Encrypted Comms Firm Denies Police Cracked User Messages

Encrypted Comms Firm Denies Police Cracked User Messages

Encrypted communications platform Sky ECC has denied Europol claims that police have managed to access messages sent by criminals using the service.

On Wednesday, the law enforcement organization claimed that police had been able to monitor the encrypted chats of 70,000 Sky ECC users, many of them having migrated from the notorious EncroChat platform used by organized crime gangs.

It said investigators in Belgium, France and the Netherlands now had access to hundreds of millions of messages which will help them disrupt over 100 planned criminal operations in EU member states and beyond.

Europol said Sky ECC has around 170,000 users and is operated from the US and Canada using servers based in Europe.

However, Sky ECC released a statement yesterday effectively branding this fake news and claiming that it has a zero-tolerance policy on criminal use of its service.

Although the firm experienced a temporary interruption in connection to its servers on Monday, it said the fault had now been corrected and it had not been contacted at any stage by law enforcement.

However, the firm did posit another theory as to how police managed to access criminals’ communications.

“Sky ECC authorized distributors in Belgium and the Netherlands brought to our attention that a fake phishing application falsely branded as Sky ECC was illegally created, modified and side-loaded onto unsecure devices, and security features of authorized Sky ECC phones were eliminated in these bogus devices which were then sold through unauthorized channels,” it said.

“Sky ECC did not authorize or cooperate with the investigative authorities or those involved with the distribution of the fake phishing application. These actions are malicious and Sky ECC is actively investigating and pursuing legal action against the offending individuals for impersonation, false lights, trademark infringement, injurious falsehood, defamation and fraud.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Molson Coors Suffers Suspected Ransomware Attack

Molson Coors Suffers Suspected Ransomware Attack

Beverage giant Molson Coors has released details of what appears to be a ransomware incident.

The firm, known for big-name brands such as Coors, Miller Lite and Foster’s, revealed the attack in a filing with the Securities and Exchange Commission (SEC) yesterday.

It claimed the firm had experienced a “systems outage caused by a cybersecurity incident” which it was in the process of managing.

“The company has engaged leading forensic information technology firms and legal counsel to assist the company’s investigation into the incident and the company is working around the clock to get its systems back up as quickly as possible,” it said.

“Although the company is actively managing this cybersecurity incident, it has caused and may continue to cause a delay or disruption to parts of the company’s business, including its brewery operations, production and shipments.”

Although the filing is light on detail, a systems outage, delays and disruption would seem to indicate the presence of ransomware.

With revenue of over $10bn in 2019, the firm would certainly seem to represent a lucrative target for such attacks.

Edgard Capdevielle, CEO at Nozomi Networks, noted that such “big game hunting” attacks are increasingly popular.

“Ransomware threat actors typically rely on spear-phishing links or vulnerable public services to gain initial entry into a network. Afterward, they move laterally to gain access to as many nodes of the network as possible, allowing them to increase the magnitude of the disruption,” he continued.

“Cybersecurity best practices such as strong segmentation, user training, proactive cyber-hygiene programs, multi-factor authentication and the use of continuously updated threat intelligence, should be used to protect IT and operational environments from ransomware and other cyber-attacks.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

“Hacker Games” Launched to Encourage Development of Secure Coding Skills

“Hacker Games” Launched to Encourage Development of Secure Coding Skills

App security testing firm Veracode has launched its inaugural Veracode Hacker Games, an event which aims to encourage the growth of secure coding skills.

Taking place over two weeks from March 15-25 2021, computer science and cybersecurity teams from eight leading universities in the UK and US will be tested on their secure coding skills in a collegiate contest. A number of individual prizes will be on offer and Veracode will donate $10,000 and $5000 for the first and second best performing universities, respectively. Additionally, all participating institutions will be given complimentary Veracode software for a year.

The participants will use Veracode Security Labs to gamify the experience, and will be tasked with discovering and fixing dangerous security flaws in real-world applications during a series of hands-on challenges.

The initiative, which is supported by the UK government, comes as cyber-attacks on organizations are increasing in prevalence and sophistication. For instance, Veracode highlighted a recent study by the University of Maryland showing that hackers are launching attacks every 39 seconds on average. Despite this, there remains a large skills gap in the cybersecurity sector and the situation does not appear to be improving, with just 3% of US bachelor’s degree graduates having cybersecurity-related skills, according to the National Center for Education Statistics.

Chris Wysopal, founder and chief technology officer at Veracode, said: “With mounting pressure on developers to deliver software that is secure and keeps society safe from harmful cyber-attacks, gaining foundational security knowledge translates to fewer exploitable problems during production and after deployment.

“Yet, training around secure coding is almost absent at the university level. We’ve launched the Veracode Hacker Games to help universities make secure coding a core part of their computer science and cybersecurity curriculum, while giving students an edge when it comes to putting their skills to the test in a real-world environment.”

Commenting on the announcement, UK Digital Infrastructure Minister, Matt Warman, outlined: “It has been another record year for investment in UK cybersecurity and we are working closely with the National Cyber Security Center (NCSC) and others to make sure this continues as we develop the next generation of digital defenders. Veracode’s first ever Hacker Games will be instilling in university students the latest and most innovative methods in coding for software security which will help to boost their career prospects. I wish all those participating the very best of luck in this fantastic competition.”

Institutions that have signed up to the contest include the University of Virginia, Tufts, and the University of Warwick. Further information about participants and the event itself can be found here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Friday Squid Blogging: On SQUIDS

A good tutorial:

But we can go beyond the polarization of electrons and really leverage the electron waviness. By interleaving thin layers of superconducting and normal materials, we can make the quantum electronic equivalents of transistors and diodes such as Superconducting Tunnel Junctions (SJTs) and Superconducting Quantum Interference Devices (affectionately known as SQUIDs). These devices take full advantage of the wave-like nature of electrons and can be used as building blocks for all sorts of novel electronics.

Because of the superconducting requirement, they need to be kept very cold, but quantum electronics have already revolutionized precision measurement. The most visible application has been in measuring the Cosmic Microwave Background (CMB). Observations of the CMB have shown that we live in an expanding Universe, determined the age of our Universe, and identified the fraction of it composed of dark matter and dark energy. Measurements of the CMB have transformed our understanding of the Universe we live in. These measurements have been largely enabled by SQUIDs and related superconducting electronics in their microwave cameras.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk