Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
SolarWinds Attackers Accessed DHS Emails, Report
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Intel Sued Under Wiretapping Laws for Tracking User Activity on its Website
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
System Update: New Android Malware
Researchers have discovered a new Android app called “System Update” that is a sophisticated Remote-Access Trojan (RAT). From a news article:
The broad range of data that this sneaky little bastard is capable of stealing is pretty horrifying. It includes: instant messenger messages and database files; call logs and phone contacts; Whatsapp messages and databases; pictures and videos; all of your text messages; and information on pretty much everything else that is on your phone (it will inventory the rest of the apps on your phone, for instance).
The app can also monitor your GPS location (so it knows exactly where you are), hijack your phone’s camera to take pictures, review your browser’s search history and bookmarks, and turn on the phone mic to record audio.
The app’s spying capabilities are triggered whenever the device receives new information. Researchers write that the RAT is constantly on the lookout for “any activity of interest, such as a phone call, to immediately record the conversation, collect the updated call log, and then upload the contents to the C&C server as an encrypted ZIP file.” After thieving your data, the app will subsequently erase evidence of its own activity, hiding what it has been doing.
This is a sophisticated piece of malware. It feels like the product of a national intelligence agency or — and I think more likely — one of the cyberweapons arms manufacturers that sells this kind of capability to governments around the world.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Whistleblower: Ubiquiti Breach “Catastrophic”
On Jan. 11, Ubiquiti Inc. [NYSE:UI] — a major vendor of cloud-enabled Internet of Things (IoT) devices such as routers, network video recorders and security cameras — disclosed that a breach involving a third-party cloud provider had exposed customer account credentials. Now a source who participated in the response to that breach alleges Ubiquiti massively downplayed a “catastrophic” incident to minimize the hit to its stock price, and that the third-party cloud provider claim was a fabrication.

A security professional at Ubiquiti who helped the company respond to the two-month breach beginning in December 2020 contacted KrebsOnSecurity after raising his concerns with both Ubiquiti’s whistleblower hotline and with European data protection authorities. The source — we’ll call him Adam — spoke on condition of anonymity for fear of retribution by Ubiquiti.
“It was catastrophically worse than reported, and legal silenced and overruled efforts to decisively protect customers,” Adam wrote in a letter to the European Data Protection Supervisor. “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.”
Ubiquiti has not responded to repeated requests for comment.
According to Adam, the hackers obtained full read/write access to Ubiquiti databases at Amazon Web Services (AWS), which was the alleged “third party” involved in the breach. Ubiquiti’s breach disclosure, he wrote, was “downplayed and purposefully written to imply that a 3rd party cloud vendor was at risk and that Ubiquiti was merely a casualty of that, instead of the target of the attack.”
In its Jan. 11 public notice, Ubiquiti said it became aware of “unauthorized access to certain of our information technology systems hosted by a third party cloud provider,” although it declined to name the third party.

In reality, Adam said, the attackers had gained administrative access to Ubiquiti’s servers at Amazon’s cloud service, which secures the underlying server hardware and software but requires the cloud tenant (client) to secure access to any data stored there.
“They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Adam said.
Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies.
Such access could have allowed the intruders to remotely authenticate to countless Ubiquiti cloud-based devices around the world. According to its website, Ubiquiti has shipped more than 85 million devices that play a key role in networking infrastructure in over 200 countries and territories worldwide.
Adam says Ubiquiti’s security team picked up signals in late December 2020 that someone with administrative access had set up several Linux virtual machines that weren’t accounted for.
Then they found a backdoor that an intruder had left behind in the system.
When security engineers removed the backdoor account in the first week of January, the intruders responded by sending a message saying they wanted 50 bitcoin (~$2.8 million USD) in exchange for a promise to remain quiet about the breach. The attackers also provided proof they’d stolen Ubiquiti’s source code, and pledged to disclose the location of another backdoor if their ransom demand was met.
Ubiquiti did not engage with the hackers, Adam said, and ultimately the incident response team found the second backdoor the extortionists had left in the system. The company would spend the next few days furiously rotating credentials for all employees, before Ubiquiti started alerting customers about the need to reset their passwords.
But he maintains that instead of asking customers to change their passwords when they next log on — as the company did on Jan. 11 — Ubiquiti should have immediately invalidated all of its customer’s credentials and forced a reset on all accounts, mainly because the intruders already had credentials needed to remotely access customer IoT systems.
“Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed, but the attacker targeted the credentials to the databases, and created Linux instances with networking connectivity to said databases,” Adam wrote in his letter. “Legal overrode the repeated requests to force rotation of all customer credentials, and to revert any device access permission changes within the relevant period.”
If you have Ubiquiti devices installed and haven’t yet changed the passwords on the devices since Jan. 11 this year, now would be a good time to care of that.
It might also be a good idea to just delete any profiles you had on these devices, make sure they’re up to date on the latest firmware, and then re-create those profiles with new [and preferably unique] credentials. And seriously consider disabling any remote access on the devices.
Ubiquiti’s stock price has grown remarkably since the company’s breach disclosure Jan. 16. After a brief dip following the news, Ubiquiti’s shares have surged from $243 on Jan. 13 to $370 as of today. By market close Tuesday, UI had slipped to $349.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US Imprisons BEC Scammer
US Imprisons BEC Scammer

A Plano resident has been sent to prison for his part in a multimillion-dollar fraud and money-laundering scheme that victimized school districts, charities, and senior citizens.
In October last year, Babatope Joseph Aderinoye was found guilty of conspiracy to commit bank fraud, wire fraud, and money laundering; wire fraud; aggravated identity theft; and mail fraud.
According to court documents, the 30-year-old would obtain fake passports in the names of other people, then use these fraudulent documents to open bank accounts and set up sham businesses.
After the fraudulent bank accounts had been opened, Aderinoye’s co-conspirators exploited them to carry out various business email compromise (BEC) scams and telephone compromise scams that defrauded individuals and businesses out of money.
“In these scams, co-conspirators would pose as a known individual and direct the targeted victims to wire or send funds to Aderinoye or the fraudulent accounts Aderinoye had set up,” said the Department of Justice.
“Once the ill-gotten money posted in Aderinoye’s fraudulent accounts, he would immediately withdraw the funds, transfer the monies to other fraudulent accounts, or wire them internationally to a bank account he had set up in Nigeria.”
Proceeds from the crimes were used to pay off co-conspirators and to bankroll additional fraudulent schemes. From June 2018 through September 2019, over $6.7 million was deposited into bank accounts opened by Aderinoye using an alias.
Law enforcement have linked Aderinoye’s name to 13 individual aliases, 12 business aliases, and over 40 fraudulent bank accounts. However, evidence suggests that he may have used more aliases.
Among the scammers’ growing list of victims are school districts such as Community ISD and Project 4031, a non-profit organization that partners with hospice and palliative care organizations to offer no-cost services to patients and families.
One elderly man targeted by Aderinoye and his associates had over $352,000 stolen from his investment account, while another individual whose identity was stolen lost every cent in his retirement account.
On March 25, Aderinoye was sentenced to 408 months in federal prison by US District Judge Amos Mazzant. The fraudster was also ordered to pay restitution in the amount of $1,919,526.13.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
More Solutions Doesn’t Mean More Protection
More Solutions Doesn’t Mean More Protection

New research has found that running multiple protection and cybersecurity solutions simultaneously did not prevent data loss in many organizations last year.
The finding was part of the second annual Cyber Protection Week survey conducted by global technology company Acronis. Researchers asked 4,400 IT users and professionals in 22 countries across six continents about their cybersecurity solutions.
The results showed that while 80% of companies now run up to 10 different solutions simultaneously to protect their data and computer systems, more than half of those organizations suffered unexpected downtime in 2020 after losing data.
“Not only does investing in more solutions not deliver more protection, in many cases trying to manage protection across multiple solutions creates greater complexity and less visibility for the IT team, which increases risk,” said an Acronis spokesperson.
Researchers identified a gap in awareness among IT professionals and users when it came to knowing what their organization’s cybersecurity capabilities actually were.
The survey found that 68% of IT users and 20% of IT professionals would be unable to tell if their data had been altered without their knowledge, because their cybersecurity solution makes determining that kind of tampering difficult.
Nearly half of IT users (43%) were in the dark when it came to knowing if their anti-malware stops zero-day threats, because their solution doesn’t make such information easily available.
A tenth of IT professionals admitted not knowing if their organization is subject to data privacy regulations, potentially exposing their company to major fines for compliance violations.
Researchers uncovered an individual approach to cybersecurity that they described as “staggeringly lax.”
While 83% of IT users said they spent more time on their devices in 2020, only half of them took extra steps to protect those devices. A third (33%) admitted waiting at least a week to update their devices with a new patch after being notified of the patch’s release.
The survey findings suggest that IT users don’t know how to back up their data correctly since 90% reported performing backups; however, 73% said they had lost data at least once.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Bumble Launches Online Safety Guide
Bumble Launches Online Safety Guide

The dating application Bumble has launched a new online safety initiative to help protect women in India from online abuse.
Stand for Safety was created in collaboration with Safecity, an Indian-based public safety platform owned by the Red Dot Foundation. The goal of the initiative is to help women identify, prevent, and tackle negative online behavior including bullying, aggression, and hateful comments.
News of the initiative follows a recent survey conducted by Bumble that found that most (83%) women in India have been the target of online harassment, with one in three experiencing it on a weekly basis.
The research also found that the majority of women (70%) say online bullying has worsened since the global health pandemic began.
“As a result of this digital abuse epidemic, well over half (59%) of women we surveyed in India said they feel unsafe,” said a spokesperson for Bumble.
“No one should have to feel afraid of harassment online, nor should they—as 1 in 3 women reported—put on a brave face and let this behavior slide for fear of retribution.”
Behavior flagged in the new safety guide includes cyber-staking, doxxing, online impersonation, and concern trolling—pretending to express concern for someone to criticize or undermine them.
Flaming, when one person attacks another online by posting disrespectful comments about them, was also highlighted, with victims advised to document incidents and to report and block them on the platform where the abuse took place.
Another form of online abuse that users are warned to look out for is “outing,” the leaking of someone’s personal videos without their consent. This abuse is punishable under India law.
“Your first priority online should always be your personal safety,” states Stand for Safety. “It’s important to know and understand your rights in the digital space.”
“Many women are silenced and intimidated in online spaces due to harassment and bullying directed towards them,” said Red Dot Foundation founder ElsaMarie D’Silva.
“Today’s environment requires everyone to be comfortable and knowledgeable when accessing and utilizing digital spaces for various aspects of life. We hope our safety guide will help them navigate these spaces safely and confidently.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
#LORCALive: More Work Required to Realize the Potential of AI in Cybersecurity
#LORCALive: More Work Required to Realize the Potential of AI in Cybersecurity

The main issues and trends in regard to the use of AI in cybersecurity were discussed by Robert Hannigan, senior executive of BlueVoyant and chair the LORCA advisory board, speaking during the LORCA Live online event.
Hannigan began by explaining that AI is often confused with automation, and that the two need to be distinguished. He defined AI as “machines that act intelligently on data” and “it’s not just about doing things at greater scale and faster and more efficiently, it’s something more than automation.”
It is for this reason that the former director of GCHQ does not believe we should be overly concerned with the often talked about scenario of cyber-criminals utilizing AI to launch attacks. “I’ve seen virtually no evidence for this at all,” he said, adding that while malicious actors are increasingly using automative tools at large scale, such as vulnerability scanning, these “are not what I would call AI.”
The one area in which cyber-criminals are leveraging AI is in social engineering attacks, according to Hannigan. Examples include pharming social media accounts at scale and using deep fake recordings: “But that’s really about AI-enabled fraud,” he noted.
In regard to the current use of AI in cyber-defense, again many of the techniques actually fall into the bracket of automation. Anomaly detection and behavioral analytics – learning what’s normal in a network from pattern analysis and finding exceptions – is the area where AI is starting to take off. However, “we have to be realistic about the fact this is not a silver bullet yet,” commented Hannigan. He explained it is all too common to run into problems with the two components of AI: data and models. “Clearly, if you don’t have enough data to work on, or if your model isn’t quite right, you’re going to either flood your customer with false positives, or you’re going to miss critical threats.”
Therefore, in the view of Hannigan, while behavioral analytics offers huge potential, it is still very much a work in progress.
Finally, Hannigan discussed the important concern of security within AI. This particularly relates to more complex AI technologies being developed in areas like medical diagnostics. He noted there has been lots of research into the very real possibility of ‘data poisoning,’ in which machines can be tricked into incorrectly categorizing data, “with potentially very serious consequences.”
Concluding, Hannigan said that these kinds of issues should not put us off from pursuing AI solutions to enhance cybersecurity, “but it is something we need to spend a lot more time on.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
ClubCISO Appoints Stephen Khan as its New Chair
ClubCISO Appoints Stephen Khan as its New Chair

ClubCISO, the international community of chief information security officers and security leaders, has announced the appointment of Stephen Khan as its new chair.
Khan is head of technology and cybersecurity risk at HSBC Group Information Security Risk, and is also the current chair of the White Hat Ball.
Khan has replaced Dr Jessica Barker as chair at ClubCISO, who will remain on the non-commercial organizations’ advisory board after serving two years as chair. Khan will look to build on Barker’s work highlighting that cybersecurity is about more than just technical expertise. Under her direction, ClubCISO has promoted the importance of culture, leadership and managing stress in the industry. Despite progress in this area, with 60% of CISOs stating they have delivered improvements in security culture in preliminary findings from this year’s ClubCISO annual survey, numerous research has demonstrated the high levels of stress and anxiety in the sector, exacerbated by the COVID-19 pandemic.
Commenting on his appointment, Khan said: “We are already seeing that security culture remains right at the top of CISO priorities for the year ahead, so I’m taking over as chair at a point where Jess has already changed hearts and minds about what the security function really entails.
“As chair of ClubCISO, I hope to bring a security practitioner’s experience to bear on the development of the CISO role. I have lived information and cybersecurity roles for many years and in many different guises. Let us be honest, every CISO role has a different set of challenges as not all organizations are the same.”
Khan has taken the reigns at a time of high growth for ClubCISO, with its community growing by 56% in the past year, meaning it now represents CISOs and security leaders from UK, European and international businesses.
On stepping down from the role of chair, Barker commented: “I have loved my time as chair and am proud that we are leading the way as a community of real CISOs with real opportunities and challenges to deal with. Stephen is going to be a brilliant chair to continue our leadership on these hugely important topics.
“We are already seeing from the preliminary findings from the 2021 ClubCISO Annual Survey that stress is affecting CISO and team performance, and that stress is increasing in intensity year-on-year. Personal resilience is a key skill we all have to harness, and the ClubCISO app, events and discussion forums are proving a very effective way for CISOs to share with their peers. We must continue to lead the debate and help our members to support one another.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk