Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Friday Squid Blogging: Searching for Giant Squid by Collecting Environmental DNA
The idea is to collect and analyze random DNA floating around the ocean, and using that to figure out where the giant squid are. No one is sure if this will actually work.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
APT Horoscope
This delightful essay matches APT hacker groups up with astrological signs. This is me:
Capricorn is renowned for its discipline, skilled navigation, and steadfastness. Just like Capricorn, Helix Kitten (also known as APT 35 or OilRig) is a skilled navigator of vast online networks, maneuvering deftly across an array of organizations, including those in aerospace, energy, finance, government, hospitality, and telecommunications. Steadfast in its work and objectives, Helix Kitten has a consistent track record of developing meticulous spear-phishing attacks.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Russia’s SolarWinds Attack and Software Security
The information that is emerging about Russia’s extensive cyberintelligence operation against the United States and other countries should be increasingly alarming to the public. The magnitude of the hacking, now believed to have affected more than 250 federal agencies and businesses — primarily through a malicious update of the SolarWinds network management software — may have slipped under most people’s radar during the holiday season, but its implications are stunning.
According to a Washington Post report, this is a massive intelligence coup by Russia’s foreign intelligence service (SVR). And a massive security failure on the part of the United States is also to blame. Our insecure Internet infrastructure has become a critical national security risk — one that we need to take seriously and spend money to reduce.
President-elect Joe Biden’s initial response spoke of retaliation, but there really isn’t much the United States can do beyond what it already does. Cyberespionage is business as usual among countries and governments, and the United States is aggressively offensive in this regard. We benefit from the lack of norms in this area and are unlikely to push back too hard because we don’t want to limit our own offensive actions.
Biden took a more realistic tone last week when he spoke of the need to improve US defenses. The initial focus will likely be on how to clean the hackers out of our networks, why the National Security Agency and US Cyber Command failed to detect this intrusion and whether the 2-year-old Cybersecurity and Infrastructure Security Agency has the resources necessary to defend the United States against attacks of this caliber. These are important discussions to have, but we also need to address the economic incentives that led to SolarWinds being breached and how that insecure software ended up in so many critical US government networks.
Software has become incredibly complicated. Most of us almost don’t know all of the software running on our laptops and what it’s doing. We don’t know where it’s connecting to on the Internet — not even which countries it’s connecting to — and what data it’s sending. We typically don’t know what third party libraries are in the software we install. We don’t know what software any of our cloud services are running. And we’re rarely alone in our ignorance. Finding all of this out is incredibly difficult.
This is even more true for software that runs our large government networks, or even the Internet backbone. Government software comes from large companies, small suppliers, open source projects and everything in between. Obscure software packages can have hidden vulnerabilities that affect the security of these networks, and sometimes the entire Internet. Russia’s SVR leveraged one of those vulnerabilities when it gained access to SolarWinds’ update server, tricking thousands of customers into downloading a malicious software update that gave the Russians access to those networks.
The fundamental problem is one of economic incentives. The market rewards quick development of products. It rewards new features. It rewards spying on customers and users: collecting and selling individual data. The market does not reward security, safety or transparency. It doesn’t reward reliability past a bare minimum, and it doesn’t reward resilience at all.
This is what happened at SolarWinds. A New York Times report noted the company ignored basic security practices. It moved software development to Eastern Europe, where Russia has more influence and could potentially subvert programmers, because it’s cheaper.
Short-term profit was seemingly prioritized over product security.
Companies have the right to make decisions like this. The real question is why the US government bought such shoddy software for its critical networks. This is a problem that Biden can fix, and he needs to do so immediately.
The United States needs to improve government software procurement. Software is now critical to national security. Any system for acquiring software needs to evaluate the security of the software and the security practices of the company, in detail, to ensure they are sufficient to meet the security needs of the network they’re being installed in. Procurement contracts need to include security controls of the software development process. They need security attestations on the part of the vendors, with substantial penalties for misrepresentation or failure to comply. The government needs detailed best practices for government and other companies.
Some of the groundwork for an approach like this has already been laid by the federal government, which has sponsored the development of a “Software Bill of Materials” that would set out a process for software makers to identify the components used to assemble their software.
This scrutiny can’t end with purchase. These security requirements need to be monitored throughout the software’s life cycle, along with what software is being used in government networks.
None of this is cheap, and we should be prepared to pay substantially more for secure software. But there’s a benefit to these practices. If the government evaluations are public, along with the list of companies that meet them, all network buyers can benefit from them. The US government acting purely in the realm of procurement can improve the security of nongovernmental networks worldwide.
This is important, but it isn’t enough. We need to set minimum safety and security standards for all software: from the code in that Internet of Things appliance you just bought to the code running our critical national infrastructure. It’s all one network, and a vulnerability in your refrigerator’s software can be used to attack the national power grid.
The IOT Cybersecurity Improvement Act, signed into law last month, is a start in this direction.
The Biden administration should prioritize minimum security standards for all software sold in the United States, not just to the government but to everyone. Long gone are the days when we can let the software industry decide how much emphasis to place on security. Software security is now a matter of personal safety: whether it’s ensuring your car isn’t hacked over the Internet or that the national power grid isn’t hacked by the Russians.
This regulation is the only way to force companies to provide safety and security features for customers — just as legislation was necessary to mandate food safety measures and require auto manufacturers to install life-saving features such as seat belts and air bags. Smart regulations that incentivize innovation create a market for security features. And they improve security for everyone.
It’s true that creating software in this sort of regulatory environment is more expensive. But if we truly value our personal and national security, we need to be prepared to pay for it.
The truth is that we’re already paying for it. Today, software companies increase their profits by secretly pushing risk onto their customers. We pay the cost of insecure personal computers, just as the government is now paying the cost to clean up after the SolarWinds hack. Fixing this requires both transparency and regulation. And while the industry will resist both, they are essential for national security in our increasingly computer-dependent worlds.
This essay previously appeared on CNN.com.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Trump Sex Scandal Video Is a RAT
Trump Sex Scandal Video Is a RAT

Cyber-attackers are disguising malware as a video file depicting a fake sex scandal involving United States President Donald Trump.
The email-based attack was discovered by cybersecurity researchers at Trustwave who were reviewing their spam traps.
Targets are sent an email with the attachment “TRUMP_SEX_SCANDAL_VIDEO.jar”. Those who click on the malicious Java Archive (JAR) file unwittingly install the Qnode Remote Access Trojan (RAT) onto their computer.
Unusually, the title of the malicious file bore no resemblance to the subject of the email to which it was attached.
When the researchers opened the email “GOOD LOAN OFFER!!,” they expected to discover nothing more than an investment scam. However, attached to the email was an archive containing the malicious JAR file.
“We suspect that the bad guys are attempting to ride the frenzy brought about by the recently concluded Presidential elections since the filename they used on the attachment is totally unrelated to the email’s theme,” wrote researchers.
An investigation into the attack revealed that the JAR file is a variant of a QRAT downloader researchers brought to the public’s attention in August. Similarities between the new and old variants include Allatori Obfuscator’s being used to obfuscate the JAR file and the installer of Node.Js’s being retrieved from the official website nodejs.org.
As is the case with the old variants, researchers found that the new downloader supports Windows platforms only.
Researchers noted that while the Trump sex scandal email campaign used to deliver the malware “was rather amateurish,” the new QRAT was more sophisticated than prior variants.
“This threat has been significantly enhanced over the past few months since we first examined it. To achieve the same end goal, which is to infect the system with a QNode RAT, the JAR file downloader characteristics and behavior were improved,” wrote researchers.
The attackers ditched the string “qnodejs,” which can distinguish the files related to this threat. And, to avoid detection, they split up the malicious code of the downloader into different buffers inside the JAR.
Researchers advised email administrators to “take a hard line” against inbound JARs and to use their email security gateways to block them.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Army Reserve Gets First Cyber General
Army Reserve Gets First Cyber General

The United States Army has promoted the first Army Reserve cyber officer to the rank of brigadier general.
Colonel Robert Powell Jr. was promoted in a December ceremony held at Signal Theater at Fort Gordon in Georgia. Having pinned the one-star rank to his Army Green Service Uniform, Powell will serve as the deputy commanding general of the 335th Signal Command (Theater).
Powell was born in Tennessee and graduated from Middle Tennessee State University in 1991. He was commissioned through the Reserve Officer Training Corps (ROTC) and started his military career as an armor officer with the 1st Cavalry Division at Fort Hood, Texas.
In 2004, Powell joined the Army Reserve as a military intelligence officer. He commanded the US Army Reserve Cyber Protection Brigade from 2016 to 2019 and recently mobilized to support the Cyber National Mission Force, US Cyber Command at Fort Meade in Maryland.
Powell’s promotion ceremony was hosted by Maj. Gen. Stephen J. Hager, deputy commander of operations, Cyber National Mission Force, US Cyber Command, who Powell met during a deployment in Kuwait. Hager recruited Powell to the Cyber National Mission Force after being tasked with finding talented senior officers for US Army Cyber Command.
“Out of over 200,000 people in the Army Reserve, there are less than 130 general officers,” said Hager. “The jump from colonel to flag officer is a very competitive endeavor.”
Hager added that with his acceptance of the new role, Powell’s allegiance to the Army had entered new territory.
“This is a major event,” said Hager. “This appointment and promotion come with a very large commitment. I often tell leaders that when you are a colonel with 25 to 30 years you are ‘seriously dating the Army. When you become a general, you are married to the Army.'”
Hager told Powell’s wife, daughter, and son, who were present at the ceremony, that they should be proud of Powell’s promotion.
“Rob is the first United States Army Reserve General Officer to come from the cyber branch. That is significant since it demonstrates to our younger troops that there is a path to general officership,” said Hager.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US Jails Cuban Credit Card Skimming Crew
US Jails Cuban Credit Card Skimming Crew

The United States has imprisoned the leader and several members of a cyber-gang that stole $5m in a skimming attack on gas pumps in the Eastern District of Virginia.
According to court documents, the six conspirators placed skimming devices on gas pumps located in Northampton County. The devices recorded the credit and debit card numbers, along with their PINs, of customers who used their card at the pump to pay for gas.
In April and May 2018, the crew traveled to various branches of the supermarket Harris Teeter, among other destinations, and used the stolen card information to withdraw money from the victims’ bank accounts. The illicitly obtained financial data was also exploited to purchase prepaid gift cards.
The all-male crew, who are all Cuban nationals residing in Florida, was sentenced on January 5 to a total of more than 28 years in prison. Four of the men were convicted of aggravated ID theft while all six were convicted of conspiracy to commit bank fraud.
Several other conspirators involved in the attack remain at large and are thought to be living in Mexico.
The Department of Justice said that many of the conspirators “had significant criminal histories involving the same conduct and were known to travel the country perpetrating this scheme.” Over the course of several years, the gang caused victims to suffer aggregate losses of over $5m.
Crew leader Yasmani Granja Quijada used his email account to deal in stolen data. The 33-year-old was found to be trading over 9,800 additional stolen credit card numbers.
Quijada received the largest sentence of 120 months in prison. Twenty-nine-year-old Luis Miguel Fernandez Cardente received 64 months; 31-year-old Jorge Bello Fuentes, 60 months; 34-year-old Guillermo Bello Fuentes, 47 months; 40-year-old Pedro Emilio Duran, 30 months; and 29-year-old Yariel Monsibaez Ruiz, 19 months.
The FBI and US Marshals Service seized numerous vehicles and other items that were purchased by the criminals with stolen funds, including a 2006 Triton 2895CC Boat and trailer, a 2017 Ford F250 Super Cab truck, a 2016 Cruise Radiance Travel Trailer RV, a 2017 Ford Escape SUV, a 2017 Maserati Ghibli, and a 2013 Porsche Panamera.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Data Stolen from London Council Published Online
Data Stolen from London Council Published Online

Sensitive data stolen from Hackney Council in the UK has allegedly been published online, three months after the ransomware attack on the local authority that took place last year.
A cyber-criminal group called Pysa/Mespinoza has claimed it has published a range of information resulting from the incident on the dark web. This includes sensitive personal data of staff and residents, such as passport documents.
In October 2020, London’s Hackney Council revealed it had been victim of a serious cyber-attack which affected many of its services and IT systems.
In a new statement on its website, the council said it was working with NCSC, National Crime Agency, Information Commissioner’s Office, the Metropolitan Police and other experts to investigate what has been published and the next steps to take.
It noted that experts believe the data has not been published on a widely available public forum and is not visible through internet search engines, adding that “at this stage, it appears that the vast majority of the sensitive or personal information held by the council is unaffected, but the council and its partners are reviewing the data carefully and will support any directly affected people.”
Mayor of Hackney, Philip Glanville, stated: “I fully understand and share the concern of residents and staff about any risk to their personal data, and we are working as quickly as possible with our partners to assess the data and take action, including informing people who are affected.
“While we believe this publication will not directly affect the vast majority of Hackney’s residents and businesses, that can feel like cold comfort, and we are sorry for the worry and upset this will cause them.
“We are already working closely with the police and other partners to assess any immediate actions we need to take, and will share further information about the additional action we will be taking as soon as we can.”
Commenting on the story, Matt Aldridge, principal solutions architect, Carbonite & Webroot, said: “Once a data breach has occurred, and the data has been exfiltrated, no amount of ransom payment can guarantee that all copies of the data will be securely destroyed. For this reason, it is critical that all organizations invest appropriately in their cyber-defenses and, wherever possible, that they have their approach validated by trusted independent third parties.
“Understanding the criticality and sensitivity of all organizational data is key, and different data types, locations and classifications should be protected appropriately, with more investment and protection being put in place to protect the most sensitive data within the organization. Regular reviews need to be made to keep on top of this situation, as data locations, types and flows are constantly changing in any modern organization.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Panaseer Appoints Jonathan Gill as New CEO
Panaseer Appoints Jonathan Gill as New CEO

Enterprise security firm Panaseer has announced the appointment of Jonathan Gill as its new CEO.
Gill succeeds Panaseer founder Nik Whitfield in the role, with Whitfield becoming chairman and chief seer of the organization.
Gill brings a proven record of accomplishment in both leadership and sales, with previous roles including VP EMEA at RSA Security, EVP of global sales for Veracode and GM EMEA for Talend. He will focus on the international growth of Panaseer.
The security firm specializes in continuous controls monitoring (CCM) with its platform monitoring over four million entities for enterprise clients across two continents – Europe and North America.
Gill, CEO, said: “Throughout my career, the most fulfilling roles have been those where I have had scope to significantly scale a business to meet a global challenge. Panaseer offers the most exciting opportunity to date. Its platform is a game-changer for the security industry. It solves a major problem; the security landscape is increasingly complex, the rate of change is only accelerating.
“I am looking forward to working with the team to fulfil our vision of ensuring all enterprises have the proper safeguards to manage risk.”
Whitfield, chairman, added: “Our mission for our clients has always been to make sure their cybersecurity safeguards are switched on and working effectively at all times. Having established Panaseer as the first-choice platform to do this, the focus needed to shift to scaling the business.
“My decision to bring in a new CEO supports this growth objective, and the board and I are convinced that Jonathan is absolutely the right person to deliver on our ambitions and values.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Deepfake Technologies Set to Become Major Threat to Businesses
Deepfake Technologies Set to Become Major Threat to Businesses

Deepfake video and audio technologies could become a major threat to businesses over the next two years, leading to substantial financial losses, according to a report by CyberCube entitled Social Engineering: Blurring reality and fake.
The cyber insurance analytics firm said that cyber-criminals have become increasingly adept at creating realistic audio and video fakes using AI and machine learning technology in recent years. Advancements in this field have accelerated further as a result of the shift to remote working during the COVID-19 pandemic, as organizations become more reliant on video and audio-based methods of communication.
The study observed that the growing number of video and audio samples of business people available online provides further opportunities to simulate individuals in order to influence and manipulate others. This includes building photo-realistic representations of influential people, and the use of mouth mapping technology, which enables the movement of the human mouth during speech to be mimicked with high accuracy.
These methods can put organizations at risk of severe financial losses. For instance, the report highlighted a case where cyber-criminals used AI-based software to impersonate a chief executive’s voice to demand the fraudulent transfer of $243,000.
The analysis also highlighted how traditional social engineering techniques have been ramped up since the start of COVID-19. This includes gathering information available online or from stolen physical records to create a fake identity for a particular target, a practice known as social profiling. Methods such as this have become easier for cyber-villains because of the greater use of online platforms in addition to the blurring of domestic and business IT systems during the pandemic.
The report’s author Darren Thomson, head of cybersecurity strategy at CyberCube, commented: “As the availability of personal information increases online, criminals are investing in technology to exploit this trend. New and emerging social engineering techniques like deepfake video and audio will fundamentally change the cyber-threat landscape and are becoming both technically feasible and economically viable for criminal organizations of all sizes.
“Imagine a scenario in which a video of Elon Musk giving insider trading tips goes viral – only it’s not the real Elon Musk. Or a politician announces a new policy in a video clip, but once again, it’s not real. We’ve already seen these deepfake videos used in political campaigns; it’s only a matter of time before criminals apply the same technique to businesses and wealthy private individuals. It could be as simple as a faked voicemail from a senior manager instructing staff to make a fraudulent payment or move funds to an account set up by a hacker.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk