Red Hat to Acquire StackRox

Red Hat to Acquire StackRox

American multinational software company Red Hat today announced the signature of a definitive agreement to acquire StackRox, a trailblazer in Kubernetes-native security.

By bringing StackRox’s Kubernetes-native security capabilities to Red Hat OpenShift, Red Hat said it hopes to take one step closer to creating a single platform that will enable users to “build, deploy and securely run nearly any application across the entirety of the hybrid cloud.”

In addition to Red Hat OpenShift, StackRox will carry on supporting multiple Kubernetes platforms, including Microsoft Azure Kubernetes Service (AKS), Amazon Elastic Kubernetes Service (EKS), and Google Kubernetes Engine (GKE).

StackRox was founded in 2014 with the goal of reinventing enterprise security. The company is headquartered in Mountain View, California, and employs around 60 people. 

For StackRox CEO Kamal Shah, the planned acquisition is confirmation of StackRox’s originality when it comes to Kubernetes security, which over the past two years has evolved to be the company’s focus.

“We’re thrilled to join forces with Red Hat, coupling the industry’s first Kubernetes-native security platform with the leading Kubernetes platform for hybrid cloud, multicloud, and edge deployments,” said Shah. 

“This is a tremendous validation of our innovative approach to container and Kubernetes security. Red Hat is an ideal partner to accelerate our vision of enabling organizations to securely build, deploy and run their cloud-native applications anywhere.”

Red Hat revealed plans to open source StackRox’s technology post-acquisition in an action that’s consistent with Red Hat’s open source heritage. Red Hat has pledged to continue to support the KubeLinter community as well as new communities as the company works to open source StackRox’s tech treasures. 

The transaction is scheduled to close in the first quarter of 2021, subject to the usual closing conditions.

“Securing Kubernetes workloads and infrastructure cannot be done in a piecemeal manner; security must be an integrated part of every deployment, not an afterthought,” said Red Hat CEO and president Paul Cormier.

“Red Hat adds StackRox’s Kubernetes-native capabilities to OpenShift’s layered security approach, furthering our mission to bring product-ready open innovation to every organization across the open hybrid cloud across IT footprints.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Emotet Tops Malware Charts in December After Reboot

Emotet Tops Malware Charts in December After Reboot

The notorious Emotet Trojan is back at the top of the malware charts, having had a makeover designed to make it more effective at escaping detection.

Check Point’s newly released Global Threat Index for December 2020 revealed that the malware variant bounced back from fifth place in November.

It now accounts for 7% of malware infections globally after a spam campaign targeted more than 100,000 users per day over the holiday period, the security vendor claimed. Emotet is closely followed by fellow modular Trojan Trickbot and info-stealer Formbook, both on 4%.

“It has now been updated with new malicious payloads and improved detection evasion capabilities: the latest version creates a dialogue box, which helps it evade detection from users,” explained Check Point.

“The new malicious spam campaign uses different delivery techniques to spread Emotet, including embedded links, document attachments, or password-protected Zip files.”

Emotet and Trickbot are often used in combination by ransomware groups to gain an initial foothold into networks. Attackers can then pick and choose which victims to go after with “hands-on-keyboard” multi-staged attacks.

In fact, a new report detailing the activities of the Ryuk variant recommended one of the best ways for organizations to mitigate the threat is to prevent initial infection by malware like Emotet.

The focus therefore should be on email security with anti-phishing capabilities and enhanced end user awareness training, although defense-in-depth is always preferable, including two-factor authentication and prompt patching to reduce the attack surface further.

“Emotet was originally developed as banking malware which sneaked on to users’ computers to steal private and sensitive information. However, it has evolved over time and is now seen as one of the most costly and destructive malware variants,” said Maya Horowitz, director of threat intelligence & research, products at Check Point.

“It’s imperative that organizations are aware of the threat Emotet poses and that they have robust security systems in place to prevent a significant breach of their data. They should also provide comprehensive training for employees, so they are able to identify the types of malicious emails which spread Emotet.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ping Identity Appoints Acclaimed CIO Paul Martin to Board of Directors

Ping Identity Appoints Acclaimed CIO Paul Martin to Board of Directors

Ping Identity has announced the appointment of Hall of Fame CIO Paul Martin to its board of directors.

Martin will help the security firm enhance its leadership strategy and IT innovation. He joins with a strong track record as an IT leader, having received a number of accolades. This includes being named to the CIO Hall of Fame by CIO Magazine in 2017 and being awarded the 2020 Chicago CIO of the Year Leadership ORBIE Award.

His most recent position was as CIO and senior vice-president for healthcare company Baxter International Inc., where he was responsible for its global IT strategy, operations, security and processes. He has also held IT leadership roles at Rexam PLC, CIT Group, BNSF Railway and Frito-Lay Inc.

Commenting on the appointment, Andre Durand, CEO of Ping Identity, said: “Few CIOs can match Paul’s proven track record of innovating IT solutions that generate bottom-line profitability and stakeholder value. His extensive experience in the CIO community will bring greater insight to Ping Technology’s leadership, and further champion our customers throughout all business operations.”

Martin is also a board member for Unisys Corporation and Baxter Credit Union as well as being a trustee at Rush University Medical Center and Ravinia Festival.

The appointment of Martin is the latest step taken by Ping Identity to expand its business during recent months. In October, it appointed Emma Maslen as its vice-president and general manager for EMEA and APAC to grow its international operations, and in November announced the acquisition of dynamic authorization company Symphonic Software.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ryuk Ransomware Attackers Have Made $150m

Ryuk Ransomware Attackers Have Made $150m

The infamous operators of the Ryuk ransomware have amassed a fortune of at least $150m, according to researchers who studied the flow of Bitcoin to the group.

A new report from US threat prevention firm AdvIntel and UK-based threat intelligence vendor Hyas is based on analysis of 61 cryptocurrency deposit addresses linked to Ryuk.

Most of the digital currency the group collects is sent to Asia-based exchanges Huobi or Binance, which may help them to escape scrutiny, the report authors argued.

“Huobi and Binance are interesting choices because they claim to comply with international financial laws and are willing to participate in legal requests but are also structured in a way that probably wouldn’t obligate them to comply. In addition, both Huobi and Binance are companies that were founded by Chinese nationals but moved their business to other countries that are more friendly to cryptocurrency exchanges,” the researchers explained.

“Both exchanges require identity documents in order to exchange crypto-currencies for fiat or to make transfers to banks, however it isn’t clear if the documents they accept are scrutinized in any meaningful way.”

The team were also able to observe “significant flows” of Bitcoin to smaller entities. These are likely to be criminal enterprises set up to help launder funds into local currencies or other types of digital money.

As a further step to obfuscate their true identity, the Ryuk attackers get victims to pay a well-known broker, who in turn makes payments to the group, sometimes in the millions but more likely in the hundreds of thousands of dollars.

Any money not cashed out at the two Asian exchanges is used to pay for goods and services on cybercrime markets, the report claimed.

Two unique Protonmail addresses are prepared to communicate with each victim. These organizations are selected according to a scoring system in precursor malware used by the attackers, which apparently assesses their likelihood of paying.

“With the limited visibility available to analysts, it is painfully clear that the criminals behind Ryuk are very business-like and have zero sympathy for the status, purpose or ability of the victims to pay,” the researchers continued.

“Sometimes the victims will attempt to negotiate with Ryuk and their significant offers are denied with a one-word response. Ryuk did not respond or acknowledge one organization that claimed to be involved in poverty relief and lacked the means to pay.”

The report recommended organizations develop counter-measures to prevent initial infection by precursor malware like Emotet or Zloader. All remote access points should require multi-factor authentication (MFA), and Office macros and remote access tools should be restricted, it added.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CEO Refutes Reports of Involvement in SolarWinds Campaign

CEO Refutes Reports of Involvement in SolarWinds Campaign

The Russian CEO of a software provider has hit back at reports that one of the firm’s products may have been exploited by Russian hackers in the recent SolarWinds campaign.

Czech-headquartered JetBrains provides tools for software developers including TeamCity, a continuous integration and deployment system at the center of the reports.

The New York Times and others claimed that unspecified US intelligence agencies and cybersecurity investigators are looking into whether Russian state attackers managed to compromise the software. They’re unsure whether it may have been used to gain a foothold into the SolarWinds developer environment, or as a direct attack vector into US government systems, it said.

According to the report, JetBrains is used at 300,000 businesses globally including 79 of the Fortune 100 and has research labs in Russia.

However, in two posts following the reports, St Petersburg-based CEO Maxim Shafirov refuted any allegations that the firm may have played an unwitting role in the audacious cyber-espionage campaign, and added that no government officials had yet been in contact.

“To date we have no knowledge of TeamCity or JetBrains having been compromised in any way that would lead to such a situation. In addition, we not only run regular scheduled audits of our software, but we are now organizing a further independent security audit of TeamCity,” he explained.

“If we are to find any vulnerability in the product that may have led to this, we will be fully transparent on the matter and inform our customers under our security and privacy policies. It’s also worth mentioning that we ourselves do not use SolarWinds Orion or any of their other software.”

Shafirov essentially argued that if JetBrains is under investigation, it is merely because TeamCity is used by SolarWinds during its build process.

However, in a separate post, he did explain a hypothetical situation in which the product may have been abused.

“It’s important to stress that TeamCity is a complex product that requires proper configuration. If TeamCity has somehow been used in this process, it could very well be due to misconfiguration, and not a specific vulnerability,” Shafirov said.

This week, the Department of Justice became the first US government entity to shed some light on the scope of the compromise, claiming attackers managed to access 3% of its Office 365 inboxes, which means more than 3000 users were affected.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk