TiG Acquires ThirdSpace

TiG Acquires ThirdSpace

British tech company TiG Data Intelligence has successfully completed the acquisition of identity and security company ThirdSpace

ThirdSpace began life in 2002 as Oxford Computer Group UK. The company’s first ever client, University West of England, is still working with them today.

Operating as a specialist arm of TiG, ThirdSpace will retain its independent capability and expertise and its current management structure. 

“We are delighted to be realising one of ThirdSpace’s strategic goals in expanding our security capabilities with a full Managed Service Cloud offering,” said Neil Coughlan, CEO at ThirdSpace.

“With Microsoft as our combined platform of choice, and with our joint security and management proposition, ThirdSpace and TiG are uniquely positioned to give our clients the peace of mind that they remain in control.”

Coughlan will join the TiG board as chief strategy officer. ThirdSpace’s sales director, Nick Lamidey, will join the TiG board as chief sales officer.

Established in 2001, TiG is a multi-award-winning managed service provider and the largest UK-based specialist provider to the financial services sector. 

“We have a long-established and strong relationship with TiG,” stated ThirdSpace on March 4. “As a team, we know and trust them implicitly, and as an organization they share the same culture of supporting and developing great people to enable client success.”

By joining forces, TiG and ThirdSpace now have over 210 employees tasked with the mission of delivering security, data, and identity solutions. The group said its ambition is to become the UK’s leading advanced digital MSP.

Des Lekerman, CEO at TiG, said: “Over the years and with a number of strategic acquisitions, we have built a business that we are extremely proud of. This acquisition is transformational as we can now provide a deeper and broader set of services to our clients. There is huge demand in the market for an advanced digital MSP with a customer-centric flexible approach. The combined suite of services are a key differentiator in the market and a fantastic opportunity for all our people.”

The acquisition was completed with the financial backing of minority investor BGF.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

McAfee Agrees Deal to Sell Enterprise Business for $4bn

McAfee Agrees Deal to Sell Enterprise Business for $4bn

Security software giant McAfee has announced it has reached a deal to sell its enterprise business for an all cash fee of $4bn. The firm said it has entered a definitive agreement with a consortium led by Symphony Technology Group (STG), with the transaction expected to be completed by the end of 2021, subject to customary regulatory approvals and closing conditions.

Following completion, McAfee will become a consumer-only business, retaining its current name. However, its enterprise business, which serves 86% of Fortune 100 companies around the world, is expected to be rebranded in the coming months, although McAfee will continue operating it until the deal has closed.

The leader in device-to-cloud cybersecurity solutions also revealed it will use the proceeds of the transaction to pay off approximately $1bn of debt it currently has.

Peter Leav, McAfee president and chief executive officer, commented: “STG is the right partner to continue strengthening our enterprise business, and this outcome is a testament to the business’ industry-leading solutions and most notably to the outstanding contributions of our employees.

“This transaction will allow McAfee to singularly focus on our consumer business and to accelerate our strategy to be a leader in personal security for consumers.”

William Chisholm, managing partner at STG, said: “McAfee is one of the most iconic brands in enterprise security and has a reputation for innovation, quality and leadership.

“We are fully committed to driving the business’ strategy to be the leading device-to-cloud cybersecurity company by partnering with McAfee’s existing world class team to continue delivering exceptional performance to enterprises and government clients globally.”

The announcement has come on the same day that McAfee’s founder, John McAfee, was officially indicted on charges of cryptocurrency fraud, money laundering and more, which could see him behind bars for decades.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

McAfee Faces Decades Behind Bars After Fraud Indictment

McAfee Faces Decades Behind Bars After Fraud Indictment

Famed anti-virus pioneer John McAfee has been indicted on charges of cryptocurrency fraud, money laundering and more.

The 75-year-old, who is in Spain awaiting extradition to the US for tax evasion, is accused of conspiring with executive advisor Jimmy Watson and others on two fraud schemes running from December 2017-October 2018.

The first was a classic pump-and-dump in which the defendants allegedly bought large numbers of publicly traded altcoins, promoted them on Twitter without revealing their stake, and then sold them for a profit.

The Department of Justice (DoJ) claimed McAfee, Watson and the others made $2m from the scalping scheme.

In the second scheme, McAfee, Watson and others used McAfee’s official Twitter account to promote initial coin offerings (ICOs) without disclosing they were being paid by ICO issuers to do so.

This made them an estimated $11m which the defendants subsequently tried to conceal from investors. The duo are also alleged to have caused another member of the team to launder the money.

McAfee and Watson, 40, are charged in a seven-count indictment with one count of conspiracy to commit commodities and securities fraud, one count of conspiracy to commit securities and touting fraud, two counts of conspiracy to commit wire fraud and two counts of substantive wire fraud and one count of conspiracy to commit money laundering.

The charges could lead to maximum sentences of decades behind bars and financial penalties.

“As alleged, McAfee and Watson used social media to perpetrate an age-old pump-and-dump scheme that earned them nearly $2m. Additionally, they allegedly used the same social media platform to promote the sale of digital tokens on behalf of ICO issuers without disclosing to investors the compensation they were receiving to tout these securities on behalf of the ICO,” said FBI assistant director, William Sweeney.

“When engaging in illegal activity, simply finding new ways to carry out old tricks won’t produce different results. Investment fraud and money laundering schemes carry a strict penalty under federal law.”

McAfee was arrested in Spain last year. The SEC has also filed civil charges against McAfee and Watson relating to the case.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FTC Busts $110m Charity Fraud Operation

FTC Busts $110m Charity Fraud Operation

The Federal Trade Commission (FTC) has joined forces with nearly 40 US states to crack a major charity fraud operation that scammed victims out of more than $110m.

The regulator teamed up with 46 agencies from 38 states and Washington DC, most of them state attorneys general, to shut down the work of Associated Community Services (ACS), sister companies Central Processing Services and Community Services Appeal, and two other fund-raising spin-offs run by ACS managers, Directele, and The Dale Corporation.

The operation was driven by illegal robocalls, which comprised most of the 1.3 billion deceptive fundraising calls that were used to elicit donations from 67 million consumers.

ACS and related defendants have agreed to settle charges by the FTC and state agencies that they tricked Americans into donating to organizations which spent next to nothing on the charitable causes they claimed to support.

The FTC claimed that, in some cases, defendants kept as much as 90 cents in every dollar that they received from their donors.

The operation had been ongoing since at least 2008, and used worthy causes such as homeless veterans, victims of house fires, breast cancer patients and children with autism to encourage victims into parting with their money.

ACS and Directele are accused of knowingly breaking an FTC regulation that prohibits robocalls to first-time donors, and automated calls to prior donors made without an opt-out.

ACS is also accused of harassing potential donors. It called more than 1.3 million phone numbers over 10 times each in a single week and 7.8 million numbers more than twice in an hour. Over 500 phone numbers were called 5000 times or more, according to the FTC.

Although ACS stopped operating in 2019, having previously been the subject of 20 law enforcement actions, two defendants are said to have continued their deceptive practices with Directele and The Dale Corporation.

Many of the “monetary judgements” made by the FTC are suspended due to an “inability to pay” on the part of the defendants. However, proceeds from the sale of a holiday home and a ski boat will be turned over to the authorities, as will a total of around $500,000.

“Deceptive fundraising can be big business for scammers, especially when they use illegal robocalls,” said Daniel Kaufman, acting director of the FTC’s Bureau of Consumer Protection. “The FTC and our state partners are prepared to hold fraudsters accountable when they target generous consumers with lies.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#IWD2021: Pandemic Fails to Shatter Glass Ceiling for Women in Cyber

#IWD2021: Pandemic Fails to Shatter Glass Ceiling for Women in Cyber

The COVID-19 pandemic appears to have had a positive impact on the careers of women working in cybersecurity, although still too few are reaching senior positions, according to two new studies.

A Tessian report released to coincide with International Women’s Day today was compiled from interviews with 202 women in cybersecurity roles and over 1000 current or recently graduated university students in the US and UK.

Just 9% of cyber-professionals claimed the pandemic had negatively affected their career, with almost half (49%) saying it had impacted them positively.

That seems to be down in part to the strong role cyber has played in supporting organizations through the crisis, especially the rapid pivot to remote working. Some 89% of respondents said they felt secure in their jobs and even more (94%) claimed they’d had to take on new hires in 2020.

However, beyond job security, there’s still much to do. Separate Eskenzi PR and Marketing research found that just 10% of board positions and 16% of management roles in the industry are held by women.

The research was compiled by studying the websites of 138 companies from the Cybersecurity Ventures Hot 150.

When asked what would encourage more women into the industry, the larges number of respondents to the Tessian study pointed to equal pay (47%), followed by more female role models (44%), a gender-balanced workforce (43%) and a greater emphasis on STEM subjects in schools (41%).

Although most younger women polled said they found the industry “important” (87%) and “interesting” (73%), just a quarter (26%) of 18-25-year-olds were likely to consider a career in the industry, versus 42% of men.

Research from the Chartered Institute of Information Security (CIISec) released last week found that most (57%) women in cybersecurity believe it will take a decade before true equality exists in the workplace, and a fifth (20%) don’t think it will ever happen.

“Greater awareness in schools is critical but businesses, too, can help build a more diverse talent pool for the future through initiatives like hiring more diverse candidates at junior levels and developing them into senior roles, and creating platforms for role models to share their stories,” argued Tessian chief financial officer, Sabrina Castiglione.

“We won’t solve the gender gap overnight, but acting now and playing the long game will have enormous benefits – both for businesses and society.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hacking Digitally Signed PDF Files

Interesting paper: “Shadow Attacks: Hiding and Replacing Content in Signed PDFs“:

Abstract: Digitally signed PDFs are used in contracts and invoices to guarantee the authenticity and integrity of their content. A user opening a signed PDF expects to see a warning in case of any modification. In 2019, Mladenov et al. revealed various parsing vulnerabilities in PDF viewer implementations.They showed attacks that could modify PDF documents without invalidating the signature. As a consequence, affected vendors of PDF viewers implemented countermeasures preventing all attacks.

This paper introduces a novel class of attacks, which we call shadow attacks. The shadow attacks circumvent all existing countermeasures and break the integrity protection of digitally signed PDFs. Compared to previous attacks, the shadow attacks do not abuse implementation issues in a PDF viewer. In contrast, shadow attacks use the enormous flexibility provided by the PDF specification so that shadow documents remain standard-compliant. Since shadow attacks abuse only legitimate features,they are hard to mitigate.

Our results reveal that 16 (including Adobe Acrobat and Foxit Reader) of the 29 PDF viewers tested were vulnerable to shadow attacks. We introduce our tool PDF-Attacker which can automatically generate shadow attacks. In addition, we implemented PDF-Detector to prevent shadow documents from being signed or forensically detect exploits after being applied to signed PDFs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk