Dog Helps Kids Stay Safe Online

Dog Helps Kids Stay Safe Online

A fictional dog is to teach elementary and middle school kids how to maintain a secure digital footprint in a new book co-authored by Fortinet’s deputy CISO. 

Lacey the pooch is the creation of Renee Tarun, a cybersecurity veteran of two and half decades. The character is based on Tarun’s pet chocolate Labrador, Lacey, who died three years ago at the age of 15. 

In Cyber Safe: A Dog’s Guide to Internet Security, Lacey shows her friend Gabbi the cat how to use the internet safely. Fortinet will make copies of the book available to schools across the United States as part of the NSE Training Institute’s initiatives to close the skills gap.

Describing what inspired her to write the book, Tarun told Infosecurity Magazine: “Having been in the cyber field for over 25 years, working in intelligence and law enforcement agencies and now the private sector at Fortinet, I know that children can be a vulnerable and lucrative target for identity thieves and for those looking to do much worse. 

“Kids spend a lot more time online these days. The internet can be a great place for kids to learn, connect with friends, etc. However, it can also put them at risk. Being a parent of two kids, I know the importance of teaching kids how to be safe wherever they go, including online.”

Asked how she chose which animals to write about, Tarun said: “Having a dog and cat are very relatable pet characters for kids. I chose the dog because of my experiences with my own dog, Lacey.  

“She was a very loyal, protective dog. She was also very smart; she figured out how to open doors and camping tents all on her own! Usually food was involved.”

The book will focus on teaching kids the fundamentals of good cyber hygiene, like keeping devices up to date, and security practices such as protecting personal information.  

“These are basic concepts that everyone (including adults) should know and continue to practice,” said Tarun.

“Unfortunately, we continue to see breaches and personal information being exposed because of not doing the basics and human error.”

Tarun is planning the next book in a series dedicated to kids, cyber, and more animal duos.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyberbullying Linked to Social Media Addiction

Cyberbullying Linked to Social Media Addiction

New research by the University of Georgia suggests the existence of a link between excessive social media use and cyberbullying behavior in teens. 

study led by principal investigator Amanda Giordano, an associate professor in the UGA Mary Frances Early College of Education, found that teens with higher social media addiction scores, who spent more hours online, were more likely to engage in cyberbullying. 

Cyberbullies, who carry out behavior such as personal attacks, harassment or discriminatory behavior, spreading defamatory information, misrepresenting oneself online, spreading private information, social exclusion, and cyberstalking, are also more likely to identify as male.

Giordano said that anonymity and freedom from consequences made cyberbullying tempting.

“There are some people who engage in cyberbullying online because of the anonymity and the fact that there’s no retaliation,” she told Mirage News.

“The perpetrator doesn’t get a chance to see how damaging their bullying is and to learn from their mistakes and do something different. It’s a scary situation because they don’t have the natural consequences they do with offline bullying.”

Giordano said adults’ expectations of how teenagers will use the internet may not be realistic.

“You have these adolescents who are still in the midst of cognitive development, but we’re giving them technology that has a worldwide audience and then expecting them to make good choices,” she said.

The 428 young people aged from 13 to 19 who participated in the study reported spending on average over seven hours online per day. The reported average maximum time spent online in a single day exceeded 12 hours.

Giordano said teens who are addicted to social media will scroll through it all night long, even if doing so results in exhaustion, poor grades at school, or arguments with their parents. 

She said teens became addicted to the dopamine hit delivered by social networking sites designed to function as popularity contests played out in public.

“It’s feeding into that addictive behavior, and they may be using cyberbullying as a way to get likes, shares, comments and retweets,” said Giordano. 

“We need schools and school counselors to do this preventative work early and educate students about the risk of addiction with some of these rewarding behaviors like gaming and social media,” she added.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#LORCALive: Nation State Cooperation Essential to Fighting Scourge of Cybercrime

#LORCALive: Nation State Cooperation Essential to Fighting Scourge of Cybercrime

Greater nation state collaboration is required to tackle the growing threat of cybercrime, according to panellists speaking during a session at the LORCA Live online event.

Troels Oerting, former head of World Economic Forum’s (WEF’s) Centre for Cybersecurity, firstly outlined the relevance of cybersecurity to the WEF’s ‘Great Reset’ agenda, which advocates a global approach to tackling the world’s problems, such as inequalities. He noted it is estimated that 80% of the unwanted activity on the internet is attributed to criminal groups operating throughout the globe. Yet despite the vast majority of crime being caused by these types of actors, “the challenge we have is the police in Denmark, UK, Russia, China, US and other places cannot cooperate on targeting ordinary cybercrime because it seems to be linked to nation state activity in one big basket.”

As a result, Oerting believes that the focus should be on establishing dialogue between all countries in order to address regular cybercrime, before seeking to develop international norms to govern cyber-warfare between nation states. “Could we have a digital Geneva convention?” he asked.

This need for a reset in the approach to cybercrime has been exacerbated by the COVID-19 pandemic, which has led to much greater reliance on the internet and digital technologies for both organizations and businesses. Eleanor Fairford, deputy director for incident management at the NCSC, explained that “it has been clear from the outset of this pandemic that this would provide the perfect opportunity for cyber-threat actors, both state-sponsored and criminal, to really exploit this increased digital connectivity we’re all undergoing in the current environment.” She added that, similarly to Oerting’s point, “the biggest threat in this space really is at the hands of those cyber-criminals.”

Working towards fostering greater collaboration between nation states in this realm, including between those in which there are a lot of tensions, is therefore vital. Sadly, at this stage, such a scenario is unrealistic in the view of Oerting. “I’m not sure that we have the right atmosphere right now,” he commented, adding that “to ask the Russians, Chinese, Americans and Europeans to be in the same room and discuss cybercrime honestly is probably one bridge too far right now.” However, while it may not be conceivable at this point, Oerting said “that shouldn’t stop us from promoting the idea” as such parties may be forced into more cooperation in the future because of the highly interconnected nature of cybercrime, affecting all parts of the world.

Fairford agreed, observing that while there is lots of collaboration in cybersecurity among like-minded nations in areas such as cyber-threat intelligence sharing, tensions with other countries have increased, largely as a result of cyber-espionage campaigns conducted by state actors during the pandemic. She said “there is still a way to go before we’re able to collaborate on those levels.” Nevertheless, “the sentiment is absolutely spot on and we should be seeking common ground and cybercrime is potentially one of those areas where we should look to work together.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Younger Ransomware Victims More Likely to Pay Up

Younger Ransomware Victims More Likely to Pay Up

New research has found that the age of a ransomware victim may affect their willingness to pay for the recovery of their data. 

study by cybersecurity company Kaspersky found that while 65% of victims aged between 35 and 44 paid their attackers for a decryption key, only 11% of victims aged 55 and over, and 52% of victims aged 16 to 24, gave in to ransom demands. 

The Kaspersky Consumer IT Security Risks Survey (Consumer ITSR) interviewed a total of 15,070 adult consumers globally between September and October 2020 about their attitudes toward online privacy and whether they had experienced any security incidents in the past 12 months.

Overall, just over half (56%) of ransomware victims paid up in the hope of getting their data back, but 17% of those did not recover their encrypted files.

Whether they handed over a ransom or not, only 29% of all victims were able to restore every single one of their affected files following an attack. Half of victims reported losing at least some files, while 32% lost a significant amount, and 13% lost virtually all their data.

Researchers found that only 39% of those surveyed claimed that they were aware of ransomware over the past 12 months. 

“This data shows we have seen a significant proportion of consumers paying a ransom for their data over the past 12 months,” said Marina Titova, head of consumer product marketing at Kaspersky. 

“But handing over money doesn’t guarantee the return of data, and only encourages cybercriminals to continue the practice. Therefore, we always recommend that those affected by ransomware do not pay as that money supports this scheme to thrive.”

Titova said that consumers should take preventative cybersecurity action and also report ransomware attacks to their local law enforcement agency.

“Consumers should make sure to invest in initial protection and security for their devices and regularly back up all data,” said Titova.

“This will make the attack itself less appealing or lucrative to cybercriminals, reducing the use of the practice, and presenting a safer future for web users.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Double-Extortion Ransomware Attacks Surged in 2020

Double-Extortion Ransomware Attacks Surged in 2020

Double-extortion ransomware attacks exploded in 2020, according to F-Secure’s Attack Landscape Update report.

The tactic involves threat actors stealing data from organizations in addition to encrypting files. This means that, as well as demanding a ransom to decrypt data, attackers can later threaten to leak the stolen information if an additional payment is not made.

The researchers observed that by the end of 2020, 15 different ransomware families had used this double-extortion approach, which compares to just one in 2019. Additionally, it was found that nearly 40% of ransomware families discovered last year utilized this ransomware method.

Commenting on this trend, Calvin Gan, a senior manager with F-Secure’s Tactical Defense Unit, explained: “Organizations with reliable backups and effective restoration procedures are in a strong position to recover from a ransomware attack without having to pay. However, managing a potential data leak is a dramatically different challenge, especially for organizations that possess confidential information.

“Ransomware actors, current and future, will likely feel emboldened to try new things and jump on vulnerabilities faster, which we’re already seeing with the recent MS Exchange vulnerabilities.”

The study also outlined a number of other significant cybersecurity trends that took place in 2020. There was a tripling in the use of Excel formulas to obfuscate malicious code in the second half of 2020. In regard to phishing attacks, the most popular brand spoofed in emails was Outlook, followed by Facebook Inc. and Office365, while web hosting services made up nearly three-quarters of domains used to host phishing pages.

In a retrospective analysis of notable supply chain attacks from the last 10 years, F Secure highlighted than more than half targeted either utility or application software.

Gan added: “In security, we place a lot of emphasis on organizations protecting themselves by having strong security perimeters, detection mechanisms to quickly identify breaches and response plans and capabilities to contain intrusions. However, entities across industries and borders also need to work together to tackle security challenges further up the supply chain. Advanced persistent threat groups are clearly ready and willing to compromise hundreds of organizations through this approach, and we should work together to counter them.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Concern as Ransomware and Exchange Server Attacks Surge

Concern as Ransomware and Exchange Server Attacks Surge

There are growing concerns that more unpatched Microsoft Exchange servers could be compromised in ransomware attacks after Check Point revealed major recent surges in ProxyLogon attacks and ransomware.

The security vendor claimed in new figures released today that it has detected a 57% increase in ransomware attacks over the past six months, with the number of affected organizations growing by 9% each month so far in 2021.

Human-operated variants such as Maze and Ryuk have been particularly prevalent over the period, with the US (12%), Israel (8%) and India (7%) the most affected countries.

Amazingly, WannaCry is trending again, four years after it caused global panic. Still using EternalBlue to propagate, the worm affected 53% more organizations in March than the start of the year.

At the same time as the continued surge in ransomware, Check Point has seen the number of attacks exploiting the ProxyLogon vulnerability to attack Exchange servers triple over the past week alone.

The most affected sectors are government/military, manufacturing and banking/finance, with the nearly half (49%) of all exploit attempts in the US, followed by the UK (5%), the Netherlands (4%) and Germany (4%).

Microsoft was the first to warn users that vulnerable Exchange endpoints could be hijacked by attackers to deploy ransomware. The DearCry variant was spotted doing so in the wild.

A few days later Sophos detected Black Kingdom ransomware being deployed in a similar way.

“The threat actor exploited the on-premises versions of Microsoft Exchange Server, abusing the remote code execution (RCE) vulnerability also known as ProxyLogon (CVE-2021-27065),” it said. “After successfully breaching the Exchange server, the adversary delivered a webshell. This webshell offers remote access to the server and allows the execution of arbitrary commands.”

The acting director of the Cybersecurity and Infrastructure Security Agency (CISA), Brandon Wales, has also urged Exchange server administrators to patch now or risk the same fate.

Check Point stopped short of linking the two trends, but joined the chorus of voices calling for urgent action to patch the remaining Exchange servers vulnerable to ProxyLogon.

“Although we have not concluded that the two trends are directly related just yet, there is reason for concern. We do believe the Microsoft Exchange vulnerabilities opened up another door into organizations. And so, Check Point Research is also raising the alarm bells, just like CISA has,” said threat intelligence manager, Lotem Finkelsteen.

“We’re urging organizations to act now, before ransomware gangs make Exchange exploits popular. In cybercrime, we rarely see businesses that demonstrate constant growth, or rapid adjustments to changing factors, as well as quick adoptions of new technologies. Ransomware is one of those rare businesses.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Fileless Malware Detections Soar 900% in 2020

Fileless Malware Detections Soar 900% in 2020

Detections of fileless malware soared by nearly 900% year-on-year in 2020 as threat actors worked hard to stay hidden from traditional security controls, according to Watchguard Technologies.

The network security vendor compiled its latest Internet Security Report based on data from its Firebox Feed, internal and partner threat intelligence including endpoint data from recently acquired Panda Security, and a research honeynet.

Fileless malware rates surged by 888% over the year as attackers sought to fly under the radar of many endpoint protection products, by conducting attacks without installing malicious code.

Toolkits like PowerSploit and CobaltStrike were particularly popular in enabling attackers to inject malicious code into running processes so that, even if the original script is identified and removed, they remain operational.

Another way for attackers to hide their intent is through encryption. Watchguard claimed that nearly half (47%) of all attacks it detected at the network perimeter in Q4 were encrypted, while malware delivered via HTTPS increased 41% and encrypted zero-day variants surged 22% over Q3.

The network perimeter itself continues to be a major target for attack, despite the shift to mass remote working: total network attack detections grew 5% in Q4 to reach their highest level in two years, while total unique attack signatures increased 4% over the previous quarter.

Elsewhere, the vendor detected 25% more cryptocurrency mining malware in 2020 over 2019 levels, thanks to the rising value of digital currency.

Interestingly, ransomware attack volumes continued to shrink for the second year in a row as cyber-criminals focused on fewer, high-value targets. From an all-time high of 5489 unique payloads in 2018, the figure for 2020 was down to 2152.

However, these variants may still have infected hundreds of thousands of endpoints worldwide, Watchguard claimed.

The rise in sophisticated, evasive threat tactics last quarter and throughout 2020 shows how vital it is to implement layered, end-to-end security protections,” said Corey Nachreiner, CTO at WatchGuard.

“The attacks are coming on all fronts, as cyber-criminals increasingly leverage fileless malware, crypto-miners, encrypted attacks and more, and target users both at remote locations as well as corporate assets behind the traditional network perimeter. Effective security today means prioritizing endpoint detection and response, network defences and foundational precautions such as security awareness training and strict patch management.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

SolarWinds Attackers Accessed DHS Secretary’s Emails — Report

SolarWinds Attackers Accessed DHS Secretary’s Emails — Report

Suspected Russian hackers managed to access the emails of Donald Trump’s last Department of Homeland Security (DHS) chief, in an intelligence coup for the Kremlin, according to a new report.

AP spoke to more than a dozen current and former US officials to discover more about the impact of the infamous SolarWinds attacks, which compromised at least nine federal agencies.

Email accounts belonging to then-acting secretary Chad Wolf were reportedly compromised by attackers during the months-long campaign, although it’s not clear what information was taken. Email accounts belonging to cybersecurity staff whose job it was to tackle foreign cyber-threats were also apparently affected.

The report revealed that another cabinet secretary, the Energy Department’s Dan Brouillette, was affected by the attacks. However, only non-confidential schedules were apparently taken.

What emerges from the interviews with anonymous officials is frustration at the inability of government IT systems to first detect the attack, which was initially flagged by FireEye, and then understand the scale of the impact.

For example, the Federal Aviation Administration (FAA) first said it was not affected by the operation, then was forced to issue a second statement a few days later admitting that its investigations were continuing.

In the end it emerged the agency was breached by the attackers, but struggled for weeks to work out how many of its servers were running SolarWinds software, according to AP.

Tim Wade, technical director at Vectra, said the news about Wolf’s emails may not be as bad as it sounds.

“We should expect that, if followed, protocols related to information classification should have precluded more sensitive details from being directly accessible and exposed without a hostile, foreign actor first finding access and exfiltration channels on classified networks,” he argued.

“Nonetheless, even unclassified communication between sensitive parties can disclose a great deal of actionable intelligence — the concerns raised by this story should not be understated.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk