Burned Out Employees Put Corporate Security at Risk

Burned Out Employees Put Corporate Security at Risk

The pressures of remote working and caregiving during the pandemic have taken a significant psychological toll on UK employees, leading to risky behavior online which could expose their employer to cyber-threats, according to Forcepoint.

The security vendor polled 1000 UK adults to better understand how life under lockdown is affecting the corporate cybersecurity posture.

Over half (52%) of respondents reported increased personal pressure over the past year, with younger employees more likely to suffer than their counterparts over 55-years-old.

Almost two-thirds (64%) of younger employees said that their stress level makes it difficult to focus, versus 29% of older workers, and 70% claimed they’re under pressure to be available outside of normal working hours, compared to half (48%) of older workers. Some 71% said they also feel stressed out by competing demands from their personal and professional lives, compared to 40% of older employees.

This appears to be translating into risky behavior: 41% of younger respondents reported making more mistakes when working from home, such as copying the wrong people into emails. Over half (54%) said distractions negatively impact decision making and 46% use shadow IT to perform certain tasks more easily.

Most (71%) caregivers also reported stress in trying to balance work and home life, with 70% claiming they feel the pressure to be available outside of normal working hours. Half (49%) said they find it difficult to make day-to-day professional decisions while working from home.

Potentially as a result, 45% said they tend to make more minor mistakes when working from home, and 40% said they need shadow IT to get their job done.

“Companies and business leaders need to take into account the unique psychological and physical situation of their home workers when it comes to effective IT protection. They need to make their employees feel comfortable in their home offices, raise their awareness of IT security and also model positive behaviors,” argued Forcepoint principal research scientist, Margaret Cunningham.

“Knowing the rules, both written and implied, and then designing behavior-centric metrics surrounding the rules can help us mitigate the negative impact of these risky behaviors.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Patch Facebook for WordPress to Fix Site Takeover Bugs

Patch Facebook for WordPress to Fix Site Takeover Bugs

Facebook has fixed two critical vulnerabilities in its popular WordPress plugin which could have been exploited to enable full site takeover, according to Wordfence.

The security company revealed yesterday that it disclosed the bugs to the social network on December 22 last year and January 27 2021. Patches for each were released on January 6 and February 7 2021, respectively.

The vulnerabilities affected the plugin formerly known as Official Facebook Pixel, which is said to be installed on around half a million sites globally. The software is designed to integrate Facebook’s Pixel conversion measurement tool with WordPress sites so it can monitor traffic and record specific user actions.

The first bug is a PHP object injection vulnerability with a CVSS score of 9.

“The core of the PHP Object Injection vulnerability was within the run_action() function. This function was intended to deserialize user data from the event_data POST variable so that it could send the data to the pixel console,” explained Wordfence threat analyst, Chloe Chamberland.

“Unfortunately, this event_data could be supplied by a user. When user-supplied input is deserialized in PHP, users can supply PHP objects that can trigger magic methods and execute actions that can be used for malicious purposes.”

As such, the bug could have been exploited to upload arbitrary files and achieve remote code execution on a vulnerable target.

The second CVE was a cross-site request forgery with a CVSS score of 8.8.

It was introduced by accident when developers updated the plugin to version 3.0, and relates to an AJAX function that was added to make the software’s integration into WordPress sites easier.

“There was a permission check on this function, blocking users lower than administrators from being able to access it, however, there was no nonce protection. This meant that there was no verification that a request was coming from a legitimate authenticated administrator session,” explained Chamberland.

“This made it possible for attackers to craft a request that would be executed if they could trick an administrator into performing an action while authenticated to the target site.”

The vulnerability could have been exploited to update the plugin’s settings, steal metric data and inject malicious backdoors into theme files or create new administrative user accounts to completely hijack a site, she added.

Users are urged to upgrade to the latest version of Facebook for WordPress (3.0.5).

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Kroll Acquires Redscan to Expand Cyber-Risk Offering

Kroll Acquires Redscan to Expand Cyber-Risk Offering

Services and digital product provider Kroll has announced the acquisition of award-winning UK cybersecurity firm Redscan.

The deal will see Kroll, which specializes in governance, risk and transparency, extend its Kroll Responder capabilities through the addition of Redscan and its extended detection and response (XDR) enabled security operations center (SOC) platform.

Redscan will join Kroll under the leadership of Andrew Beckett, managing director and head of the EMEA cyber-risk practice and Marc Brawner, managing director and global head of managed services.

Redscan’s CEO Mike Fenton, COO Gubi Singh and CTO Mark Nicholls will all be staying with the firm, it was confirmed, and will continue to play key roles within a newly created Cyber Risk business unit at Kroll, which will be headed up by Jason Smolanoff, global head of cyber-risk.

Commenting on the announcement, Jacob Silverman, CEO of Kroll, said: “The acquisition of Redscan perfectly complements the new chapter we have entered under our Kroll brand, reinforcing our commitment to supporting our clients’ most complex challenges. Together, our professionals will harness the power of technology and their deep expertise to provide clarity and cyber resilience for clients, solidifying our position at the forefront of cybersecurity solutions. I look forward to building on this mandate with our expanded, global Cyber Risk team.”

Redscan has previously been recognized for the quality of its services, including its proprietary cloud native MDR solution which correlates events and intelligence from an array of leading telemetry sources.

“Merging Redscan’s innovative culture and leading managed security services with Kroll’s unparalleled incident response experience and end-to-end cyber-risk management capabilities allows us to provide a unique global offering,” added Fenton. “This combination will build fantastic value for our clients, who will benefit from a global team of world-class seasoned experts monitoring their environments and an expanded platform to grow our proprietary technology capabilities.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hacking Weapons Systems

Lukasz Olejnik has a good essay on hacking weapons systems.

Basically, there is no reason to believe that software in weapons systems is any more vulnerability free than any other software. So now the question is whether the software can be accessed over the Internet. Increasingly, it is. This is likely to become a bigger problem in the near future. We need to think about future wars where the tech simply doesn’t work.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Activist Denies Facebook Fraud

Activist Denies Facebook Fraud

A political activist from Ohio has denied impersonating a leader of the political group Black Lives Matter on social media for his own personal profit.

Toledo resident Sir Maejor Page, a.k.a. Tyree Conyers-Page, was arrested in September on one count of wire fraud and two counts of money laundering.

An investigation was launched into the 32-year-old after a complaint was filed with the FBI’s National Threat Operations Center in April 2020. 

The complaint alleged that Page was fraudulently using a non-profit organization by way of misrepresentations and also posing as a Black Lives Matter leader.

Law enforcement determined that Page had created and operated a Facebook page named Black Lives Matter of Greater Atlanta (BLMGA). Page set BLMGA up as a non-profit organization, capable of accepting monetary donations, and also listed it as a non-profit organization with the fundraising website GoFundMe.

In 2018, Page opened up a bank account named “Black Lives Matter of Greater Atlanta, Inc.” to which he is the sole signatory. 

Up until the death of George Floyd on May 25, 2020, the balance of the account remained under $5,000. However, between June and August 2020, BLMGA’s social media page received approximately $467,342.18 in donations, all of which was transferred to the Black Lives Matter of Greater Atlanta, Inc. bank account, owned and operated by Page.

Court documents allege that in June, July, and August last year, Page repeatedly used a debit card linked to this same account to purchase food, dining, entertainment, furniture, a home security system, tailored suits, and accessories. 

On August 21, he allegedly used the money in the account to buy a residence and an adjacent vacant lot in Toledo for a total of approximately $112,000.

“In summary, Page has spent over $200,000 on personal items generated from donations received from the BLMGA social media page with no identifiable purchase or expenditure for social or racial justice,” said the FBI.

Acting US Attorney Bridget Brennan said: “It is our sincere hope that these charges help raise awareness about online scams and efforts by some to exploit the name and purpose of non-profit organizations for personal gain.”

On March 10, Page entered a not guilty plea to all charges. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk