Capcom Data Breach May Have Impacted Extra 40k Customers

Capcom Data Breach May Have Impacted Extra 40k Customers

Gaming company Capcom has discovered that the number of customers whose data may have been compromised following a recent cyber-attack is much higher than previously thought. 

The Osaka-headquartered company became the victim of a ransomware attack in the beginning of November last year. 

On November 16, Capcom announced that it had verified that the personal information of 9 people had been compromised in this attack. A further 350,000 individuals were confirmed to be at risk of data compromise, including 134,000 customers who used the video game support help desk in Japan; 14,000 Capcom Store members in North America; 4,000 Esports website members in North America; 40,000 shareholders; 153,000 former employees, their families, and applicants; and 14,000 employees “and related parties” taken from HR.

In a third update to its ongoing investigation, issued on January 12, the company has now confirmed that the personal data of an additional 16,406 people had been exposed to cyber-criminals. Among the information exposed was names, addresses, phone numbers, email addresses of business partners, employees, and former employers, along with sales reports and game development documents.

Capcom added that the data of tens of thousands of additional individuals may have been exposed. The developer of Resident Evil stated that “the company has also ascertained that the potential maximum number of customers, business partners and other external parties etc., whose personal information may have been compromised in the attack is approximately 390,000 people (an increase of approximately 40,000 people from the previous report).”

None of the at-risk data was found to contain credit card information. Capcom said it does not maintain such information internally as the company’s online transactions are handled by a third-party service provider.

Capcom added: “Additionally, the areas that were impacted in this attack are unrelated to those systems used when connecting to the internet to play or purchase the company’s games online, which have continued to utilize either an external third-party server or an external server.”

The company offered its sincerest apologies for any complications and concerns that this latest update may bring to its potentially impacted customers as well as to its many stakeholders.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Mimecast Cert Abused to Target Inboxes in “Sophisticated” Attack

Mimecast Cert Abused to Target Inboxes in “Sophisticated” Attack

Mimecast has disclosed that some of its customers have been targeted by an advanced attack designed to compromise their Microsoft 365 (M365) environments.

The security vendor said in a brief statement yesterday that a “sophisticated threat actor” obtained one of its certificates used to authenticate Mimecast Sync and Recover, Continuity Monitor and IEP products to Microsoft 365 Exchange Web Services.

Although 10% of customers use this certificate, the attacker only targeted a “low single-digit number” of customer M365 tenants. These organizations have already been contacted by Mimecast to remediate the problem.

“As a precaution, we are asking the subset of Mimecast customers using this certificate-based connection to immediately delete the existing connection within their M365 tenant and re-establish a new certificate-based connection using the new certificate we’ve made available,” the statement continued.

“Taking this action does not impact inbound or outbound mail flow or associated security scanning.”

There’s no news yet on who might be responsible for this sophisticated attack and/or whether nation state actors were involved. SolarWinds revealed in a filing with the SEC last month that it had been notified by Microsoft of a compromise of its Office 365 emails via an unspecified “attack vector.”

“SolarWinds, in collaboration with Microsoft, has taken remediation steps to address the compromise and is investigating whether further remediation steps are required, over what period of time this compromise existed and whether this compromise is associated with the attack on its Orion software build system,” it explained at the time.

“SolarWinds also is investigating in collaboration with Microsoft as to whether any customer, personnel or other data was exfiltrated as a result of this compromise but has uncovered no evidence at this time of any such exfiltration.”

In the meantime, Mimecast said it has hired a third-party forensics firm to help with its investigation, and is working closely with Microsoft and law enforcement.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#COVID19 Led to Surge in Malware Attacks Last Year

#COVID19 Led to Surge in Malware Attacks Last Year

Malware authors continued to successfully leverage the COVID-19 pandemic last year to launch a wide variety of attacks, according to the 2020 Avira Report on Cybersecurity.

The cybersecurity firm detected that cyber-attacks went up by 15% last year compared to 2019, observing that the rate of scams rose and fell at the same rate and time as the virus appeared across the world. The peak rate of blocked attempts was in April, during the first wave of the pandemic.

As COVID-19 cases rose again in the final quarter of 2020, malware attacks correspondingly went up rapidly, with a correlation found between the number of attacks launched and the number of people working from home.

One major tactic utilized has been the development of special variants of well-known malware families that use COVID-19 lures to entice unsuspecting users to install them on their devices. An example highlighted in the study was a variant of the Android banking Trojan ‘Cereberus,’ which in many cases was distributed via phishing messages under the name ‘Corona-App.apk.’ The total number of Andorid banking Trojans detected in 2020 went up by 35% year-on-year, which the authors partially attributed to increasing use of mobile banking during the pandemic.

Looking ahead to the coming year, Avira said it expects stalkerware to become increasingly prevalent. This form of spyware, which can be installed without the knowledge or consent of the device owner, secretly monitors users and spies on personal information such as pictures, videos, messages and location data. A stealth mode enables the app to hide itself while in use.

Alexander Vukcevic, director of Avira Protection Labs, commented: “For many years, authors of malware have been using psychological tricks to lure unsuspecting users. Currently, we are in a situation where many people are looking for answers and are worried because of COVID-19. The authors of malware are specifically exploiting this uncertainty.” 

He added: “Banking Trojans have always played an important role in the Android malware scene and this year they had an even bigger presence. In addition to the strategy of using COVID-19 as a cover, they also use the classic approach: they disguise themselves as a widely used app and ask for unusual permissions in order to obtain credit card data, for example.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#CES2021: Raising the Bar on Privacy and Trust Online in 2021

#CES2021: Raising the Bar on Privacy and Trust Online in 2021

Big tech companies need to “raise the bar” on enhancing privacy and trust in their services in 2021. This was the message from a panel discussion at the Consumer Electronics Show (CES) 2021, which included representatives from Google, Twitter and Amazon.

This need for greater transparency has emerged as a result of the growing reliance on digital technology to conduct everyday life since the start of the COVID-19 crisis last year. This includes for work purposes and to be able to stay in touch with friends and family, trends that are set to stay in place in the future, at least to some degree. Anne Toth, director of Alexa Trust-Amazon, explained: “We’re seeing more and more cases where people are using our product for very important interactions…those kind of use cases raises the bar on how to be transparent on the privacy controls and the trustworthiness of the product.”

While privacy online has been a major issue for a number of years, the events of 2020 have really brought it to the fore. Keith Enright, chief privacy officer at Google, commented: “Users are feeling more nervous than they have in the past; they’re relying on technology more than they have in the past to live their lives and to do the things that are important to them.”

Tech companies therefore have a duty to help users feel safe online. As well as transparent privacy controls and data protection rules, Enright added it’s also vital to “work across industry and with regulators and others to identify opportunities where we can meaningfully improve the privacy and security that governs users’ behavior online.”

Additionally, the ways in which artificial intelligence (AI) and machine learning tools collect and share user data must be clearly displayed. Damien Kieranchief privacy officer at Twitter, said: “As those technologies become more ubiquitous to everything that we’re using and doing online, I think transparency in that space is going to be incredibly important.”

Privacy-related events and updates last year are also likely to have big implications for consumer tech firms going forward. This includes the development of new privacy laws in countries like the US, following the implementation of the GDPR in Europe, which will need to be navigated. Another significant event last year was the ruling that the US-EU privacy shield mechanism for data transfers was unlawful.

Kieran highlighted how such trends offer the potential for greater “balkanization” of the internet, where data and privacy are managed differently across regions. He commented: “There is the potential for a damaging impact, both to industry and to trust for consumers in terms of how these products and services work every day.” He added that helping users understand these changes is currently a major focus of Twitter.

The panellists also expressed a wish for a US Federal privacy law to be enacted over the next couple of years to help address this issue, particularly with the various US state laws now creating a “patchwork” of privacy legislation.

Looking towards the incoming Biden administration, Enright said that Google is looking for “strong consistent protections for individual rights, uniformity of controls, as its useful if users have a consistent experience when they’re interacting with online services wherever they are in the world.”

In terms of actions by tech firms themselves, Toth added that she expects there to be a continuous progression of privacy protocols, noting that at Alexa, “every product released is coupled with a privacy feature release.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Fixes Windows Defender Zero-Day Bug

Microsoft Fixes Windows Defender Zero-Day Bug

Microsoft has patched a zero-day bug in Windows Defender being actively exploited in the wild, as part of its monthly update round.

The first Patch Tuesday of 2021 featured fixes for 83 vulnerabilities in Windows OS, Edge, Office, Visual Studio, .Net Core, .Net Repository, ASP .Net, Azure, Malware Protection Engine and SQL Server.

Remote code execution bug CVE-2021-1647 is the most urgent, according to Chris Goettl, director of product management for security products at Ivanti. He recommended organizations ensure their Microsoft Malware Protection Engine is version 1.1.17700.4 or higher.

“Microsoft frequently updates malware definitions and the malware protection engine and has already pushed the update to resolve the vulnerability,” Goettl explained.

“For organizations that are configured for automatic updating no actions should be required, but one of the first actions a threat actor or malware will try to attempt is to disrupt threat protection on a system so definition and engine updates are blocked.”

Another CVE high up the priority list this month is CVE-2021-1648, a bug in the Windows splwow64 service that could allow an attacker to elevate their privilege level. Although publicly disclosed last month it isn’t thought to have been exploited yet.

Experts also highlighted CVE-2021-1666 as worthy of attention: the flaw in Microsoft’s GDI+ component impacts the unsupported Windows 7 and Windows Server 2008 products, as well as newer versions.

Allan Liska, senior security architect at Recorded Future, also flagged CVE-2021-1709, an elevation of privilege vulnerability in the Win32 kernel. The bug, which affects Windows 8-10 and Windows Server 2008-2019, should be prioritized despite its “Important” rating, he argued.

“Unfortunately, this type of vulnerability is often quickly exploited by attackers,” Liska warned. “For example, CVE-2019-1458 was announced on December 10 2019, and by December 19 an attacker was seen selling an exploit for the vulnerability on underground markets.”

Elsewhere, Adobe released fixes for vulnerabilities in its Adobe Bridge, Captivate, InCopy, Campaign Classic, Animate, Illustrator and Photoshop products. There was also a critical Mozilla Thunderbird update.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Healthcare Hit by 187 Million Monthly Web App Attacks in 2020

Healthcare Hit by 187 Million Monthly Web App Attacks in 2020

Web application attacks in the healthcare sector surged in December as distribution of the first COVID-19 vaccines began, according to new data from Imperva.

The security vendor claimed that attacks jumped 51% last month from detected volumes in November in a vertical that has been bombarded by cyber-criminals over the past year.

Four specific attack types saw the largest increases: cross-site scripting (XSS) detections jumped 43%; SQL injection attacks surged 44%; protocol manipulation attacks soared 76%; and remote code execution/remote file inclusion detections increased 68% in December.

XSS and SQLi attacks represented the number one and two threats detected by volume.

Imperva SVP Terry Ray claimed it had been an “unprecedented year” of cyber activity, with global healthcare organizations (HCOs) experiencing 187 million attacks per month on average. That amounts to nearly 500 attacks per HCO each month — a 10% increase year-on-year.

The US, Brazil, UK and Canada were the top countries targeted last year.

Like organizations in many sectors, HCOs have been looking to digital transformation to help them survive and adapt through an extraordinary year. However, their reliance on third-party applications to save time and money may also have exposed them, according to Ray.

“While there are sometimes business advantages to third-party applications, the risks include: patching only on the vendor’s timeline, known exploits that are widely publicized and constant zero-day research on widely used third-party tools and APIs,” he argued.

“Reliance on JavaScript APIs and third-party applications creates a threat landscape of more complex, automated, and opportunistic cybersecurity risks that are increasingly challenging for all organizations to detect and stop. And while ransomware attacks commonly land healthcare organizations in the news, it’s only the vulnerable application front-end to all healthcare data that experiences the variety and volume of daily attacks noted above.”

Ray also warned that many organizations may have a nasty surprise waiting for them as they start 2021, when the impact of December attacks start to become clear. HCOs’ focus in 2020 on supporting remote working and coping with the surge in COVID patients means less time may have been spent on incident response, he added.

In just the first three days of 2021, Imperva saw a 43% increase in data leakage.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cybereason to Adopt Intel’s PC Hardware Ransomware Solution

Cybereason to Adopt Intel’s PC Hardware Ransomware Solution

Cybereason has announced a new partnership with Intel to add new ransomware protections to its multi-layered defense platform.

Under the agreement, Cybereason will adopt Intel’s Hardware Shield protections for ransomware that are available on the 11th Gen Intel Core vPro mobile platforms. As a result, it can leverage Intel’s threat detection technology, enabling CPU-based behavioral prevention of ransomware. This solution is the first occasion in which PC hardware plays a direct role in ransomware cyber-defense.

It can now form part of Cybereason’s defense platform which combines detection and response, next gen anti-virus and proactive threat hunting.

The move comes amid rising and increasingly sophisticated ransomware attacks, with numerous high profile attacks recorded last year. Suspected victims of such attacks included a Massachusetts power station, French container shipping giant CMA CGM and English football club Manchester United. A study in October last year found that ransomware was the most observed threat in 2020.

Cybereason expects to be able to bring this collaboration to market during the first half of 2021.

Lior Div, CEO and co-founder, Cybereason, commented: “This collaboration with Intel to add CPU based threat detection bolsters our long history and industry-leading capabilities in detecting and eradicating ransomware. The combination of best-of-class hardware, software, and security know-how provides defenders with full-stack visibility critical to ending the era of double extortion that is currently costing organisations hundreds of millions each year.”

Stephanie Hallford, client computing group vice-president and general manager of business client platforms at Intel, said: “Ransomware was a top security threat in 2020, software alone is not enough to protect against ongoing threats. Our new 11th Gen Core vPro mobile platform provides the industry’s first silicon enabled threat detection capability, delivering the much needed hardware based protection against these types of attacks. Together with Cybereason’s multi-layered protection, businesses will have full-stack visibility from CPU telemetry to help prevent ransomware from evading traditional signature-based defenses.”

Last month, Cybereason announced it has adopted the Oracle Cloud Infrastructure to run its automated Cyber Defense Platform.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk