EU Council Adopts Cybersecurity Strategy

EU Council Adopts Cybersecurity Strategy

The Council of the European Union announced today that it has officially adopted a new cybersecurity strategy.

The strategy, which looks ahead to the next decade, was presented to the council in December 2020 by the European Commission and the high representative for foreign affairs.

It contains a framework for how to defend businesses, organizations, and EU citizens from cyber-attacks and promote secure information systems. The strategy also outlines plans to make international cyberspace “open, free and secure,” according to the council.

“The conclusions note that cybersecurity is essential for building a resilient, green and digital Europe,” said the council in a statement released today.

“They set as a key objective achieving strategic autonomy while preserving an open economy. This includes reinforcing the ability to make autonomous choices in the area of cybersecurity, with the aim to strengthen the EU’s digital leadership and strategic capacities.”

The conclusions include a strong commitment by the council to swiftly complete the implementation of the EU 5G toolbox measures and to continue efforts to guarantee the security of 5G networks and the development of future network generations.

Actions laid out in the conclusions include the creation of a network of security operation centers across the Union to improve both threat detection and anticipation and the possible establishment of a cyber-intelligence working group to strengthen the EU Intelligence and Situation Centre (INTCEN). 

Another proposed measure is the definition of a joint cyber unit that “would provide clear focus to the EU’s cybersecurity crisis management framework.”

Accelerating the adoption of key internet security standards is another action point listed in the conclusions. This step, which the council says will require “a joint effort,” is described as being “instrumental to increase the overall level of security and openness of the global internet while increasing the competitiveness of the EU industry.”

Other actions include addressing the need to support the development of strong encryption as a means of protecting fundamental rights and digital security, while simultaneously ensuring that law enforcement agencies and judicial authorities can exercise the offline and online powers that have been granted to them.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Heading for “Catastrophic” Digital Skills Shortage

UK Heading for “Catastrophic” Digital Skills Shortage

There has been a substantial decline in students enrolling on IT courses in recent years, meaning the UK is facing a “catastrophic” digital skills shortage, impacting the cybersecurity sector.

This is according to a new report by the Learning & Work Institute, which showed that the number of students enrolling in ICT at GCSE level fell by 40% from 2015 to 2020. While this is partly as a result of the phasing out of ICT GCSE in favor of the computer science GCSE, the number of entries into the latter subject has not made up for the fall in pupils taking ICT.

The research also found there has been a significant reduction in participation in further education courses in ICT. Compared with the academic year 2017/18, there was a 18% decline in enrolment in these courses and a 28% fall in completions.

More encouragingly, there was a small rise in ICT as a proportion of all apprenticeships in the first quarter of 2020/21 (up from 4.9% in 2017/18 to 6.0% in 2020/21). However, they still remain rare, accounting for just one in 20 apprenticeship starts.

Additionally, there has been a steady increase in the number of people starting an undergraduate degree in computer science in the UK, rising by 17% between 2014/15 and 2018/19.

The figures are concerning given the growing demand for digital skills in the UK economy, including in cybersecurity. Over three-quarters (76%) of businesses said a lack of digital skills would affect the profitability of their business and 88% of young people stated that digital skills will be essential for their career.

Discussing the findings, Adam Philpott, EMEA president at McAfee, commented: “To tackle the skills gap, organizations need to encourage a ‘top-of-the-funnel’ intervention and investment from government organizations. We must also collaborate across the industry to create concrete measures focused on closing the gap.

“One example of this is bringing talent in further down the line, by up-skilling employees internally or running returnship programs for those looking for a career change. We must ensure, however, that we have more talent available in the first place. This is why we should encourage those interested in IT or cybersecurity as early as possible and provide a school pathway into the industry.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Cybersecurity Programs to Protect US Energy

New Cybersecurity Programs to Protect US Energy

The United States is launching three new research programs to protect the security of America’s energy system. 

The Department of Energy’s (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER), which announced the new programs, said that they will help “to safeguard the US energy system from growing cyber and physical hazards.”

Potential vulnerabilities in the global supply chain will be addressed by the new schemes, which will also explore ways to shield critical infrastructure from geomagnetic and electromagnetic interference. 

Creating a research and talent pipeline for the next generation of cybersecurity professionals is another area that the freshly announced programs will be focused on. 

“Securing U.S. critical infrastructure, particularly in the energy sector, is one our most important and complex national security challenges,” said CESER Acting Assistant Secretary Patricia Hoffman. “Our vision with these programs is to bring together key partners—from industry to the states to universities—with the expertise and inventiveness needed to enhance energy sector resilience.”

Threats facing America’s critical energy infrastructure include digital hazards like cyber-attacks, and environmental dangers such as wildfires, extreme weather, and climate change, according to CESER. 

“Our energy system faces unprecedented threat levels from hackers, foreign actors, and natural catastrophes supercharged by climate change—which is why enhancing security is a priority for this administration,” said Jennifer M. Granholm, Secretary of Energy, in a government statement. 

“What’s more, President Biden’s clean energy goals all depend on resilient electrical infrastructure. These new programs will help put us a step ahead of all manner of threats so we can provide safe, reliable power to American households.”

News of the programs comes days after 21 states led by attorneys general from Texas and Montana sued President Joe Biden for cancelling the Keystone XL pipeline project that they argue would bolster US energy independence and security. 

The three research programs were welcomed by the chairman of the house energy and commerce committee, Congressman Frank Pallone, Jr, who said that “foreign adversaries are taking new and aggressive tactics to compromise our critical infrastructure, including our electric grid.”

“We must increase our efforts to ensure our energy sector is prepared to mitigate any threat that poses a risk to Americans’ connectivity and access to power,” he added.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Govt Department Loses 306 Mobiles and Laptops in Two Years

UK Govt Department Loses 306 Mobiles and Laptops in Two Years

A UK government department has lost a total of 306 mobile and laptop devices since 2019, according to official figures.

The data, obtained under a Freedom of Information (FoI) request by Parliament Street Think Tank, revealed that the Department for Business, Energy and Industrial Strategy had 234 mobiles and 72 laptops lost or stolen during the calendar years of 2019 and 2020.

In 2019, 26 laptops were reported stolen and 17 lost. This fell to 19 laptops stolen and 10 laptops lost in 2020. In regard to mobiles, 126 were reported lost and 30 stolen in 2019, while the figures were 65 and 13, respectively, in 2020.

The large number of lost or stolen devices raises concerns about highly sensitive government data falling into the hands of malicious actors.

Commenting on the figures, Edward Blake, area vice-president, Absolute Software UK&I, said: “Amidst the chaos caused by COVID-19, managing a large, distributed workforce is no easy task, and keeping tabs on valuable devices like laptops is growing increasingly difficult.

“However, if one of these lost devices ends up in the wrong hands, the organization in question could be facing a far more costly predicament than first anticipated. For example, sophisticated cyber-criminals can steal the data contained on these devices, access more businesses files or intercept emails between colleagues, all with relative ease once a device has been compromised.

“Therefore, it is more critical than ever to have a permanent digital connection to every endpoint, as well as the ability to lock, freeze or wipe the device if it is at risk of being compromised.”

There have been numerous examples of device loss in the UK government in recent years. Last year, for instance, it was reported that over 2000 mobile devices used by UK government employees went missing in the space of a year, a significant number of which were unencrypted.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Firms Urged to Patch as Attackers Exploit Critical F5 Bugs

Firms Urged to Patch as Attackers Exploit Critical F5 Bugs

Security experts are urging F5 customers to patch a critical vulnerability in the vendor’s BIG-IP and BIG-IQ networking products after warning of mass exploitation attempts in the wild.

CVE-2021-22986 is a flaw in the products’ REST-based iControl management interface which could allow for authentication bypass and remote code execution.

With a CVSS rating of 9.8, it was patched on March 10 along with several other bugs that could be chained in attacks. These are: CVE-2021-22987, CVE-2021-22988, CVE-2021-22989 and CVE-2021-22990.

Although no public exploit was known about at the time of patching, a week later researchers began to post PoC code online after reverse engineering an F5 patch.

NCC Group warned on Friday that as the REST API in question is designed to facilitate remote administration, an attacker could choose from multiple endpoints in an organization which ones to target.

“Starting this week and especially in the last 24 hours (March 18th, 2021) we have observed multiple exploitation attempts against our honeypot infrastructure. This knowledge, combined with having reproduced the full exploit-chain we assess that a public exploit is likely to be available in the public domain soon,” it said.

“NCC Group believes it is in the best interests of all to release our internal notes and detection logic to prevent further harm once public exploits become available.”

Networking firm F5 serves some of the world’s biggest organizations, including tech and financial services giants, so both state actors and financially motivated cyber-criminals will be keen to probe for unpatched endpoints.

The US Cybersecurity and Infrastructure Security Agency (CISA) has already sounded the alarm, urging customers to patch the issue promptly.

However, as we’ve seen with the recent Exchange Server attacks, many organizations are finding it challenging to fix or mitigate issues quickly, even if official updates are available.

Vdoo CTO, Asaf Karas, argued that the threat landscape for connected products has become complicated and multi-dimensional.

“Networking devices such as load balancers and access gateways are desirable targets for threat actors, as they’re used to control the traffic in and out of large corporate networks, government agencies, data centers and across ISP infrastructure,” he added.

“Once inside the network, attackers can move laterally to take control of critical resources and data.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FBI: State and Local Governments Losing Millions to BEC

FBI: State and Local Governments Losing Millions to BEC

The FBI has warned state and local government organizations to be on the lookout for business email compromise (BEC) scams after revealing that millions have already been lost during the past two years.

Losses from BEC campaigns ranged from $10,000 to $4m between November 2018 and September 2020, according to a new Private Industry Notification.

Attackers are targeting state, local, tribal and territorial (SLTT) government entities, masquerading as vendors and suppliers. They use phishing attacks to hijack email accounts at these companies and send urgent fake invoices to their government clients.

The ready availability of dark web phishing kits and information on government contractors, combined with poor security awareness among government employees, is making their job easier, according to the FBI.

“The substantial amount of publicly available SLTT government operating information required by government transparency requirements enables cyber-criminals to acquire information on SLTT leadership, vendor relationships and associated contractors, allowing them to tailor attacks directly to victims,” the notification revealed.

“Cyber-criminals may also determine those SLTT entities with inadequate cybersecurity protocols, such as a lack of personnel training, that they can compromise with the least amount of effort. Phishing kits — which bundle phishing tools and resources into user-friendly software — are increasingly available for purchase on the dark web, enabling even inexperienced cyber-criminals with minimal technical skills to conduct more sophisticated attack.”

The chances of success have also risen during the pandemic, with remote government workers potentially even more likely to click through on phishing links. An SLTT assessment last year by the Cybersecurity and Infrastructure Security Agency (CISA) revealed a click rate of nearly 14%.

BEC costs organizations nearly $1.9bn in total last year, up 5% from 2019 figures.

The FBI urged SLTT entities to improve education and awareness training, verify all payment changes in person or via a known telephone number, prevent automatic email forwarding, require multi-factor authentication and more.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Musk Denies Tesla Security Claims After Chinese Military Ban

Musk Denies Tesla Security Claims After Chinese Military Ban

Elon Musk has hit out at claims that Tesla vehicles are a security risk, after the Chinese military reportedly banned them from its facilities.

The tech billionaire and founder of the electric car company told attendees at a Beijing conference held by the government that it would be game over for his firm if such allegations were true.

“There’s a very strong incentive for us to be very confidential with any information,” Musk said during a virtual discussion attended by Reuters on Saturday. “If Tesla used cars to spy in China or anywhere, we will get shut down.”

The remarks to high-level business attendees of the China Development Forum came after sources told the newswire on Friday that the country’s military had banned Tesla vehicles over concerns about the cameras installed in them.

It’s unclear whether the move was made for partly commercial reasons. Tesla is said to have sold nearly a third of its vehicles last year to Chinese customers, but faces increasingly close competition from local rivals like Nio and Geely.

The firm also makes cars in China and must therefore tread carefully in order not to displease the authorities.

However, Tesla has had its cybersecurity and privacy problems in the past. Back in 2018 hackers managed to breach the firm’s public cloud environment to steal non-public data and install cryptomining malware.

Then last year, researchers discovered old car parts being sold on eBay but still containing user data belonging to the previous owner. Information including home and work address, saved Wi-Fi passwords, calendar entries, call lists and address books from paired phones were leaked in a sign of problems with Tesla’s retrofitting service.

In January last year an individual shared allegedly stolen designs for new vehicle hardware on Twitter.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk