SonicWall Zero-Day

Hackers are exploiting zero-day in SonicWall:

In an email, an NCC Group spokeswoman wrote: “Our team has observed signs of an attempted exploitation of a vulnerabilitythat affects the SonicWall SMA 100 series devices. We are working closely with SonicWall to investigate this in more depth.”

In Monday’s update, SonicWall representatives said the company’s engineering team confirmed that the submission by NCC Group included a “critical zero-day” in the SMA 100 series 10.x code. SonicWall is tracking it as SNWLID-2021-0001. The SMA 100 series is a line of secure remote access appliances.

The disclosure makes SonicWall at least the fifth large company to report in recent weeks that it was targeted by sophisticated hackers. Other companies include network management tool provider SolarWinds, Microsoft, FireEye, and Malwarebytes. CrowdStrike also reported being targeted but said the attack wasn’t successful.

Neither SonicWall nor NCC Group said that the hack involving the SonicWall zero-day was linked to the larger hack campaign involving SolarWinds. Based on the timing of the disclosure and some of the details in it, however, there is widespread speculation that the two are connected.

The speculation is just that — speculation. I have no opinion in the matter. This could easily be part of the SolarWinds campaign, which targeted other security companies. But there are a lot of “highly sophisticated threat actors” — that’s how NCC Group described them — out there, and this could easily be a coincidence.

Were I working for a national intelligence organization, I would try to disguise my operations as being part of the SolarWinds attack.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NoxPlayer Android Emulator Supply-Chain Attack

It seems to be the season of sophisticated supply-chain attacks.

This one is in the NoxPlayer Android emulator:

ESET says that based on evidence its researchers gathered, a threat actor compromised one of the company’s official API (api.bignox.com) and file-hosting servers (res06.bignox.com).

Using this access, hackers tampered with the download URL of NoxPlayer updates in the API server to deliver malware to NoxPlayer users.

[…]

Despite evidence implying that attackers had access to BigNox servers since at least September 2020, ESET said the threat actor didn’t target all of the company’s users but instead focused on specific machines, suggesting this was a highly-targeted attack looking to infect only a certain class of users.

Until today, and based on its own telemetry, ESET said it spotted malware-laced NoxPlayer updates being delivered to only five victims, located in Taiwan, Hong Kong, and Sri Lanka.

I don’t know if there are actually more supply-chain attacks occurring right now. More likely is that they’ve been happening for a while, and we have recently become more diligent about looking for them.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

South Carolina Plans Cyber-Ecosystem

South Carolina Plans Cyber-Ecosystem

The University of South Carolina (UofSC) has struck up a partnership with the Palmetto State to develop a statewide cyber-ecosystem aimed at making South Carolina a highly competitive player in the cyber-industry.

The new alliance was announced Thursday, February 4, by South Carolina governor Henry McMaster and the University’s president, Bob Caslen. Under the ecosystem, the efforts of South Carolina’s public and private organizations operating in the cyber-field will be aligned according to one unified vision. 

“The university looks forward to joining government and industry in this critical statewide effort,” said Caslen. “As South Carolina’s flagship university, we are uniquely positioned to help develop the future cyber-workforce the state needs as well as inform stakeholders on emerging cyber-research and best practices that impact security and the state’s economy.”

An initial study to inventory the state’s cyber-assets, analyze key strengths and gaps, and form a development strategy was announced by McMaster at a State House press conference. The study will take a reading of South Carolina’s current cyber-ecosystem by recording verticals in defense partnerships, investment, education, public awareness, and workforce and industry development.

“This statewide cyber-strategy is an opportunity to develop a cyber ecosystem that trains, attracts, and produces a workforce for the knowledge economy’s high-tech, high-paying jobs,” said McMaster. “Cyber-professionals are in high demand, and through these efforts we can make South Carolina one of the nation’s premier cyber-hubs.”

Key public and private stakeholders in the cyber industry will be selected to join a coordinating committee whose role it will be to guide the study, support data collection, and conduct an assessment of the state’s cyber-assets. The results of the study will form the basis of a plan to improve cyber-coordination, capability, and capacity across South Carolina. 

South Carolina’s cyber-assets include the Naval Information Warfare Center in Charleston and the recently announced Savannah River National Laboratory collaboration involving the US Department of Energy and three South Carolina universities.

Bill Kirkland, executive director of UofSC’s Office of Innovation, Partnerships, and Economic Engagement, said that the University’s long-term plans include the creation of a new asset: a Cyber Institute that will combine education, research, outreach, and workforce development.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-Attack on Woodland Trust

Cyber-Attack on Woodland Trust

A charity that protects and restores woodland in England, Northern Ireland, Scotland, and Wales has been targeted by a “sophisticated, high level” cyber-attack. 

According to a security incident notification published by the Woodland Trust on its website, attackers gained unauthorized access to the charity’s IT systems in December. 

An investigation is under way to determine what, if any, data held by the Trust was compromised. Upon learning of the incident, the charity disconnected all of its IT systems in an effort to prevent any further unauthorized access from occurring. 

“We believe the incident took place after 7pm on 14 December,” stated the charity in its security notification. “As soon as we became aware of the incident, we took immediate action to mitigate the impact, appointing a number of third-party experts including forensic IT specialists and legal counsel, to determine the nature of the criminal activity.”

The charity did not give a timeline for when the investigation into the incident will be completed.

Trust members were told: “Investigations of this nature take time due to the complexity of the work being carried out. As soon as new information becomes available, we will of course share further updates with you. 

“In the event of confirmed data loss, we will identify and inform those affected immediately, in accordance with GDPR.”

While the notification does not specify the type of information that may have been compromised in the attack, its wording suggests that contact details and financial data belonging to Trust members may have been exposed. 

“We understand this news will concern and worry our members and supporters. We would like to reassure you we are doing all we can to determine fully the nature and scope of the incident as quickly as possible, including as a priority what data, if any, may have been impacted,” states the notice.

“As a precaution, we are encouraging all our supporters to be mindful of any suspicious activity, especially unexpected emails or phone calls from unknown sources or purporting to come from your bank.”

The charity said that relevant authorities have been notified of the attack, including the Information Commissioner’s Office, the Charity Commission, and the police.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

National Cyber League Expands HBCU Scholarship Program

National Cyber League Expands HBCU Scholarship Program

America’s National Cyber League has announced a new set of scholarships to help financially disadvantaged students at historically black colleges and universities (HBCUs) compete in its latest competition.

Last fall, the non-profit organization collaborated with HBCUs to award scholarships to more than 60 students so they could participate in the NCL games. Today, the NCL announced that it has expanded this collaboration by committing to offering 150 HBCU students scholarships to take part in its springtime competition. 

“HBCU computer science students may be stressed about their future careers. How will they land a good job in these crazy times of a pandemic and racial unrest?” states the NCL website

“One way to stand out from the crowd is by taking advantage of the learning and community engagement of the NCL games.”

The gesture equates to a total grant of $5,250, as regular registration for the event costs $35 per person. The deadline for applications is March 1, 2021.

The National Cyber League is a virtual collegiate offensive and defensive cybersecurity capture-the-flag competition featuring nine different categories that align with the CompTIA Security+ and the NIST NICE framework. The categories are open source intelligence, cryptography, log analysis, password cracking, network traffic analysis, scanning, forensics, web application exploitation, and enumeration and exploitation. 

Powered by content and platform partner Cyber Skyline, the NCL games attract more than 10,000 student participants from over 550 schools across the United States. 

Students who take part receive individual scouting reports that detail the skills they have demonstrated while competing. Included in the document is the student’s national rank, score, flag capture, flag attempts, and accuracy in the competition.

These reports can be presented as proof of practical experience by students who go on to apply for jobs in the cybersecurity industry. 

Participants are sorted into four ability categories during a week-long pre-season game that starts on March 15. Students then take place in an individual game that generates their scouting report. Each participant is then offered the opportunity to join or create a team with others from their school and compete against other schools in a three-day team game that starts on April 9. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

BA Data Breach Victims Granted Extension to File Claims

BA Data Breach Victims Granted Extension to File Claims

Victims of the two British Airways (BA) data breaches in 2018 have been granted an additional two months to file a compensation claim after the Group Litigation Order (GLO) window was extended.

The claims relate to two breaches recorded back in 2018: between August and September 2018, it was revealed that 380,000 transactions were compromised and later, 185,000 customers were notified that their personal and financial details were exposed between April and July 2018. Data compromised included payment card information, such as card numbers, expiry dates, and (in tens of thousands of cases) the CVV security code, as well as customer names, billing addresses and email addresses.

Evidence has been given by the defendant’s solicitor at the GLO application hearing that the total number of unique payment cards that may have been affected is 429,420.

Last month, Consumer action law firm Your Lawyers, which is leading the action, reported that the UK-based airline is planning to begin settlement discussions that could lead to a compensation pay-out of up to £3bn. However, BA responded with a statement continuing to deny liability and setting out their intention to fight the litigation.

The original deadline to join the GLO was April 3, but this has now been moved to June 3 2021. Beyond that date, affected customers will no longer be able to automatically join this group litigation.

The extension has been granted to allow new claimants to prepare their cases following a huge surge in sign-ups recently.

Your Lawyers has estimated that the average compensation award for each claimant could be around £6000, ranging from £500 to £15,000. This would leave BA with a total bill of up to £2.4bn.

Aman Johal, director at Your Lawyers, commented: “With affected customers given an additional two months to join the GLO, they should act without delay.

“It is concerning that BA continues to defend the litigation despite the fact their legal representatives have written to the court to express their intentions to enter into settlement negotiations. The impact and, therefore, the value of claims arising from this breach cannot be understated. Victims can suffer considerable distress when personal and sensitive information is exposed and they are at risk of being targeted for fraud and theft. It is a serious issue, and many of the thousands of clients that we represent have suffered severe consequences after a breach event. Many have fallen victim to fraud and have been forced to change how they use services forever.

“It is time for the airline to publicly acknowledge what they must privately accept – that they are liable and will have to pay compensation.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Experts: Foxtons Breach Was Egregor Ransomware

Experts: Foxtons Breach Was Egregor Ransomware

A widely reported data breach from last year at Foxtons Group was due to a ransomware attack by the Egregor group, according to threat intelligence experts.

The incident made the news this week after reports revealed a customer of the high street estate agent discovered a large number of customers’ personal and financial info on the dark web.

This reportedly included over 16,000 card details, addresses and private messages, discovered by the individual on October 12 last year. A statement from Foxtons explained that its Alexander Hall mortgage broking business was hit by unspecified malware that same month but that all the data was judged to be old, incomplete and posed no danger to customers.

Tel Aviv-headquartered Kela has since been in touch with Infosecurity to reveal that the information was stolen as part of a ransomware attack on Foxtons.

Ransomware groups are increasingly stealing data before deploying their malware in so-called “double extortion” attacks designed to increase the pressure on corporate victims to pay up.

If victim organizations refuse to pay, then more data is usually leaked online.

“We don’t suspect that this is a separate incident than the ransomware attack that occurred several months back, especially since the ‘customer’ that shared this data said he found it online on October 12, the same day that the victim was posted on Egregor’s blog,” Kela’s spokesperson explained.

They did question why only 1% of the data allegedly stolen had been posted online so far. However, a note on the group’s blog claims that data is being sold privately.

In any case, the link to the original data is currently broken and the Egregor group blog had previously been taken offline for several weeks, leading some to speculate that its operations may have been deliberately disrupted.

Egregor first came to light in September/October 2020 just as the infamous Maze group was winding down its operations. Attacks on US bookstore Barnes & Noble and video game developers Ubisoft and Crytek presaged scores of successful compromises around the world.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Data Sharing Critical to AI’s Use in Cybersecurity

Data Sharing Critical to AI’s Use in Cybersecurity

Strategies for enabling the effective use of AI technologies in cyber-defense were highlighted by a panel of experts during the RSAC 365 webinar ‘AI Meets Cybersecurity: Crossing the Streams and How to Manage the Dynamic Results.’

The panellists firstly outlined the fact that the growth in AI tools has negative as well as positive connotations. While organizations are increasingly using AI to detect and predict threats across their networks, such tools are also readily available to cyber-criminals to discover any vulnerabilities in a system. In many respects, it is easier for malicious actors to achieve their aims through AI than defenders. Jermon Bafaty, CEO & founder of Platinum Technologies, commented: “If I as a bad actor have access to open source technologies that I can mess around with until I find that one thing in an application that might have been around for five years, I pretty much have the advantage.”

Heng Xu, professor of information technology and analytics at the American University highlighted a major issue surrounding a lack of data about attacks that have been carried out, which makes it difficult “to twin the models to better predict future attacks.”

In the view of Dr Chenxi Wang, general partner at Rain Capital, the focus should be on developing AI models that aren’t necessarily searching for threats, but will nevertheless be aware of their presence. “We need to build models to say what is normal and hence when we see something that is abnormal we can potentially flag it,” she stated.  

However, she noted we are still a long way from having an understanding of what is normal, as there are so many elements in an organization’s infrastructure that are connecting to different IP addresses. This makes it impossible to ascertain the “intended behavior of everything.” As such, Wang observed that “there is an urgent need for us to use data to really understand the intended behavior and profile for things inside our environment.”

A difficulty with getting to this point is that it requires significant information sharing, which if accessed by attackers, can be used against organizations. “It is this chicken and the egg problem,” noted Bafaty, adding “it’s a real challenge in trying to decipher and decide how much information we really share and to who.”

The speakers went on to discuss how AI can be utilized to redefine cyber-defense. Xu highlighted the importance of different organizations sharing data about their infrastructure, but being aware of the unique environments in which AI tools will operate in. “How can we transfer learning from one company or one giant dataset within one context and then deploy it with some adaptations to other contexts?” she asked.

It is critical, therefore, that methods for exchanging data safely between entities are developed. Wang added: “I’m hoping the new administration will start some meaningful initiatives for public and private data sharing, and potentially utilizing emerging tech will allow you to exchange data without sacrificing privacy.” This approach will ultimately enable more accurate AI prediction models to be built.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk