High Demand for Hacker Services on Dark Web Forums

High Demand for Hacker Services on Dark Web Forums

Nine in 10 (90%) users of dark web forums are searching for a hacker who can provide them with a particular resource or who can download a user database. This is according to new research by Positive Technologies, which analyzed activity on the 10 most prominent forums on the dark web, which offer services such as website hacking and the buying/selling of databases.

The study highlights the growing demand for hackers’ services and stolen data, exacerbated by the increased internet usage by both organizations and individuals since the start of COVID-19.

Gaining access to a web resource was found to be the most common goal of dark web forum users, with this making up 69% of ad inquiries. Obtaining user or client databases from a targeted resource was the next most frequent type of inquiry, comprising 21% of all ads. The researchers noted that the parties most interested in acquiring this type of information were competitors and spammers who collect lists of addresses for targeted phishing attacks aimed at a specific audience.

Just 7% of forum messages involved individuals offering their services to hack websites while 3% were focused on promoting hacking tools, programs and finding like-minded people for sharing hacking experience.

In addition, a consistently high demand for access to online store sites was observed, with prices ranging from $50-$2000 for purchasing and selling hacking services and website access. This is fuelled by the fact that users enter their credit card details on such sites, providing attackers with the opportunity to inject malicious JavaScript code into these websites to intercept the information entered, according to the researchers.

Positive Technologies analyst Yana Yurakova commented: “Since March 2020, we have noticed a surge of interest in website hacking, which is seen by the increase in the number of ads on forums on the dark web. This may have been caused by an increase in the number of companies available via the internet, which was triggered by the COVID-19 pandemic. As a result of this, organizations that previously worked offline were forced to go online in order to maintain their customers and profits, and cyber-criminals, naturally, took advantage of this situation.”

Vadim Solovyov, senior information security analyst at Positive Technologies, added: “Insufficient web application security and the ability of criminals to easily find an experienced hacker or a ready-made tool for hacking a web resource pose an undoubted threat to both users and companies. Hacking a company’s web applications can lead to global consequences, ranging from data leaks to penetrating the company’s local network and using its resources in subsequent attacks.”  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Tanium Adds Matt Thompson to Board of Directors

Tanium Adds Matt Thompson to Board of Directors

IT endpoint management and security provider Tanium has announced that Matt Thompson has joined its board of directors.

Thompson joins as an independent director and will help the firm scale as it works toward its next chapter of growth. He most recently held the role of executive vice-president of worldwide field operations at Adobe and currently sits on the board of NCR and Ellucian.

“Having worked closely throughout my career with C-suite executives, I’ve seen firsthand the evolving complexity that an expanding IT landscape presents,” said Thompson. “Tanium’s open endpoint management platform delivers exactly what business leaders working in a complex environment crave: a solution that easily plugs into the existing tech stack to give them real-time visibility and control across their endpoint landscape.

“I look forward to being a member of the board of directors and helping accelerate the next chapter of Tanium’s growth.”

Commenting on the announcement, Tanium co-founder and CEO, Orion Hindawi, said he is thrilled to welcome Thompson’s deep sales, marketing and partnership knowledge to the company.

“His impressive scale and growth mindset aligns with Tanium’s vision for the future and his GTM knowledge will be indispensable to Tanium as we focus on serving a broader range of customers to provide manageability, security and insight where digital business begins, at the endpoint.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Council Will Drive UK’s Cyber-Training and Standards

New Council Will Drive UK’s Cyber-Training and Standards

A new independent body has been launched with the aim of boosting professional standards and career prospects for those working in cybersecurity.

The UK Cyber Security Council will be funded by the Department for Digital, Culture, Media & Sport (DCMS) as part of the government’s five-year National Cyber Security Strategy, designed to make the UK the safest place to live and work online.

The aim is to create a cyber-equivalent of the Law Society or the General Medical Council (GMC) – a single governing body that will help to advance the profession and help to provide a clear roadmap for those entering or progressing through roles in the cybersecurity industry.

It will work with training providers to accredit courses and qualifications, and give employers the information they need to recruit effectively, according to the government.

It will also work closely with GCHQ arm the National Cyber Security Center (NCSC).

“Cybersecurity is a growing industry in the UK and it’s vital for high standards of practice and technical expertise to be at the heart of the profession as it develops,” said NCSC deputy director for cyber-growth, Chris Ensor.

“We look forward to working with the council to help ensure that future generations of cybersecurity professionals have the skills and support they need to thrive and make the UK the safest place to live and work online.”

An inaugural board of trustees will help to guide the council’s work over the coming years. It includes former Diageo and Department for Work and Pensions CISO Claudia Natanson, Palo Alto Networks senior director, Carla Baker and former GlobalData chief analyst, Jessica Figueras.

“Having spent many years in cybersecurity, I’m very aware of the excellent work done by many varied organizations – but I’m also conscious that the time for an umbrella organization has come in order to drive the profession forward in a unified way,” said council chair Natanson.

“It’s a privilege and a challenge to be part of the leadership of the council, knowing that the future security and prosperity of the UK depends in part on the council succeeding in its mission to develop the profession.”

The UK’s thriving cybersecurity sector is worth £8.3bn, according to a government report published a year ago.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyberpunk 2077 Developer Hit By Cyber-Attack

Cyberpunk 2077 Developer Hit By Cyber-Attack

Polish video game company CD Projekt has revealed it has fallen victim to a cyber-attack in which some of its internal systems have been compromised and a number of devices in its network encrypted.

The developer of the well-known video game Cyberpunk 2077 reported the incident in a tweet this morning, also publishing a ransom note left by the attackers. In the message, the hackers claimed to have accessed the source code for the games Cyberpunk 2077, Witcher 3, Gwent and an “unreleased version of Witcher 3” as well as “documents relating to accounting, administration, legal, HR, investor relations and more!” They threatened to sell or leak this information online if “we will not come to an agreement.”

However, CD Projekt said it is refusing to negotiate with the attackers, adding that it is investigating the incident in collaboration with IT forensic specialists and has informed the relevant authorities of the breach. It acknowledged that “certain data belonging to CD Projekt capital group” was taken and that some devices in its network had been encrypted, although its backups remain intact and it has started the process of restoring the data.

The company also confirmed that “to its best knowledge” no personal data of users of its services have been compromised.

In the statement, CD Projekt said: “We will not give in to the demands nor negotiate with the actor, being aware that this may eventually lead to the release of the compromised data. We are taking necessary steps to mitigate the consequences of such a release, in particular by approaching any parties that may be affected due to the breach.”

Commenting on the incident, Jake Moore, cybersecurity specialist at ESET, outlined: “This is quite possibly the eventuality that CD Projekt have been expecting for some time. As frustrating as it must be, it appears that the company has the correct protocol in place to withstand such demands and upheaval, and are refusing to pay the attackers. All good businesses have critical redundancies in place to mitigate the risk and this can only be truly simulated by testing the backups regularly and red teaming the company.

“We unfortunately live in a world where very little remains untouchable but the forward thinking decision makers understand this risk and spend money and time in reducing the impact.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Experts Warn of “Beg Bounty” Extortion Attempts

Experts Warn of “Beg Bounty” Extortion Attempts

Sophos has warned businesses to be on the lookout for unsolicited and often generic emails attempting to extract a bug bounty from them with borderline extortion tactics.

So-called “beg bounty” messages typically involve automated scanning for basic misconfigurations or vulnerabilities, followed by a cut-and-paste of the results into a pre-defined email template, explained Sophos principal research scientist, Chester Wisniewski.

Small businesses are typical targets: even though they do not have a bug bounty program, and perhaps because of this fact, the senders often believe they may be more inclined to pay.

“Beg bounty queries run the gamut from honest, ethical disclosures that share all the needed information and hint that it might be nice if you were to send them a reward, to borderline extortion demanding payment without even providing enough information to determine the validity of the demand,” said Wisniewski.

“Knowing these businesses did not have a bug bounty program and in fact probably didn’t even know what code ran their website, it seemed odd for a legitimate researcher to be wasting their time on the smallest fish in the pond.”

The Sophos scientist was able to gather and analyze a few sample beg bounty incidents, which featured varying degrees of professionalism. Some leant more towards extortion and one contained factually inaccurate information, referring to an organization’s lack of DMARC as a “vulnerability in your website.”

Wisniewski warned of reports claiming that engaging with the bounty hunter could lead to a slew of further bug reports and demands for more payment.

He urged small business owners to take the emails and the issues they raise seriously, but to not engage with the sender, and instead seek out a reputable security provider.

“Most of the bugs that were found were not even bugs. They were simply internet scans that discovered the lack of an SPF or DMARC record. Others were genuine vulnerabilities that could be easily found without skill by using freely available tools,” he concluded.

“None of the vulnerabilities I investigated were worthy of a payment. The problem is that there are millions of poorly secured sites owned by small businesses that don’t know any better and are intimidated into paying for services out of fear.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-Attacker Tries to Remotely Poison Florida City

Cyber-Attacker Tries to Remotely Poison Florida City

The cyber-risks associated with connected operational technology (OT) systems were laid bare on Monday after an unknown online assailant tried to remotely poison the water supply of a Florida city.

The attacker accessed the water treatment system for Oldsmar city in Pinellas County and tried to increase the amount of sodium hydroxide (lye) in the water almost 100-fold, officials said yesterday.

Also known as caustic soda, sodium hydroxide could cause vomiting, diarrhoea and damage to internal organs if swallowed.

An operator at the plant monitoring the system saw what he assumed to be his boss remotely accessing it at around 8am on Friday morning. Around five-and-a-half hours later the same worker was left bemused as their mouse suddenly started to move while a remote user tried to ramp up the lye levels in the water.

The operator immediately changed the levels back once the attacker had logged-off, according to Pinellas County sheriff Bob Gualtieri.

In any case, it would have taken more than a day for the sodium hydroxide to enter the water supply and redundancies in the system would have spotted the change in pH level and sounded the alarm, explained Oldsmar mayor, Eric Siedel.

“The important thing is to put everybody on notice,” he warned at the press conference. “That’s really the purpose of today, to make sure that everyone realizes that these bad actors are out there; it’s happening, so take a hard look at what you have in place.”

Stuart Reed, UK director of Orange Cyberdefense, argued that the Florida incident is what security experts have been warning about for years.

“The incident in Florida will go down as yet another near miss, but it is clear that critical infrastructure (CNI) will remain a key target for hackers – inaction can no longer be tolerated,” he said.

“CNI organizations need to ensure that a layered approach to cybersecurity is in place, focusing on installing the best and most up-to-date software and technology possible, supplemented by investment in both people and process.”

Karl Sigler, senior security research manager, SpiderLabs at Trustwave, added that any systems used for critical networks should have very limited internet access.

“User accounts and credentials used to authenticate locally on the workstation and for TeamViewer should be changed frequently and utilize multi-factor authentication,” Sigler explained.

“In this instance, it was lucky that the user was physically there to see the remote control and what settings had changed, but all critical activities should be audited, logged and monitored for abuse.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk