Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Google Forms Set Baseline For Widespread BEC Attacks
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Google Searches Expose Stolen Corporate Credentials
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
SVR Attacks on Microsoft 365
FireEye is reporting the current known tactics that the SVR used to compromise Microsoft 365 cloud data as part of its SolarWinds operation:
Mandiant has observed UNC2452 and other threat actors moving laterally to the Microsoft 365 cloud using a combination of four primary techniques:
- Steal the Active Directory Federation Services (AD FS) token-signing certificate and use it to forge tokens for arbitrary users (sometimes described as Golden SAML). This would allow the attacker to authenticate into a federated resource provider (such as Microsoft 365) as any user, without the need for that user’s password or their corresponding multi-factor authentication (MFA) mechanism.
- Modify or add trusted domains in Azure AD to add a new federated Identity Provider (IdP) that the attacker controls. This would allow the attacker to forge tokens for arbitrary users and has been described as an Azure AD backdoor.
- Compromise the credentials of on-premises user accounts that are synchronized to Microsoft 365 that have high privileged directory roles, such as Global Administrator or Application Administrator.
- Backdoor an existing Microsoft 365 application by adding a new application or service principal credential in order to use the legitimate permissions assigned to the application, such as the ability to read email, send email as an arbitrary user, access user calendars, etc.
Lots of details here, including information on remediation and hardening.
The more we learn about the this operation, the more sophisticated it becomes.
In related news, MalwareBytes was also targeted.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
DDoS-Guard To Forfeit Internet Space Occupied by Parler
Parler, the beleaguered social network advertised as a “free speech” alternative to Facebook and Twitter, has had a tough month. Apple and Google removed the Parler app from their stores, and Amazon blocked the platform from using its hosting services. Parler has since found a home in DDoS-Guard, a Russian digital infrastructure company. But now it appears DDoS-Guard is about to be relieved of more than two-thirds of the Internet address space the company leases to clients — including the Internet addresses currently occupied by Parler.

The pending disruption for DDoS-Guard and Parler comes compliments of Ron Guilmette, a researcher who has made it something of a personal mission to de-platform conspiracy theorist and far-right groups.
In October, a phone call from Guilmette to an Internet provider in Oregon was all it took to briefly sideline a vast network of sites tied to 8chan/8kun — a controversial online image board linked to several mass shootings — and QAnon, the far-right conspiracy theory which holds that a cabal of Satanic pedophiles is running a global child sex-trafficking ring and plotting against President Donald Trump. As a result, those QAnon and 8chan sites also ultimately ended up in the arms of DDoS-Guard.
Much like Internet infrastructure firm CloudFlare, DDoS-Guard typically doesn’t host sites directly but instead acts as a go-between to simultaneously keep the real Internet addresses of its clients confidential and to protect them from crippling Distributed Denial-of-Service (DDoS) attacks.
The majority of DDoS-Guard’s employees are based in Russia, but the company is actually incorporated in two other places: As “Cognitive Cloud LLP” in Scotland, and as DDoS-Guard Corp. based in Belize. However, none of the company’s employees are listed as based in Belize, and DDoS-Guard makes no mention of the Latin American region in its map of global operations.
In studying the more than 11,000 Internet addresses assigned to those two companies, Guilmette found that approximately 66 percent of them were doled out to the Belize entity by LACNIC, the regional Internet registry for the Latin American and Caribbean regions.
Suspecting that DDoS-Guard incorporated in Belize on paper just to get huge swaths of IP addresses that are supposed to be given only to entities with a physical presence in the region, Guilmette filed a complaint with the Internet registry about his suspicions back in November.
Guilmette said LACNIC told him it would investigate, and that any adjudication on the matter could take up to three months. But earlier this week, LACNIC published a notice on its website that it intends to revoke 8,192 IPv4 addresses from DDoS-Guard — including the Internet address currently assigned to Parler[.]com.
LACNIC has not yet responded to requests for comment. The notice on its site says the Internet addresses are set to be revoked on Feb. 24.
DDoS-Guard CEO Evgeniy Marchenko maintains the company has done nothing wrong, and that DDoS-Guard does indeed have a presence in Belize.
“They were used strongly according [to] all LACNIC policies by [a] company legally substituted in LACNIC region,” Marchenko said in an email to KrebsOnSecurity. “There is nothing illegal or extremist. We have employers and representatives in different countries around the world because we are global service. And Latin America region is not an exception.”
Guilmette said DDoS-Guard could respond by simply moving Parler and other sites sitting in those address ranges to another part of its network. But he considers it a victory nonetheless that a regional Internet registry took his concerns seriously.
“It appeared to me that it was more probable than not that they got these 8,000+ IPv4 addresses by simply creating an arguably fraudulent shell company in Belize and then going cap in hand to LACNIC, claiming that they had a real presence in the Latin & South American region, and then asking for 8,000+ IPv4 addresses,” he said. “So I reported my suspicions to the LACNIC authorities in early November, and as I have only just recently learned, the LACNIC authorities followed up diligently on my report and, it seems, verified my suspicions.”
In October, KrebsOnSecurity covered another revelation by Guilmette about the same group of QAnon and 8chan-related sites that moved to DDoS-Guard: The companies that provided the Internet address space used by the sites were defunct businesses in the eyes of their respective U.S. state regulators. In other words, the American Registry for Internet Numbers (ARIN) — the non-profit which administers IP addresses for entities based in North America — was well within its contract rights to revoke the IP space.
Guilmette brought his findings to ARIN, which declined to act on the complaint and instead referred the matter to state investigatory agencies.
Still, Guilmette’s gadfly efforts to stir things up in the RIR community sometimes do pay off. For example, he spent nearly three years documenting how $50 million worth of the increasingly scarce IPv4 addresses were misappropriated from African companies to dodgy Internet marketing firms.
His complaints about those findings to the African Network Information Centre (AFRINIC) resulted in an investigation that led to the termination of a top AFRINIC executive, who was found to have quietly sold many of the address blocks for personal gain to marketers based in Europe, Asia and elsewhere.
And this week, AFRINIC took the unusual step of officially documenting the extent of the damage wrought by its former employee, and revoking discrete chunks of address space .
In a detailed report released today (PDF), AFRNIC said its investigation revealed more than 2.3 million IPv4 addresses were “without any lawful authority, misappropriated from AFRINIC’s pool of resources and attributed to organizations without any justification.”
AFRINIC said it began its inquiry in earnest back in March 2019, when it received an application by the U.S. Federal Bureau of Investigation (FBI) about “certain suspicious activities regarding several IPv4 address blocks which it held.” So far, AFRNINIC said it has reclaimed roughly half of the wayward IP address blocks, with the remainder “yet to be reclaimed due to ongoing due diligence.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Kentucky Senior Arrested for Identity Theft
Kentucky Senior Arrested for Identity Theft

Two women in Kentucky have been arrested in connection with a year-long cybercrime operation involving stolen identities and fraudulent benefit claims.
An investigation was launched by police in West Buechel at the beginning of January when they received a call from a local branch of the bank BB&T to say that a fraudulently authorized check for nearly $40,000 had just been cashed.
Police traced the fraudulent check to 57-year-old Lori Davis and subsequently obtained a search warrant for her home.
West Buechel Detective Robert Monroe told local news source WDRB that a search of Davis’ residence led to the discovery of “lots of evidence of stolen mail, stolen identity.”
As a result of the search, a second female suspect, 70-year-old Julianna Whobrey, emerged. Upon searching Whobrey’s residence, police discovered evidence that included mail addressed to other people at locations all over the country.
Davis was charged with theft by deception and engaging in organized crime. Whobrey was charged on January 18 with trafficking in stolen identities, engaging in organized crime, misuse of computer information, intent to defraud to obtain benefits, receiving goods by fraud, and theft by deception.
Monroe said that the suspects were work colleagues who used their jobs in a Louisville mailroom to cover up their illegal activity. The pair allegedly bought stolen identities on the dark web then used them to fraudulently obtain unemployment benefits and cards pre-paid with thousands of dollars.
“These suspects both had other people’s unemployment applications from other states, specifically New York State Department of Labor,” Monroe said.
“These envelopes were addressed to different people at different addresses, and what they’re doing is collecting all the information out of this mail, and they’re actually creating people who either don’t exist, are dead, or people who do exist. And what they’re doing is they’re clogging up the dissemination of these benefits for people who actually need them.”
Police believe that the two women have been scamming victims for a year and were acting as money mules for a third suspect who resides in another country.
Monroe said: “I’m forwarding the case to the FBI with all I’ve gathered so far, and I’m going to work with them.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Trump Pardons Google Trade Secret Thief
Trump Pardons Google Trade Secret Thief

A former executive of Google subsidiary Waymo, imprisoned in the United States for stealing a trade secret and sharing it with rival company Uber, has been pardoned by outgoing president Donald Trump.
On March 19, 2020, Anthony Scott Levandowski pleaded guilty to one of 33 counts of trade secrets theft originally filed against him in 2019. The 40-year-old was sentenced to 18 months in jail and a 3-year period of supervised release by US District Judge William Alsup on August 4, 2020.
As per his plea agreement, Levandowski admitted that from 2009 to 2016 he worked in Google’s self-driving car program, known then as Project Chauffer, which had a confidentiality requirement.
Levandowski left the Google subsidiary to found his own business, Ottomotto, an autonomous driving hardware and software developer that was acquired by Uber Technologies in 2016 for $680m.
As part of his plea agreement, the entrepreneur admitted downloading thousands of Project Chauffer files onto his personal laptop prior to leaving Waymo. He also admitted downloading a variety of files from a corporate Google Drive repository.
Among these files was an internal tracking document entitled “Chauffeur TL weekly updates – Q4 2015” that contained confidential details regarding the status of Project Chauffer. Levandowski admitted that he downloaded this file with the intent to use it to benefit himself and Uber Technologies, Inc.
Levandowski further admitted that the stolen document was Google’s trade secret, and that stealing it caused the company to lose an estimated $1,500,000.
In addition to the custodial sentence, Judge Alsup ordered former exec Levandowski to pay a $95,000 fine and $756,499.22 in restitution to Waymo LLC, as Google’s self-driving program is now known.
Yesterday, Levandowski was one of 73 convicted criminals who were pardoned by President Trump on his final day in office.
In pardoning Levandowski, Trump wrote: “Mr. Levandowski pled guilty to a single criminal count arising from civil litigation. Notably, his sentencing judge called him a ‘brilliant, groundbreaking engineer that our country needs.’
“Mr. Levandowski has paid a significant price for his actions and plans to devote his talents to advance the public good.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US Marines Create “Blue Team”
US Marines Create “Blue Team”

The United States Marine Corps today announced the creation of a Marine Corps’ Adversarial Cyber Assessment “Blue Team” (MCAT).
A Blue Team is a group of people who identify security threats and risks in the operating environment and analyze the network environment and its current state of security readiness.
Using their findings and expertise, a Blue Team will typically provide recommendations that integrate into an overall community security solution to increase a customer’s cybersecurity readiness posture.
MCAT was established by Marine Corps Tactical Systems Support Activity (MCTSSA) and comprises eight to ten people from a variety of backgrounds, including cybersecurity, computer engineering, and information technology.
In a memo authorizing the new adversarial Blue Team designation, Commander of Marine Corps Forces Cyberspace Command Maj. Gen. M.G. Glavy said that the newly formed Blue Team will support Marine Corps Systems Command’s (MCSC’s) Programs of Record (PoRs), which enhances acquisitions’ cyber testing and evaluation capabilities.
The new team is authorized to perform evaluator, tester, and aggressor roles in accordance with the Mission Focused Cyber Hardening memo released in October 2019 by the Office of the Under Secretary of Defense Acquisition and Sustainment.
“This capability strengthens our acquisition cyber footprint while also enhancing our Corps’ operational cyber resiliency,” said MCTSSA commanding officer Lt. Col. Michael Liguori.
“The cyber ‘Blue Team’ is another example of MCTSSA’s dedication to support MCSC and our Corps’ cyber efforts in contested environments.”
MCAT will assess the security and defense of MCSC and Program Executive Officer Land Systems PoRs for systems in the field and for those that are still in the developmental test phase.
“I would agree that having the first cyber ‘Blue Team’ designation for the Marine Corps is an important step and I’m proud be a plank owner,” said Gunnery Sgt. Patrick McKelvey, staff non-commissioned officer in charge of the Test and Certification Division.
“It also enables MCTSSA to potentially increase manning for Defensive and Offensive Cyberspace Operators, those with the 17XX military occupational specialty, to support the mission.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Panel Reflects on How Orgs Should Approach Security in 2021
Panel Reflects on How Orgs Should Approach Security in 2021

The growing importance of ethical hacking in protecting organizations against the current threat landscape was discussed by a panel speaking during a HackerOne webinar entitled ‘Hacker Powered Security Predictions for 2021 EMEA.’
Moderator Mårten Mickos, CEO of HackerOne, firstly emphasized how the shift to digital, including remote working, had “opened up a lot of new attack surfaces and exposures to various forms of criminality.” In addition, the SolarWinds attack at the end of last year demonstrated just how interconnected everything is, with one security breach impacting numerous organizations throughout the world. Mickos added this showed “we are not really cyber-secure until everything is cyber-secure.”
Julien Ahrens, a full-time ethical hacker, believes that in this environment, organizations firstly must embrace transparency, clearly communicating when an attack has taken place or when a vulnerability has been discovered. He said: “If I’m going to report a security vulnerability in a system, then I would expect the company to be transparent about how they tackled the issue and when they plan to release a fix.” Ahrens added this approach can help ethical hackers like him to find further security issues.
Teemu Ylhaisi, CISO at OP Financial Group, concurred, saying this kind of external transparency is “vital” in the financial industry. “This is an area where financial institutions do not need to compete – we’re not competing against each other – we have a common enemy, the criminals, and we’re working together to fight them.”
In regard to the use of bug bounty programs to find vulnerabilities, both Ylhaisi and Ahrens acknowledged that many industries have some reluctance, but Ahrens noted that “as soon as you explain the principle and the details to stakeholders, they tend to agree.”
Mickos commented: “The best way to develop resistance to COVID-19 is to take the vaccine, and similarly, ethical hacking is the immune system of the internet – it’s better to take the ethical hackers and the reports that they give you than to allow a breach to happen.”
As well as bug bounty programs, Mickos highlighted the growth of vulnerability disclosure programs (VDPs), particularly favored by governmental organizations in the US. Here, “the organization will say anybody’s welcome to report vulnerabilities to us but we don’t promise to pay you anything.” Mickos added that “it’s a way of having an official channel for anybody who finds a flaw to report it.”
In the view of Ahrens, these can be useful for companies in learning about their security weaknesses, but generally won’t be as effective as paid bug bounty initiatives, “where you usually get the attention of hackers that are on more of a professional level.”
Looking ahead to the coming year, Ylhaisi outlined that “visibility, detection capabilities and the reaction to incidents is key” for organizations to protect themselves.
Early detection is critical as the panellists acknowledged that it is virtually impossible for organizations to block every potential pathway into a system. The best way of achieving this, according to Ylhaisi, is improving user awareness of staff, as the targeting of employees through tactics such as phishing is by far the most common cause of system breaches. He noted that staff at his company now report 35,000 email threats monthly. “This has helped us a lot to react at the very early phases,” he stated.
Summing up, Mickos compared the situation to being a soccer goalkeeper, stating “you cannot cover the whole goal but if you are very quick in your reactions and if you can predict where they [the cyber-criminal] will try, you can jump there to catch it.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
#Inauguration2021: Cyber-Experts React as Joe Biden Set to Become 46th US President
#Inauguration2021: Cyber-Experts React as Joe Biden Set to Become 46th US President

Today, January 20 2021, Joe Biden will be sworn in as the 46th President of the Unites States of America.
He and Vice-President-elect Kamala Harris will take their oaths of office on the West Front of the US Capitol.
The Inauguration Day celebrations will take place in unprecedented circumstances, with increased security measures following the January 6 attack on the US Capitol building and a variety of social distancing precautions due to the ongoing COVID-19 pandemic.
Experts in the cybersecurity field have commented on the key cybersecurity matters that are likely to play pivotal roles in the Biden/Harris administration over the next four years.
“The first days of 2021 have been marked by tumultuous events that have diverted attention and resources from what should be a safe and streamlined transfer of power,” said Andrew Rubin, CEO and co-founder, Illumio.
“On top of that, the US is dealing with the SolarWinds breach, which is perhaps the largest and most catastrophic single breach event our country has ever seen. Together, this has created a perfect storm for cyber-attacks and left the United States with a heightened level of cyber-risk, which threatens the safety and security of the country as a whole.”
Biden therefore has a huge amount of work to do in the cybersecurity area, with attacks at an all-time high against the US public and private sector, added Chris Morales, head of security analytics at Vectra.
“We did not improve the nation’s cybersecurity posture over the last four years,” he argued.
A key area of concern is the debate over end-to-end encryption and law enforcement, Morales continued. “The Trump administration believed that private industry should provide access to encryption, which fundamentally breaks personal privacy.”
Furthermore, at the end of Trump’s term, “he fired the top level cybersecurity official at DHS, Chris Krebs, who routinely countered Trump’s statements as contradictory. Chris Krebs did a great job of aligning government with industry and cybersecurity.”
Rubin argued that, moving forward, the US needs a more robust, multi-pronged strategy to mitigate future attacks that couples prevention and monitoring with an effective perimeter protection strategy for all critical entities.
“Given the current situation and vulnerabilities, the US should assume that bad actors are already in their environment. To keep people and information safe, the government should prioritize measures, like establishing deeper layers of security, that can mitigate the impact and spread of a breach.”
Morales concurred, adding: “I would like to see a pivot from cyber-warfare back to risk mitigation and personal privacy. While going on the offensive sounds like a deterrent, it is not aligned with how cyber-attacks truly occur.
“The target is a mix of public/private, and every organization is left to its own defenses. Attacks happen on home turf, not in a distant land where a military can wage war, and cyber-attacks end up hurting the end users more than the army waging war. It is good to have offensive capabilities, but we’ve got to shore up our own internal defenses first. For example, solving ransomware targeting local/state governments with small security staffs and lack of budget.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
