Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Linux Devices Under Attack by New FreakOut Malware
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Attackers Steal E-Mails, Info from OpenWrt Forum
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Injecting a Backdoor into SolarWinds Orion
Crowdstrike is reporting on a sophisticated piece of malware that was able to inject malware into the SolarWinds build process:
Key Points
- SUNSPOT is StellarParticle’s malware used to insert the SUNBURST backdoor into software builds of the SolarWinds Orion IT management product.
- SUNSPOT monitors running processes for those involved in compilation of the Orion product and replaces one of the source files to include the SUNBURST backdoor code.
- Several safeguards were added to SUNSPOT to avoid the Orion builds from failing, potentially alerting developers to the adversary’s presence.
Analysis of a SolarWinds software build server provided insights into how the process was hijacked by StellarParticle in order to insert SUNBURST into the update packages. The design of SUNSPOT suggests StellarParticle developers invested a lot of effort to ensure the code was properly inserted and remained undetected, and prioritized operational security to avoid revealing their presence in the build environment to SolarWinds developers.
This, of course, reminds many of us of Ken Thompson’s thought experiment from his 1984 Turing Award lecture, “Reflections on Trusting Trust.” In that talk, he suggested that a malicious C compiler might add a backdoor into programs it compiles.
The moral is obvious. You can’t trust code that you did not totally create yourself. (Especially code from companies that employ people like me.) No amount of source-level verification or scrutiny will protect you from using untrusted code. In demonstrating the possibility of this kind of attack, I picked on the C compiler. I could have picked on any program-handling program such as an assembler, a loader, or even hardware microcode. As the level of program gets lower, these bugs will be harder and harder to detect. A well-installed microcode bug will be almost impossible to detect.
That’s all still true today.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
New Charges Derail COVID Release for Hacker Who Aided ISIS
A hacker serving a 20-year sentence for stealing personal data on 1,300 U.S. military and government employees and giving it to an Islamic State hacker group in 2015 has been charged once again with fraud and identity theft. The new charges have derailed plans to deport him under compassionate release because of the COVID-19 pandemic.
Ardit Ferizi, a 25-year-old citizen of Kosovo, was slated to be sent home earlier this month after a federal judge signed an order commuting his sentence to time served. The release was granted in part due to Ferizi’s 2018 diagnosis of asthma, as well as a COVID outbreak at the facility where he was housed in 2020.
But while Ferizi was in quarantine awaiting deportation the Justice Department unsealed new charges against him, saying he’d conspired from prison with associates on the outside to access stolen data and launder the bitcoin proceeds of his previous crimes.
In the years leading up to his arrest, Ferizi was the administrator of a cybercrime forum called Pentagon Crew. He also served as the leader of an ethnic Albanian group of hackers from Kosovo known as Kosova Hacker’s Security (KHS), which focused on compromising government and private websites in Israel, Serbia, Greece, Ukraine and the United States.
In December 2015, Ferizi was apprehended in Malaysia and extradited to the United States. In January 2016, Ferizi pleaded guilty to providing material support to a terrorist group and to unauthorized access. He admitted to hacking a U.S.-based e-commerce company, stealing personal and financial data on 1,300 government employees, and providing the data to an Islamic State hacking group.
Ferizi gave the purloined data to Junaid “Trick” Hussain, a 21-year-old hacker and recruiter for ISIS who published it in August 2015 as part of a directive that ISIS supporters kill the named U.S. military members and government employees. Later that month, Hussain was reportedly killed by a drone strike in Syria.
The government says Ferizi and his associates made money by hacking PayPal and other financial accounts, and through pornography sites he allegedly set up mainly to steal personal and financial data from visitors.
Junaid Hussain’s Twitter profile photo.
Between 2015 and 2019, Ferizi was imprisoned at a facility in Illinois that housed several other notable convicts. For example, prosecutors allege that Ferizi was an associate of Mahmud “Red” Abouhalima, who was serving a 240 year sentence at the prison for his role in the 1993 World Trade Center bombing.
Another inmate incarcerated at the same facility was Shawn Bridges, a former U.S. Secret Service agent serving almost eight years for stealing $820,000 worth of bitcoin from online drug dealers while investigating the hidden underground website Silk Road. Prosecutors say Ferizi and Bridges discussed ways to hide their bitcoin.
The information about Ferizi’s inmate friends came via a tip from another convict, who told the FBI that Ferizi was allegedly using his access to the prison’s email system to share email and bitcoin account passwords with family members back home.
The Justice Department said subpoenas served on Ferizi’s email accounts and interviews with his associates show Ferizi’s brother in Kosovo used the information to “liquidate the proceeds of Ferizi’s previous criminal hacking activities.”
[Side note: It may be little more than a coincidence, but my PayPal account was hacked in Dec. 2015 by criminals who social engineered PayPal employees over the phone into changing my password and bypassing multi-factor authentication. The hackers attempted to send my balance to an account tied to Hussain, but the transfer never went through.]
Ferizi is being tried in California, but has not yet had an initial appearance in court. He’s charged with one count of aggravated identity theft and one count of wire fraud. If convicted of wire fraud, he faces a maximum penalty of 20 years in prison and a fine of $250,000. If convicted of aggravated identity theft, he faces a mandatory penalty of 2 years in prison in addition to the punishment imposed for a wire fraud conviction.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
No US Trial for Irish Hacker
No US Trial for Irish Hacker

The United States has withdrawn an extradition request for an Irish hacker convicted of breaking into virtual wallets to steal millions of dollars in cryptocurrency.
Conor Freeman was identified by US Homeland Security as one of at least five co-conspirators involved in a string of digital thefts that robbed multiple victims of their life savings in 2018.
Freeman was arrested at his Dublin home in May 2019 on a warrant issued by US authorities. Following his arrest, the hacker handed over stolen Bitcoin worth $2,187,977 to Gardaí.
Freeman, of Dun Laoghaire, pleaded guilty to stealing cryptocurrency, dishonestly operating a computer to make a gain, and knowingly engaging in the possession of the proceeds of crime. In November 2020, the 21-year-old was sentenced to three months in prison minus one month served in custody by Judge Martin Nolan in Dublin Circuit Criminal Court.
The US had asked Freeman to be surrendered and extradited to the United States to face charges of one count of conspiracy to commit wire fraud, four counts of aiding and abetting wire fraud, and four counts of aiding and abetting aggravated identity theft.
US authorities alleged that Freeman was a member of an organized online criminal gang called The Community that conspired to steal from targets they picked out on social media. The gang used SIM-swapping to gain control of a victim’s phone number, leveraging it to break into their virtual wallets.
A member of The Community, arrested in Michigan in May 2018, gave US authorities access to his computers. The member’s online chat records revealed an individual calling himself Conor was involved in the thefts.
IP addresses used by this Conor were linked to an Irish mobile phone and residential internet service providers used by Conor Freeman.
The High Court heard this morning that following his conviction in Ireland, the United States was no longer seeking to prosecute Freeman, who had no prior convictions.
Had Freeman been convicted in the US on all counts, the Dubliner could have been sentenced to a maximum of 108 years behind bars.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
EEMA Appoints Digital Identity Expert to Board of Management
EEMA Appoints Digital Identity Expert to Board of Management

EEMA, the leading independent European think tank focused on identity, privacy and trust, has announced the appointment of Steve Pannifer to its board of management. Pannifer, who is chief operations officer at Consult Hyperion, is renowned for his expertise in the field of digital identity.
Joining Consult Hyperion back in 1999, Pannifer has worked on numerous identity and payments initiatives for card schemes, banks and governments globally. He has also played a major role within the EEMA community, including as an advisory board member on the Horizon 2020 project. Additionally, he has chaired panel sessions with the ENISA and EEMA board management members Kim Cameron and Dave Birch during the EEMA Annual Conference in June 2020 as well as in EEMA’s ISSE 2020 webinar The European Single Identity System in November 2020.
Pannifer joins a host of big names in the field of identity and security who are part of the EEMA board of management. These include Hans Graux, partner at law firm Timelex, who was appointed in June last year.
Commenting on his appointment to the board, Pannifer said: “Through my work at Consult Hyperion I am fortunate to be involved in many interesting developments around the world, especially in identity and payments. My hope is that this will enable me to bring ideas and connections that will help to shape and guide EEMA’s future activities.
“EEMA presents a fantastic way to connect into the many digital identity and related developments across Europe and beyond. The combination of conferences, fireside sessions and projects is unique. As well as meeting people EEMA offers the chance to work with those people on forward looking projects.”
Jon Shamah, chair of EEMA, stated: “I am delighted to welcome Steve to the EEMA board of management. He is very well respected in the field of digital identity and has long been a generous contributor to our community, sharing his wealth of experience and expertise.”
Brussels-based EEMA provides events, projects, collaboration, education, engagement, communication, participation and networking for companies, the public sector and individuals as part of an effort to enable the building of enduring and mutually beneficial working relationships.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Health Insurer Fined $5.1m Over Data Breach
Health Insurer Fined $5.1m Over Data Breach

An American health insurer has agreed to pay $5.1m to the Office for Civil Rights (OCR) at the US Department of Health and Human Services (HHS) to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules.
The agreement entered into by Excellus Health Plan, Inc. relates to a data breach that lasted 17 months and affected over 9.3 million people.
Excellus is a New York–based health services corporation that provides health insurance coverage to over 1.5 million people in upstate and western New York.
A breach report filed by Excellus on September 9, 2015, stated that cyber-attackers had gained unauthorized access to the company’s information technology systems.
The breach began on or before December 23, 2013, and dragged on until May 11, 2015. After gaining entry to the company’s systems, malicious hackers installed malware and conducted reconnaissance activities that ultimately resulted in the disclosure of protected health information (PHI) of more than 9.3 million individuals.
Information exposed in the attack included names, addresses, dates of birth, email addresses, Social Security numbers, bank account information, health plan claims, and clinical treatment information.
Plans affected by the breach were BlueCard Members; BlueCross BlueShield of Central New York; BlueCross and BlueShield of the Rochester area; BlueCross BlueShield of Utica-Watertown; and Excellus BlueCross BlueShield.
OCR’s investigation into the security incident found potential violations of the HIPAA rules, including failures to implement risk management, information system activity review, and access controls and failure to conduct an enterprise-wide risk analysis.
“Hacking continues to be the greatest threat to the privacy and security of individuals’ health information. In this case, a health plan did not stop hackers from roaming inside its health record system undetected for over a year, which endangered the privacy of millions of its beneficiaries,” said OCR director Roger Severino.
“We know that the most dangerous hackers are sophisticated, patient, and persistent. Health care entities need to step up their game to protect the privacy of people’s health information from this growing threat.”
In addition to paying a sizable monetary settlement, Excellus has agreed to undertake a corrective action plan that includes two years of monitoring.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
NSA Appoints Cyber Director
NSA Appoints Cyber Director

The United States National Security Agency has announced the appointment of Roy Joyce as the new leader of its Cybersecurity Directorate.
Joyce will take over from Anne Neuberger, who was first to lead the NSA’s Cybersecurity Directorate when it was established in October 2019.
Neuberger was recently appointed Deputy National Security Advisor for Cyber and Emerging Technology for the National Security Council (NSC) by the incoming Biden administration.
Joyce has worked in NSA’s Cybersecurity and Signals Intelligence missions since 1989. Currently, he is serving as the NSA’s special liaison officer at the US Embassy in London. Prior to that he worked as a senior advisor for cybersecurity strategy to the NSA director.
In 2018 Joyce won a place on the Federal 100 list. At the time of his win, Joyce was a special assistant to the president and cybersecurity coordinator in the NSC for the Trump administration.
His role at the White House was to lead the development and implementation of national and international cybersecurity strategy and policy for the US, ensuring that the federal government was effectively partnering with the private sector, nongovernmental organizations, other branches and levels of government, and other nations. Joyce also served as deputy homeland security advisor and acting homeland security advisor.
From 2013 to 2017, Rob served as the chief of Tailored Access Operations (TAO), the NSA’s mission element that provided tools and expertise in computer network exploitation to deliver foreign intelligence. Prior to being named chief, he served as the deputy director of the Information Assurance Directorate (IAD) at the NSA, where he led efforts to harden, protect, and defend the nation’s most critical national security systems and improve cybersecurity for the nation.
Joyce has also spoken at major tech events, including the 2019 edition of the RSA conference, where he presented sessions on the weaponization of the internet and reverse engineering.
Outside of cybersecurity, Joyce is known for planning elaborate computerized light displays set to music over the holiday period. His 2020 festive efforts, titled “Notre Dame” and inspired by college football, were so impressive that NBC Sports shared a video on Twitter of the display in action.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
MoD Experiences 18% Growth in Personal Data Loss Incidents
MoD Experiences 18% Growth in Personal Data Loss Incidents

The UK’s Ministry of Defense (MoD) experienced an 18% rise in personal data loss incidents in the financial year 2019/20, according to official figures analyzed by the Parliament Street Think Tank.
The UK government’s defense department revealed there were 546 reported incidents of personal data loss during the last financial year, up from 463 in 2018/19. Seven of the incidents were reported to the Information Commissioner’s Office (ICO) owing to their serious nature.
The vast majority (454) of incidents were recorded under the category of unauthorized disclosure. A further 49 were classified under loss of inadequately protected electronic equipment, devices or paper documents from secured government premises, with another 19 reported from outside of government premises.
Of the seven most serious incidents reported to the ICO, one involved a sub-contractor incorrectly disposing of MoD originated material in July 2019, which led to the personnel and health data of two former employees being accidently disclosed. Another occurred when a recorded delivery package containing the claims for forms of five individuals was lost in transit between two stations in February 2020. A third example revolved around a whistleblowing report that had not been properly anonymized.
Commenting on the figures, Tim Sadler, CEO at Tessian, said: “Time and time again we see how simple incidents of human error can compromise data security and damage reputation. The thing is that mistakes are always going to happen. So, as organizations give their staff more data to handle and make employees responsible for the safety of more sensitive information, they must find ways to better secure their people.
“Education on safe data practices is a good first step, but business leaders should consider how technology can provide another layer of protection and help people to make smarter security decisions, in order to stop mistakes turning into breaches.”
The data is likely to add to fears over the vulnerability of public sector organizations to data breaches, particularly since the shift to remote working during COVID-19.
In December, Parliament Street reported that the Ministry of Justice (MoJ) had suffered 17 serious data breaches during the last financial year.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
