Huge Rise in Hackers Submitting Vulnerabilities During #COVID19

Huge Rise in Hackers Submitting Vulnerabilities During #COVID19

The number of hackers submitting vulnerabilities went up by 63% in 2020, according to HackerOne’s 2021 Hacker Report.

The bug bounty platform noted that hackers ramped up their workload in response to the digital shift during COVID-19, with 38% of those surveyed stating they have spent more time hacking since the start of the pandemic.

There was also an increased focus on emerging threats last year. This includes security weaknesses linked to cloud adoption, with misconfiguration vulnerabilities rising by 310%, while submissions for both improper access control and privilege escalation went up by 53%.

Additionally, hackers increasingly targeted different types of technologies in 2020. This included a 694% growth in hackers saying they spend time hacking APIs, a 663% rise in those hacking Android and a 1000% increase in hackers focusing on IoT compared to 2019.

Interestingly, half of the hackers surveyed revealed they have not disclosed a bug they found, with lack of a clear reporting focus (27%), previous negative experiences with the company in question (27%) and no bounty being offered (19%) cited as the main factors in this decision.

HackerOne also asked hackers about their motivation, finding that money is not the only factor; for instance, 85% cited learning and 62% cited advancing their career.

Overall, the report said that hackers earned over $40m in bounties last year, which brings total hacker earnings to over $100m.

Jobert Abma, HackerOne co-founder, commented: “This year’s Hacker Report demonstrates the depth of vulnerability insights that hackers bring to a security program. We’re seeing huge growth in vulnerability submissions across all categories and an increase in hackers specializing across a wider variety of technologies. As we see slower growth in some common vulnerabilities that are easily found and fixed, we’re seeing hackers be more creative in their attempt to discover new attack vectors. Every time a hacker links several low severity vulnerabilities together to help a customer avoid a breach, or finds a unique bypass to a software patch, it proves that machines will never truly outpace humankind.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Veriff Appoints Duncan Steblyna as New VP of Product

Veriff Appoints Duncan Steblyna as New VP of Product

Duncan Steblyna has been appointed as the new VP of product at online identity verification company Veriff.

Steblyna brings more than 10 years of experience in product development and strategy to the role, having previously held leadership positions at OLX Markets and global internet group Naspers.

He will now lead Veriff’s product team through its next phase of rapid growth, meeting the rising demand from customers for reliable identity verification solutions.

“The growing concerns around identity theft in our increasingly digital world present a substantial opportunity for Veriff to scale its product offering,” he said. “Veriff is solving a very significant global issue as protecting personal identity is something that matters to everyone. I’m thrilled to join Veriff’s warm, welcoming and extremely motivated team to support its next generation of growth.”

In an interview published on Veriff’s website, Steblyna outlined what he sees as the biggest initial challenges of his new role.

“Veriff is going through a phase of rapid expansion, so a lot of the things that worked at a startup level now need to rapidly scale. This means setting up new guidelines and systems to support that growth to be able to serve many more customers.

“My first few months will involve understanding how things are working within the company and how we can avoid some of the issues that startups face in this phase. Veriff has grown considerably and many of the tools and methods that got us here will not work at scale. Every company solves this kind of problem in slightly different ways and I’m looking forward to exploring how we figure this out with the Veriff team.”

Veriff co-founder and CPO, Janer Gorohhov, added that Steblyna brings extensive expertise of building client-centric product teams during pivotal times where trusted identity is becoming a fundamental part of businesses online.

“We are fortunate to have an experienced leader who has helped organizations scale globally to join our mission. With Duncan on board, his leadership and experience will be an integral part of our operations as we steer Veriff through growth led by the increased global demand.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

10 Google Play Apps Found Containing Banking Malware

10 Google Play Apps Found Containing Banking Malware

Security researchers have discovered a malware dropper hidden inside 10 Google Play apps, which could have put users at risk of remote access and banking malware.

Check Point said it found the Clast82 dropper inside a variety of applications on the official marketplace, including VPNs, QR readers and music players.

Clast82 drops the malware-as-a-service AlienBot Banker, which is designed to circumvent two-factor authentication codes on banking apps to give attackers access to users’ accounts. It is also capable of loading a mobile remote access trojan (MRAT) capable of remotely controlling the victim’s phone with TeamViewer.

It’s designed to bypass Google Play Protect with two main tactics. The first is by using Google-owned Firebase for command-and-control (C&C) communications. The threat actor also disabled the dropper’s malicious behavior as it was being evaluated by Google, according to Check Point.

Second, it downloads the payload from GitHub, creating a new developer user for Google Play for each application, alongside a repository on their GitHub account. This enabled the attacker to distribute different payloads to devices infected by each malicious version of the app.

Aviran Hazum, manager of mobile research at Check Point, branded the tactics “creative, but concerning” in their apparent simplicity.

“The victims thought they were downloading an innocuous utility app from the official Android market, but what they were really getting was a dangerous Trojan coming straight for their financial accounts,” he added.

“The dropper’s ability to remain undetected demonstrates the importance of why users should install a mobile security solution on their device. It is not enough to just scan the app during the evaluation period, as a malicious actor can, and will, change the application’s behavior using readily available third-party tools.”

After reporting its findings to Google on January 28 2021, Check Point saw that all Clast82 apps were removed from Google Play on February 9.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DARPA Ramps-Up FHE Encryption Project with Intel

DARPA Ramps-Up FHE Encryption Project with Intel

The US Defense Advanced Research Projects Agency (DARPA) has announced four new research teams including one led by Intel that will try to make Full Homomorphic Encryption (FHE) a practical reality.

FHE has long been an aspiration for encryption experts: enabling computation, analysis and other uses of encrypted information without actually needing to decrypt it. This would help to strike a better balance between being able to use sensitive data to its fullest extent and minimizing the risk of exposure, DARPA says.

The problem up until now has been the computing power and time required to achieve this.

“A computation that would take a millisecond to complete on a standard laptop would take weeks to compute on a conventional server running FHE today,” argued DARPA program manager, Tom Rondeau.

To speed-up this processing time from weeks to seconds or milliseconds, DARPA is hoping to build a hardware accelerator as part of its Data Protection in Virtual Environments (DPRIVE) program, which would in theory offer major advances over software-based approaches.

The research teams announced by DARPA yesterday are Intel’s government-focused subsidiary Intel Federal, Duality Technologies, Galois and non-profit SRI International.

The job of each is to create an FHE accelerator hardware and software stack designed to process FHE calculations at a similar speed to unencrypted data operations.

In so doing, they will explore the use of CPUs with different sizes of “words” –  the units of data that determine a processor’s design. They’ll try everything from the 64-bit words used in modern processor designs to 1000 bits.

They’ll also be looking into “novel approaches to memory management, flexible data structures and programming models, and formal verification methods,” according to DARPA.

If they’re successful, it could have significant military and commercial applications.

“We currently estimate we are about a million-times slower to compute in the FHE world then we are in the plaintext world,” concluded Rondeau.

“The goal of DPRIVE is to bring FHE down to the computational speeds we see in plaintext. If we are able to achieve this goal while positioning the technology to scale, DPRIVE will have a significant impact on our ability to protect and preserve data and user privacy.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NCSC: Don’t Fall for Mother’s Day Scams This Week

NCSC: Don’t Fall for Mother’s Day Scams This Week

UK security experts have warned online shoppers to be aware of scams ahead of Mothering Sunday this weekend.

The National Cyber Security Center (NCSC), an offshoot of spy agency GCHQ, issued the notice yesterday, claiming that the mass shift to e-commerce during the pandemic has exposed more consumers to fraud.

It gave no specific details of current campaigns to look out for, although cyber-criminals will usually tailor their efforts according to current events.

Unsolicited emails and social media messages in the week before Mother’s Day may contain links designed to deploy malware or harvest credentials and personal information.

There’s also an increased risk of sites luring users to enter their card details with massive discounts on non-existent flowers, chocolates and other popular items.

“Cyber-criminals are opportunistic and always ready to exploit peak online shopping moments, and unfortunately, family occasions like Mother’s Day are no different,” warned NCSC deputy director for economy and society, Sarah Lyons.

“We want everyone to shop with confidence and peace of mind this Mother’s Day. The Cyber Aware website has advice on the six key behaviors that can be easily followed to protect yourself.”

These include: using strong, unique passwords and saving them to the browser, switching two-factor authentication on where possible, updating all devices and apps regularly and backing-up data.

Mothering Sunday is celebrated in the UK and Ireland on a different date to the US.

In related news, Europol yesterday announced the seizure of €16m worth of fake toys during the recent festive period, and the arrest of 11 individuals.

The operation to clamp down on counterfeit products resulted in nearly 5000 inspections, over 44,000 samples tested in labs and the opening of 125 judicial cases across the region.

Toy cars, board games and dolls from popular children’s TV shows were among the most seized items.

Although many were almost exact copies of the real thing, they were not subject to strict safety tests and did not feature warning labels. Europol argued that thousands of these items could be a choking hazard, contained toxic chemicals and/or exceeded safe decibel limits for children’s ears.

Such counterfeits are often made of popular items that are likely to sell-out in legitimate retail stores, driving parents online to hunt them down for their children.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Dark Web Markets for Stolen Data See Banner Sales

Despite an explosion in the sheer amount of stolen data available on the Dark Web, the value of personal information is holding steady, according to the 2021 Dark Web price index from Privacy Affairs. That leaves these thriving dirty data dealers in a familiar predicament — they need to lock down their growing businesses for […]

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk