Winners of Inaugural SBRC Cyber Community Awards Announced

Winners of Inaugural SBRC Cyber Community Awards Announced

The winners of the first Cyber Community Awards have been announced by the Scottish Business Resilience Center (SBRC) – a non-profit organization that supports and protects Scottish businesses.

The SBRC-run awards – established to recognize the contributions of individuals and organizations helping to strengthen and secure Scotland’s online communities – include three main categories of Student Community Champion, Outstanding Cyber Community Event and Cyber Community Hero.

The winners, announced during a virtual awards ceremony held on February 25, are Allan Goodwill, Abertay University; Getting it Right…Keeping Your Child Safe – Perth and Kinross Council, Education and Children’s Services; and Annabel Turner, CyberSafe Scotland, respectively.

Two special awards were also made to Gordon Mcdonald, Police Scotland (receiving the Special Recognition Award) and Alison Stone, SCVO; Beverly Bowles, Police Scotland; Jana Vidis, IFB; Michael McCullagh, Police Scotland and Robbie Ross, Converged Communication Solutions (each receiving the ‘Shine the Light’ Award).

Jude McCorry, CEO of the SBRC, said: “Last night’s awards highlight that despite the challenges every one of us has faced over the last 12 months, there continues to be an incredible amount of good being done to elevate cyber-education and awareness. With the programs and contributions supporting a broad range of people – from young people and their parents to peers and other professionals – I take great pride in all that is being done to increase cyber-resilience across Scotland.”

As part of its ongoing mission of improving online safety in Scotland, the SBRC recently updated its facilitation of the National Cyber Security Center’s Exercise in a Box training program to add workshops designed specifically to help businesses tackle the threat of ransomware.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Learning Tree International Named First (ISC)² Global Premier Partner

Learning Tree International Named First (ISC)² Global Premier Partner

Cybersecurity training and certifications organization (ISC)2 has named instructor-led education provider Learning Tree International as its first global Premier Partner.

The collaboration between the two companies is part of a new tiered partnership program for Official Training Providers which will see (ISC)2 and Learning Tree International work together to engage with and educate aspiring cybersecurity professionals around the world to help address the cyber-skills shortage.

“In the mission to provide education for the world’s future cybersecurity leaders, Learning Tree has been an invaluable partner,” said Greg Clawson, vice-president of sales and marketing, (ISC)². “The demand for skilled cybersecurity professionals has never been greater or more global in nature, and the reach that Learning Tree provides enables us to meet learners where they are in more regions around the world, on their journey along the path to certification.”

Via its virtual learning platform, Learning Tree AnyWare, Learning Tree delivers the full suite of Official (ISC)² CBK Training Seminars and provides hands-on, real-world skills-based training to cybersecurity professionals.

David Brown, CEO of Learning Tree, added: “Having the right cybersecurity strategy, processes and talent in place has never been more critical. We are poised to better support our clients in their mission to safeguard their brands and data through our comprehensive cybersecurity training approach from skills assessments to training to coaching – work we take great pride in at Learning Tree – and we appreciate this recognition as (ISC)²’s first global Premier Partner.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

TikTok Set for Massive $92m Payout Over Privacy Suit

TikTok Set for Massive $92m Payout Over Privacy Suit

TikTok has agreed to pay $92m to settle multiple privacy lawsuits alleging the social network took and shared user data without consent, according to reports.

The proposed settlement applies to 89 million US TikTok users whose data the firm is alleged to have sold to advertisers in violation of state and federal laws. Some of these third parties are said to be China-based businesses.

According to NPR, the settlement comes on the back of 21 federal lawsuits filed mostly on behalf of children which claim the Chinese-owned company engaged in the “theft of private and personally identifiable TikTok user data.”

Lawyers for the plaintiffs claimed that even draft videos that were never published were harvested by the social media giant. User information using facial recognition technology was also reportedly taken and shared.

Some of the children involved in the lawsuit were as young as six, according to the settlement.

“What is more, unknown to its users, included in the TikTok app is surveillance software developed in China. The TikTok app has clandestinely vacuumed up and transferred to servers in China (and to other servers accessible from within China) vast quantities of private and personally identifiable user data and content that could be employed to identify, profile and track the physical and digital location and activities of United States users now and in the future,” it continued.

“Users are further at risk because defendants’ conduct exposes TikTok user data to access by the Chinese government to assist that government in meeting two of its crucial and intertwined state objectives: (a) world dominance in artificial intelligence and (b) population surveillance and control.”

Under the terms of the settlement, TikTok would have to stop sending user data overseas and cease collecting biometric infomation including facial recognition data, as well as GPS data.

Last year, Donald Trump attempted to ban the app in the US and then force a sale to Oracle. The Biden administration is currently reviewing the national security risks posed by all Chinese technology, while the Committee on Foreign Investment in the United States is conducting a national security review of TikTok.

TikTik agreed to pay the FTC a record $5.7m fine in 2019 to settle a case in which it was accused of illegally collecting the personal data of children who used it.

Infosecurity has contacted TikTok for comment.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Chinese Hackers Target Tibetans with Malicious Firefox Extension

Chinese Hackers Target Tibetans with Malicious Firefox Extension

Chinese Communist Party-backed hackers have been spying on Tibetan activists via a malicious new Firefox extension, according to Proofpoint.

The security vendor explained that it had seen low-level phishing campaigns against the Tibetan diaspora since March 2020, but that these took another turn in the first two months of 2021 with the use of a customized malicious extension dubbed “FriarFox.

“We attribute this activity to TA413, who in addition to the FriarFox browser extension, was also observed delivering both Scanbox and Sepulcher malware to Tibetan organizations in early 2021,” it added.

“Proofpoint has previously reported on Sepulcher malware and its links to the Lucky Cat and Exile Rat malware campaigns that targeted Tibetan organizations.”

TA413 itself is believed to be an APT group aligned with the Chinese state.

The malware is delivered via spear-phishing emails spoofing senders such as the Bureau of His Holiness the Dalai Lama in India and the Tibetan Women’s Association. They typically feature a malicious link leading to a fake ‘Adobe Flash Player Update’ which will execute JavaScript to scan the target’s machine.

These scripts will then decide whether to deliver the FriarFox payload, which provides access to the victim’s Gmail account.

It has been designed to search for, archive, read, delete, forward and mark emails as spam, as well as access browser tabs on Firefox, modify privacy settings and access user data for all websites.

The attackers also try to download ScanBox malware, a “JavaScript-based reconnaissance framework” dating back to 2014 which can track visitors to certain websites, perform keylogging and collect user data for use in future intrusion attempts.

“Unlike many APT groups, the public disclosure of campaigns, tools and infrastructure has not led to significant TA413 operational changes,” Proofpoint concluded. “Accordingly, we anticipate continued use of a similar modus operandi targeting members of the Tibetan diaspora in the future.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Npower Ditches App After Credential Stuffing Attacks

Npower Ditches App After Credential Stuffing Attacks

One of the UK’s largest energy firms has been forced to deactivate its mobile app after reports emerged of a coordinated credential stuffing campaign against users.

Npower has informed all of the affected customers, although it’s unclear exactly how many had their accounts hijacked by attackers.

Data that may have been viewed includes personal information like: dates of birth, contact details and addresses, partial financial information including sort codes and the last four digits of bank account numbers and contact preferences, according to MoneySavingExpert.

Although there’s no obvious information for affected customers on the Npower website, they were reportedly contacted about the incident in early February.

“We immediately locked any online accounts that were affected, blocked suspicious IP addresses and deactivated the Npower app,” a statement from the firm noted.

“We’ve also notified the Information Commissioner’s Office and Action Fraud. Protecting customers’ security and data is our top priority.”

The app was set to be canned even before the incident, but the credential stuffing campaign accelerated the process, the report claimed.

Credential stuffing attacks are primarily the fault of customers/end users that reuse passwords across multiple sites. That means if one of those companies is breached, attackers can feed these stolen credentials into automated software, which tries them in large numbers across other websites.

James McQuiggan, security awareness advocate at KnowBe4, explained that consumers could try free monitoring services like HaveIBeenPwned to check if their logins have been previously breached.

“Keeping track of your passwords in a password vault is the first step toward protecting your accounts. The second step is to always change that password when it has been compromised in a data breach,” he said.

“The third step is to have unique and strong passwords for each account you create, reducing the likelihood of a credential stuff attack. Finally, using multi-factor authentication (MFA), wherever provided by the organization, can add that extra layer of protection to an account.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

David Birch Appointed Honorary President of EEMA

David Birch Appointed Honorary President of EEMA

EEMA has announced the appointment of David W.G. Birch as its honorary president, joining creator of the Seven Laws of Identity paper, Kim Cameron, in holding this title.

Birch has been a member of the EEMA board of management for the past five years, representing the European Think Tank as a speaker, author, advisor and commentator on digital financial services and digital identity.

Birch holds a number of board and advisory positions in Europe and North America, including as member of the governing council of the Center for the Study of Financial Innovation. He has been ranked in the top 100 global fintech influencers for 2021 and is recognized as one of the top 10 most influential voices in banking by Financial Brand.

Birch has also published three books exploring issues such as identity and digital currency: Identity is the New Money (2014), Before Babylon, Beyond Bitcoin (2017) and The Currency Cold War – Cash and Cryptography, Hash Rates and Hegemony (2020). He recently participated alongside Cameron during EEMA’s first virtual conference in a debate entitled ‘Why digital identity doesn’t yet exist?’

Commenting on the announcement, EEMA chair, Jon Shamah, said: “The EEMA board of management and executive office are proud of the long association and friendship with two of the most well recognized, respected and affable figures in the world of identity. David and Kim both go above and beyond to support EEMA initiatives and so many of our members have benefited from their generosity of time and words of wisdom.”

Birch stated: “I am honored to accept this prestigious position given to me by EEMA, especially alongside Kim Cameron, whose pioneering ideas around digital identity were a significant inspiration to my own work in the field.”

Last month, EEMA, which focuses on identity, privacy and trust, appointed Steve Pannifer to its board of management.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk