Breakup Plan for Cyber Command and NSA

Breakup Plan for Cyber Command and NSA

The Trump administration has come up with a proposal to split up the leadership of US Cyber Command and the National Security Agency (NSA).

Under the existing “dual-hat” arrangement, the posts of CYBERCOM commander and NSA director are held by one individual. Right now, that person is General Paul Nakasone.

The proposal, which could significantly reshape America’s defense policy, was received by the joint chiefs of staff and joint chiefs chairman General Mark Milley at the end of last week. 

Milley, together with Acting Defense Secretary Chris Miller, must certify that the plan meets a particular set of standards laid out by Congress in 2016. 

Given that he told Congress in 2019 that the current leadership structure was effective and should continue, Milley is unlikely to approve the proposal. 

In his Senate nomination hearing for chairman of the joint chiefs of staff on July 11, Milley said: “The current ‘dual hat’ configuration between US Cyber Command and the National Security Agency is working well and should be maintained.”

He added that the joint chiefs of staff would benefit from a cyber-readiness review similar to that conducted by the US Navy and reported on in March 2019, including annual cyber-training for all personnel, including military, government, and contractors.

Colonel Dave Butler, a spokesperson for Milley, said on Saturday that the chairman “has not reviewed nor endorsed any recommendation to split CYBERCOM and NSA.”

US Cyber Command, the digital attack–fighting branch of America’s military, was established in 2009. 

The timing of the proposal to split the role into two distinct posts comes just after the United States was struck by a large-scale cyber-attack that impacted at least six federal agencies. An investigation into the true extent of the assault and from whence it originated is ongoing. 

In a joint statement issued on Sunday, Senators Ben Sasse and Angus King and Representatives Mike Gallagher and Jim Langevin said that the timing of the proposal, mere weeks before the end of Trump’s presidency, was all wrong. 

“Regardless of whether it’s better to keep or end the dual-hat arrangement between NSA and CYBERCOM, now is not the time to do it,” said the statement.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Attacks Surge in Q3 as Cyber-Criminals Shift Tactics

Ransomware Attacks Surge in Q3 as Cyber-Criminals Shift Tactics

A record growth in ransomware attacks took place in Q3 of 2020 compared to Q2, from 39% to 51% of all malware attempts, according to Positive Technologies’ Cybersecurity Threatscape: Q3 2020 report.

The study also found that hacking accounted for 30% of all attacks during Q3, with cyber-criminals reducing their emphasis on social engineering tactics compared with earlier this year. The researchers noted that the percentage of social engineering attacks using COVID-19 as a lure fell from 16% in Q2 to just 4% in Q3, which they attribute to people becoming more accustomed to this crisis. Additionally, social engineering attacks targeting organizations fell from 67% of all attempts in Q1 to under half (45%) in Q3.

Healthcare organizations were heavily targeted in this period, including pharmaceutical sites where COVID-19 vaccine research was being conducted. Half of all attacks against this sector involved ransomware, which resulted in serious consequences, such as the crippling of hospital functions.

The cybersecurity firm added that attackers continued to target increased network insecurity brought about by the mass shift to remote working, with exploitation of vulnerabilities up by 12 percentage points quarter-on-quarter (to 30%).

Encouragingly, there was a slow-down in the growth in attacks experienced during the first two quarters of the year, with the number of incidents rising by 2.7 percentage points compared to the previous quarter. However, the rate of targeted attacks went up from 63% to 70%.

Yana Yurakova, analyst at Positive Technologies, commented: “According to our data, COVID-19 is being exploited in attacks on individuals as well as organizations. In regard to individuals, we see that the number of phishing emails related to COVID-19 is dropping quickly. Pandemic-themed messages fell from 16% of social engineering attacks in Q2 to just 4% in Q3.

 In the previous quarter, phishing emails would advertise personal protective equipment or offer information about the virus, whereas now they are exploiting interest in a vaccine. One mailing addressed to people in the UK claimed that local vaccine efforts were going slowly and offered a supposed vaccine for sale on the site of a Canadian pharmacy chain. Individuals need to stay extra vigilant of the threats which are circulating linked to the pandemic.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Gallagher Appoints Three New Cybersecurity Specialists

Gallagher Appoints Three New Cybersecurity Specialists

Insurance broker Gallagher has announced the appointment of three new cybersecurity specialists to grow its cyber-risk knowledge, thereby helping clients better prepare themselves against attacks.

The appointments are designed to enhance Gallagher’s cyber-practice within its UK retail division, which provides clients with cyber-protection and insurance cover to prevent cyber-incidents in addition to protection in the event they suffer a cyber-attack.

Jay Lucas has taken on the role of cyber-risk technical lead, in which he will oversee penetration and vulnerability testing to allow clients to identify security weaknesses across their network architecture. Lucas was previously a cybersecurity specialist at IntaForensics and prior to that, worked for Leicestershire Police for 16 years.

Gallagher has also appointed two new cyber-risk consultants, Stephen Randles and John Clarke, who will help clients achieve relevant industry accreditation, such as Cyber Essentials. They will also conduct open source intelligence investigations on behalf of clients to understand the risk of sensitive information being harvested by those with malicious intent towards the business. Randles joins from McLaren Automotive while Clarke moves from insurance broker Clearview Credit and Financial Risks Limited.

Johnty Mongan, cyber-risk consultant at Gallagher, commented: “As businesses become more reliant on their digital capability, in part driven by the increase in remote working as a result of COVID-19, ensuring they have a high level of protection against cyber-attacks, and identifying ways in which common cybersecurity risks can be mitigated against, is now an important consideration for companies of all sizes. 

“There isn’t a one size fits all approach to cybersecurity, and our practice plays a crucial role in helping organizations identify, mitigate and respond to any cyber-risk they might be facing, and ensuring they have appropriate insurance cover in place should they become victim to cyber-criminals.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Stolen Card Prices Soar 225% in Two Years

Stolen Card Prices Soar 225% in Two Years

The price of stolen credit card details and cybercrime tools has in many cases seen triple-digit growth over the past two years, according to new dark web research compiled by Flashpoint.

The risk intelligence firm trawled some of the more established cybercrime marketplaces across the deep and dark web, across eight categories: from government-issued IDs to DDoS-for-hire services, exploit kits, RDP server access and “fullz.”

The cost of credit card dumps soared 225%, from $12.44 in 2018 to $26.50 this year, it revealed. Fake US passports can reach around $525 while the price rises even higher ($3500) for UK versions.

DDoS-for-hire services have nearly quadrupled in price since 2017, to around $165 for a fully managed attack, or provider-specific options potentially hitting $250.

According to Flashpoint, the “as-a-service” model has become increasingly popular of late because it enables those managing the services to customize on-the-fly, in order to improve success rates in response to enhanced mitigation on the defender side.

Access to RDP servers is often paired with online payment accounts to facilitate quick and easy fraud — available for upwards of $575. US bank account and routing numbers can also fetch hundreds, going for $530 when additional linked accounts are included in packages, said Flashpoint.

Phishing kits with “how-to” guides go for as little as $35, while exploit kits targeting Office 365 can cost $125.

Flashpoint argued that stolen data and cybercrime tools have increased in price across 2020 thanks to more online activity in general over the past year.

“The pricing analysis we conducted heading into 2021 illuminates some of the unique market dynamics and trends we see throughout dark web marketplaces — such as the long-tail effects of the global coronavirus pandemic and changes in buying and selling behavior stemming from an increase in working from home and online shopping,” added head of intelligence, Tom Hoffman.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New US Bill Will Punish Foreign Firms’ IP Theft

New US Bill Will Punish Foreign Firms’ IP Theft

The US Senate has unanimously passed a new bipartisan bill designed to punish foreign firms that actively seek to steal American intellectual property (IP).

Co-authored by senators Chris Van Hollen and Ben Sasse, the Protecting American Intellectual Property Act will allow the authorities to place sanctions on firms and individuals associated with such activity.

It will require a report to Congress every six months identifying any individual or firm that has engaged in or benefitted from serial theft of US trade secrets, and whether this could be construed as a threat to national security, foreign policy, the economy and/or financial stability of the nation.

If a firm is identified as such, the President must impose property blocking sanctions or prohibit US exports for it, while individuals will also be hit with property blocking sanctions and be banned from entering the US.

There’s also a national interest waiver in the legislation.

Although China is not mentioned by name in the legislation, it’s clear which country and types of company were front-of-mind when the senators were drawing it up.

Van Hollen argued that the US can’t sit by while companies and the governments enabling them “cheat their way to success.

“Foreign companies are working overtime to steal US technology, damaging our economy and our national security in the process. The need to fight back could not be more urgent — especially after the series of cyber-attacks we have witnessed aimed at the COVID-19 vaccine,” he added.

“This bill draws a line in the sand — outlining clear consequences these bad actors will face if they steal American innovation and technology. I was proud to work with senator Sasse on this bipartisan effort, and I’m glad to see the Senate act to hold these foreign entities accountable and protect American jobs.”

The legislation must now make its way through the House of Representatives, although there’s broad bipartisan support for tougher action on China. The House passed another bill co-sponsored by Van Hollen earlier this month. It was designed to prevent fraudulent foreign companies listed on US stock markets from escaping regulatory scrutiny, as Chinese ones have for over a decade

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Indicts Former Zoom China Liaison for Doing PRC’s Bidding

US Indicts Former Zoom China Liaison for Doing PRC’s Bidding

A former China liaison at Zoom has been indicted by the US for interfering in meetings, monitoring users and fabricating evidence against them as per Beijing’s instructions.

Xinjiang (“Julien”) Jin, faces a maximum 10 years in prison if found guilty of conspiracy to commit interstate harassment and unlawful conspiracy to transfer a means of identification. However, Jin is unlikely to face trial given that he’s based in China.

The former Zoom man was originally hired at the behest of the Communist Party after it blocked the service in China in autumn 2019. His alleged role appears to have been something akin to an unofficial content censor and spy.

“Part of Jin’s duties included providing information to the PRC government about [Zoom] users and meetings, and in some cases he provided information – such as Internet Protocol addresses, names and email addresses – of users located outside of the PRC,” the indictment noted.

“Jin was also responsible for proactively monitoring [Zoom] video communications platform for what the PRC government considers to be ‘illegal’ meetings to discuss political and religious subjects unacceptable to the Chinese Communist Party (CCP) and the PRC government.”

Most notably, Jin is said to have terminated four meetings held to remember the Tiananmen Square massacre. He and others are alleged to have infiltrated the meetings, and fabricated evidence using fake emails to claim that the attendees were supporting terrorist organizations, inciting violence and/or distributing child pornography.

They used this ‘evidence’ to justify shutting down the meeting and, in turn, the government in Beijing used it to intimidate attendees and/or their families based in China.

“The allegations in the complaint lay bare the Faustian bargain that the PRC government demands of US technology companies doing business within the PRC’s borders, and the insider threat that those companies face from their own employees in the PRC,” argued acting US attorney Seth DuCharme. 

“As alleged, Jin worked closely with the PRC government and members of PRC intelligence services to help the PRC government silence the political and religious speech of users of the platform of a US technology company. Jin willingly committed crimes, and sought to mislead others at the company, to help PRC authorities censor and punish US users’ core political speech merely for exercising their rights to free expression.”

Zoom has published a blog post in response highlighting the things it is doing to improve transparency and internal controls to protect freedom of speech. These include: end-to-end encryption, strict geo-fenced data routing to prevent content being routed through China, restricted access controls for Chinese employees and improved data protection training for all employees.

It also said that all government requests must now first be approved by Zoom’s US legal team.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk