Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Ethical Hackers Breach U.N., Access 100,000 Private Records
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Cloning Google Titan 2FA keys
This is a clever side-channel attack:
The cloning works by using a hot air gun and a scalpel to remove the plastic key casing and expose the NXP A700X chip, which acts as a secure element that stores the cryptographic secrets. Next, an attacker connects the chip to hardware and software that take measurements as the key is being used to authenticate on an existing account. Once the measurement-taking is finished, the attacker seals the chip in a new casing and returns it to the victim.
Extracting and later resealing the chip takes about four hours. It takes another six hours to take measurements for each account the attacker wants to hack. In other words, the process would take 10 hours to clone the key for a single account, 16 hours to clone a key for two accounts, and 22 hours for three accounts.
By observing the local electromagnetic radiations as the chip generates the digital signatures, the researchers exploit a side channel vulnerability in the NXP chip. The exploit allows an attacker to obtain the long-term elliptic curve digital signal algorithm private key designated for a given account. With the crypto key in hand, the attacker can then create her own key, which will work for each account she targeted.
The attack isn’t free, but it’s not expensive either:
A hacker would first have to steal a target’s account password and also gain covert possession of the physical key for as many as 10 hours. The cloning also requires up to $12,000 worth of equipment and custom software, plus an advanced background in electrical engineering and cryptography. That means the key cloning — were it ever to happen in the wild — would likely be done only by a nation-state pursuing its highest-value targets.
That last line about “nation-state pursuing its highest-value targets” is just not true. There are many other situations where this attack is feasible.
Note that the attack isn’t against the Google system specifically. It exploits a side-channel attack in the NXP chip. Which means that other systems are probably vulnerable:
While the researchers performed their attack on the Google Titan, they believe that other hardware that uses the A700X, or chips based on the A700X, may also be vulnerable. If true, that would include Yubico’s YubiKey NEO and several 2FA keys made by Feitian.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Microsoft Patch Tuesday, January 2021 Edition
Microsoft today released updates to plug more than 80 security holes in its Windows operating systems and other software, including one that is actively being exploited and another which was disclosed prior to today. Ten of the flaws earned Microsoft’s most-dire “critical” rating, meaning they could be exploited by malware or miscreants to seize remote control over unpatched systems with little or no interaction from Windows users.

Most concerning of this month’s batch is probably a critical bug (CVE-2021-1647) in Microsoft’s default anti-malware suite — Windows Defender — that is seeing active exploitation. Microsoft recently stopped providing a great deal of detail in their vulnerability advisories, so it’s not entirely clear how this is being exploited.
But Kevin Breen, director of research at Immersive Labs, says depending on the vector the flaw could be trivial to exploit.
“It could be as simple as sending a file,” he said. “The user doesn’t need to interact with anything, as Defender will access it as soon as it is placed on the system.”
Fortunately, this bug is probably already patched by Microsoft on end-user systems, as the company continuously updates Defender outside of the normal monthly patch cycle.
Breen called attention to another critical vulnerability this month — CVE-2020-1660 — which is a remote code execution flaw in nearly every version of Windows that earned a CVSS score of 8.8 (10 is the most dangerous).
“They classify this vulnerability as ‘low’ in complexity, meaning an attack could be easy to reproduce,” Breen said. “However, they also note that it’s ‘less likely’ to be exploited, which seems counterintuitive. Without full context of this vulnerability, we have to rely on Microsoft to make the decision for us.”
CVE-2020-1660 is actually just one of five bugs in a core Microsoft service called Remote Procedure Call (RPC), which is responsible for a lot of heavy lifting in Windows. Some of the more memorable computer worms of the last decade spread automatically by exploiting RPC vulnerabilities.
Allan Liska, senior security architect at Recorded Future, said while it is concerning that so many vulnerabilities around the same component were released simultaneously, two previous vulnerabilities in RPC — CVE-2019-1409 and CVE-2018-8514 — were not widely exploited.
The remaining 70 or so flaws patched this month earned Microsoft’s less-dire “important” ratings, which is not to say they’re much less of a security concern. Case in point: CVE-2021-1709, which is an “elevation of privilege” flaw in Windows 8 through 10 and Windows Server 2008 through 2019.
“Unfortunately, this type of vulnerability is often quickly exploited by attackers,” Liska said. “For example, CVE-2019-1458 was announced on December 10th of 2019, and by December 19th an attacker was seen selling an exploit for the vulnerability on underground markets. So, while CVE-2021-1709 is only rated as [an information exposure flaw] by Microsoft it should be prioritized for patching.”
Trend Micro’s ZDI Initiative pointed out another flaw marked “important” — CVE-2021-1648, an elevation of privilege bug in Windows 8, 10 and some Windows Server 2012 and 2019 that was publicly disclosed by ZDI prior to today.
“It was also discovered by Google likely because this patch corrects a bug introduced by a previous patch,” ZDI’s Dustin Childs said. “The previous CVE was being exploited in the wild, so it’s within reason to think this CVE will be actively exploited as well.”
Separately, Adobe released security updates to tackle at least eight vulnerabilities across a range of products, including Adobe Photoshop and Illustrator. There are no Flash Player updates because Adobe retired the browser plugin in December (hallelujah!), and Microsoft’s update cycle from last month removed the program from Microsoft’s browsers.
Windows 10 users should be aware that the operating system will download updates and install them all at once on its own schedule, closing out active programs and rebooting the system. If you wish to ensure Windows has been set to pause updating so you have ample opportunity to back up your files and/or system, see this guide.
Please back up your system before applying any of these updates. Windows 10 even has some built-in tools to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once. You never know when a patch roll-up will bork your system or possibly damage important files. For those seeking more flexible and full-featured backup options (including incremental backups), Acronis and Macrium are two that I’ve used previously and are worth a look.
That said, there don’t appear to be any major issues cropping up yet with this month’s update batch. But before you apply updates consider paying a visit to AskWoody.com, which usually has the skinny on any reports about problematic patches.
As always, if you experience glitches or issues installing any of these patches this month, please consider leaving a comment about it below; there’s a better-than-even chance other readers have experienced the same and may chime in here with some helpful tips.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
SolarWinds: What Hit Us Could Hit Others
New research into the malware that set the stage for the megabreach at IT vendor SolarWinds shows the perpetrators spent months inside the company’s software development labs honing their attack before inserting malicious code into updates that SolarWinds then shipped to thousands of customers. More worrisome, the research suggests the insidious methods used by the intruders to subvert the company’s software development pipeline could be repurposed against many other major software providers.
In a blog post published Jan. 11, SolarWinds said the attackers first compromised its development environment on Sept. 4, 2019. Soon after, the attackers began testing code designed to surreptitiously inject backdoors into Orion, a suite of tools used by many Fortune 500 firms and a broad swath of the federal government to manage their internal networks.
Image: SolarWinds.
According to SolarWinds and a technical analysis from CrowdStrike, the intruders were trying to work out whether their “Sunspot” malware — designed specifically for use in undermining SolarWinds’ software development process — could successfully insert their malicious “Sunburst” backdoor into Orion products without tripping any alarms or alerting Orion developers.
In October 2019, SolarWinds pushed an update to their Orion customers that contained the modified test code. By February 2020, the intruders had used Sunspot to inject the Sunburst backdoor into the Orion source code, which was then digitally signed by the company and propagated to customers via SolarWinds’ software update process.
Crowdstrike said Sunspot was written to be able to detect when it was installed on a SolarWinds developer system, and to lie in wait until specific Orion source code files were accessed by developers. This allowed the intruders to “replace source code files during the build process, before compilation,” Crowdstrike wrote.
The attackers also included safeguards to prevent the backdoor code lines from appearing in Orion software build logs, and checks to ensure that such tampering wouldn’t cause build errors.
“The design of SUNSPOT suggests [the malware] developers invested a lot of effort to ensure the code was properly inserted and remained undetected, and prioritized operational security to avoid revealing their presence in the build environment to SolarWinds developers,” CrowdStrike wrote.
A third malware strain — dubbed “Teardrop” by FireEye, the company that first disclosed the SolarWinds attack in December — was installed via the backdoored Orion updates on networks that the SolarWinds attackers wanted to plunder more deeply.
So far, the Teardrop malware has been found on several government networks, including the Commerce, Energy and Treasury departments, the Department of Justice and the Administrative Office of the U.S. Courts.
SolarWinds emphasized that while the Sunspot code was specifically designed to compromise the integrity of its software development process, that same process is likely common across the software industry.
“Our concern is that right now similar processes may exist in software development environments at other companies throughout the world,” said SolarWinds CEO Sudhakar Ramakrishna. “The severity and complexity of this attack has taught us that more effectively combatting similar attacks in the future will require an industry-wide approach as well as public-private partnerships that leverage the skills, insight, knowledge, and resources of all constituents.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Francisco Partners Completes Forcepoint Acquisition
Francisco Partners Completes Forcepoint Acquisition

Cybersecurity vendor Forcepoint has been acquired from defense contractor Raytheon Technologies by global investment firm Francisco Partners.
The firm announced the closing of the transaction today. The financial details of the deal were not disclosed.
Forcepoint, formerly known as Websense, provides behavior-based cybersecurity solutions that protect the critical data and networks of thousands of customers worldwide by adapting to risk in real-time.
Four appointments were made by Forcepoint to coincide with the transaction’s closing. Dave Stevens was named senior vice president of strategy and execution, John DiLullo is the company’s new chief revenue officer, and Sean Berg has been promoted to president of global governments and critical infrastructure from his previous role as senior VP and general manager for Forcepoint’s business unit.
The company’s board of directors has appointed Manny Rivelo as chief executive officer with immediate effect. Previous executive roles held by Rivelo include chief customer officer at Arista Networks, president and CEO as well as executive vice president, security, service provider and strategic solutions at F5 Networks, president and CEO of AppViewX, and various senior leadership roles at Cisco Systems.
“Cybersecurity has never been more important for businesses and governments around the world,” said Rivelo. “As we continue to see broad-scale global attacks, the cybersecurity industry needs to evolve to deliver security capabilities to match those of today’s sophisticated threat actors.”
Rivelo added that all organizations need to evolve their security posture so that cybersecurity is holistically integrated across their business operations and into their culture.
“It can no longer be viewed as ‘just an IT issue’,” said Rivelo.
As CEO, Rivelo intends to focus the company’s strategy on accelerating enterprise and government-agency adoption of emerging Secure Access Service Edge (SASE) architecture.
“I look forward to solidifying Forcepoint’s leadership position as the global cybersecurity partner of choice for enterprises and government agencies,” said Rivelo.
Founded in 1999 and based in San Francisco, Francisco Partners specializes in partnering with technology and technology-enabled businesses. Since its launch, the firm has raised over $24bn in committed capital and invested in more than 300 technology companies.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
(ISC)² Offers Online Exam Proctoring
(ISC)² Offers Online Exam Proctoring

The largest non-profit association of certified cybersecurity professionals in the world is launching an online exam proctoring pilot program.
(ISC)²‘s new program, announced today, will embrace the association’s entire portfolio of cybersecurity certifications, including the famed independent information security certification CISSP.
As of July 1, 2020, there were 141,607 (ISC)² members holding the CISSP certification worldwide.
Offering certification online is part of the association’s efforts to counter the effects of the global outbreak of the novel coronavirus on the lives of security professionals.
“In the wake of COVID-19, (ISC)² has spent considerable time and effort to ensure the integrity of our exam process while taking into consideration that many candidates are facing extraordinary uncertainty and restrictions due to the pandemic,” said Dr. Casey Marks, chief product officer and vice president, (ISC)².
“Our pilot test program will enable us to gather the data we need to weigh the integrity and effectiveness of the exams while making them more easily accessible during these unprecedented times.”
Under the pilot test, a maximum of 2,000 total examinations will be delivered. Candidates can register for the (ISC)² online proctoring pilot test beginning today.
In this pilot program, test deliveries are being limited to candidates who are located within the United States and who have no past (ISC)² disciplinary actions on record. Tests will only be available in the English language.
The pilot program will be exclusively administered through Pearson VUE, which will offer exam appointments on a first-come, first-served basis.
Online examinations for the CAP, CCSP, CSSLP, HCISPP, CISSP-ISSAP, CISSP-ISSEP, CISSP-ISSMP, and SSCP certifications will be administered February 15, 2021 – February 21, 2021. Online CISSP examinations will be administered February 22, 2021 – February 28, 2021.
The cost for examinations offered online as part of the pilot scheme has been set at the same rate charged for test center–delivered examinations. But, where test center candidates typically receive diagnostic information regarding how they performed in their tests, online candidates will only be given a pass/fail result.
(ISC)², which has a membership of more than 150,000 security professionals, celebrates its 31st anniversary this year.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Bridewell Appoints Martin Riley as Director of Managed Security Services
Bridewell Appoints Martin Riley as Director of Managed Security Services

Bridewell Consulting has announced the appointment of Martin Riley as its director of managed security services.
Riley, who has joined Bridewell’s board from today, is tasked with leading the expansion of the cybersecurity and data privacy consultancy’s managed security service (MSS) portfolio. This includes its 24/7 security operations center (SOC) and managed detection and response (MDR) service.
Riley comes with nearly 20 years of experience in helping scale up organizations’ security infrastructure and digitalization as well as leading enterprise managed services.
Most recently, Riley held the position of chief technology officer at Timico, where he led the strategic direction and digital transformation of the business. He was also previously head of infrastructure at cloud services and integrator company Adapt.
Scott Nicholson, director, Bridewell Consulting, comment: “Martin brings tremendous expertise and experience to our business and will be instrumental in helping us deliver on our ambitious growth strategy. Our 24/7 managed detection and response capability around Azure Sentinel and Defender XDR is already best in class across the industry, but with Martin’s support, we hope to strengthen this further and deliver high end security automation and operations across critical national infrastructure.”
Speaking on his new position, Riley said: “I have been passionate about the role cybersecurity plays in infrastructure and cloud services for many years and am excited to work for an ambitious and fast growth business like Bridewell. Managed security services continues to be one of the biggest growth areas in IT and I look forward to helping develop opportunities to expand Bridewell’s services, mature our capabilities and strengthen our position in the security market.”
Anthony Young, director, Bridewell Consulting, added: “When first meeting Martin, it was clear to see he had passion for cybersecurity and delivering an excellent service to customers which aligns with our values. That, coupled with his experience across managed services and scaling businesses through technology automation, makes him a brilliant addition to the board and will help us deliver on our growth plans.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US Announces Controversial State Department Cyber-Bureau
US Announces Controversial State Department Cyber-Bureau

The US government has announced the creation of a new cybersecurity agency to align with the country’s diplomatic efforts.
The Bureau of Cyberspace Security and Emerging Technologies (CSET) was finally approved by outgoing secretary of state, Mike Pompeo — over a year-and-a-half after Congress was first notified of the plans.
A brief statement from the department explained that the need to “reorganize and resource” the government’s cybersecurity and diplomacy has become even more critical in the intervening months. China, Russia, Iran, North Korea and “emerging technology competitors and adversaries” were name-checked in the note.
“The CSET bureau will lead US government diplomatic efforts on a wide range of international cyberspace security and emerging technology policy issues that affect US foreign policy and national security, including securing cyberspace and critical technologies, reducing the likelihood of cyber-conflict, and prevailing in strategic cyber-competition,” it continued.
“The secretary’s decision to establish CSET will permit the department to posture itself appropriately and engage as effectively as possible with partners and allies on these pressing national security concerns.”
However, the reason for that 18-month delay to the creation of CSET was former House Foreign Affairs Committee chairman Eliot Engel, who argued at the time that its focus was too narrow.
A 2018 bipartisan bill, the Cyber Diplomacy Act, sets out to establish not a bureau but an Office of International Cyberspace Policy at the State Department.
“While Congress has pursued comprehensive, bipartisan legislation, the State Department has plowed ahead in its plan to create a bureau with a much narrower mission focused only on cybersecurity,” Engel is reported saying at the time.
“This move flies in the face of repeated warnings from Congress and outside experts that our approach to cyber-issues needs to elevate engagement on economic interests and internet freedoms together with security.”
A former State department cybersecurity diplomat under Obama and Trump also dismissed the move.
“Laughable that this is done @ the 11th hr when this was not adequately resourced or prioritized for four yrs,” tweeted Chris Painter. “Also, this formulation only preserves stovepipes rather than coordination.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Over 100,000 UN Employee Records Accessed by Researchers
Over 100,000 UN Employee Records Accessed by Researchers

Security researchers revealed today that it took them just hours to access over 100,000 personal records and credentials belonging to United Nations employees.
A team from Sakura Samurai had decided to look for bugs to report to the UN under its vulnerability disclosure program, first probing multiple endpoints that were in scope.
It initially found an exposed subdomain for UN body the International Labour Organization (ILO), according to Sakura Samurai founder John Jackson. This gave them access to Git credentials which they used to takeover a legacy MySQL database and a survey management platform. Exfiltration of these credentials was done with the git-dumper tool.
Although these assets contained “hardly anything of use,” the researchers then discovered an exposed subdomain related to the United Nations Environment Programme (UNEP), which was a much bigger privacy risk. The domain was also leaking Git credentials.
“Ultimately, once we discovered the GitHub credentials, we were able to download a lot of private password-protected GitHub projects and within the projects we found multiple sets of database and application credentials for the UNEP production environment,” Jackson explained.
“In total, we found seven additional credential pairs which could have resulted in unauthorized access of multiple databases. We decided to stop and report this vulnerability once we were able to access PII that was exposed via database backups that were in the private projects.”
In total, the team discovered over 100,000 employee records including names, ID numbers, gender, pay grade, records of travel details, work sub-areas and departments, evaluation reports and funding source records.
The UN is a frequent target for nation state attackers and its cybersecurity has often been found wanting in the past.
A year ago it emerged that hundreds of gigabytes of internal data, potentially including highly sensitive information on human rights activists, had been stolen in 2019 by attackers.
Controversially, the organization itself appeared to use its diplomatic immunity to keep the incident a secret.
Fortunately, this time around the UN is believed to have quickly patched the vulnerabilities in question and secure the exposed data.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk