Tenable Announces Intent to Acquire Alsid

Tenable Announces Intent to Acquire Alsid

Tenable Holdings today announced that it has entered into a definitive agreement to acquire Active Directory security startup Alsid SAS for $98m in cash.

Alsid specializes in providing a Software as a Service (SaaS) solution that monitors the security of Active Directory in real time. The company was founded in France in 2016 by two former incident responders from the French National Cybersecurity Agency (ANSSI), Emmanuel Gras and Luc Delsalle. 

After securing €13m in Series A funding in 2019, Alsid entered into a period of growth. Once the planned acquisition has been completed, Alsid users will benefit from a more comprehensive approach to cybersecurity readiness, according to Gras, Alsid’s CEO. 

“We started Alsid to help organizations solve one of the biggest security challenges, an unprotected Active Directory, which is one of the most common ways for threat actors to move laterally across enterprise systems,” said Gras.

“Our approach has always focused on helping our customers anticipate future attacks so they can keep their business running as usual. We believe Tenable cherishes this same vision of cybersecurity, and we’re excited to join forces and to have the opportunity to provide our users with a better, more complete approach to cyber preparedness.”

Tenable chairperson and CEO Amit Yoran said that the acquisition is timely as exploiting user privileges via Active Directory is a popular tactic among today’s cyber-attackers. 

“Tightly controlling the privileges of accounts in Active Directory is as foundational to reducing risk to the business as the basic blocking and tackling of deploying security updates. As we’ve seen with the flurry of hacks, ranging from the sophisticated SolarWinds compromise all the way down to common ransomware attacks, attackers go after the Active Directory infrastructure to increase access and establish persistence,” said Yoran.

“We’re impressed with the insights that Alsid brings to enterprise customers and look forward to working with the Alsid team to add this critical element to Cyber Exposure and risk management.”

The acquisition is expected to close earlier in the second quarter of 2021, subject to regulatory approval. It will be Tenable’s second acquisition as a public company following the acquisition of Indegy in 2019.

Tenable Holdings today announced that it has entered into a definitive agreement to acquire Active Directory security startup, Alsid SAS, for $98 million in cash.

Alsid specializes in providing a Software as a Service (SaaS) solution that monitors the security of Active Directory in real time. The company was founded in France in 2016 by two former incident responders from the French National Cybersecurity Agency (ANSSI), Emmanuel Gras and Luc Delsalle. 

After securing €13m in Series A funding in 2019, Alsid entered into a period of growth. Once the planned acquisition has been complete, Alsid users will benefit from a more comprehensive approach to cybersecurity readiness, according to Gras, Alsid’s CEO. 

“We started Alsid to help organizations solve one of the biggest security challenges, an unprotected Active Directory, which is one of the most common ways for threat actors to move laterally across enterprise systems,” said Gras.

“Our approach has always focused on helping our customers anticipate future attacks so they can keep their business running as usual. We believe Tenable cherishes this same vision of cybersecurity, and we’re excited to join forces and to have the opportunity to provide our users with a better, more complete approach to cyber preparedness.”

Tenable chairperson and CEO Amit Yoran said that the acquisition is timely as exploit user privileges via Active Directory is a popular tactic among today’s cyber-attackers. 

“Tightly controlling the privileges of accounts in Active Directory is as foundational to reducing risk to the business as the basic blocking and tackling of deploying security updates. As we’ve seen with the flurry of hacks, ranging from the sophisticated SolarWinds compromise all the way down to common ransomware attacks, attackers go after the Active Directory infrastructure to increase access and establish persistence,” said Amit Yoran.

“We’re impressed with the insights that Alsid brings to enterprise customers and look forward to working with the Alsid team to add this critical element to Cyber Exposure and risk management.”

The acquisition is expected to close earlier in the second quarter of 2021, subject to regulatory approval. It will be Tenable’s second acquisition as a public company following the acquisition of Indegy in 2019.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Researcher Hacks Apple and Microsoft

Researcher Hacks Apple and Microsoft

A researcher claims to have hacked into the internal systems of major companies including Apple and Microsoft using a novel supply chain attack. 

Alex Biran created malicious node packages and uploaded them to the npm registry under unclaimed names. The node packages collected information through their preinstall script about the machines upon which they were installed. 

Next, Biran came up with a way to get the packages to send information back to him. 

“Knowing that most of the possible targets would be deep inside well-protected corporate networks, I considered that DNS exfiltration was the way to go,” wrote Biran.

The data was hex-encoded and used as part of a DNS query, which reached the researcher’s custom authoritative name server, either directly or through intermediate resolvers. Biran then found private package names inside JavaScript files. 

“Apple, Yelp, and Tesla are just a few examples of companies who had internal names exposed in this way,” Biran wrote.

In the latter half of 2020, Biran scanned millions of domains belonging to targeted companies and extracted hundreds of JavaScript package names that hadn’t been claimed on the npm registry. He uploaded his malicious code to the package-hosting services and achieved a success rate that he described as “simply astonishing.”

“Squatting valid internal package names was a nearly sure-fire method to get into the networks of some of the biggest tech companies out there, gaining remote code execution, and possibly allowing attackers to add backdoors during builds,” said Biran.

“This type of vulnerability, which I have started calling dependency confusion, was detected inside more than 35 organizations to date, across all three tested programming languages.” 

The vast majority of affected companies employed over a thousand people.

“This is an incredibly serious industry-wide problem,” Craig Young, principal security researcher at Tripwire, told Infosecurity Magazine. 

“When software development firms allow their employees to download and start working with arbitrary coding modules from public repositories, they are exposing themselves to both security and legal risks. In this case, it was a researcher with an innocuous ‘phone home’ payload, but it could have just as easily been an APT deploying a malware implant or a patent troll deploying a commercially licensed algorithm.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hacker Admits Stealing College Girls’ Nude Snaps

Hacker Admits Stealing College Girls’ Nude Snaps

A man from New York has admitted hacking into the social media accounts of female college students and stealing intimate photographs to trade online.

Over a two-year period, Rochester resident Nicholas Faber compromised the accounts of dozens of women attending State University of New York (SUNY) Plattsburgh to access videos and images in which his victims appeared in a state of undress. 

The 25-year-old did not commit his crimes alone. Faber admitted working with co-conspirator Michael Patrick Fish from 2017 to 2019 to hack into victims’ school email accounts. The men then used the information contained within those email accounts to gain access to victims’ social media accounts, including their private messages.

Faber and Fish trawled their victim’s accounts for any embarrassing videos and photographs and any images or footage in which the victims appeared nude. Both men admitted stealing these compromising images and trading them online with other people. 

Fish, who is also aged 25, reportedly further exploited victims by creating and selling collages featuring personal photos of the victims, sexually explicit images, and formal graduation photos. 

As a result of Fish and Faber’s crimes, the university had to allocate money and staff to identifying accounts that had been compromised, reviewing computer and server access logs, resetting passwords, and notifying students and parents of the security breach.

Faber, who obtained an undergraduate degree from SUNY Plattsburgh, graduating in 2017, yesterday pleaded guilty to one count of computer intrusion causing damage and one count of aggravated identity theft. He has agreed to pay $35,430 in restitution to SUNY Plattsburgh.

Fish, who was a student at SUNY Plattsburgh between 2016 and 2019 and later attended Albany Law School, pleaded guilty on May 19, 2020, to computer hacking, aggravated identity theft, and child pornography offenses.

On January 29, 2021, Fish was  further charged with obstruction of justice and violating release conditions after allegedly submitting six fraudulent letters attesting to his own good character to US District Judge Mae D’Agostino. 

Among the individuals allegedly impersonated by Fish in the letters were a Catholic priest, a top aide to US Representative Elise Stefanik, and the defendant’s own mother and grandparents.

Sentencing for Fish is scheduled for March 19, while Faber is due to be sentenced on June 9.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Identity Verification Firm Veriff Appoints Amish Mody as New CFO

Identity Verification Firm Veriff Appoints Amish Mody as New CFO

Estonia-based online identity verification company Veriff has announced the appointment of Amish Mody as its new chief financial officer (CFO).

Mody joins Veriff from FinTech firm Monese, where he served as VP of finance for five years, overseeing the company’s development from pre-launch to a headcount of several hundred, with operations in four countries.

At Veriff, Mody will head the financial planning, accounting, business intelligence and other finance-related matters of the organization.

“I am really excited to join Veriff, especially because I see a huge growth potential for the whole identity verification industry as the global digitalization has accelerated over the last year,” Mody said.

“So far I’ve experienced the ID verification business from a client’s perspective, and now I’ll get to see the other side. Any fast growing and successful company needs a great team – the enthusiasm, professionalism and friendliness of Veriff’s people made the decision to join the journey an easy one for me,” he added.

Veriff’s founder and CEO, Kaarel Kotkas, commented: “Veriff has been growing fast, on a global scale, and financial management has a key role to play. With Amish on board, we have an experienced CFO who knows the startup world inside out and has been working in the finance world on a global scale. He’s got a unique background and I am glad he can join our team in Estonia.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Credential Theft Attacks Doubled Between 2016 and 2020

Credential Theft Attacks Doubled Between 2016 and 2020

The number of attacks resulting in large-scale credential theft has almost doubled over the past four years, although the volume of breached login pairs declined, according to F5.

The security vendor’s 2021 Credential Stuffing Report warned that although average breach volumes declined from 63 million records in 2016 to 17 million in 2020, poor security practice is driving downstream risk exposure.

Perhaps unsurprisingly, plaintext storage of passwords was responsible for by far the greatest number of spilled credentials (43%), followed by unsalted SHA-1 hashed passwords (20%), while discredited hashing algorithm MD5 still remains surprisingly common.

Organizations are also poor at detecting breach attempts: median time to discovering a credential spill between 2018 and 2020 was 120 days, while the average time to discovery was 327 days.

This matters, because once credentials are in the hands of cyber-criminals, they can use them to crack open consumer accounts across the web.

An Akamai report from 2020 claimed that over 60% of the 100 billion credential stuffing attacks detected over the previous two years were targeted at retail, travel and hospitality businesses, with retail accounting for over 90% of these.

A separate report from the vendor from 2019 estimated that credential stuffing attacks cost EMEA organizations on average $4m each year through application downtime ($1.2m), lost customers ($1.6m) and IT security overtime ($1.2m), as well as the cost of follow-on fraud.

“Credential spills are like an oil spill: once leaked, they are very hard to clean up because credentials do not get changed by unassuming consumers, and credential stuffing solutions are yet to be widely adopted by enterprises,” said Sara Boddy, senior director of F5 Lab.

“It is not surprising that during this period of research, we saw a shift in the number one attack type from HTTP attacks to credential stuffing. This attack type has a long-term impact on the security of applications and is not going to change any time soon.”

F5 also warned that attackers are increasingly using “fuzzing” techniques to optimize credential exploit success by checking variants of a stolen password as well as the original.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Romance Fraud Surges in Lockdown Following Shift to Online Dating

Romance Fraud Surges in Lockdown Following Shift to Online Dating

Bank transfer romance fraud rose 20% year-on-year between January and November 2020, according to new figures from UK Finance.

Published shortly before this year’s Valentine’s Day, the trade association revealed that the total value of this type of scam – in which victims are duped into sending money to criminals who have convinced them they are in a genuine relationship – has increased by 12% to £18.5m.

In addition, the UK’s national fraud and cybercrime reporting center, Action Fraud, said it has received a rise in reports from the general public who have fallen victim to romance fraud last year, with total reported losses in excess of £68m. As well as bank transfers, other ways of losing money included sending fraudsters gift cards, vouchers and presents, and providing them with access to their bank account or card.

This rise in romance scams is linked to the growing number of people who have turned to online dating amid ongoing social distancing restrictions during COVID-19. For instance, the Online Dating Association (ODA) has estimated that over 2.3 million Brits used dating apps during the first lockdown. This has provided more opportunities for cyber-criminals to launch scams, often manipulating people they pretend to have a romantic interest in by playing on their emotions, such as claiming they need money for emergency medical care.

The ODA also observed that over half of people in its survey are having longer conversations on dating sites during lockdown, enabling scammers more opportunities to build a relationship with victims over time.

Katy Worobec, managing director of economic crime at UK Finance, explained: “With the rising use of online dating service users during lockdown, criminals are using clever tactics to exploit people who think they’ve met their perfect partner online.

“Romance scams can leave customers out of love and out of pocket, but there are steps people can take to keep themselves or their family and friends safe – both on and offline. People can help their loved ones spot the signs of a scam, particularly as romance scammers can be very convincing by forming an emotional attachment with their victims.”

Pauline Smith, head of Action Fraud, commented: “Last year, we sadly saw criminals exploit the coronavirus pandemic as a means to commit fraud, and romance fraud was no exception. The national lockdowns, and other restrictions on our social lives implemented because of the coronavirus outbreak, have meant more people have been seeking companionship online and this has undoubtedly affected the number of reports we have seen.

“It’s important to say that most online dating sites, social media sites and gaming apps are perfectly safe. However, any online platform that allows you to connect with and talk to other people could be targeted by romance fraudsters, so it’s important to remain vigilant.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Scammers Selling Fake #COVID19 Vaccination Cards for Just $20

Scammers Selling Fake #COVID19 Vaccination Cards for Just $20

Fraudsters are setting up Shopify-backed online stores to sell fake COVID-19 vaccination cards to anti-vaxxers, according to DomainTools.

Due to the decentralized nature of the US healthcare system, the cards, which carry the logo of the US Centers for Disease Control and Prevention (CDC), were judged to be the simplest way the authorities can keep track of who has had the jab.

Yet with 13% of Americans stating they will refuse the vaccine, there has now emerged a black market for those who still want to enjoy the benefits immunisation will bring as towns and cities start to relax lockdowns.

The security firm claimed to have seen authentic-looking cards selling for as little as $20 each on domains like covid-19vaccinationcards[.]com, which features a Let’s Encrypt TLS certificate.

“Though selling a printed card is not necessarily illegal, the pricing, logo and cardstock of these ‘vaccination records’ demonstrate a level of intent to pass as legitimate cards from the CDC,” explained DomainTools senior security researcher, Chad Anderson.

“The DomainTools research team has reached out to Shopify regarding this site and is monitoring for similar instances of COVID-19 vaccine cards.”

Those already in receipt of legitimate cards have been posting photos on social media, leading to warnings from fraud experts that scammers may be able to copy batch numbers and other details to help craft counterfeits.

Anderson claimed DomainTools has observed over 18,500 Shopify stores selling COVID-themed products, including fraudulent home tests and non-medical grade PPE, although not all of these are illegal/counterfeit.

“As scams continue to shift with these new themes, we urge users to be extra vigilant when signing up for medical services online as many phishing scams, both over text message and email, are already appearing leveraging COVID-19 vaccinations as a lure,” concluded Anderson.

“Furthermore, we’d encourage you to not pay for anything through a web portal if it isn’t through your official healthcare provider.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Zero-Day and Six Publicly Disclosed CVEs Fixed by Microsoft

Zero-Day and Six Publicly Disclosed CVEs Fixed by Microsoft

Microsoft has fixed 56 CVEs as part of this month’s Patch Tuesday, including several already publicly disclosed and one zero-day being actively exploited in the wild.

Although the workload is relatively light for sysadmins this month, there’s plenty to be concerned about.

The zero-day is CVE-2021-1732, a Windows Win32k.sys elevation of privilege vulnerability affecting Windows 10 and Windows Server 2019. Although rated as “important” rather than critical by Microsoft, its active exploitation should push it up to the top of the priority list.

Windows DNS Server remote code execution (RCE) vulnerability CVE-2021-24078 should be second on the to-do list, according to Recorded Future senior security architect, Allan Liska.

“This vulnerability impacts Windows Server 2008 through 2019. This is a critical vulnerability to which Microsoft has assigned a CVSS score of 9.8,” he added.

“Similar to SIGRed, which was disclosed last year, this vulnerability can be exploited remotely by getting a vulnerable DNS server to query for a domain it has not seen before — e.g. by sending a phishing email with a link to a new domain or even with images embedded that call out to a new domain.”

There are six additional CVEs in total for which proof-of-concept code or other information has been publicly released which could help attackers develop an exploit.

CVE-2021-1733 is a bug in Sysinternals PsExec which could allow an attacker to elevate their privileges. PSExec is commonly used in “living off the land” techniques for lateral movement.

Next come a couple of CVEs in .Net Core (RCE bug CVE-2021-26701) and .Net Core and Visual Studio (Denial of Service flaw CVE-2021-1721).

An information disclosure bug in DirectX (CVE-2021-24106) affects Windows 10 and Server 2016 and newer systems, while an elevation of privilege vulnerability in Windows Installer (CVE-2021-1727) impacts Windows 7 and Server 2008 and newer operating systems.

Finally, Microsoft fixed a DoS vulnerability in Windows Console Driver (CVE-2021-24098).

Ivanti senior director of product management, Chris Goettl, highlighted the importance of the .Net Core and PSExec fixes.

“As these development and IT tools do not follow the same update process as OS and application updates it is important to review your DevOps processes and determine if you are able to detect and respond to updates for common dev components,” he explained.

“For tools like PsExec it is important to understand your software inventory and where these tools are installed and ensure you can distribute updated versions as needed.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk