The Fastest Route to SASE

Shortcuts aren’t always the fastest or safest route from Point A to Point B. Providing faster “direct to cloud” access for your users to critical applications and cloud services can certainly improve productivity and reduce costs, but cutting corners on security can come with huge consequences. The Secure Access Service Edge (SASE) framework shows how to achieve digital transformation without compromising security, but organizations still face a number of difficult choices in how they go about it. Now, McAfee can help your organization take the shortest, fastest, and most secure path to SASE with its MVISION Unified Cloud Edge solution delivered alongside SD-WAN.

Decision makers seek a faster, more efficient high road to cloud and network transformation without compromising security. The need for speed and scalability is crucial, but corners cannot be cut when it comes to maintaining data and threat protection. Safety and security cannot be left behind in a cloud of transformation dust. This blog will look at the major trends driving SASE adoption, and will then discuss how a complete SASE deployment can deliver improved performance, superior threat & data security, lower complexity, and cost savings. We’ll then explain why fast AND secure cloud transformation requires an intelligent, hyperscale platform to accelerate SASE adoption.

Dangerous Detours, Potholes, and Roadblocks

While digital transformation promises substantial gains in productivity and efficiencies, the journey is littered with security and efficiency challenges that can detour your organization from its desired upgrades and safe destination.

Digital transformation challenges that must be addressed include:

  • The Big Shift – Shifting your organization’s applications and data out of corporate data centers and into the cloud.
  • Going More Mobile – The proliferation of mobile devices leaves your corporate resources more vulnerable as they are being accessed by a growing number of devices many of which are personally owned and unmanaged.
  • Work from Anywhere– The seemingly permanent shift towards “Work from Home” creates an increased demand for more efficient distributed access to cloud-based corporate resources that secures visibility and control amidst the eroding traditional network.
  • Costly Infrastructure – MPLS connections, VPN concentrators, and huge centralized network security infrastructure represent major investments with significant operational expense. The fact that multiple security solutions typically operate in distinct siloes compounds management effort and costs.
  • Slow Performance, High Latency, and Low Productivity – Dedicated MPLS and VPN lines are also slow and architecturally inefficient, requiring all traffic to go to the data center for security and then all the way back out to internet resources – NOT a straight line.
  • Data Vulnerability – Data resides and moves completely outside the scope of perimeter security through collaboration from the cloud to third parties, between cloud services, and access by unmanaged devices, leaving it prone to incidents without security teams knowing.
  • Evolving Threats and Techniques – Staying ahead of the latest malware remains a priority, but many modern attacks are emerging that use techniques like social engineering to exploit the features of cloud providers and mimic user behavior with legitimate credentials. Detecting these seemingly legitimate behaviors is extremely difficult for traditional security tools.

Feel the Need for Safe, But Less Costly Speed

The increasingly difficult challenge of providing a fast and safe cloud environment to an increasingly distributed workforce has become a major detour in the drive to transform from traditional enterprise networks and local data centers. Companies have had to meet the challenge to “adapt or die” in connecting their employees and devices to corporate resources, but many have generally needed to choose between two unsatisfactory compromises: secure but slow and expensive, or fast and affordable but not secure. Adopting a SASE framework is the way to achieve all of the benefits of cloud transformation without compromise:

  • Reduction in Cost and Complexity – A great benefit for your SOC and IT teams, SASE promotes a network transformation that simplifies your technology stack, reducing costs and complexity.
  • Increased Speed and Productivity – Fast, uninterrupted access to applications and data boosts the user experience and improves productivity. SASE provides ubiquitous, low-latency connectivity for your workforce – even remote workers – via a fast and ubiquitous cloud service, and uses a streamlined “single pass” inspection model that ensures they aren’t bogged down by security.
  • Multi-Vector Data Protection – SASE mandates the protection of data traveling through the internet, within the cloud, and moving cloud to cloud, enabling Zero Trust policy decisions at every control point.
  • Comprehensive Threat Defense – A SASE framework fortifies an organization’s threat defense capabilities for detecting both cloud-native and advanced malware attacks within the cloud and from any web destination.

Selecting the Best Path to Transformation

When network and security decision makers come to the proverbial fork in the road to network transformation, what is the best path that enables fast and affordable access without leading to unacceptable security risk? A recent blog by McAfee detailed four architectural approaches based on the willingness to embrace new technologies and bring them together. After examining the pros and cons of these four paths, the ideal solution to achieve fast, secure, and cost-effective access to web and cloud resources is a SASE model that brings together a ubiquitous, tightly integrated security stack with a robust, direct-to-cloud SD-WAN integrated networking solution. This combination provides a secure network express lane to the cloud, cruising around the latency challenges of slow, expensive MPLS links for connectivity to your applications and resources.

MVISION Unified Cloud Edge (UCE) + SD-WAN: Fast, Furious and Secure

Fast Network. Data Protection. Threat Protection. Speed, security and safety turbocharged connectivity throughout a hyperscale cloud network without compromise.

MVISION UCE is the best framework for implementing a SASE architecture to accelerate digital transformation with cloud services, enabling cloud and internet access from any device while empowering ultimate workforce productivity. MVISION UCE brings SASE’s most important security technologies – Cloud Access Security Broker (CASB), Next-gen Secure Web Gateway (SWG), Data Loss Prevention (DLP), and Remote Browser Isolation (RBI) – together in a single cloud-native hyperscale service edge that delivers single-pass security inspection with ultra-low latency and 99.999% availability.

With MVISION Unified Cloud Edge and our SD-WAN integration partners, you can lead a network transformation that reduces costs and speeds up the user experience by using fast, affordable broadband connections instead of expensive MPLS.

MVISION UCE and SD-WAN transforms your network architecture by enabling users to directly access cloud resources without having to go back through their corporate network through MLPS or VPN connection. Now users can directly access cloud resources, and the McAfee cloud infrastructure is so well-optimized that they can often access resources even FASTER than if there was no intervening security stack! Read how Peering POPs make negative latency possible in this McAfee White Paper.

Because of the way we’ve delivered our product, MVISION UCE + SD-WAN unleashes SASE’s benefits, with data and threat protection that other vendors can’t match.

Reduction in Cost and Complexity, Increased Speed and Agility

  • The resulting converged cloud service is substantially more efficient than building your own SASE by manually integrating separate cloud-based technologies
  • Minimize inefficient traffic backhauling with intelligent, efficient, and secure direct-to-cloud access
  • Protect remote sites via SD-WAN using industry standard Dynamic IPSec and GRE protocols leveraging SD-WAN technology that gets office sites to cloud resources faster and more directly than ever before
  • Enjoy low latency and unlimited scalability with a global cloud footprint and cloud-native architecture that includes global Peering POPs (Point of Presence) reducing delays
  • As a cloud service with 99.999% uptime (Maintained Service Availability) and internet speeds faster than a direct connection, you improve the productivity of your workforce while reducing the cost of your network infrastructure.

Multi-Vector Data Protection

  • The McAfee approach to data protection is unified, meaning each control point works as part of a whole solution.
  • All access points are covered using the same data loss prevention (DLP) engine, giving you an easily traceable path from device to cloud
  • Your data classifications can be set once, and applied in policies that protect the endpoint, web traffic and any cloud interaction
  • All incidents are centralized in one management console for a single view of your data protection practice, giving you a streamlined incident management experience

Comprehensive Threat Defense

  • Intelligence-driven unified protection – CASB, Next-gen SWG, DLP – against the most sophisticated cyberattacks and data loss
  • Remote Browser Isolation (RBI) protection from web-based threats and malware through the remote exclusion and containment of all browsing activities to a remote server hosted in the cloud
  • The industry’s most effective in-line emulation sandbox, capable of removing zero-day malware at line speed
  • User and entity behavior analytics (UEBA) monitoring all cloud activity for anomalies and threats to your data

If you are looking for improved productivity and lower costs of cloud transformation without cutting corners, McAfee MVISION UCE offers the fastest route to SASE — without compromising your data and threat security.

Learn more about MVISION UCE and our unique approach to SASE here.

Live Webinar

Take the Fastest Route to SASE with MVISION UCE

Thursday, March 18, 2020
10am PT | 12pm CT | 1pm ET

Register Now

 

The post The Fastest Route to SASE appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Attention Android Users: This Free VPN App Leaked the Data of 21 Million Users

Attention Android Users: This Free VPN App Leaked the Data of 21 Million Users

To live our digital lives to the fullest, we rely on a variety of technologies to support our online activities. And while some apps and devices are meant to make certain tasks more convenient or provide us with greater security, others simply offer a false sense of security and could potentially lead to online misfortune. One such platform is SuperVPN. While users may applaud themselves for using a VPN to protect their privacy, this Android app is unfortunately spilling their secrets without their knowledge.

Let’s unpack how SuperVPN works and its recent involvement in a data breach.

SuperVPN or Super Villain?

VPNs (virtual private networks) are intended to create a secure tunnel between your device and the internet, offering you privacy and freedom from IP-based tracking. It protects your identity and financial information by encrypting, or scrambling, the data that flows through the tunnel, and can mask your true location, making it appear as though you are connecting from somewhere else. VPN apps have become much more popular in recent years as our awareness around privacy and security has grown. But, such is the case with all apps, it’s important to do your research before you select one to install on your phone.

According to Forbes, critical security warnings around the app SuperVPN surfaced last year. They reported research stating that 105 million people might have had their credit card details stolen, and that hackers could intercept messages between the user and provider. As of last Friday, someone leaked three databases on a popular hacking forum that purportedly contained user credentials and device data stolen from three different Android VPN services: SuperVPN, considered one of the most dangerous VPNs on Google Play with 100 million installs, GeckoVPN (10 million installs), and ChatVPN (50,000 installs). This breach exposed the data of 21 million users, including names, email addresses, usernames, payment data, device information, and even location data logs —  a major red flag for a VPN.

You Can’t Put a Price on Data Protection

Although a free VPN might seem like an ideal solution at first, there are multiple consequences that could potentially put your online safety in jeopardy. Since free VPNs are not making money directly from their users, many make revenue indirectly, through advertising. This means that not only will you be bombarded with ads, but you’re also exposed to tracking and malware. In fact, one study of 283 free VPN providers found that 72% included trackers. Beyond the frustration of ads, slowness, and upgrade prompts is the fact that some free VPN tools include malware that can put your sensitive information at risk. The same study found that 38% of the free VPN applications in the Google Play Store were found to have malware and some even stole the data off of users’ devices, similar to SuperVPN.

If you choose a verified, paid VPN service, however, you’ll enjoy a plethora of benefits including unlimited bandwidth, speedy performance, protection across multiple devices, and much more. Aside from choosing a premium VPN service, following these tips will help you stay secure against SuperVPN and others like it and protect your daily online communications:

1. If you have SuperVPN, uninstall it

Delete SuperVPN from your device as soon as possible. There are at least six other apps like SuperVPN, with identical descriptions and logos from different creators on Google Play Store. Steer clear of downloading these apps altogether to avoid any cyber misfortune.

2. Do your research

While some malicious apps do make it through the app store screening process, most attack downloads appear to stem from social media, fake ads, and other unofficial app sources. Before downloading an app to your device, do some quick research about the origin and developer.

3. Read app reviews with a critical eye

Reviews and rankings are still a suitable method of determining whether an app is legitimate. However, watch out for assessments that reuse repetitive or straightforward phrases, as this could be a sign of a fraudulent review.

4. Place a fraud alert

If you suspect that your data might have been compromised, place a fraud alert on your credit. This not only ensures that any new or recent requests undergo scrutiny, but also allows you to have extra copies of your credit report so you can check for suspicious activity.

5. Upgrade to holistic security for your peace of mind

A comprehensive security suite like McAfee Total Protection includes our McAfee® Safe Connect standalone VPN with auto-renewal and takes the worry out of connecting, so you can focus on what’s important to you.

Stay Updated

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home  on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook.

 

The post Attention Android Users: This Free VPN App Leaked the Data of 21 Million Users appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

At Least 30,000 U.S. Organizations Newly Hacked Via Holes in Microsoft’s Email Software

At least 30,000 organizations across the United States — including a significant number of small businesses, towns, cities and local governments — have over the past few days been hacked by an unusually aggressive Chinese cyber espionage unit that’s focused on stealing email from victim organizations, multiple sources tell KrebsOnSecurity. The espionage group is exploiting four newly-discovered flaws in Microsoft Exchange Server email software, and has seeded hundreds of thousands of victim organizations worldwide with tools that give the attackers total, remote control over affected systems.

On March 2, Microsoft released emergency security updates to plug four security holes in Exchange Server versions 2013 through 2019 that hackers were actively using to siphon email communications from Internet-facing systems running Exchange.

In the three days since then, security experts say the same Chinese cyber espionage group has dramatically stepped up attacks on any vulnerable, unpatched Exchange servers worldwide.

In each incident, the intruders have left behind a “web shell,” an easy-to-use, password-protected hacking tool that can be accessed over the Internet from any browser. The web shell gives the attackers administrative access to the victim’s computer servers.

Speaking on condition of anonymity, two cybersecurity experts who’ve briefed U.S. national security advisors on the attack told KrebsOnSecurity the Chinese hacking group thought to be responsible has seized control over “hundreds of thousands” of Microsoft Exchange Servers worldwide — with each victim system representing approximately one organization that uses Exchange to process email.

Microsoft said the Exchange flaws are being targeted by a previously unidentified Chinese hacking crew it dubbed “Hafnium,” and said the group had been conducting targeted attacks on email systems used by a range of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.

Microsoft’s initial advisory about the Exchange flaws credited Reston, Va. based Volexity for reporting the vulnerabilities. Volexity President Steven Adair said the company first saw attackers quietly exploiting the Exchange bugs on Jan. 6, 2021, a day when most of the world was glued to television coverage of the riot at the U.S. Capitol.

But Adair said that over the past few days the hacking group has shifted into high gear, moving quickly to scan the Internet for Exchange servers that weren’t yet protected by the security updates Microsoft released Tuesday.

“We’ve worked on dozens of cases so far where web shells were put on the victim system back on Feb. 28 [before Microsoft announced its patches], all the way up to today,” Adair said. “Even if you patched the same day Microsoft published its patches, there’s still a high chance there is a web shell on your server. The truth is, if you’re running Exchange and you haven’t patched this yet, there’s a very high chance that your organization is already compromised.”

Reached for comment, Microsoft said it is working closely with the U.S. Cybersecurity & Infrastructure Security Agency (CISA), other government agencies, and security companies, to ensure it is providing the best possible guidance and mitigation for its customers.

“The best protection is to apply updates as soon as possible across all impacted systems,” a Microsoft spokesperson said in a written statement. “We continue to help customers by providing additional investigation and mitigation guidance. Impacted customers should contact our support teams for additional help and resources.”

Adair said he’s fielded dozens of calls today from state and local government agencies that have identified the backdoors in their Exchange servers and are pleading for help. The trouble is, patching the flaws only blocks the four different ways the hackers are using to get in. But it does nothing to undo the damage that may already have been done.

A tweet from Chris Krebs, former director of the Cybersecurity & Infrastructure Security Agency, responding to a tweet from White House National Security Advisor Jake Sullivan.

By all accounts, rooting out these intruders is going to require an unprecedented and urgent nationwide clean-up effort. Adair and others say they’re worried that the longer it takes for victims to remove the backdoors, the more likely it is that the intruders will follow up by installing additional backdoors, and perhaps broadening the attack to include other portions of the victim’s network infrastructure.

Security researchers have published several tools for detecting vulnerable servers. One of those tools, a script from Microsoft’s Kevin Beaumont, helps companies identify exposed servers.

KrebsOnSecurity has seen portions of a victim list compiled by running such a tool, and it is not a pretty picture. The backdoor web shell is verifiably present on the networks of thousands of U.S. organizations, including banks, credit unions, non-profits, telecommunications providers, public utilities and police, fire and rescue units.

“It’s police departments, hospitals, tons of city and state governments and credit unions,” said one source who’s working closely with federal officials on the matter. “Just about everyone who’s running self-hosted Outlook Web Access and wasn’t patched as of a few days ago got hit with a zero-day attack.”

Another government cybersecurity expert who participated in a recent call with multiple stakeholders impacted by this hacking spree worries the cleanup effort required is going to be Herculean.

“On the call, many questions were from school districts or local governments that all need help,” the source said, speaking on condition they were not identified by name. “If these numbers are in the tens of thousands, how does incident response get done? There are just not enough incident response teams out there to do that quickly.”

When it released patches for the four Exchange Server flaws on Tuesday, Microsoft emphasized that the vulnerability did not affect customers running its Exchange Online service (Microsoft’s cloud-hosted email for businesses). But sources say the vast majority of the organizations victimized so far are running some form of Internet-facing Microsoft Outlook Web Access (OWA) email systems in tandem with Exchange servers internally.

“It’s a question worth asking, what’s Microsoft’s recommendation going to be?,” the government cybersecurity expert said. “They’ll say ‘Patch, but it’s better to go to the cloud.’ But how are they securing their non-cloud products? Letting them wither on the vine.”

The government cybersecurity expert said this most recent round of attacks is uncharacteristic of the kinds of nation-state level hacking typically attributed to China, which tends to be fairly focused on compromising specific strategic targets.

“Its reckless,” the source said. “It seems out of character for Chinese state actors to be this indiscriminate.”

Microsoft has said the incursions by Hafnium on vulnerable Exchange servers are in no way connected to the separate SolarWinds-related attacks, in which a suspected Russian intelligence group installed backdoors in network management software used by more than 18,000 organizations.

“We continue to see no evidence that the actor behind SolarWinds discovered or exploited any vulnerability in Microsoft products and services,” the company said.

Nevertheless, the events of the past few days may well end up far eclipsing the damage done by the SolarWinds intruders.

This is a fast-moving story, and likely will be updated multiple times throughout the day. Stay tuned.

Update, 8:27 p.m. ET: Wired cybersecurity reporter Andy Greenberg has confirmed hearing the same number of victim numbers cited in this report: “It’s massive. Absolutely massive,” one former national security official with knowledge of the investigation told WIRED. “We’re talking thousands of servers compromised per hour, globally.” Read Greenberg’s account here.

Also, the first and former director of CISA, Chris Krebs (no relation) seems to be suggesting on Twitter that the victim numbers cited here are conservative (or just outdated already):

Update 8:49 p.m.: Included a link to one of the more recommended tools for finding systems vulnerable to this attack.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cryptocurrency Fraudster Steals $16m

Cryptocurrency Fraudster Steals $16m

A Swedish businessman has admitted conning thousands of victims out of millions of dollars with a reversed pension cryptocurrency investment scam. 

Roger Nils-Jonas Karlsson pleaded guilty today to securities fraud, wire fraud, and money laundering charges that he defrauded 3,575 victims of more than $16m.

Karlsson and his now defunct company, Eastern Metal Securities (EMS), were charged in a criminal complaint filed on March 4, 2019. The 47-year-old, who uses at least six different aliases including Euclid Deodoris and Paramon Larasoft, was arrested three months later in Thailand and extradited to the United States. 

From November 2012 to June 2019, Karlsson and EMS used the website www.easternmetalsecurities.com to make false representations and convince victims to buy shares in a “pre-funded reversed pension plan” (PFRPP) using virtual currency.  

Victims were promised an eventual payout of 1.15 kilograms of gold per $100 share. Karlsson gave his investors a guarantee that if the gold payout didn’t happen, he would refund 97% of their investment. 

In reality, Karlsson transferred the money sent to him by investors into his own personal bank account then used it to buy expensive homes and a resort in Thailand. He admitted to US authorities that he had no way to pay back investors. 

Karlsson used a second website, www.hci25.com, to make multiple false communications to potential investors designed to delay the moment when investors realized that they would not be getting their money back.

Among the lies told by Karlsson via the site was one that stated EMS was working with the US Securities and Exchange Commission to prepare the way for a payout. Another said the payout had to be delayed because releasing so much money at once would negatively impact the world’s financial systems. 

The website www.easternmetalsecurities.com has been seized, according to a warrant issued by the United States District Court for the Northern District of California. 

Karlsson faces a maximum sentence of 20 years in prison and a maximum $250,000 fine for the wire fraud and securities fraud charges, and 20 years in prison and a $500,000 maximum fine for the money laundering charge. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Two-Thirds of Irish Women Harassed Online

Two-Thirds of Irish Women Harassed Online

A survey by a global humanitarian NGO has found that two-thirds of Ireland’s young women and girls have been harassed while using the internet. 

The research, conducted by Plan International, found 67% of young female users had been subjected to virtual violence while online. In the majority of cases, the abuse was perpetrated via the social media platforms Snapchat and Instagram.

Among the harassing behaviors experienced by victims was cyberstalking, threats of sexual or physical violence, being sent unsolicited sexually explicit images or messages, and being in receipt of abusive and threatening messages or comments.

The highest volume of harassment was experienced by girls with disabilities, girls and young women from the LGBTQ+ community, and girls and young women from racial and ethnic minorities. 

Many girls said that they had become targets of abuse after posting content in which they expressed their personal views. For 15% of the victims, the impact of the online harassment was felt so keenly that they have simply stopped sharing their views virtually.

On average, girls in Ireland first start experiencing online harassment at the age of 13. The youngest age at which online harassment was experienced was recorded as eight years old. 

According to victims, the nature of the abuse they experienced revolved around physical appearance and gender. Just over half (54%) of girls said they believed their gender identity had been targeted, while 86% said they had been attacked over the way they look.

Asked about the efficacy of abuse-reporting mechanisms on social media platforms, girls in Ireland said companies were too slow at deleting abusers’ accounts. They also complained of abusers creating fake profiles to carry out their abuse while hiding their identities. 

Fourteen thousand girls and young women aged 15–25 from 22 countries took part in the research. Globally, the percentage of girls and young women who experienced some form of online harassment was 58%.

For a quarter of the victims, the abuse was so bad that it had made them feel physically unsafe in their offline lives. Three-quarters of the girls said the harassment had lowered their self-esteem and degraded their self-confidence, while 65% said it had caused them emotional or mental stress.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Attack on Arizona Optometrist

Ransomware Attack on Arizona Optometrist

A cyber-attack on an optometrist located in Sierra Vista, Arizona, has affected up to 100,000 patients. 

Cyber-criminals successfully hit Cochise Eye and Laser with ransomware in January, encrypting the office’s patient scheduling and billing software. 

Patient data stored in the billing software included names, dates of birth, addresses, phone numbers, and in some cases Social Security numbers.

While the attack prevented staff from accessing certain data, a spokesperson for the office said that no signs had been found to indicate that any data theft or exfiltration had taken place.

A breach notice issued by Cochise explained: “There is no evidence that the data was taken, only that it was encrypted, and in some cases deleted, making it impossible for us to access anything in our scheduling system.”

Since the attack, which occurred on January 13, 2021, Cochise has been forced to fall back on paper and pens and undertake the laborious task of rebuilding its appointment schedule. 

“Our office is still operating with paper charts, so we can continue care of our patients,” said the spokesperson. “We will be using charts to rebuild our schedules.

“Everyone seen after January 1st, 2020 will be called to reschedule follow up appointments, as we have no way of knowing when they were originally scheduled.” 

The optometrist’s office said it planned to increase cybersecurity following the attack. 

“We have been working on implementing increased security measures, recovering data, and a new offsite backup,” said Cochise.

Although no evidence has been found that data was taken, the incident is still considered a breach of protected health information and has been reported to the HHS’ Office for Civil Rights as affecting up to 100,000 patients.

Cochise Eye and Laser provides ophthalmology and optometry services in Cochise County and throughout Southeastern Arizona via two optometry clinics and a surgical office. 

The eye-care provider advised its patients to place a fraud alert on their credit file and to request and review their credit reports.  

Cochise told its customers: “We are committed to patient privacy and continued exceptional patient care. We apologize for the inconvenience and appreciate your patience with our staff as they navigate through these challenging times.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Experts Discuss How to Achieve Greater Gender Equality in the Tech Industry

Experts Discuss How to Achieve Greater Gender Equality in the Tech Industry

There has been significant progress in the area of gender diversity in the technology industry, but much more work is required, according to a panel speaking on a webinar during Women’s History Month.

The discussion came on the back of Kaspersky’s recent Women in tech report, in partnership with Ada’s List, a global community for women in tech. This study highlighted that a lot of progress is being made in improving representation of women in the tech industry, with over half (56%) of female respondents agreeing that gender equality has improved in their organization over the past two years.

This has been the experience too of Claire Hatcher, head of business development, Kaspersky Fraud Prevention, who explained that when she started in the industry around 15 years ago, “I was often the only woman at the table in meetings and regularly one of very few women in the room in general. However, over the years, I’m happy to see more women are coming up through the ranks and also seeing more women in engineering and R&D roles, and there is a significant portion of female leaders as well.”

Businessman Tim Campbell MBE, a small business advocate, concurred with this, but cautioned that it is important to not get complacent. In particular, he believes there needs to be a greater focus on outlining the tech career options available to school- and college-aged girls. “I am really imploring employers, ERG Group leaders and politicians to be doing much more around advocating the clear pathway from education to employment, because that bridge is really important,” he commented.

Another way of achieving progress is to make the case that greater gender diversity has huge business benefits rather than simply being a matter of equality. Having teams of people from diverse backgrounds and experiences will lead to more effective and innovative outcomes for the organization, according to Hatcher, relating it to her role in fraud prevention at Kaspersky. “Fraudsters typically come from all different backgrounds and they make their money through looking at anomalies and patterns to find vulnerabilities. So diversity is really important in terms of the fight against cybercrime, because you have to change your thought patterns to think like a cyber-criminal in order to find those potential vulnerabilities,” she explained.

In terms of what more employers can do to advance gender diversity in the tech industry, Dr Patricia Gestoso, member of Ada’s list and head of scientific customer support at BIOVIA, said it was important to tailor opportunities within organizations to different groups, including women. She noted, for example, that simply having better maternity conditions isn’t enough. “We need to have different paths for promotion that don’t penalize people for taking time off, mentoring, but most importantly, sponsorship and networking events,” stated Gestoso.

Another interesting aspect of the report was that the shift to home working in the past year appears to be providing benefits such as flexibility for women in the tech industry, with 46% of those surveyed saying this dynamic has improved gender equality in the sector. Nevertheless, this hybrid way of working can have a negative impact on some women, for example leading to burnout due to responsibilities such as childcare and chores. In the view of Campbell, this means there needs to be a far greater emphasis on equality issues in the home environment as well as in the workplace as we shift to a hybrid way of working. “Over this pandemic time, myself and my wife have had to really analyze the allocation of work at home,” he explained, adding that he would like to see men at home look at “what they are actually doing to change the conversation about equality.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Financial Crime Surges in 2020 Following Shift to Digital Banking and Commerce

Financial Crime Surges in 2020 Following Shift to Digital Banking and Commerce

A huge rise in financial crime was recorded last year, driven by the rapid shift to digital banking and commerce following COVID-19 lockdowns. This is according to Feedzai’s Financial Crime Report Q1 – 2021, which compared the volume of financial fraud and crime in Q4 and Q1 2020, with the latter quarter mainly unaffected by the pandemic.

The study found there was a 650% surge in account takeover (ATO) in Q4 compared to Q1, with malicious actors taking advantage of the growth in online accounts during the crisis. The authors noted that the expansion of online banking and real-time payment functions have made it easier for fraudsters to transfer funds or buy goods with stolen credentials once an account has been accessed.

There was also a 250% increase in attempted fraud on online banking detected between the two periods, fuelled by a 200% growth in mobile banking. This shift to digital banking led to a reduction in telephone and branch fraud rates.

As demand for digital media went up last year following social distancing measures, including for e-books and streaming for music and movies, whilst attempted fraud attacks in this area increased by 178% since January 2020 in North America and EU.

In regard to card fraud, the researchers revealed there was a 48% fall in card present attacks as physical shopping declined during the pandemic, with this type of transaction dropping by 20%. Card not present transactions went up by 35% between Q1 and Q4 2020, and unsurprisingly, fraud attacks targeting this increased, making up 70% of all fraud.

Jaime Ferreira, senior director of global data science at Feedzai, commented: “2020 was a year of rapid growth in financial crime. Fraudsters tried to take advantage of the convergence between a fast-paced digital environment and a new wave of inexperienced consumers to perpetrate a multitude of attacks that created a significant uptick in fraud.

“Financial institutions need to further invest in technologies to protect their customers while developing educational approaches. Robust technology and informed consumers are a powerful combination when fighting financial crime.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#COVID19 Vaccine Phishing Scams Surge 26% in Three Months

#COVID19 Vaccine Phishing Scams Surge 26% in Three Months

Vaccine-related phishing and Business Email Compromise (BEC) attempts jumped 26% in a recent three-month period, as scammers ramped up their efforts against organizations, according Barracuda Networks.

The security vendor’s Threat Spotlight, analyzed phishing emails between October 2020 and January 2021.

It revealed that, while the volume of vaccine-related spear-phishing attacks increased by 12% following announcements from Pfizer and Moderna in November 2020, this figure had more than doubled by the end of January 2021, after successful rollouts of the jab.

This clearly shows the extent to which cyber-criminals tweak their campaigns to coincide with real-world news events and public awareness.

Unlike some vendors, Barracuda Networks tracks BEC as a type of spear-phishing. It said this and brand impersonation were the most common types of vaccine-related phishing attempts it spotted.

In terms of brand impersonation, phishers may link to a phishing website advertising early access to vaccines, offering vaccinations in exchange for payment, or impersonating health care professionals requesting personal information to check eligibility for a jab, the vendor claimed.

Barracuda Networks also spotted BEC scams attempting to trick recipients into making fund transfers. Two ways of doing so are by impersonating employees requesting an urgent favor while they are getting a vaccine, or HR managers requesting money for a batch of non-existent vaccines secured for employees.

The security firm’s CTO, Fleming Shi, urged all employees to be skeptical of any such emails.

“Scammers are also adapting email tactics to bypass gateways and spam filters, so it’s critical to have a purpose-built solution that uses machine learning to analyse normal communication patterns within your organization, so that it can also spot anomalies that may indicate an attack, or if an internal email has been compromised,” he added.

“Finally, establishing strong internal policies and training staffers on how to recognize and report all attacks, not just those pertaining to the vaccine, will be the most effective method to bolstering defenses against the ever-evolving email threat.”

Last month, Mimecast warned of a new campaign designed to trick individuals into handing over personal and financial details by claiming they had been selected by the NHS for early vaccination.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Attacks Soared 150% in 2020

Ransomware Attacks Soared 150% in 2020

Ransomware surged by 150% in 2020 with the average extortion amount doubling, according to a new report from Group-IB.

The Singapore-based security firm analyzed over 500 attacks last year to compile its Ransomware Uncovered 2020-2021 report, which maps for the first time the most common tactics, techniques and procedures (TTPs) to the MITRE ATT&CK framework.

The average ransom demand stood at $170,000 last year, but groups like Maze, DoppelPaymer, and RagnarLocker averaged between $1 million and $2 million, it claimed.

This is because of their focus on “big-game hunting” — going after large and usually privately held organizations that are judged rich enough to pay large sums to avoid downtime. In fact, the average ransomware victim suffered 18 days of outages last year, which could have a chilling effect on revenue and reputation.

This is also why most of the attacks Group-IB studied were targeted at North America and Europe, where most Fortune 500 firms are located.

Even nation state groups like North Korea’s Lazarus and China’s APT27 have been getting involved, the report claimed.

However it was the Maze (20%), Egregor (15%) and Conti (15%) groups that accounted for most of the attacks analyzed by Group-IB.

The Ransomware-as-a-Service (RaaS) model accounted for the majority (64%) of attacks studied for this paper, and 15 new affiliate programs appeared in 2020.

Although the Maze group appeared to bow out in late 2020 while police managed to disrupt variants such as Egregor and Netwalker, new entrants to the market like Conti and DarkSide were also quick to appear during the year.

In a reflection of the shift to mass remote working during the pandemic, over half (52%) of attacks studied in the report used publicly accessible RDP servers to gain initial access, followed by phishing (29%) and exploitation of public-facing applications (17%).

Oleg Skulkin, senior digital forensics analyst at Group-IB, argued that going forward RaaS programs would continue to grow, with more cyber-criminals focusing their efforts on specific niches such as initial network access for resale and data exfiltration.

“The pandemic has catapulted ransomware into the threat landscape of every organization and has made it the face of cybercrime in 2020,” said Oleg Skulkin, senior digital forensics analyst at Group-IB. “From what used to be a rare practice and an end-user concern, ransomware has evolved last year into an organized multi-billion industry with competition within, market leaders, strategic alliances and various business models. This successful venture is only going to get bigger from here.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk