New Zealand Central Bank Breach Hit Other Companies

New Zealand Central Bank Breach Hit Other Companies

A data breach at New Zealand’s central bank affected other customers of a file-sharing service, potentially exposing sensitive information, it has emerged.

The Reserve Bank of New Zealand issued a brief statement on Sunday noting that the incident affected a third-party file-sharing service used by the institution.

Although the breach has been contained, an urgent investigation into the unauthorized access has begun.

However, in an update on Monday, it revealed the name of the vendor affected: Accellion. The Palo Alto-headquartered firm’s File Transfer Application (FTA) was targeted by malicious third parties, presumably going after the sensitive info stored and shared via the service.

“We are actively working with domestic and international cybersecurity experts and other relevant authorities as part of our investigation. This includes the GCSB’s National Cyber Security Center which has been notified and is providing guidance and advice,” said governor Adrian Orr, in a statement.

“We have been advised by the third-party provider that this wasn’t a specific attack on the Reserve Bank, and other users of the file sharing application were also compromised.”

Reports claim that a vulnerability in the legacy FTA product was patched by Accellion in mid-December, hinting that those customers affected in this attack may not have updated their systems.

“Many organizations in New Zealand are still quite conservative when it comes to cyber-protection – with increased infrastructure complexity and dependencies on modern systems, this makes them more susceptible to external attacks and to internal mistakes caused by the human factor,” argued Acronis CISO, Kevin Reed. 

“New Zealand is still ranked among the top 50 countries for cybersecurity, and has been stepping up on measures to boost its cyber-defenses, taking part in intelligence sharing with other major countries around the world – which, ironically, makes it a juicy target for attackers.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Third Malware Strain Discovered as Part of SolarWinds Attack

Third Malware Strain Discovered as Part of SolarWinds Attack

Security researchers have uncovered yet another malware strain used by Russian attackers to compromise SolarWinds.

Sunspot was used by attackers to inject the Sunburst backdoor code into the vendor’s Orion platform without setting off any internal alarms, CrowdStrike said in a blog post yesterday.

According to the security firm, which did not attribute the attack to anyone, the attackers went to great lengths to “ensure the code was properly inserted and remained undetected, and prioritized operational security to avoid revealing their presence in the build environment to SolarWinds developers.”

Sunspot worked by sitting on SolarWinds’ build server and monitoring running processes for instances of MsBuild.exe, which is part of Microsoft Visual Studio development tools. If it saw that Orion software was being built, it would hijack the operation to insert Sunburst.

The resulting Trojanized version of Orion was then installed on SolarWinds customer systems. Around 33,000 such customers exist around the world, but only a relatively small handful were singled out by the attackers for the next stage of the campaign.

These victims, including multiple US government entities such as the Department of Justice, were monitored by Sunburst and then hit with a secondary Trojan, Teardrop, which delivered further payloads.

According to a timeline from SolarWinds released yesterday, the attackers first accessed its internal systems in September 2019, and around a week later they injected test code to effectively check the efficacy of Sunspot.

Sunburst was then compiled and deployed into the Orion platform in February 2020, although it was only in December, when FireEye discovered it was hit in the same campaign, that the whole story started to become clear.

Also yesterday, Kaspersky released new research indicating that the Sunburst malware contains multiple similarities with the Kazuar remote access backdoor previously linked to the long-running Russian APT group Turla.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Chinese Startup Leaks Social Profiles of 214 Million Users

Chinese Startup Leaks Social Profiles of 214 Million Users

A cloud configuration error at a Chinese startup exposed the personal data of at least 214 million social media users including celebrities, researchers have warned.

The privacy snafu occurred at social media management firm Socialarks, which suffered a similar incident in August last year when 150 million users were exposed, according to Safety Detectives.

This time, a team led by Anurag Sen came across an Elasticsearch database left completely open without any password protection or encryption, during a routine IP scan.

The 408GB trove contained over 318 million records in total, although the exact number of users affected is still not known given the size of the leak. What the researchers do know is that it was illegally scraped from social media profiles on Facebook, Instagram and LinkedIn, contrary to the policy on those sites.

They discovered nearly 12 million Instagram user profiles, including names, phone numbers, usernames, email addresses, profile pictures and locations.

The trove also contained data on 82 million Facebook profiles including full names, email addresses, phone numbers, Messenger IDs, pictures and more.

Finally, the researchers uncovered 66 million LinkedIn user profiles containing full names, email addresses, job profiles and company names, amongst other data points.

Safety Detectives said it was unclear how private information such as phone numbers and email addresses were obtained by Socialarks, given its scraping tools should have lifted only publicly available information.

“In some cases, scraped data can be weaponized to carry out a specific goal of extracting personal information for criminal purposes. Potential ramifications of exposing personal information include identity theft and financial fraud conducted across other platforms including online banking,” the firm warned.

“Contact information can be harnessed to target people with targeted scams including sending personalized emails containing other personal information about the target, thereby gaining their trust, and setting the stage for a deeper intrusion into their privacy.”

Although Socialarks never replied to the research team, it remediated the leak on December 14, the day it was notified.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Big Tech Bans Social Networking App

Big Tech Bans Social Networking App

A social networking app used by millions is seeking a new home after being suspended by big tech over claims of failure to remove egregious content from its platform.

Parler was launched in 2018 as an antidote to sites like Twitter and Facebook that take action to censor particular content and suspend or block user accounts based on the perceived nature of content posted.

Amazon said it had made the decision to block Parler from using its AWS hosting services over concerns regarding “violent content.”

In an email, Amazon’s AWS Trust and Safety team informed Parler’s chief policy officer Amy Peikoff that the social network “does not have an effective process to comply with the AWS terms of service.”

“AWS provides technology and services to customers across the political spectrum, and we continue to respect Parler’s right to determine for itself what content it will allow on its site,” the letter said.

“However, we cannot provide services to a customer that is unable to effectively identify and remove content that encourages or incites violence against others.”

Google removed Parler from its app store on Friday, and on Saturday Apple followed suit. 

Parler’s chief executive John Matze described the concurrent actions of Google, Apple, and Amazon as “a coordinated attack by the tech giants to kill competition in the marketplace.”

Responding to Google’s ban, Matze said: “We won’t cave to politically motivated companies and those authoritarians who hate free speech.”

The move to silence Parler’s approximately 10 million users comes after an executive order on preventing online censorship was issued by President Donald Trump on May 28 2020.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Lack of Funding Could Lead to “Lost Generation” of Cyber-Startups

Lack of Funding Could Lead to “Lost Generation” of Cyber-Startups

Early-stage cybersecurity companies in the UK have seen a year-on-year funding decline of 96% since March 2020, a trend which threatens to significantly curtail advancements in the sector. This is according to a new analysis by innovation center Plexal and database for fast-growth companies, Beauhurst, which found that cybersecurity startups seeking funding for the first time received only £11.9m in investment since the start of the COVID-19 lockdowns. This compares to £265m during the same period in 2019.

This is despite UK cybersecurity startups as a whole securing £651m since the pandemic struck, which represents a year-on-year rise of 52%. While average investment in these companies was larger, with a wider range receiving capital compared to 2019, funding was almost entirely targeted towards businesses with a proven track record. This included a number of very large follow-on investments to companies such as OneTrust (£224m), Synk (£154m) and Privitar (£70m).

This imbalance has led to fears of a “lost generation” of cyber-startups, which could be damaging to the industry over the long-term.

Saj Huq, director of innovation at Plexal and director of the London Office for Rapid Cybersecurity Advancement (LORCA), commented: “While increased total funding demonstrates the relevance of cybersecurity and shows that the UK’s cyber-industry has not been impacted to the same extent as others, the almost complete absence of backing for early-stage firms puts the sector’s future at risk. It is these companies that we will ultimately rely on to solve the inevitable new cyber-challenges arising from a society that is increasingly digital-first.

“COVID-19 has accelerated digital transformation, increased the demand for digital services and reinforced the relevance of security as a crucial business enabler. More cybersecurity companies are receiving investment as a result, but the caution exercised by investors is preventing the UK’s cyber-sector from becoming the key driver of the economic recovery that it should be. Investors, industry, academic institutions and government must come together to safeguard the future of our brightest, early-stage cyber-startups or they could become a lost generation.”

The analysis of nearly 40,000 startups and fast-growth businesses also showed that the cybersecurity startups had faired substantially better than counterparts in other sectors. While the number of deals involving cybersecurity startups went up by 33% since March 2020, deals across all sectors fell by 26% in the same period.

Last year, LORCA revealed that cybersecurity startup and scaleup firms that have progressed through its innovation program have collectively raised over £150m in investment in two years, 280% above its original target.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk