Metadata Left in Security Agency PDFs

Really interesting research:

“Exploitation and Sanitization of Hidden Data in PDF Files”

Abstract: Organizations publish and share more and more electronic documents like PDF files. Unfortunately, most organizations are unaware that these documents can compromise sensitive information like authors names, details on the information system and architecture. All these information can be exploited easily by attackers to footprint and later attack an organization. In this paper, we analyze hidden data found in the PDF files published by an organization. We gathered a corpus of 39664 PDF files published by 75 security agencies from 47 countries. We have been able to measure the quality and quantity of information exposed in these PDF files. It can be effectively used to find weak links in an organization: employees who are running outdated software. We have also measured the adoption of PDF files sanitization by security agencies. We identified only 7 security agencies which sanitize few of their PDF files before publishing. Unfortunately, we were still able to find sensitive information within 65% of these sanitized PDF files. Some agencies are using weak sanitization techniques: it requires to remove all the hidden sensitive information from the file and not just to remove the data at the surface. Security agencies need to change their sanitization methods.

Short summary: no one is doing great.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

School Boss Resigns After Porn Found on Computer

School Boss Resigns After Porn Found on Computer

An Arizona county school superintendent has resigned following the discovery of pornographic material on his work-issued computer, according to records obtained by The Associated Press.

Coconino County announced the resignation of 67-year-old Tommy Lewis Jr. at the end of January 2021. At the time, the county said that Lewis was stepping down for personal reasons. 

However, when questioned by the AP, a county spokesperson later confirmed that Lewis was under investigation for potential criminal activity.

Lewis’ proclivity for porn was discovered during a random internal security scan run by the county’s IT department. County software blocked over 100 attempts to access sexually explicit websites in the weeks that followed Lewis’ election to the position of county superintendent.

US News reports that pornographic material, including images of potentially underage females, was found by the county on Lewis’ computer.

Department Director Matt Fowler notified other county officials and law enforcement after the discovery of what he described as “questionable” content.

While Lewis was found to be in violation of county policy for using his work device to store and access pornographic content, an investigation into the material he was viewing by the Yavapai County Sheriff’s Office did not result in any charges being brought. 

None of the material involved the exploitation of children; however, one image prompted the detectives to contact the police department in Albuquerque, New Mexico. 

The image flagged by police was found on a flash drive that Lewis had left plugged into his computer. It depicts a woman’s intimate area in what appears to be an upskirt, a non-consensual photograph taken under a skirt.

Lewis, who has worked among tribal communities in a career that has spanned decades, said publicly that he is not a criminal. 

“I am very sorry and shameful,” Lewis wrote to the Coconino County Board of Supervisors and the then-county manager in an email dated January 21. 

“Thank you for giving me an opportunity to work with you. I wish you the best.” 

A week after sending the email, Lewis sent a text message to the county’s human resources manager requesting that the flash drive containing pornographic images be returned to him. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Another 210,000 Americans Affected by Netgain Ransomware Attack

Another 210,000 Americans Affected by Netgain Ransomware Attack

The number of Americans affected by a cyber-attack on a cloud hosting and IT services provider has increased by 210,000.

Netgain Technologies LLC, in St. Cloud, Minnesota, was forced to take some of its data centers offline after falling victim to a ransomware attack on November 23 last year. A few days after the attack, customers were emailed warnings that system outages or slowdowns may occur. 

The company provides services to several organizations in the healthcare and accounting industries, including Woodcreek Provider Service, a medical-practice management company in Washington state that provides support to pediatric clinics and urgent care centers owned and operated by MultiCare Health System.

On December 3, Netgain notified Woodcreek that the protected health information of patients was stored on servers affected by the cyber-attack and may have been accessed by threat actors. Other data that may have been compromised included the personal information of Woodcreek employees, healthcare providers, applicants, contractors, and individuals receiving services delivered by MultiCare Health Systems and/or Woodcreek Provider Service. 

According to a statement released March 9 by Woodcreek: “The information included names and addresses, medical record numbers, dates of birth, social security numbers, health insurance policy and identification numbers, insurance claims, explanation of benefits, statements, clinical notes, referral requests, laboratory reports, decision not to vaccinate forms, authorization requests for services, treatment approvals, records requests, immunization information, vaccine records, prescription requests, release of information forms, subpoena records requests, medical record disclosure logs, incident reports, invoices, correspondence with patients, student identification numbers, bank account numbers, employment related documents, court documents, Drug Enforcement Agency certificates, payroll withholding and insurance deduction authorizations, benefit and tax forms, employee health information and some medical records.”

Confirmation of what data was involved in the attack was only received by Woodcreek on January 18, 2021. The company is now taking steps to notify affected individuals in writing.

Woodcreek said that since the incident took place, it has enhanced cybersecurity protocols and practices to improve the security of the data in its care. The company said it had received written assurances from Netgain that the IT services provider has added security enhancements within its network to proactively defend against future threats.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Trans Tracking Plugin Reported to Norwegian Authorities

Trans Tracking Plugin Reported to Norwegian Authorities

A plugin that flags social network pages and users as transphobic or trans-friendly has been reported to Norwegian authorities over concerns that it is in violation of data protection laws.

Shinigami Eyes uses a color-coding system to denote the attitude of a site or a user toward the trans community. The extension turns green to denote a trans-friendly site or user and red when that site or user is considered anti-trans. 

A mix of manual labeling, user contributions, and machine learning is used to decide whether a site is phobic or friendly.

In the gaming world, Shinigami Eyeballs or Eyes of the Shinigami are eyes that can see both the names and the lifespans of humans floating above their heads.

Nonprofit civil liberties organization Electronic Frontier Norway (EFN) asked the Norwegian Data Protection Authority to investigate the legality of the plugin after hearing radio host Hilde Sandvik express concerns about it on the program Norsken, Svensken og Dansken.

After downloading and analyzing the plugin’s source code from GitHub, EFN found that the classification of people and organizations into friendly or phobic is uploaded to a server based in the US and hosted by Amazon.

“EFN finds that the use of the program and the operation of the database it uses likely constitutes multiple violations of the GDPR and its Norwegian implementation,” said a spokesperson for EFN.

“The most egregious of these being the clear violation of Article 9 which prohibits the registrations of people’s political views, philosophical convictions and physical persons’ sexual relations or sexual orientations etc.”

EFN warned that the app could put people in danger by marking them as trans-friendly or transphobic without their knowledge or consent. 

“The software can be used to identify targets for online harassment, doxing, cyberstalking and even physical attacks,” said the NGO. 

EFN also expressed concerns over the opacity of the plugin’s governance process for databases containing personal data. 

“It is unknown who operates the service, what the editorial process constitutes, who to contact to get copies of the data stored about oneself, and protocols and procedures for demanding being left out of the database entirely.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Sumo Logic Agrees Deal to Acquire DFLabs

Sumo Logic Agrees Deal to Acquire DFLabs

Security event management company Sumo Logic has announced it has reached an agreement to acquire DF Labs S.p.A.

The deal will allow Sumo Logic to incorporate DFLabs’ security orchestration, automation and response (SOAR) software into its cloud-native SIEM solution.

Sumo Logic said these new capabilities are especially important amid the rapid digital transformation taking place across organizations since the start of the COVID-19 pandemic. This includes increased cloud adoption and the shift to remote working. DFLabs’ SOAR software is designed to enable security operations centers to effectively automate and manage security operations and incident response processes from a single platform.

This will form part of Sumo Logic’s overall Continuous Intelligence Platform, which provides security intelligence across multi-cloud and hybrid infrastructures.

Expected to be available shortly after the transaction is closed, Sumo Logic aims for the SOAR software to link upstream emerging DevSecOps models with downstream SOC workflows.

Once the deal is completed, the entire DFLabs team will join Sumo Logic’s security business unit. Additionally, it’s Milan office will add to Sumo’s portfolio of corporate buildings.

Greg Martin, vice-president and general manager of Sumo Logic’s Security Business Unit, commented: “Security in the modern world is moving from a human-scale problem to a machine-scale problem. Customers are looking for a new approach to help them overcome the pain and complexity around an increasingly perimeter-less world. The DFLabs team are experts in helping customers navigate this new world. By aligning our cybersecurity expertise, customer validated and leading security portfolios, we believe we will be able to address the critical challenges our customers face as they navigate this changing threat landscape.”

Dario Forte, CEO of DFLabs, said: “Joining Sumo Logic will be an exciting next step for all of us, as the value we believe we can provide together is very clearly understood. Best in class security operations solutions require broad functionality and deep integration to effectively address the modern threat environment, and when combined, the expanded Sumo Logic Cloud SIEM will provide best in class analytics and automation out of the box.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ajay Sabhlok Appointed Rubrik’s First Joint CIO and CDO

Ajay Sabhlok Appointed Rubrik’s First Joint CIO and CDO

Cloud data management company Rubrik has announced the appointment of Ajay Sabhlok to the dual role of Chief Information Officer (CIO) and Chief Data Officer (CDO).

Sabhlok has more than 10 years of experience in the technology industry and first joined Rubrik as VP and head of IT enterprise business applications in 2018, developing its IT applications and architecture functions.

Prior to that, he oversaw various IT application portfolios at VMware including business intelligence, advanced analytics and master data management.

In his new combined role, Sabhlok will oversee comprehensive IT, data and advanced analytics strategies. It is the first time that Rubrik has had a joint CIO and CDO position.

“IT environments are only increasing in complexity, and as data continues to grow exponentially, so does the need to protect this data. Following a highly successful tenure as VP of IT, Ajay is in the perfect position to deliver immediate impact in his new role as CIO and CDO,” said Kiran Choudary, Rubrik CFO.

“His experience in technology and applications makes him an ideal leader for our next stage of growth and development. As our enterprise sector continues to grow, Ajay will play a critical role in our expansion moving forward.”

Commenting on his appointment, Sabhlok explained that today, more than ever, leading businesses are hungry to create meaningful business value from their data.

“This new role presents the perfect opportunity for Rubrik to continue to deliver on its promise to enable enterprises to maximize value from their data in increasingly complex and fragmented environments across data centers and clouds. I’m thrilled to lead our IT and analytics strategies for Rubrik and unlock new insights and possibilities for our valued customers.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Third of Office Workers Warned After Sharing Data Via Unofficial Apps

Third of Office Workers Warned After Sharing Data Via Unofficial Apps

Almost a third (30%) of global office workers have been admonished by their bosses after sending sensitive business and personal information via non-approved online channels, according to Veritas Technologies.

The data protection vendor polled 12,500 white collar workers in Europe, the Middle East, APAC and the US to better understand the risks they’re taking during lockdown.

The vast majority admitted to sharing business-critical data (71%) and sensitive personal information (75%) via IM or online collaboration apps like Teams and Zoom.

This includes corporate passwords and card details, client details and business plans, banking and salary information, and even COVID-19 test results and medical details.

In the UK, just a fifth (23%) said they’d been reprimanded by their boss and half (51%) admitted sharing sensitive info via collaboration apps. Many more workers have been warned about inappropriate data sharing in the US (39%) and South Korea (40%), while in China 80% admitted sharing details via IM.

The problem isn’t necessarily that these platforms aren’t secure – many of them now support end-to-end encryption. It’s that if they are not approved by IT, then organizations could run into compliance issues.

“There are two major challenges with this type of information sharing. Firstly, some of it should never be shared with anyone – no one should be sharing their PIN, for example,” argued Veritas GM of digital compliance, Ajay Bhatia.

“Secondly, some of it should only be shared in the right way. Business information that’s shared without leaving a permanent record can cause legal and compliance issues for companies. The same can be true for personal information if it becomes something that you later need for tax or medical reasons, or, worse, if the person you’re chatting with turns out to be scamming you.”

Unfortunately, 79% of global respondents said they’d still share sensitive business information again in the same way in the future.

“Our message to bosses is simple: don’t fight it – fix it. If a third of all employees have already been reprimanded without behaviors changing, a new approach is required,” Bhatia concluded. 

“Embracing messaging apps and business collaboration tools fully into data management and protection strategies means that organizations can take back control of the data and ensure that they’re compliant and protected.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Record Number of Cyber-Incidents Hit US Schools in 2020

Record Number of Cyber-Incidents Hit US Schools in 2020

Publicly disclosed cybersecurity incidents at US schools surged 18% over the past year to hit a record number of breaches, ransomware outbreaks and more, according to a new report.

Non-profit the K12 Security Information Exchange claimed there were 408 such incidents in 2020, which equates to more than two per school day.

The largest number (45%) were recorded as unattributed malware, class and meeting invasions, email invasion, website and social media defacement, and a large number of “related and/or low-frequency incidents.”

However, over a third (36%) were data breach incidents, 12% were ransomware-related and the rest were recorded as DDoS (5%) or phishing (2%).

The report claimed that a rapid shift to remote learning was to blame for much of this extra cyber-risk. New insecure devices were deployed rapidly to students, teachers had little training and were allowed to use unvetted free apps and services, and IT staff were often unable to physically update and configure devices, it noted.

Worse, many remote learning devices may have been reintroduced to school networks for districts that returned in autumn without proper security vetting.

The non-profit argued that policymakers and school leaders have historically ignored matters of cybersecurity.

“Notwithstanding the heroic education IT-related efforts to ensure remote learning was possible for large numbers of elementary and secondary students and their teachers during 2020, it should hardly be surprising that school district responses to the COVID-19 pandemic also revealed significant gaps and critical failures in the resiliency and security of the K-12 educational technology ecosystem,” it argued.

“Indeed, the 2020 calendar year saw a record-breaking number of publicly-disclosed school cyber-incidents. Moreover, many of these incidents were significant: resulting in school closures, millions of dollars of stolen taxpayer dollars and student data breaches directly linked to identity theft and credit fraud.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware “Paralyzes” Spanish Employment Agency

Ransomware “Paralyzes” Spanish Employment Agency

The Spanish employment agency has been struck by a major ransomware attack, knocking out hundreds of offices around the country at a time when the pandemic had already put tremendous strain on the department.

A note on the website of SEPE explained that a “security incident” had affected the availability of its ITC systems and that work had been carried out to isolate and mitigate its impact.

“Currently, work is being done with the objective of restoring priority services as soon as possible, among which is the portal of the State Public Employment Service and then gradually other services to citizens, companies, benefit and employment offices,” it said.

SEPE confirmed that the attack would not affect access to unemployment benefits, but it has extended the deadline for applicants for as long as the service is down.

Although the payroll system is said not to be affected, face-to-face appointments have had to be cancelled around the country, as the attack has knocked out workstations in 710 SEPE offices and the laptops of remote workers, according to trade union CSIF. It claimed the agency had been “paralyzed” by the attack.

“This situation has caused a delay in the management of hundreds of thousands of appointments throughout Spain, which will add to the workload of subsequent days, with the difficulties that all this entails in the face of the avalanche of files that SEPE has been facing since the start of the pandemic,” it argued.

“We have been asking for decisive support in technological investment for months, since computer applications and systems have an average age of about 30 years.”

SEPE workers are currently being forced to process requests manually and take contact details down in case follow-ups are needed.

Nominet government cybersecurity expert, Steve Forbes, argued that a new approach is needed to secure public sector infrastructure.

“Often these organizations are relatively small and under-resourced,” he added. “We must pull together to ensure they can benefit from intelligence and resilience built into an overarching strategy for cyber defense.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk