Michigan Computer Science Professor Charged with Sex Crime

Michigan Computer Science Professor Charged with Sex Crime

A professor of computer science and engineering at the University of Michigan has been charged with first degree sexual misconduct.

Peter Chen was arraigned on January 27 and given a personal recognizance bond. The 55-year-old professor has taught at the university for 27 years.

Dean of the College of Engineering, Alec Gallimore, announced to students and faculty that Chen had been placed on paid administrative leave on Thursday.

Ann Arbor police launched an investigation into the professor after allegations were made that Chen had sexually assaulted a minor whom he was coaching in robotics. 

According to the police, Chen began assaulting a female victim during the summer of 2017 when she was aged 11. The alleged sexual assaults continued into the fall of 2018, occurring mostly at Chen’s residence. 

Additional assaults allegedly occurred in a men’s bathroom during a field trip to the Ann Arbor wastewater treatment plant and in a location in Detroit where Chen and the victim were attending a robotics camp in April 2018. 

The mother of the alleged victim reported Chen to the police in November 2019. In the report, Chen is described as a family friend who attended the same church as the victim and her family. 

Chen, who denies the allegations of sexual misconduct with a minor, is being legally represented by Bloomfield Hills–based law firm Smith Blythe, PC, a dedicated criminal sexual conduct defense firm. 

His attorneys issued the following statement: “On January 26, 2021 Mr. Chen was made aware of the criminal sexual conduct allegations that had been made against him. He completely denies the allegations and has cooperated fully with the Ann Arbor Police Department to assist them in their investigation. 

“Mr. Chen is confident that the truth will prevail and that he will be fully exonerated. Mr. Chen thanks the numerous people who have reached out in support of him over the last few days.”

Chen became CSE department chair last year when the previous chair, Brian Noble, stepped down. Noble left his position following a February 2020 investigation by The Verge into allegations of sexual misconduct involving the university’s computer science instructor Jason Mars.

In a notice to students and faculty announcing Chen’s leave, U of M spokesperson Rick Fitzgerald wrote that “the continued allegations of misconduct involving CSE faculty are troubling.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Rapid7 Expands Cloud Security Portfolio with Acquisition of Alcide

Rapid7 Expands Cloud Security Portfolio with Acquisition of Alcide

Rapid7 has announced the acquisition of Kubernetes security provider Alcide.IO as part of efforts to enhance its cloud native security platform.

The deal is worth approximately $50m, subject to certain adjustments.

The announcement has come amid growing use of Kubernetes by developers in order to quickly develop containerized applications as part of the overall shift to the cloud.

Israel-based Alcide’s technology helps ensure Kubernetes security is fully embedded into the DevOps lifecycle to enable cloud applications to be employed rapidly and securely. It’s cloud workload protection platform (CWPP) offers real-time visibility and network monitoring, as well the ability to detect, audit and investigate security threats.

Rapid7 will now integrate this platform with its existing cloud security posture management (CSPM) and infrastructure entitlements (CIEM) capabilities, providing customers with a broader range of security tools to tackle threats to their cloud native applications.

Corey Thomas, chairman and CEO of Rapid7, commented: “We are thrilled to welcome Alcide to Rapid7. The technical talent within Israel’s cybersecurity ecosystem is unparalleled and we look forward to working together with the Alcide team to provide organizations with comprehensive cloud security that drives business growth and innovation.”

Amir Ofek, CEO at Alcide, added: “Today marks the beginning of an exciting new journey for Alcide. We are excited to join Rapid7 not only because of our shared commitment to providing customers with innovative and accessible cloud security solutions, but this also gives us an opportunity to bring our market-leading Kubernetes security platform to a broader set of customers.”

The deal represents Rapid7’s second acquisition of a cloud security vendor in the past year, following the purchase of cloud security posture management specialist DivvyCloud in April 2020.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

China Steals Personal Data of 80% of US Adults

China Steals Personal Data of 80% of US Adults

The Chinese government may have stolen personal data from 80% of adults in the United States, according to a 60 Minutes report that aired yesterday on American television and radio network CBS. 

In the report, former director of the US National Counterintelligence and Security Center, Bill Evanina, warned that the PRC is actively working to gather and exploit Americans’ DNA and other health information.

Evanina described how Chinese company BGI Group had approached six different states with offers to construct and operate coronavirus testing labs. The company accompanied the offers with promises to “make additional donations” to the states.

Suspicious of the offer and what the data collected may be used for, the former security official warned the states not to accept the Group’s proposal.

“We put out an advisory to not only every American, but to hospitals, associations, and clinics,” said Evanina. “Knowing that BGI is a Chinese company, do we understand where that data’s going?”

He added: “Current estimates are that 80% of American adults have had all of their personally identifiable information stolen by the Communist Party of China.” 

The 60 Minutes report described the quest to obtain and control humanity’s biodata—and, in turn, control health care’s future—as the new space race. The PRC has publicized its ambition to lead the world in DNA science and technology public in a manifesto. 

“They have something called Made in China 2025,” said former biochemist turned FBI Supervisory Special Agent Edward You, “and in these national strategies, they absolutely call out wanting to be the dominant leader in this biological age.” 

Special Agent You said that America could soon be dependent on the PRC for far more than PPE and face masks. 

“What happens if we realize that all of our future drugs, our future vaccines, future health care are all completely dependent upon a foreign source?” said You. 

Commenting to Infosecurity Magazine on the special report, Dirk Schrader, global VP at New Net Technologies, said: “Recent cyber-security research about the status of data protection in the health sector indicates that there is no real need for any foreign government to use advanced hacking methods to have access to personal health information (PHI) of US citizens. 

“For example, radiology data of approximately six million US citizens was discovered unprotected in late 2019, with no substantial improvement to that a year later. On top of that, the largest provider who had left its radiology archives connected to the public internet without any protection, is owned by a Chinese investor.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Facial Recognition Ethical Framework Launched by BSIA

Facial Recognition Ethical Framework Launched by BSIA

The British Security Industry Association’s (BSIA) video surveillance section has launched an ethical and legal use guide for Automated Facial Recognition (AFR).

The guide, recommended by the Organization for Economic Co-operation and Development, outlines the considerations organizations should make regarding the responsible use of facial recognition technology, encompassing useful terms, abbreviations and ethical issues.

The framework, designed to be accessible to both industry experts and the public, has a specific focus on the distinctive application types of verification and identification.

Dave Wilkinson, director of technical services at the BSIA, said: “This collaborative piece of work among industry experts has produced a guide with advice and recommendations on ethical and legal AFR usage, which will appeal to anyone in or out of the physical security industry. Its aim is to ensure it does not cause harm or discriminate against any persons in either a public or private setting.”

The use of AI is an exponentially growing part of daily life and we must ensure that all stakeholders are aware of the ethical and legal considerations of using these solutions, he added.

“If not, this beneficial technology could be misused, leading to loss of trust and increased skepticism of the technology. We want to make sure the general public know that this ethical and legal guidance is out there for companies to follow. Compliance with the law is paramount using when this technology, and this guide will provide companies with the basis to demonstrate their commitment to complying with the ethical realities, consequences and impacts of using an AI/AFR solution.”

Automated Facial Recognition: A Guide to ethical and legal use is available to download from the BSIA today.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Researchers Spot SonicWall Exploit in the Wild

Researchers Spot SonicWall Exploit in the Wild

Security researchers believe that they’ve observed attacks in the wild exploiting a recently discovered SonicWall vulnerability.

The technical Twitter account for global information assurance firm NCC Group posted yesterday referencing the original SonicWall advisory.

“We’ve identified and demonstrated exploitability of a possible candidate for the vulnerability described and sent details to SonicWall – we’ve also seen indication of indiscriminate use of an exploit in the wild – check logs,” it urged.

Followers of the account probed for more details, but NCC Group was careful not to disclose too much to potential cyber-criminals monitoring the situation.

It explained that monitoring logs for “source IPs hitting management interfaces you would not expect” would be a good place to start in trying to weed out the threat.

The news comes as SonicWall continued to update its customers on the status of the incident.

It noted on Friday that the presence of the zero-day in its SMA 100 series products remains unconfirmed. The security vendor first observed attacks on the secure remote access products “exploiting probable zero-day vulnerabilities,” when sophisticated threat actors targeted its own internal systems.

The update late last week claimed that some customer reports of potentially compromised SMA 100 series devices were actually the result of attackers using previously breached credentials.

“The SMA appliance, due to its nature and due to prevalence of remote work during the pandemic, effectively acts as a ‘canary’ to raising an alert about inappropriate access. These specific cases came to light through, and were mitigated by, MFA or End Point Control (EPC),” it said.

“This further emphasizes the importance of enabling these features, not only on the SMA series, but across the entire enterprise as a generally recommended security practice.  In the age of cloud services and remote work, credentials can be the key to the kingdom and attackers are keenly aware of this.”

SonicWall also clarified that although some recent social media posts have shared PoC exploit code and screenshots of allegedly compromised devices, this code is not effective against firmware updates released after a 2015 patch.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Trickbot Trojan Back from the Dead in New Campaign

Trickbot Trojan Back from the Dead in New Campaign

Security researchers are warning of a resurgence of prolific Trojan malware Trickbot, which had its infrastructure disrupted by a Microsoft-led coalition late last year.

Menlo Security said it had observed a new malicious spam campaign designed to trick North American users in the legal and insurance sectors into downloading the Trojan.

Whereas weaponized email attachments were a common feature of previous Trickbot campaigns, this one encourages users to click on a phishing link, which redirects them to a compromised server.

After sending users along a redirection chain, they’re finally presented with a web page warning them that they’ve been found guilty of an unspecified “traffic infringement.”

A large download button encourages them to click through to view the photos of their alleged  ‘negligent driving.’

“Clicking on the ‘Download Photo Proof’ button, downloads a zip archive with a malicious JavaScript file to the endpoint,” Menlo Security explained.

“The embedded JavaScript is heavily obfuscated, which has been a TTP typical of the Trickbot malware. If the user opens the downloaded JavaScript file, an HTTP request is made to the C&C server to download the final malicious binary.”

The initial URL and the C&C used in the campaign are both tracked on threat feed URLHaus as being associated with Trickbot, the researchers claimed. Worse, many of the URLs used in the attack aren’t yet being detected on VirusTotal, it said.

There were high hopes after Microsoft and other security vendors used a US court order to disable any IP addresses being used to host the bot, and “block any effort by the Trickbot operators to purchase or lease additional servers.”

However, without arrests of those behind a malicious campaign it is very hard to stop them rebuilding bot infrastructure elsewhere. It remains to be seen whether a similar law enforcement attempt to disrupt Emotet recently will be more successful.

“Where there’s a will, there’s a way. That proverb certainly holds true for the bad actors behind Trickbot’s operations,” concluded Menlo Security.

“While Microsoft and its partners’ actions were commendable and Trickbot activity has come down to a trickle, the threat actors seem to be motivated enough to restore operations and cash in on the current threat environment.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Global Government Outsourcer Serco Hit by Ransomware

Global Government Outsourcer Serco Hit by Ransomware

A multi-national outsourcing company that runs part of the UK’s COVID-19 Test and Trace system has been hit by ransomware, according to reports.

British services business Serco, which employs 50,000 staff and manages hundreds of contracts worldwide, confirmed to Sky News that it had suffered an attack. However, the firm did not comment on the impact or whether it had paid the ransom demand.

It did claim, however, that only its mainland European operations were impacted, meaning NHS Test and Trace was unaffected.

The news site caught wind of the incident after spotting a sample of the Babuk ransomware uploaded to VirusTotal. Apparently included was the ransom note addressed to Serco, in which the attackers claimed: “We’ve been surfing inside your network for about three weeks and copied more than 1TB of your data.”

The note reportedly hinted that Serco partners such as NATO and the Belgian army may have had documents exposed in the attack. However, there’s no evidence of any stolen information being published online as yet.

There’s relatively little information on new variant Babuk, although ransom fees are said not to have exceeded $85,000 in attacks to date. Its leak site claims the group doesn’t target hospitals, schools or companies with less than $4m in annual revenue, according to security vendor Cyberint.

Serco’s revenue of over £ bn in 2019 would have made the company an attractive target for ransomware.

The NHS Test and Trace program has been frequently criticized for slow test results and ineffective contact tracing. The government’s decision to centralize the process and bring the private sector in to run it rather than draw on the experience of local health authorities, also exasperated many experts.

However, health secretary Matt Hancock tweeted last week that over 90% of test results are being returned the next day and the same number of contacts are being reached and told to self-isolate.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk