasing endpoint explosion, hackers may again have an easy entry point to conduct crime. All industries are vulnerable, but the financial services industry remains forever-lucrative due to the monetary gains that could be achieved.
With an increase in virtual transactions and use of personal devices to conduct business, the industry is ripe for phishing attempts, malware, and ransomware attacks. Hackers are taking advantage of these surges, with McAfee and IC3 data indicating that business email compromise (BEC) scams have been increasing. This means, it may not take a zero-day approach or strategy from hackers to infiltrate if existing systems and solutions already prove insecure.
Cost is often a barrier to entry for many industries, but the financial services industry has shown it is committed to investing in cybersecurity, knowing it has the most to lose. There has been success across the industry due to this guarantee, but the breaches that do get thwarted do not make the headlines. Nonetheless, undetected breaches – and the reputation-damaging headlines that appear alongside them – lead to more information and data loss and disruption to business. For financial institutions seeking to eliminate the losses associated with cybercrime, XDR is worth exploring.
Want to learn more about McAfee’s investment in XDR and explore its approach? Check out McAfee MVISION XDR and schedule a check-up for your SOC.
The post More Money, Less Problems: XDR Investment Can Protect the Financial Services Industry appeared first on McAfee Blogs.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Ransom Gangs Emailing Victim Customers for Leverage
Some of the top ransomware gangs are deploying a new pressure tactic to push more victim organizations into paying an extortion demand: Emailing the victim’s customers and partners directly, warning that their data will be leaked to the dark web unless they can convince the victim firm to pay up.
This letter is from the Clop ransomware gang, putting pressure on a recent victim named on Clop’s dark web shaming site.
“Good day! If you received this letter, you are a customer, buyer, partner or employee of [victim],” the missive reads. “The company has been hacked, data has been stolen and will soon be released as the company refuses to protect its peoples’ data.”
“We inform you that information about you will be published on the darknet [link to dark web victim shaming page] if the company does not contact us,” the message concludes. “Call or write to this store and ask to protect your privacy!!!!”
The message above was sent to a customer of RaceTrac Petroleum, an Atlanta company that operates more than 650 retail gasoline convenience stores in 12 southeastern states. The person who shared that screenshot above isn’t a distributor or partner of RaceTrac, but they said they are a RaceTrac rewards member, so the company definitely has their email address and other information.
Several gigabytes of the company’s files — including employee tax and financial records — have been posted to the victim shaming site for the Clop ransomware gang.
In response to questions from KrebsOnSecurity, RaceTrac said it was recently impacted by a security incident affecting one of its third-party service providers, Accellion Inc.
For the past few months, attackers have been exploiting a a zero-day vulnerability in Accellion File Transfer Appliance (FTA) software, a flaw that has been seized upon by Clop to break into dozens of other major companies like oil giant Shell and security firm Qualys.
“By exploiting a previously undetected software vulnerability, unauthorized parties were able to access a subset of RaceTrac data stored in the Accellion File Transfer Service, including email addresses and first names of some of our RaceTrac Rewards Loyalty users,” the company wrote. “This incident was limited to the aforementioned Accellion services and did not impact RaceTrac’s corporate network. The systems used for processing guest credit, debit and RaceTrac Rewards transactions were not impacted.”
The same extortion pressure email has been going out to people associated with the University of California, which was one of several large U.S. universities that got hit with Clop ransomware recently. Most of those university ransomware incidents appeared to be tied to attacks on attacks on the same Accellion vulnerability, and the company has acknowledged roughly a third of its customers on that appliance got compromised as a result.
Clop is one of several ransom gangs that will demand two ransoms: One for a digital key needed to unlock computers and data from file encryption, and a second to avoid having stolen data published or sold online. That means even victims who opt not to pay to get their files and servers back still have to decide whether to pay the second ransom to protect the privacy of their customers.
As I noted in Why Paying to Delete Stolen Data is Bonkers, leaving aside the notion that victims might have any real expectation the attackers will actually destroy the stolen data, new research suggests a fair number of victims who do pay up may see some or all of the stolen data published anyway.
The email in the screenshot above differs slightly from those covered last week by Bleeping Computer, which was the first to spot the new victim notification wrinkle. Those emails say that the recipient is being contacted as they are a customer of the store, and their personal data, including phone numbers, email addresses, and credit card information, will soon be published if the store does not pay a ransom, writes Lawrence Abrams.
“Perhaps you bought something there and left your personal data. Such as phone, email, address, credit card information and social security number,” the Clop gang states in the email.
Fabian Wosar, chief technology officer at computer security firm Emsisoft, said the direct appeals to victim customers is a natural extension of other advertising efforts by the ransomware gangs, which recently included using hacked Facebook accounts to post victim shaming advertisements.
Wosar said Clop isn’t the only ransomware gang emailing victim customers.
“Clop likes to do it and I think REvil started as well,” Wosar said.
Earlier this month, Bleeping Computer reported that the REvil ransomware operation was planning on launching crippling distributed denial of service (DDoS) attacks against victims, or making VOIP calls to victims’ customers to apply further pressure.
“Sadly, regardless of whether a ransom is paid, consumers whose data has been stolen are still at risk as there is no way of knowing if ransomware gangs delete the data as they promise,” Abrams wrote.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Ubiquiti All But Confirms Breach Response Iniquity
For four days this past week, Internet-of-Things giant Ubiquiti did not respond to requests for comment on a whistleblower’s allegations the company had massively downplayed a “catastrophic” two-month breach ending in January to save its stock price, and that Ubiquiti’s insinuation that a third-party was to blame was a fabrication. I was happy to add their eventual public response to the top of Tuesday’s story on the whistleblower’s claims, but their statement deserves a post of its own because it actually confirms and reinforces those claims.

Ubiquiti’s IoT gear includes things like WiFi routers, security cameras, and network video recorders. Their products have long been popular with security nerds and DIY types because they make it easy for users to build their own internal IoT networks without spending many thousands of dollars.
But some of that shine started to come off recently for Ubiquiti’s more security-conscious customers after the company began pushing everyone to use a unified authentication and access solution that makes it difficult to administer these devices without first authenticating to Ubiquiti’s cloud infrastructure.
All of a sudden, local-only networks were being connected to Ubiquiti’s cloud, giving rise to countless discussion threads on Ubiquiti’s user forums from customers upset over the potential for introducing new security risks.
And on Jan. 11, Ubiquiti gave weight to that angst: It told customers to reset their passwords and enable multifactor authentication, saying a breach involving a third-party cloud provider might have exposed user account data. Ubiquiti told customers they were “not currently aware of evidence of access to any databases that host user data, but we cannot be certain that user data has not been exposed.”
Ubiquiti’s notice on Jan. 12, 2021.
On Tuesday, KrebsOnSecurity reported that a source who participated in the response to the breach said Ubiquiti should have immediately invalidated all credentials because all of the company’s key administrator passwords had been compromised as well. The whistleblower also said Ubiquiti never kept any logs of who was accessing its databases.
The whistleblower, “Adam,” spoke on condition of anonymity for fear of reprisals from Ubiquiti. Adam said the place where those key administrator credentials were compromised — Ubiquiti’s presence on Amazon’s Web Services (AWS) cloud services — was in fact the “third party” blamed for the hack.
From Tuesday’s piece:
“In reality, Adam said, the attackers had gained administrative access to Ubiquiti’s servers at Amazon’s cloud service, which secures the underlying server hardware and software but requires the cloud tenant (client) to secure access to any data stored there.
“They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Adam said.
Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies.
Such access could have allowed the intruders to remotely authenticate to countless Ubiquiti cloud-based devices around the world. According to its website, Ubiquiti has shipped more than 85 million devices that play a key role in networking infrastructure in over 200 countries and territories worldwide.
Ubiquiti finally responded on Mar. 31, in a post signed “Team UI” on the company’s community forum online.
“Nothing has changed with respect to our analysis of customer data and the security of our products since our notification on January 11. In response to this incident, we leveraged external incident response experts to conduct a thorough investigation to ensure the attacker was locked out of our systems.”
“These experts identified no evidence that customer information was accessed, or even targeted. The attacker, who unsuccessfully attempted to extort the company by threatening to release stolen source code and specific IT credentials, never claimed to have accessed any customer information. This, along with other evidence, is why we believe that customer data was not the target of, or otherwise accessed in connection with, the incident.”
Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.”
Ubiquiti’s statement largely confirmed the reporting here by not disputing any of the facts raised in the piece. And while it may seem that Ubiquiti is quibbling over whether data was in fact stolen, Adam said Ubiquiti can say there is no evidence that customer information was accessed because Ubiquiti failed to keep logs of who was accessing its databases.
“Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed, but the attacker targeted the credentials to the databases, and created Linux instances with networking connectivity to said databases,” Adam wrote in a whistleblower letter to European privacy regulators last month. “Legal overrode the repeated requests to force rotation of all customer credentials, and to revert any device access permission changes within the relevant period.”
It appears investors noticed the incongruity as well. Ubiquiti’s share price hardly blinked at the January breach disclosure. On the contrary, from Jan. 13 to Tuesday’s story its stock had soared from $243 to $370. By the end of trading day Mar. 30, UI had slipped to $349. By close of trading on Thursday (markets were closed Friday) the stock had fallen to $289.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Intelligence Analyst Fed Secrets to Reporter
Intelligence Analyst Fed Secrets to Reporter

A former intelligence analyst who was once a United States military service member has pleaded guilty to obtaining classified information and passing it to a reporter.
Daniel Everette Hale served as an enlisted airman in the US Air Force from July 2009 to July 2013. After language and intelligence training, the 31-year-old from Nashville, Tennessee, was assigned to work at the National Security Agency (NSA) and deployed to Afghanistan as an intelligence analyst.
It was in April 2013, while working for the National Security Agency (NSA), that Hale began communicating with the reporter.
Using his Top Secret // Sensitive Compartmented Information (TS//SCI) security clearance, Hale accessed and printed classified information regarding America’s national defense. He then passed some of the documents on to the reporter, who published them in their news outlet.
According to court records, Hale communicated with the reporter via phone, text message, email, and an encrypted messaging platform. The pair also met in person on multiple occasions.
In July 2013, Hale left the Air Force and was hired by a defense contractor who assigned him to the National Geospatial-Intelligence Agency (NGA), where he worked as a political geography analyst between December 2013 and August 2014.
In February 2014, Hale printed six classified documents, all of which were later published by the reporter’s news outlet following an exchange of messages between the reporter and Hale. None of the documents were relevant to Hale’s work at the NGA.
In total, Hale printed 36 documents from his Top Secret computer while he was working at the NGA. Only 13 of these documents were related to his work for the Agency. Of the 23 unrelated documents, Hale provided at least 17—including 11 Top Secret or Secret documents—to the reporter and/or the reporter’s online news outlet, which published them.
On March 31, Hale pleaded guilty to retention and transmission of national defense information. He is scheduled to be sentenced on July 13, 2021, and faces a maximum penalty of 10 years in prison.
Assistant Attorney General John Demers said that Hale’s conduct “undermined the efforts of our Intelligence Community to keep us safe.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Troll Fined $81 After Victim Kills Herself
Troll Fined $81 After Victim Kills Herself

A cyber-bully has been fined for sending hateful messages to a professional wrestler before she took her own life.
Japanese wrestler and Netflix reality show star Hana Kimura was just 22 years old when she killed herself on May 23 last year by inhaling toxic gas in her Tokyo home.
Kimura became a target for internet trolls after the airing of an episode of Terrace House: Tokyo in which she was shown arguing with a housemate who had damaged her expensive wrestling gear.
Before her death, Kimura posted photos on social media suggesting that she was being cyber-bullied and was struggling with self-harm. The last post she ever made, uploaded the day before her death, featured a photo of the star and her cat along with the message “goodbye.”
On March 31, the Washington Post reported that a man from Osaka who had been convicted of the crime “insults” over his cyber-bullying of Kimura had been fined 9,000 yen—the equivalent of $81.
The unidentified man, who is aged in his 20s, posted multiple comments about Kimura. In one he told the wrestler that she had an “awful personality” and in another he asked her “when will you die?”
Japanese media reported that after Kimura’s death, the cyber-bully apologized to her family for his actions.
The Terrace House show, in which six young people shared a home in Japan’s capital city, started in 2012 but was later canceled.
Kimura’s mother Kyoko Kimura filed a human rights violation claim against the show’s makers, accusing them of stoking conflict between the show’s participants and of failing to provide them with adequate aftercare.
This week, the Japan Times reported that the human rights committee of the Broadcasting Ethics & Program Improvement Organization had found that no human rights violation had taken place. However, the committee did find that Fuji TV should have done more to secure the mental and physical well-being of the show’s participants, and the company had “problems in terms of broadcasting ethics.”
Kimura’s mother said: “I hope that Fuji Television reevaluates how they produce programs and not see people as mere pawns but treat them with care as actual individuals.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Microsoft Suffers Second Outage in Two Weeks
Microsoft Suffers Second Outage in Two Weeks

American multinational technology company Microsoft has been hit by its second outage in two weeks.
Striking the company on April Fool’s Day, the substantial cloud outage knocked Microsoft’s Azure cloud services, Teams, Office 365, and OneDrive offline. Skype, Xbox Live, and Bing were also impacted.
News of the outage began emanating from Twitter users at around 5pm ET yesterday. The situation was confirmed by website DownDetector, which reported receiving thousands of notices about the outage from users of Office, Teams, and Xbox Live.
At 5:39pm, Microsoft’s Azure Support account on Twitter shared a message acknowledging that all was not well. It stated: “We are aware of an issue affecting the Azure Portal and Azure services, please visit our alternate Status Page here status2.azure.com for more information and updates.”
A tweet posted by the Microsoft 365 Twitter status account revealed the cause of the outage, revealing that a “DNS issue affecting multiple Microsoft 365 and Azure services” was being investigated.
An hour after the problem arose, Microsoft tweeted to say that it was evaluating its mitigation options. By 6:30pm, the company had managed to bring the Azure status page back online.
Visitors were greeted with the message that they may experience “intermittent issues” while Microsoft grappled with a worldwide outage impacting network infrastructure in every region.
The tech company’s solution, shared on Twitter at 6:33pm, was to reroute traffic “to our resilient DNS capabilities” and to continue to “investigate the cause of the DNS issue.”
At 10:37pm ET, the MSFT365Status account reported that the problem had been overcome, sharing the message: “We’ve successfully resolved the issue that was causing residual impact for SharePoint Online and we’ve confirmed that all Microsoft 365 services have returned to a healthy state.”
The incident comes only two weeks after Microsoft Azure was affected by an outage that took Teams, Office 365, and Xbox Live offline for four hours. Unlike yesterday’s DNS issue, the March 15 outage was caused by “a recent change to an authentication system,” according to Microsoft.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Trustwave Uncovers Vulnerability in Popular Website CMS
Trustwave Uncovers Vulnerability in Popular Website CMS

Cybersecurity firm Trustwave has uncovered a security vulnerability in the popular website CMS, Umbraco. In a blog post on its website, Trustwave researchers outlined details of a privilege escalation issue which allows low privileged users to elevate themselves to the status of admin.
The problem resides in an API endpoint that does not properly check the user’s authorization prior to returning results found to the application’s logging section.
In the CMS, higher privileged users, i.e. administrators, are able to view log data in the administrative UI, which contains any information inserted into the application logs. To test the risk of any of this information being leaked, the administrator creates a lower privileged user who is placed into the Writers group. This means the low privileged user can only view the content tab indicating the intent of limiting what Writers can do or see within the application.
The low privileged user then authenticates to the application, and is provided with the necessary cookies and headers to access it; these identifiers can then enable the low privileged user to access the API endpoint, which returns log data that should only be available to the administrator.
Trustwave revealed the reason for this was that in the Umbraco.Web.dll, the LogViewerController class uses no granular authorization attributes on its exposed endpoints, meaning numerous endpoints are accessible for lower privileged users.
Jonathan Yarema, managing consultant, SpiderLabs at Trustwave, commented in the blog: “Conversely, there are other areas which do protect resources such as the UsersController wherein some methods are explicitly limited to Administrative users (“[AdminUsersAuthorize]” attribute) or must otherwise give permission to the controller (“[UmbracoApplicationAuthorize]”). A similar approach should be used for the LogViewerController to limit unauthorized access to its data.”
The issue has been observed in Umbraco versions 8.9.0 and 8.6.3.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Cybersecurity Firm ReliaQuest Announces New Senior Appointments
Cybersecurity Firm ReliaQuest Announces New Senior Appointments

Cybersecurity platform provider ReliaQuest has announced two new senior appointments.
Kara Wilson has been appointed to the ReliaQuest board of directors, whilst Alex Bender joins the company as its new chief marketing officer.
Wilson brings more than 25 years of experience in driving go-to-market strategies for both large and medium companies along with startups, having previously helped to grow some of the most influential technology companies in the world including Okta, FireEye and Cisco. She also currently serves as a board member for a number of companies including Paychex, KnowBe4 and OneStream.
Bender boasts a similarly impressive background with a proven record of accomplishment in driving growth in both revenue and brand marketing for influential cyber-brands including Tripwire, McAfee and RSA over the last 20 years. He most recently served as Mimecast’s SVP of global marketing.
At ReliaQuest, he will oversee the brand’s global brand and revenue marketing growth strategies.
Commenting on the appointments, ReliaQuest CEO and co-founder Brian Murphy, said: “Providing world class cybersecurity capabilities requires a world-class team, working together with the common goal of building trust and confidence for businesses of all sizes and sectors.
“It is a great honor for me to bring both Kara and Alex on board during this exciting chapter for ReliaQuest.”
Bender added that ReliaQuest delivers a unified detection, investigation and response approach that is transforming security operations by delivering the right data, from the right systems at the right time, making security teams more efficient and focused to take decisive action.
“I am truly honored to be joining ReliaQuest and working with an extremely talented team that is laser focused on extending the company’s rapid growth trajectory as we build business resilience and security confidence on a global scale.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
