FDM Group Makes Pledge to Hire 2000+ New Global IT Trainees in 2021

FDM Group Makes Pledge to Hire 2000+ New Global IT Trainees in 2021

The FTSE 250 professional services firm FDM Group has announced an intention to hire more than 2000 new IT trainees globally in 2021 as part of a major recruitment drive.

FDM Group – which specializes in recruiting and equipping graduates, ex-armed forces personnel and women returners with the latest digital skills – said the recruitment goal comes amid a surge in demand for tech talent.

Key specialisms requested in the last few months include DevOps, data skills, digital transformation expertise, as well as information security and cloud computing specialists, the firm added. It estimates that around a third of new hires will be in the UK, with the remaining split across FDM Group’s US and APAC offices.

Rod Flavell, CEO, FDM Group, said: “The COVID-19 outbreak sent shockwaves through the global business community, forcing many employers to scale back operations and shift to a remote working model to adhere to social distancing rules.

“One year on, with the vaccine program in full swing and infection rates declining, businesses are raring to go, with plans to build back better and drive a major economic recovery. Digital skills sit at the very heart of this mission, enabling businesses to operate efficiently, adapt to new market conditions and transform customer services.”

Flavell added that, for those looking to forge a career in the technology industry, there has never been a better time to put your name forward, “with digital skills being a must-have for ambitious companies looking to reboot, rebuild and grow again.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Half of Apps Contain at Least One Serious Exploitable Vulnerability

Half of Apps Contain at Least One Serious Exploitable Vulnerability

At least 50% of apps used in sectors such as manufacturing, public services, healthcare, retail, education and utilities contain one or more serious exploitable vulnerabilities, according to a new study by WhiteHat Security.

This is particularly concerning given the shift to digital across most sectors in the past year increasing the number of apps being utilized.

Manufacturing had the highest “window of exposure,” with nearly 70% of applications in the sector having at least one serious exploitable vulnerability, according to the AppSec Stats Flash Volume 2 report, a monthly analysis launched this year.

The top five vulnerability classes recorded by WhiteHat over the previous three months were information leakage, insufficient session expiration, cross site scripting, insufficient transport layer protection and content spoofing. The report authors noted that “the effort and skill required to discover and exploit these vulnerabilities is fairly low, thus making it easier for the adversary.”

Part of the problem appears to be the high average time to fix critical vulnerabilities, which was revealed to be 189 days across all industries. More encouragingly, there was a five-day improvement in the 12-month average compared to last month, falling from 194 days. Three sectors – educational services, public administration and real estate – took over a year on average to fix critical vulnerabilities.

Setu Kulkarni, VP, corporate strategy and business development at WhiteHat Security, commented: “In 2021, we have more detailed security and breach data than ever before. Yet, the state of application security remains very concerning. No application is built the same way and therefore each presents an entirely unique attack surface. That, combined with the fact that applications today are increasingly polymorphic presenting web, mobile and API-based interfaces, makes application security a multi-dimensional challenge.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Breaches Cost US Healthcare Organizations $13bn in 2020

Breaches Cost US Healthcare Organizations $13bn in 2020

Last year saw a double-digit surge in the volume of healthcare data breach incidents in the US, with over 26 million people affected, according to Bitglass.

The cloud security firm’s seventh annual Healthcare Breach Report was compiled from US Department of Health and Human Services records of breached protected health information (PHI).

It revealed that incidents increased by over 55% on 2019 figures to reach 599 breaches in the sector, impacting over 26.4 million people.

The vast majority (67%) were down to “hacking and IT incidents” stemming from external attackers. This category also accounted for larger breaches than the others, amounting to over 91% of compromised records.

Loss or theft of endpoint devices came next, accounting for over 584,000 individuals affected, followed by unauthorized disclosure of data by internal parties or systems (763,000). The “other” category of miscellaneous breaches and leaks impacted over 584,000 patients.

Although the number of victims dropped slightly from the 27.5 million recorded in 2019, the average cost per breached record increased from $429 to $499 over the period. That means healthcare organizations were on the hook for $13.2bn as a result of breaches last year. The sector also comes top of IBM’s Cost of a Data Breach list, with an average of over $7.1m per breach.

“The vast majority of healthcare organizations process and store protected health information (PHI) such as Social Security numbers, medical history and other personal data. It is no surprise that these entities would be targeted by malicious cyber-criminals seeking to access sensitive data for monetary gain,” said Anurag Kahol, CTO of Bitglass.

“The exceedingly high number of hacking and IT incidents highlight the shifting strategies of malicious actors. As healthcare organizations continue to embrace cloud migration and digital transformation, they must leverage the proper tools and strategies to successfully protect patient records and respond to the growing volume of threats to their IT ecosystems.”

Healthcare organizations across the US and beyond have also had to contend with a surge in ransomware attacks, many of them also stealing sensitive data, as cyber-criminals sensed that hospitals would be distracted by the fight against COVID-19.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Two More Lazarus Group Members Indicted for North Korean Attacks

Two More Lazarus Group Members Indicted for North Korean Attacks

The US has named and indicted two more members of the infamous North Korean military hacking group known as Lazarus, which it said is responsible for stealing over $1.3bn from various entities.

A federal indictment unsealed yesterday named three members of military intelligence agency the Reconnaissance General Bureau (RGB), aka Lazarus or APT38.

Park Jin Hyok, 36, was previously charged in a complaint unsealed in 2018, and is joined by Jon Chang Hyok, 31 and Kim Il, 27.

The Department of Justice (DoJ) claimed the three were involved in some of the group’s most audacious campaigns, including: attacks on Sony Pictures Entertainment and AMC Theaters, cyber-heists targeting SWIFT transfers at Bangladesh Bank and other financial institutions, and the creation of WannaCry.

They’re also accused of ATM cash-out thefts, including the $6.1m October 2018 raid of BankIslami Pakistan, creating and deploying malicious cryptocurrency apps to provide backdoor access to victim machines and stealing tens of millions from cryptocurrency companies.

The trio were named as conspirators in spear-phishing campaigns targeting multiple US government, energy, defense, tech and aerospace organizations, and the development of a Marine Chain Token designed to secretly funnel investor funds to the Hermit Kingdom.

Prosecutors also unsealed one charge against Ghaleb Alaumary, 37, of Mississauga, Ontario, for his role as a money launderer for North Korean schemes including the above ATM cash-outs, BEC attacks and other fraud. Alaumary has already pleaded guilty and is currently being prosecuted in Georgia for involvement in a separate BEC scheme.

He is said to have organized “teams” of co-conspirators in the US and Canada to launder millions for the Kim Jong-un regime.

The US Cybersecurity and Infrastructure Security Agency (CISA) yesterday released further information on the malicious cryptocurrency apps mentioned above.

Posing as legitimate trading platforms, the AppleJeus malware is actually designed to steal cryptocurrency from victims, and has been around since 2018.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK’s Cybersecurity Sector Experiences Record Growth

UK’s Cybersecurity Sector Experiences Record Growth

The UK’s cybersecurity sector attracted record levels of investment last year, despite the challenges posed by the COVID-19 pandemic, according to a government study.

The latest DCMS Annual Cyber Sector Report revealed there was a record £821m of investment raised by companies in this field across 73 deals in 2020, more than doubling the amount recorded in 2019.

This investment helped enable a 21% increase in cybersecurity firms operating in the UK in the period of April 2019 to December 2020, taking the total number up to 1483. There was also a 9% rise in employment in the sector, with over 3800 new full time jobs created, taking the total number of UK cyber-jobs to 46,683. A large majority (65%) of this workforce are employed by large firms that have 250+ employees, according to the analysis.

The sector in the UK is now estimated to be worth £8.9bn, with its total annual revenue rising by 7% in the most recent financial year. It also contributed over £4bn to the economy in this period, an increase of 6%.

The report also outlined the most commonly provided cybersecurity products and services by these companies, which included cyber-professional services, threat intelligence, monitoring, detection and analysis. Additionally, there was a significant growth in companies offering solutions for industrial control systems and IoT security, pointing to future requirements to secure smart cities.

Commenting, digital minister Matt Warman, said: “The need for cutting-edge cybersecurity has never been greater and this resilient sector is growing, diversifying and solidifying its status as a jewel in the UK’s tech crown.

“With more than 3800 new jobs created, firms – large and small – are doing vital work keeping people and businesses secure online so we can build back safer from the pandemic. 

“I am committed to supporting the industry to reach new heights, create more jobs and lead new innovations in this field.”

Julian David, chief executive officer, techUK, added: “Reliable cybersecurity is essential for all organizations as they accelerate digital transformation in the wake of ongoing COVID-19 disruption and the UK industry is responding to that need. This research shows a sector going from strength to strength, with increasing investment in our growing cyber-ecosystem and, perhaps most significantly, uptake of the technologies and services keeping UK citizens and business safe.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Singtel Breach Hits 129,000 Customers

Singtel Breach Hits 129,000 Customers

Singtel has revealed that 129,000 customers were impacted by a recently disclosed breach, as well as a handful of employees, partners and corporate customers.

The APAC telco giant first notified last week that it was affected by a malicious campaign which appears to have targeted multiple customers of a legacy third-party file-sharing system.

Yesterday it confirmed that over 100,000 customers had personal information compromised, including Singaporean ID cards (NRIC), names, dates of birth, mobile numbers and addresses.

Also exposed in the breach were the bank account details of 28 former Singtel employees, the credit card details of 45 employees of a corporate customer and unspecified information on 23 suppliers, partners and corporate customers.

The firm’s CEO, Yuen Kuan Moon, said it had already begun notifying those affected.

“Given the complexity and sensitivity of our investigations, we are being as transparent as possible and providing information that is accurate to the best of our knowledge,” he added. “I want to emphasize that our core operations and functions remain unaffected and sound and this incident involves a standalone system provided by a third-party vendor.”

Other organizations said to have been impacted by exposure to the same product, Accellion’s FTA platform, include the New Zealand central bank and US legal giant Jones Day, although the latter denies it was compromised.

Although attackers appear to have compromised the New Zealand bank in early January via a vulnerability patched in late December, the same isn’t true of Singtel.

It claimed that the threat actors exploited a zero-day vulnerability which it only found out about when Accellion informed the telco on January 23.  

“Singtel immediately took the system offline. On January 30, Singtel’s attempt to patch the new vulnerability in the FTA system triggered an anomaly alert. Accellion informed thereafter that the system could have been breached,” it explained.

“Singtel’s investigations later confirmed this and identified January 20 as the date the breach occurred. The FTA system has been kept offline since January 23. On February 9, Singtel established that files were taken as a result of the breach and informed the public two days later on February 11.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk