Dropbox to Make Password Manager Feature Free for All Users

Dropbox to Make Password Manager Feature Free for All Users

File hosting service Dropbox has announced that it will be making its password manager feature, Dropbox Passwords, available to all users free-of-charge.

From April, anyone with a basic, free Dropbox plan will be able to try a limited version of Dropbox Passwords, the company explained.

Originally launched last year for its paid plans only, Dropbox Passwords aids users in securely managing and storing passwords and signing into websites.

Now, with Passwords in Dropbox Basic, non-paying users will also be able to take advantage of a selection of password management benefits, including the ability to:

  • Store 50 passwords in one secure place
  • Access passwords anywhere with automatic syncing on up to three devices
  • Securely share passwords with others (to be made available post the initial April launch)

Speaking to Infosecurity about the announcement, Joseph Carson, chief security scientist and advisory CISO at Thycotic, said: “The latest news from Dropbox is a major reminder of how important managing and securing passwords is and that it is a top priority to ensure more people are using password managers.”

He pointed out, however, that it is also important that organizations go beyond just password managers as they still require employees to manage them and organizations must move to securing privileged access and helping move passwords into the background.

“The move by Dropbox is a positive one; however, it would be better if it also required MFA by default to add more protection.”

Tim Wade, technical director, CTO team at Vectra concurred, adding: “At the end of the day, using a password manager is not without some risk, but generally that risk will be less than folks attempting to do it the hard way. Most folks will just be safer, and more secure using a password manager.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

50% of Incident Response Pros Want Better Work-Life Balance

50% of Incident Response Pros Want Better Work-Life Balance

Half of cybersecurity incident response professionals desire a better work-life balance from their role, according to recruitment firm Stott and May.

The survey of 100 incident response professionals in the UK and US sought to determine the key factors that personnel in this area look for in a prospective employer.

It found that close to a third (29%) of respondents saw the quality and calibre of potential new team members as the number one factor that makes an organization stand out. In terms of the hiring process, consistent communication and feedback was cited as the most important element in keeping candidates engaged in the hiring process.

When deciding whether to accept a job offer, the respondents highlighted salary (37%) and potential for career growth (27%) as the most important considerations.

The study also showed that challenge of the day-to-day role and responsibilities are the most important factors for incident response professionals to stay in their job (17%). This was followed by team chemistry (14%).

Technical skills, adaptability and a strong focus on personal development were the most essential qualities required to succeed in this role, according to those surveyed.

Andrew Gee, chief revenue officer at Stott and May, commented: “The incident response talent market is a highly competitive one. That is evident with 66% of the candidate sample getting approached at least once a week regarding a new role. Companies are therefore in a constant battle to ensure their employee value proposition stands out, whilst consistently optimizing their hiring process to maintain candidate engagement.

“Work-life balance is also key when it comes to retaining the best incident response talent, putting the onus on employers to manage against employee burnout in the backdrop of ever-increasing demands on the function.”

The three most attractive employers in the incident response space were ranked as Crowdstrike, Crypsis and FireEye, according to the survey.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

SEC Charges Man Over Cannabis Firm Pump-and-Dump

SEC Charges Man Over Cannabis Firm Pump-and-Dump

A Californian man has been charged by a US regulator for tweeting false information to his followers in a secret bid to inflate the value of his shares in a defunct cannabis company.

The Securities and Exchange Commission (SEC) this week announced fraud charges and an asset freeze against Irvine-based Andrew Fassari.

He’s alleged to have bought over 41 million shares in Nevada-based Arcis Resources Corporation (ARCS), before tweeting lies to his thousands of followers that the firm was reviving its operations and expanding its business, backed by “huge” investors.

Using the Twitter handle @OCMillionaire, Fassari is said to have made 120 tweets in December 2020 referencing “$ARCS,” dozens of which were labelled “misleading” by the SEC.

In one, he claimed that “this CEO has big plans for us,” and in another he apparently crowed about the firm’s “380,000 indoor cultivation 1 Million+ sq ft processing,” according to the SEC.

“The complaint further alleges that, over the next several days, ARCS’s share price skyrocketed, ultimately increasing over 4000%,” it noted.

“The complaint also alleges that Fassari made false statements about his own trading in ARCS. Between December 10 and 16 2020, Fassari allegedly sold all his shares in ARCS for profits of over $929,000, all while continuing to publish false and misleading information about ARCS and his trading in ARCS.”

The regulator’s complaint charges Fassari with violating the anti-fraud provisions of federal securities laws, and seeks a permanent injunction, disgorgement, prejudgment interest and a civil penalty from him.

The SEC also secured an order earlier this month temporarily suspending trading in ARCS securities.

This kind of “pump-and-dump” scam has become increasingly common of late thanks to the proliferation of social media and the ease with which investors can trade in securities today.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Chinese Threat Actors Target Global 5G Operators

Chinese Threat Actors Target Global 5G Operators

Security researchers have discovered a new cyber-espionage campaign targeting global telecoms operators for IP and information relating to 5G.

Named Operation Diànxùn by McAfee, the campaign is likely to be the work of Chinese threat actors RedDelta and Mustang Panda.

“While the initial vector for the infection is not entirely clear, the McAfee ATR team believes with a medium level of confidence that victims were lured to a domain under control of the threat actor, from which they were infected with malware which the threat actor leveraged to perform additional discovery and data collection,” explained McAfee regional solutions architect, Andrea Rossini.

“It is our belief that the attackers used a phishing website masquerading as the Huawei company career page.”

After visiting the fake Huawei phishing page, a victim would unwittingly download malware masquerading as Adobe Flash, which acts as a dropper for a .NET payload. This in turn acts as a tool “to manage and download backdoors to the machine and configure persistence,” Rossini explained.

The final stage of the attack involves creating a backdoor for full remote control of the victim’s system, using Cobalt Strike Beacon and a command-and-control (C&C) server.

The threat actors are thought to have been targeting mobile operators since last summer, in APAC, North America and Europe.

“To defeat targeted threat campaigns like Operation Dianxun, defenders must build an adaptive and integrated security architecture which will make it harder for threat actors to succeed and increase resilience in the business,” concluded Rossini.

In July last year, RedDelta attackers were detected inside the Vatican’s IT network in the run-up to a meeting between the Catholic Church and Beijing focusing on the religion’s status in China.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

More Than a Quarter of Threats Never Seen Before

More Than a Quarter of Threats Never Seen Before

Over a quarter (29%) of threats spotted in Q4 2020 had never before been detected in-the-wild, giving attackers an advantage over their victims, according to HP Inc.

The tech giant’s latest Quarterly Threat Insights Report was compiled from data gathered from its global customers’ Sure Click virtual machines from October to December 2020.

While these isolated micro-VMs effectively segment malware from the endpoint and let it execute harmlessly, the widespread use of packers and obfuscation techniques would help malicious code bypass traditional detection-based filters, HP claimed.

Some 88% of threats were delivered via email, and it took nearly nine days on average for AV engines to recognize their hash. Fake invoice attachments were the most common lure.

Trojans accounted for 66% of malware in the period, driven by spam campaigns delivering banking malware Dridex.

Malicious executables surged by 12%, with CVE-2017-11882 accounting for nearly three-quarters of detections. Another legacy bug, CVE-2017-0199, accounted for a 12% growth in malware designed to run malicious scripts when a victim opens an Office document.

The two findings are a reminder that, despite the current focus on attacks exploiting zero-day vulnerabilities, many campaigns look to capitalize on the fact that organizations often overlook flaws left unpatched from years ago.

Other trends spotted by HP include email thread-hijacking designed to distribute Emotet in government organizations in Central America, the return of the ZLoader banking Trojan and a new Office malware builder (APOMacroSploit) used to craft delivery themed spam campaigns to distribute BitRAT malware.

“Opportunistic cybercrime does not show any signs of slowing. Low-cost malware-as-a-service kits are an attractive prospect to cyber-criminals and we have seen these continue to proliferate in underground forums. Kits like APOMacroSploit, which emerged in Q4 2020, can be bought for as little as $50 USD,” said Alex Holland, senior malware analyst at HP Inc.

“We have also seen threat actors continue to experiment with malware delivery techniques to improve their chances of establishing footholds into networks. The most effective execution techniques we saw in Q4 2020 involved old technologies like Excel 4.0 macros that often offer little visibility to detection tools.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk