Hacker Earns $2m in Bug Bounties

Hacker Earns $2m in Bug Bounties

An ethical hacker from Romania has become the first person to earn $2m in bug bounties through the bounty hunting platform HackerOne.

Talented hacker Cosmin Lordache, also known by his HackerOne handle @inhibitor181, hit his first significant earning milestone almost a year ago when he became the seventh person to pass the million-dollar earning milestone by reporting 468 flaws through the bug bounty hunting platform.

Today, HackerOne announced on the social media platform Twitter that Lordache’s all-time earnings had reached the $2m mark.

The company said: “334 days ago we announced Lordache as the 7th hacker to reach $1 million dollars in earnings. Today we celebrate his achievement to be the FIRST to reach $2 million! Please join us in congratulating @inhibitor181!”

Lordache, who is 30 and now lives in Germany with his wife and two dogs, started hunting for bug bounties just three years ago while working as a full-stack developer. Since taking up bug bounty hunting, he has been crowned The Assassin at both the h1-65 live hacking event in Singapore and last year’s h1-4420 live hacking event in London. 

Santiago Lopez, whose hacker handle is @try_to_hack, was just 19 when he became the first bug bounty millionaire. Today, his name is joined by eight others on the bug bounty millionaire list. 

Australian Nathaniel Wakelam, known to the hacking community as @nnwakelam, is the second-highest bug bounty earner behind Lordache. To date, Wakelam has earned $1.8m, making him just $200k shy of his next major money milestone.

Demonstrating excellent sportsmanship, Wakelam shared Twitter’s post regarding Lordache’s achievement along with the comment “Beat me by $200k. Congratulations to @inhibitor181!”

The Aussie even encouraged his bug bounty hunting rival to keep up the good work, adding: “See you at 3M.”

In 2019, HackerOne reportedly paid out approximately $40m in bug bounties, with most hackers earning under $20k per year from detecting and reporting bugs. So far, the platform has paid ethical hackers in over 170 different counties a total of $82m.

The platform currently has more than six million bug bounty hunters—a figure that has nearly doubled over the past 12 months—and hosts bug bounty hunting programs for more than 1,700 government agencies and companies. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

White Ops Acquired by Goldman Sachs

White Ops Acquired by Goldman Sachs

American cybersecurity company White Ops announced today that it has been acquired by Goldman Sachs‘ Merchant Banking Division in partnership with ClearSky Security and NightDragon

Terms of the transaction, which follows Goldman Sachs’ and ClearSky’s initial investment in White Ops earlier this year, were not disclosed.

The business was acquired from previous investors Paladin Capital Group, Grotech Ventures, and other shareholders.

White Ops was founded in 2012 and is based in New York City. The company’s core focus is protecting enterprises from fraud and sophisticated bot attacks, including account takeover, automated account creation, and web scraping, by verifying interactions. 

In a year that has seen many businesses struggle and fail, White Ops has grown the number of customers it serves by 40%. To deal with the extra workload, the company increased the number of people it employs by 25% to 170.

According to statements made on its website, White Ops currently verifies over 10 trillion interactions per week.

CEO and co-founder of White Ops Tamer Hassan said that the acquisition will help White Ops to accelerate its expansion into new markets. 

“Goldman Sachs, ClearSky, and NightDragon are ideal partners to support the next phase of the Company’s evolution and growth across multiple markets, use cases and geographies,” said Hassan.

“Their continued support of our mission to disrupt the economics of cybercrime, global network of relationships, and market expertise provides a very strong foundation to execute on our vision to enable collective protection for the internet.”

Jay Leek, managing partner at ClearSky, said that the strength and quality of White Ops’ platform was impressive. 

“As fraud and abuse become increasingly prevalent across the digital ecosystem, enterprises and internet platforms require sophisticated threat protection now more than ever,” said Leek. 

“White Ops has proven that it can stop fraud and abuse at tremendous scale.”

Leek, along with representatives from Goldman Sachs, will join the Board of Directors representing ClearSky. Founder and managing director of NightDragon Dave DeWalt will join the Board of Directors representing NightDragon and serve as White Ops’ vice chairman.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

SolarWinds Hackers “Impacting” State and Local Governments

SolarWinds Hackers “Impacting” State and Local Governments

America’s Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning over the widespread impact of a recent hacking attack that compromised the SolarWinds Orion software supply chain.

The assault on SolarWinds hit the headlines earlier this month after it was discovered and disclosed by researchers at FireEye. The advanced persistent threat (APT) group behind the attack was able to compromise government agencies, critical infrastructure, and private-sector organizations.

Recognizing the serious nature of the attack, CISA put out an emergency directive on December 13 calling “on all federal civilian agencies to review their networks for indicators of compromise and disconnect or power down SolarWinds Orion products immediately.”

On Wednesday, the agency described the pervasive campaign as a “significant cyber incident” and said that it is affecting US government at all levels. 

In a statement posted to its website, the agency said that it “is tracking a significant cyber incident impacting enterprise networks across federal, state, and local governments, as well as critical infrastructure entities and other private sector organizations.”

CISA stated that the APT actor responsible for compromising the SolarWinds Orion software supply chain has also carried out widespread abuse of commonly used authentication mechanisms and is well resourced. 

The agency then went on to warn organizations to focus on handling the threat posed by this particular campaign before tackling any other cybersecurity issues.   

“This threat actor has the resources, patience, and expertise to gain access to and privileges over highly sensitive information if left unchecked,” warned the agency. 

“CISA urges organizations to prioritize measures to identify and address this threat.”

The agency has teamed up with the Federal Bureau of Investigation (FBI) and the Office of the Director of National Intelligence (ODNI) to form a Cyber Unified Coordination Group (UCG) that will coordinate a whole-of-government response to the SolarWinds attack.

CISA said that it remains available to help organizations victimized by the incident.

The agency said that it “remains in regular contact with public and private sector stakeholders and international partners, providing technical assistance upon request, and making information and resources available to help those affected to recover quickly from incidents related to this campaign.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

HelpSystems Acquires Vera to Expand Data Security Offerings

HelpSystems Acquires Vera to Expand Data Security Offerings

HelpSystems has announced the acquisition of cloud-based data protection provider Vera.

The IT software firm said the deal will enable it to expand its data security portfolio and help meet a growing demand for solutions that can protect information throughout the full data lifecycle. This includes data classification, file transfer, data loss prevention and encryption.

The need for improved data security has been driven by the shift to remote working in many organizations as a result of the COVID-19 pandemic this year. With sensitive data now being managed across multiple networks and devices rather than within the secure perimeter walls of corporate buildings, organizations have become more vulnerable to breaches. Increasingly, businesses are using cloud technology to store sensitive IP, and keeping this secure is crucial.

Vera helps address this issue by enabling organizations to secure, track, audit and revoke data access at any time by attaching military-grade encryption, access controls, security and policy directly to data.

Kate Bolseth, CEO of HelpSystems, commented: “The market for data security is evolving fast to require a comprehensive approach to discovery, detection, classification and dynamic encryption. Vera seamlessly integrates and expands HelpSystems data security solution offerings and we welcome the Vera employees and their expertise to the global HelpSystems family.”

Shri Dodani, Vera president and CEO, said: “I’m pleased Vera is joining a global company with a comprehensive set of solutions empowering customers to strengthen their approach to data security.

“Vera solutions extend HelpSystems’ existing data security portfolio meeting the needs of our combined customers and partners.  We have been working together at some of our largest customers and have proven the joint value proposition and look forward to expanding our go-to-market leveraging HelpSystems global footprint and resources.” 

It is the latest move by HelpSystems to expand its information security options following the acquisition of two data classification companies in June.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Government Security Experts Issue Farmers with New Advice

Government Security Experts Issue Farmers with New Advice

The UK’s National Cyber Security Centre (NCSC) has issued its first ever guidance for farmers, in a sign of the growing cyber-threat facing rural businesses.

Published on Tuesday, Cybersecurity for Farmers is a comprehensive guide to best practices covering everything from spotting suspicious emails and phone calls to password management, device security and the importance of backing up.

The UK’s farms are increasingly run with the aid of technologies such as automated machinery, smart security cameras and back-office management and productivity software, the NCSC claimed.

National Farmers’ Union (NFU) deputy president, Stuart Roberts, warned that this makes the sector attractive to cyber-criminals.

“Cyber-attacks can be devastating for businesses and the individuals who are victims to fraudulent activity. It can affect agricultural businesses in a number of ways, including leaking of confidential data or financial losses,” he argued.

“As farms rely more on technologies such as GPS, remote sensing and unmanned vehicles, the risks increase. Cyber-criminals are becoming increasingly sophisticated and savvy, finding new ways to exploit us or find vulnerabilities in our technological security to steal passwords, money or data.”

The guide urges farmers to: regular patch any software, replaced/update operating systems and devices when they reach end-of-life, switch on password protection and use encryption tools to protect devices and ensure firewalls and anti-malware are on and up-to-date.

There was also advice for creating strong passwords and supplementing this with two-factor authentication, as well as anti-phishing, smishing and vishing tips.

“Technology plays a huge role in modern farming and offers many benefits that will help the industry to thrive in the 21st century,” said NCSC deputy director for economy and society, Sarah Lyons.

“We are teaming up with the NFU to share best online practice to the sector, as an increased use of technology also sees an increased risk of being targeted by cyber-criminals.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Misconfigured AWS Bucket Exposes Hundreds of Social Influencers

Misconfigured AWS Bucket Exposes Hundreds of Social Influencers

A misconfigured cloud storage bucket has exposed the personal details of hundreds of social media influencers, potentially putting them at risk of fraud and harassment, according to researchers.

A team at vpnMentor discovered the AWS S3 bucket wide open with no encryption or password protection, back in early November. Action has apparently yet to be taken by the company responsible, Barcelona-based “social commerce” company 21 Buttons.

For a commission, influencers upload their photos to the firm’s app and link to the e-commerce stores where users can buy the clothes they’re wearing.

According to vpnMentor, the firm has around two million monthly active users and partnerships with many of the biggest brands in Europe.

Of the 50 million files exposed in the snafu, which were mainly influencer photos and videos, the research team discovered hundreds of invoices said to relate to payments made to these social media stars.

Among the personally identifiable information (PII) exposed were full names, postal codes, bank details, national ID numbers, PayPal email address and value of sales commissions.

Those caught in the data leak included Carlota Weber Mazuecos, Freddy Cousin Brown, Marion Caravano, Irsa Saleem and Danielle Metz – influencers that between them have millions of followers on the site.

The vpnMentor team warned that if cyber-criminals get hold of the PII, the victims could be exposed to follow-on phishing scams designed to obtain more bank and card details, identity fraud and stalking.

“If somebody shared the invoices publicly, bad actors would have plenty of material to identify any private accounts held by influencers, as well as their homes and workplaces,” it claimed.

“This doesn’t just make the people affected vulnerable to phishing and fraud. They’re also at risk from an invasion of privacy, doxing, stalking and harassment – both online and offline.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Lawsuit Takes Aim at Ring After Smart Doorbell Hijacking

New Lawsuit Takes Aim at Ring After Smart Doorbell Hijacking

Dozens of customers of a popular smart doorbell are suing the Amazon-owned manufacturer after their devices were hijacked, according to a new class action lawsuit.

The new legal case joins together complaints filed by over 30 users in 15 families who say that their devices were hacked and used to harass them.

They allege that the company has failed to update its security measures in the aftermath of these incidents and that it “blamed the victims, and offered inadequate responses and spurious explanations,” according to The Guardian.

A notable case last year involved a Ring camera which was installed in an eight-year-old girl’s room by her parents. It was subsequently hijacked by a man claiming to be Santa Claus who played unsettling music through its speaker, taunted the child and asked her if they could be friends.

Other incidents cited in the case involved users being threatened with sexual assault, murder, racial slurs and blackmail, according to the report.

Although Ring’s position has been to blame users for not setting up strong enough passwords on their devices, thereby allowing attackers to brute force or guess them, the suit alleges that the company itself should have required strong passwords and two-factor authentication (2FA) out-of-the-box.

It also claims that Ring may be to blame for a 2019 incident in which compromised usernames, camera names and passwords for over 3600 users were found online.

The firm has denied that it was breached, claiming the list could have been compiled from compromises elsewhere. However, the addition of Ring camera names to the trove would seem to rule out standard credential stuffing.

Other key contention of the lawsuit is that Ring “has not sufficiently improved its security practices or responded adequately to the ongoing threats its products pose to its customers.”

The smart device market is increasingly in need of regulation to mandate baseline security for users. The UK is taking a lead on this, by forcing all consumer devices to require unique passwords which are not resettable to factory defaults, alongside other measures.

However, there’s no mention of how strong these passwords need to be, and 2FA seems to have been left out of the law.

The US lawsuit apparently covers the tens of thousands of customers who bought a Ring doorbell between 2015 and 2019, even if they were not hacked. Lead attorney on the case, Hassan Zavareei, has claimed that there may be many more users affected who don’t yet know they were hacked.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk