New KrebsOnSecurity Mobile-Friendly Site

Dear Readers, this has been long overdue, but at last I give you a more responsive, mobile-friendly version of KrebsOnSecurity. We tried to keep the visual changes to a minimum and focus on a simple theme that presents information in a straightforward, easy-to-read format. Please bear with us over the next few days as we hunt down the gremlins in the gears.

We were shooting for responsive (fast) and uncluttered. Hopefully, we achieved that and this new design will render well in whatever device you use to view it. If something looks amiss, please don’t hesitate to drop a note in the comments below.

NB: KrebsOnSecurity has not changed any of its advertising practices: The handful of ads we run are still image-only creatives that are vetted by me and served in-house. If you’re blocking ads on this site, please consider adding an exception here. Thank you!

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

IRS Warns of Higher Education Phishing Scam

IRS Warns of Higher Education Phishing Scam

The United States’ Internal Revenue Service (IRS) has issued a warning over an ongoing phishing scam targeting higher education establishments in the United States. 

In a statement released yesterday, the IRS said that it was being actively impersonated over email by cyber-attackers seeking to trick victims into handing over sensitive data.  

Students and staff have received phishing emails directing them to a fraudulent website. The site asks users to provide their Social Security number, full name, date of birth, prior year annual gross income, driver’s license number, address, and electronic filing PIN. 

“The IRS’ phishing@irs.gov has received complaints about the impersonation scam in recent weeks from people with email addresses ending in ‘.edu,'” said the IRS. 

“The phishing emails appear to target university and college students from both public and private, profit and non-profit institutions.”

The scam emails display the IRS logo and use a number of different subject lines including “Tax Refund Payment” or “Recalculation of your tax refund payment.” 

Recipients are asked to click a malicious link and submit a form to claim a tax refund.

The IRS is asking anyone who receives this scam email to save it and forward it as an attachment to phishing@irs.gov

“Students and staff are not only dealing with the chaos of the pandemic, but now are being targeted in relation to their tax refunds,” commented Niamh Muldoon, global data protection officer at OneLogin.

“Distractions are plentiful as people start to reconnect and adjust to hybrid learning and schedules. Information floods in, typically by email and collaboration tooling. Unfortunately, recipients are often ill-prepared to determine if devices are configured with security in mind.”

Asked what schools and universities could do to protect themselves from phishing threats, Muldoon told Infosecurity Magazine: “Seeing that cybercriminals have consistently targeted academic institutions through various threat vectors, including phishing campaigns, it would be wise for these education institutions to offer support and training. 

“The training really should be provided prior to providing devices and online system access. It is only through security awareness training that students and staff can make better-informed decisions.”

She added: “Partnering with IAM trusted providers to implement two-factor authentication reduces associated risks of unauthorized access to education devices and systems.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CISA and RH-ISAC to Run Cybersecurity Drill

CISA and RH-ISAC to Run Cybersecurity Drill

Top trade associations in retail, hospitality, and travel are partnering with Retail and Hospitality ISAC (RH-ISAC) and the United States federal government’s Cybersecurity and Infrastructure Security Agency (CISA) to host the first industry-wide cybersecurity exercise.

Day-long virtual exercise EX-RH2021 will take place on a currently unassigned date  in June 2021, opening with a training session on how participants can get the most out of the event. 

Participating information security teams will be challenged to perform executive decision making, operational decision making and coordination, and cross-disciplinary coordination to combat a range of cybersecurity threats that can endanger corporate environments.

“RH-ISAC is the epicenter for information sharing for retail, hospitality, and travel organizations, and as such is the ideal host for the first sector-wide exercise,” said Suzie Squier, president of RH-ISAC, in a statement released yesterday. 

“Together, with CISA and key trade associations, we’ll be able to mature our enterprise security activities as well as our collective coordination.” 

Threat scenarios participants can expect to encounter will include what to do in the event of a data breach and how to cope should cyber-attackers compromise operational technology including point-of-sale and reservation/property management systems.

“CISA is proud to support the retail, hospitality, and travel industry in their first exercise and to assist with testing communication, coordination, and decision-making protocols if an incident were to occur,” said CISA executive assistant director for infrastructure security Dr. David Mussington. 

“This exercise is essential to preparing for an incident and participants will be able to gain valuable information on how to handle and respond to an incident within the industry.” 

RH-ISAC is the sector’s operational community for sector-specific cybersecurity information and intelligence sharing and collaboration. 

The information sharing and analysis center said that the summer ‘s new virtual exercise was specifically designed “to serve and support the interests of all retail, hospitality, and travel companies, including retailers, restaurants, hotels, gaming casinos, food retailers, consumer products, and other consumer-facing companies.” 

RH-ISAC and CISA say C-level executives, including chief legal officers, chief security officers, chief information security officers, chief financial officers, chief marketing officers, chief commercial officers, and chief operating officers, would benefit from participating in the exercise. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Reality Show Members Charged with Telemarketing Scam

Reality Show Members Charged with Telemarketing Scam

Two cast members of an American reality TV show have been indicted in connection with a nationwide telemarketing fraud scheme that victimized the elderly. 

Real Housewives of Salt Lake City stars Jennifer Shah and Stuart Smith were arrested on March 30 and charged with conspiracy to commit wire fraud and conspiracy to commit money laundering. 

It is alleged that from 2012 until March 2021, 47-year-old Shah and 43-year-old Smith defrauded hundreds of victims throughout the United States by selling “lead lists” for fictitious business opportunities. 

Victims, many of whom were aged 55 or over, were sold services that were supposed to make their online businesses easier to manage, more efficient, or more profitable. 

In exchange for payment, victims were sent electronic or paper pamphlets or were provided with “coaching sessions.”

However, the Department of Justice stated in a press release dated March 30 that “at no point did the defendants intend that the Victims would actually earn any of the promised return on their intended investment, nor did the victims actually earn any such returns.” 

It is alleged that the defendants, both Utah residents, worked hard to conceal their involvement in the fraudulent scheme, using encrypted messaging to communicate with their co-conspirators, incorporating their business entities using third parties’ names, and placing fraudulently obtained proceeds in offshore bank accounts. 

Manhattan US Attorney Audrey Strauss said: “Jennifer Shah, who portrays herself as a wealthy and successful businessperson on ‘reality’ television, and Stuart Smith, who is portrayed as Shah’s ‘first assistant,’ allegedly generated and sold ‘lead lists’ of innocent individuals for other members of their scheme to repeatedly scam.  

“In actual reality and as alleged, the so-called business opportunities pushed on the victims by Shah, Smith, and their co-conspirators were just fraudulent schemes, motivated by greed, to steal victims’ money.”

Shah, of Park City, and Smith, of Lehi, are each charged with one count of conspiracy to commit wire fraud in connection with telemarketing through which they victimized 10 or more persons over the age of 55, and one count of conspiracy to commit money laundering. 

If convicted on both counts, each defendant faces a maximum sentence of 50 years in prison. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Winner Crowned in “Hacker Games” Contest Promoting Secure Coding Skills

Winner Crowned in “Hacker Games” Contest Promoting Secure Coding Skills

The University of Warwick has been crowned as the winner of Veracode’s inaugural Hacker Games competition.

After coming out on top in a collegiate contest between eight universities from across the UK and US, the WMG Cyber Security Center at the University of Warwick was awarded a $10,000 charitable donation. Tufts University came in second place, earning a $5000 donation. Additionally, prize money was given to each individual player from the winning teams and overall top scorers.

During the event, announced earlier this month, a total of nearly 90 computer science and cybersecurity students undertook a series of hands-on coding challenges over a two-week period (March 15-25). Held in Veracode’s Security Labs to gamify the experience, the participants successfully solved a total of 8500 labs and accumulated nearly 100,000 points.

The initiative, which is supported by the UK government, aims to help close the cybersecurity skills gap by encouraging the development of secure coding skills among the younger generation.

Chris Wysopal, founder and chief technology officer at Veracode, commented: “The cybersecurity skills gap is proving costly to corporations worldwide. The Hacker Games are a way for us to demonstrate the importance of secure coding to the next generation of software developers. The passion, competitive spirit and commitment from each participating university was impressive and we’re excited to work with each of these schools to make software security a more regular part of their curriculum.”

Professor Tim Watson, director of the WMG Cyber Security Center at the University of Warwick, said: “The Hacker Games were a fantastic way to promote secure software development and provided our students with a highly challenging experience. The labs are tremendous resources and we will be encouraging our students to take advantage of them to further their skills and experience. We are very grateful to Veracode for creating such a wonderful environment and competition.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Most Global Chip Companies Show Signs of Compromise

Most Global Chip Companies Show Signs of Compromise

The vast majority of the world’s semiconductor companies have glaring security gaps which may have already been exploited by threat actors, according to a new study from BlueVoyant.

The security services firm appraised the security posture of the 17 most prominent players in one of the globe’s most strategically important supply chains. These included companies in Asia, Europe and the US such as “fabless” chip designers, semiconductor software designers, manufacturers of equipment that fabricates semiconductors, foundries, and integrated device manufacturers (IDMs).

BlueVoyant said its data came from “publicly available and proprietary datasets and tools over a 30-day period.”

The report revealed some surprising lapses in security, considering the quality of the IP at stake and the potential impact a successful ransomware attack could have on production.

Nearly all (94%) of the companies studied had open, at-risk ports, while a quarter (24%) had open RDP ports, one of the top vectors for ransomware. A similar number had open authentication ports (24%) and open datastore ports (18%) were also commonplace.

What’s more, 88% of the companies demonstrated evidence of high-severity vulnerabilities which could allow attackers to gain a foothold into systems.

This matters, because 100% are already experiencing inbound targeting and 88% were being targeted by IPs associated with ransomware. A further 94% showed evidence of brute-force attacks.

In some cases, the report may be too late to stop breaches: over three-quarters (76%) of chip companies studied presented evidence of outbound traffic to known malicious infrastructure. This indicates that the organizations in question may already have been compromised.

BlueVoyant argued that such attacks are preventable if companies proactively scan for and patch vulnerabilities, close open high-risk ports and monitor internal traffic for signs of compromise.

“Our digital economy hinges on the availability of semiconductors and so does any digital transformation going forward,” the report warned. “While high volumes of targeting are not necessarily a surprising discovery, the widespread lack of adequate protections against such targeting certainly is.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Cyber Security Council Officially Launches as Independent Body

UK Cyber Security Council Officially Launches as Independent Body

The UK Cyber Security Council – a self-regulatory organization responsible for boosting professional standards and career prospects for those working in cybersecurity – has officially started work as an independent body.

The Formation Project to create the council has now been completed, meaning it has fully transitioned from the Cyber Security Alliance-led formation project.

The council will now undertake its role in representing the cybersecurity profession, driving awareness and excellence across the industry, with the ultimate aim of growing the UK’s cyber-skills base. This will involve delivering thought leadership, career tools and resources for those in the cybersecurity industry and those looking to pursue a career in the sector, as well as working with government, industry and academia to close the skills gap.

The UK Cyber Security Council was commissioned by the UK government in 2018, and last month it was confirmed it would be ready to launch as an independent entity by the end of March 2021. Earlier this month, the council’s first four trustees were announced.

The first priorities are to appoint a permanent leadership team to work alongside the Board of Trustees as well as recruit personnel to build on the work of the Formation Project in areas such as professional ethics and recognition for cybersecurity practitioners. The council has also been invited by the NCSC to participate at the UK government’s cybersecurity conference, CYBERUK, in May.

Dr Claudia Natanson, chair of the Council’s Board of Trustees, commented: “The Formation Project has put down solid foundations on which the council can build, and that is what the council is able to, and will do, from today. The next few months will be especially busy; we are now able to hire and start work on gaining traction and momentum across and beyond the profession. We’ll also be engaging with government to ensure the delivery of the standards and governance needed to ensure a strong cybersecurity profession now and in the future. The trustees assure all those involved in the council to date of our maximum efforts to take their work forward.”

Discussing the official launch, (ISC)2, a non-profit association of certified cybersecurity professionals and part of the Cyber Security Alliance, called for more industry collaboration to address the cyber-skills shortage. Clar Rosso, CEO of (ISC)2, said: “Our shared vision and commitment to the creation of the council, and our ongoing support for it as a founder member of the Alliance, has brought our industry together, and it is important we do not squander the opportunity for progress and innovation that cooperation creates. It is imperative, not only for the future success of the council, but for the benefit of all our members and organizations, that the sector continues to work together with the same vigor and enthusiasm to support the council in the months and years to come.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

James Reynolds Joins SecureAge Technology to Lead Security Product Strategy

James Reynolds Joins SecureAge Technology to Lead Security Product Strategy

Data security company SecureAge has announced the appointment of James Reynolds as its new chief product officer (CPO).

The firm, headquartered in Singapore, said the appointment reflects increasing demands for data-centric cybersecurity solutions along with its own global expansion plans.

Reynolds brings a proven record of accomplishment and wealth of IT experience to the role, with a 30-year career encompassing positions in development and engineering through to CTO.

He most recently served as CTO of DomainTools, having previously held the role of group director of engineering at Synopses, R&D director of a cyber-warfare program at DARPA in the US and project manager at SAIC.

Reynolds has also operated within roles at Deutsche Bank in Germany and commercial encryption company Secude GmbH in Switzerland.

At SecureAge – used by governments, research institutes and organizations to defend against advanced, persistent cyber-threats – Reynolds will lead product management efforts for the company’s suite of products.

The newly created position will see him serve as a critical communication and planning link among internal groups as well as external agencies, SecureAge added.

Commenting on his appointment, Reynolds said: “It is a pleasure to join SecureAge as CPO during this exciting growth stage of the company. I’m eager to help innovate and expand our security products for enterprise use worldwide.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk