Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
SolarWinds Orion Bug Allows Easy Remote-Code Execution and Takeover
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Five Critical Android Bugs Patched, Part of Feb. Security Bulletin
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
More SolarWinds News
Microsoft analyzed details of the SolarWinds attack:
Microsoft and FireEye only detected the Sunburst or Solorigate malware in December, but Crowdstrike reported this month that another related piece of malware, Sunspot, was deployed in September 2019, at the time hackers breached SolarWinds’ internal network. Other related malware includes Teardrop aka Raindrop.
Details are in the Microsoft blog:
We have published our in-depth analysis of the Solorigate backdoor malware (also referred to as SUNBURST by FireEye), the compromised DLL that was deployed on networks as part of SolarWinds products, that allowed attackers to gain backdoor access to affected devices. We have also detailed the hands-on-keyboard techniques that attackers employed on compromised endpoints using a powerful second-stage payload, one of several custom Cobalt Strike loaders, including the loader dubbed TEARDROP by FireEye and a variant named Raindrop by Symantec.
One missing link in the complex Solorigate attack chain is the handover from the Solorigate DLL backdoor to the Cobalt Strike loader. Our investigations show that the attackers went out of their way to ensure that these two components are separated as much as possible to evade detection. This blog provides details about this handover based on a limited number of cases where this process occurred. To uncover these cases, we used the powerful, cross-domain optics of Microsoft 365 Defender to gain visibility across the entire attack chain in one complete and consolidated view.
This is all important, because MalwareBytes was penetrated through Office 365, and not SolarWinds. New estimates are that 30% of the SolarWinds victims didn’t use SolarWinds:
Many of the attacks gained initial footholds by password spraying to compromise individual email accounts at targeted organizations. Once the attackers had that initial foothold, they used a variety of complex privilege escalation and authentication attacks to exploit flaws in Microsoft’s cloud services. Another of the Advanced Persistent Threat (APT)’s targets, security firm CrowdStrike, said the attacker tried unsuccessfully to read its email by leveraging a compromised account of a Microsoft reseller the firm had worked with.
On attribution: Earlier this month, the US government has stated the attack is “likely Russian in origin.” This echos what then Secretary of State Mike Pompeo said in December, and the Washington Post‘s reporting (both from December). (The New York Times has repeated this attribution — a good article that also discusses the magnitude of the attack.) More evidence comes from code forensics, which links it to Turla, another Russian threat actor.
And lastly, a long ProPublica story on an unused piece of government-developed tech that might have caught the supply-chain attack much earlier:
The in-toto system requires software vendors to map out their process for assembling computer code that will be sent to customers, and it records what’s done at each step along the way. It then verifies electronically that no hacker has inserted something in between steps. Immediately before installation, a pre-installed tool automatically runs a final check to make sure that what the customer received matches the final product the software vendor generated for delivery, confirming that it wasn’t tampered with in transit.
I don’t want to hype this defense too much without knowing a lot more, but I like the approach of verifying the software build process.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Medical Researcher Jailed for Selling Secrets to China
Medical Researcher Jailed for Selling Secrets to China

The United States has imprisoned a woman who admitted conspiring with her husband to steal secret research from an Ohio’s children’s hospital and selling the stolen data to China.
Hospital researcher Li Chen pleaded guilty in July 2020 to conspiring to commit wire fraud and to stealing scientific trade secrets related to exosomes and exosome isolation from Nationwide Children’s Hospital’s Research Institute for her own personal financial gain.
The 47-year-old former resident of Dublin, Ohio, was yesterday sentenced to 30 months in prison by a United States District Court.
Chen worked in a medical research lab at the Research Institute from 2007 to 2017. Her 50-year-old husband and co-conspirator, Yu Zhou, was employed in a separate lab at the Research Institute from 2008 until 2018.
Together the couple conspired to steal and then monetize research into exosomes, which play a key role in the research, identification, and treatment of a range of medical conditions, including liver fibrosis, liver cancer, and necrotizing enterocolitis, a condition found in premature babies.
Court documents state that after stealing the trade secrets, Chen conspired to monetize them by creating and selling exosome “isolation kits.”
Chen started a company in China to sell the kits and received benefits from the Chinese government, including the State Administration of Foreign Expert Affairs and the National Natural Science Foundation of China. She also applied to multiple Chinese government talent plans, which the Department of Justice said is a known tactic used by China to transfer foreign research and technology to the Chinese government.
In addition to serving a custodial sentence, Chen was ordered to pay $2.6m in restitution. The researcher will also forfeit approximately $1.25m, 500,000 shares of common stock of Avalon GloboCare Corp., and 400 shares of common stock of GenExosome Technologies Inc.
“This sentence should serve as a deterrent to anyone else committing similar acts that the FBI will work closely with our partners to ensure the United States remains a world leader in science and technology innovation,” said the special agent in charge of the FBI’s Cincinnati Division, Chris Hoffman.
Zhou and Chen were arrested in California in July 2019. Zhou has pleaded guilty to his part in the conspiracy and awaits sentencing.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Indiana Launches Cyber Blog
Indiana Launches Cyber Blog

The state of Indiana has launched a new blog to promote cybersecurity best practices and share tips on how to stay cyber-safe.
The Indiana Cyber Blog is hosted on the Hoosier State’s Cybersecurity Hub website, where residents can go to report a cybercrime, research cyber training courses and careers, and get the low-down on the latest digital threats.
Posts will cover a wide range of topics, including data privacy, identity theft awareness, strong password creation, and how to stay secure while working from home. There will also be Covid-era advice on such subjects as how to balance working from home while living with children who are attending school virtually.
A number of guest bloggers will be invited to share their particular expertise with readers. Among the talent already booked are the first African American woman to become chief information officer of NASA, and Tracy Barnes, Indiana’s state CIO.
“Every aspect of our lives, it seems, relies on computers and the Internet, and cybersecurity is at the heart of it all,” said Barnes. “As a digital transformation continues, the way we communicate with emails and texts on our phones and other electronic devices is changing rapidly.
“Our entertainment, shopping, and transportation, even our health and well-being depend on our personal information and being safe, secure, and protected from the reach of cyber criminals.”
Other special guests will include cybersecurity business owners, academic advisors, state officials, local government officials, and nationally recognized cybersecurity experts.
“Here in Indiana, we are fortunate to have a lot of incredible partners who have made such a huge difference in the cybersecurity field, in addition to lots of resources that can be found easily at www.in.gov/cyber to help everyone be cybersafe,” said Chetrice Mosley-Romero, Indiana’s cybersecurity program director.
“We’re pleased and excited to launch this blog along with a Twitter and Facebook account to get much-needed information about how cybersecurity affects us in every way, and more importantly, what each of us can do to protect ourselves, our family, and our employers.”
Blog visitors can sign up for a free subscription to receive notifications each time a new blog post is added.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
South Carolina County Still Reeling from January Cyber-Attack
South Carolina County Still Reeling from January Cyber-Attack

The road to recovery is proving to be a long one for a South Carolina county targeted by cyber-attackers last month.
Georgetown County’s network was brought down by cyber-criminals on January 23 in what officials described as a “major infrastructure breach.”
While 911 systems and operations at the Georgetown County Detention Center were unaffected by the attack, the county’s electronic systems and email were disrupted.
Ten days after the attack took place, cybersecurity experts are still working to recover systems and analyze the full extent of the breach, and county emails have not yet been restored.
County staff put in extra hours over the weekend to ensure payroll and other essential functions could be finished on time. Authorities said departments such as courts, the treasurer’s office, and the auditor’s office won’t be back online for at least another five days.
“County offices are utilizing a combination of mobile access points and other temporary equipment to continue operations to the greatest extent possible,” stated the county in a press release issued earlier today.
“The county’s administration is working on putting additional measures in place to provide departments with additional functionality until network issues can be completely resolved. It is still unknown when a complete resolution may be achieved.”
Although investigations into the attack are ongoing, the county said that so far, there has been “no indication that any personal information belonging to either employees or taxpayers was compromised in the cyber-attack.”
Members of the public have been asked to contact Georgetown County staff via phone until email issues are resolved.
Georgetown County, which is home to around 60,000 people, does have insurance against cyber-attacks.
A September 2019 ransomware attack on Jasper County, South Carolina, took weeks to resolve. Speaking in October 2019, county chairman Tom Johnson said: “Our safeguards and staff responded appropriately. Unfortunately, appropriately means shutting everything down.
“So, it’s created quite a nuisance and inconvenience and also, to some extent, an expense. But we haven’t written any checks to criminals.”
Georgetown County has not shared any details about what kind of malware was used in the cyber-attack.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
CISOs: Vendor Relationships a Factor in Ongoing Remote Working Dangers
CISOs: Vendor Relationships a Factor in Ongoing Remote Working Dangers

The IT infrastructure of UK businesses continues to be at high risk of cyber-attacks as a result of home working, according to a new study by Kaspersky. IT leaders highlighted a disconnect between organizations and security vendors as a primary factor in this ongoing risk.
The survey of 240 CISOs and 2000 UK workers showed that insecure staff behaviors remain prevalent, nearly a year since the mass shift to remote working as a result of COVID-19. Over one-third of employees said they are less sure of their employers’ security measures whilst working from home, with a similar proportion believing their organizations’ security protocols are less important when working remotely. As a result, more than a quarter of staff have bypassed their employers’ security measures to download unauthorized software and close to a third (30%) have connected to a mobile hotspot in order to get around security measures.
Security leaders appear to be aware of the scale of the problem, with almost three-quarters of CISOs surveyed recognizing that their employees are less likely to adhere to cybersecurity measures while working from home.
Interestingly, a substantial proportion of these security leaders pointed to a poor relationship with their cybersecurity vendors as a major reason for such insecure behaviors persisting. Almost six in 10 stated that they find it difficult to action the guidance provided by security vendors in relation to their business, while a similar proportion do not feel the information they receive from vendors is relevant to their organization in the first place.
Another stark finding from the survey was that 63% of security leaders found the information provided by vendors too complicated to even attempt to share with their staff, while 58% said they don’t believe vendors understand the threats their business faces.
David Emm, principal security researcher at Kaspersky, commented: “The fact that so many employees feel confident and safe enough to bypass the messages they’re being given by their employers is concerning. It would be easy to attribute the problem to this communication within enterprises, but we shouldn’t overlook the statistics relating to vendor understanding and messaging.
“If businesses and CISOs don’t feel they are receiving guidance and information that is tailored to their needs and resources, they’re less likely to translate the actual significance of cybersecurity to their colleagues. Given the ongoing reliance on remote working that we’re expecting in 2021, it’s vital that this relationship improves quickly.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Barclays: 2020 the Highest Year on Record for Scams
Barclays: 2020 the Highest Year on Record for Scams

A record number of scams were recorded in the UK last year, according to figures published by Barclays.
The banking giant recorded a particularly large growth in the amount of victims scammed in the second half of 2020, up by 66% compared with the first six months. This was fuelled by high value and complex scams, with fraudsters seeking to take advantage of the panic and uncertainty caused by the COVID-19 pandemic.
The analysis found that the types of scams resulting in the highest value claims were investment and impersonation (both 29%). Investment scams normally involve the use of cloned webpages that look legitimate, while in impersonation scams, victims are tricked into believing their account is at risk and end up moving their money into a supposed ‘safe account’. Impersonation scams were also the most commonly recorded by Barclays, representing 22% of all incidents.
Despite the increasing prevalence of fraud, with over a third (35%) of Brits admitting they have fallen victim to a scam, there is a significant reluctance to report incidents. According to the poll by Barclays, over half (54%) of those who have been scammed are too embarrassed to report the crime. The bank said that sharing stories to enable others to know what to look out for is crucial in fighting against fraud.
Jim Winters, head of fraud at Barclays, said: “With more and more Brits finding themselves the victim of fraud and scams, Barclays is challenging the stigma associated with being embarrassed and encouraging people to speak out about their experiences.
“There are actionable steps you can take to help protect yourself against being scammed. If you’re suspicious, talk to someone you trust. Don’t be afraid to admit to being duped into a scam. When you receive a suspicious email, phone call or text message, never assume it’s who you think. Most importantly, don’t ignore your concerns. If ever in doubt, speak out.”
To help encourage more victims to speak out, Barclay’s has partnered with well-known lexicographer and star of the TV show Countdown, Susie Dent.
Dent commented: “There are plenty of things that people could find embarrassing. Being mocked by some of Britain’s top comedians on national television could be one of them, or publishing a book full of spelling errors could be another, but being a victim of fraud and scams shouldn’t be. Through talking about our experiences, we can work to remove the harmful stigma and embarrassment that comes from being duped.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Social Media Oversharing Exposes 80% of Office Workers
Social Media Oversharing Exposes 80% of Office Workers

Over 80% of British and American employees overshare on social media, potentially exposing themselves and their organization to online fraud, phishing and other cyber-threats, according to Tessian.
The email security vendor polled 4000 UK and US professionals and interviewed 10 hackers specializing in social engineering to compile its latest research: How to Hack a Human.
It revealed that half of respondents share names and photos of their children, 72% mention birthdays and even more (81%) update their job status on social media.
Even worse, over half (55%) admitted they have public profiles on Facebook, and only one third (32%) have a private Instagram account.
An overwhelming majority (84%) post on social media every week and over two-fifths (42%) do so every day.
The report highlighted numerous ways scammers can use this readily available online information to target individuals; for example, by spoofing a senior exec in a new company they have just revealed as joining.
“Most people are very verbose about what they share online. You can find virtually anything,” explained MyCrypto security and anti-phishing expert, Harry Denley. “Even if you can’t find it publicly, it’s easy enough to create an account to social engineer details or get behind some sort of wall. For example, you could become a ‘friend’ in their circle.”
Even out of office messages, if they contain too much information, could be used against the individual, by giving the green light to a hacker to impersonate them online, Tessian warned.
The vendor claimed its own analysis reveals that social engineering attacks and wire fraud attacks both increased by 15% during the last six months of 2020, versus the previous six. Some 88% of respondents said they had received a suspicious email in 2020.
The vendor’s CEO, Tim Sadler, argued that the vast volume of personal information being shared online is making cyber-criminals’ jobs much easier.
“While all these pieces of information may seem harmless in isolation — a birthday post, a job update, a like — hackers will stitch them together to create a complete picture of their targets and make scams as believable as possible,” he added.
“Remember, hackers have nothing but time on their hands. We need to make securing data feel as normal as giving up data. We also need to help people understand how their information can be used against them, in phishing attacks, if we’re going to stop hackers hacking humans.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk