Cloudhouse Acquires UpGuard Core to Help Customers Resolve Compliance Issues

Cloudhouse Acquires UpGuard Core to Help Customers Resolve Compliance Issues

Tech firm Cloudhouse Technologies has announced the acquisition of UpGuard Core, an infrastructure monitoring platform previously owned by UpGuard Inc. Cloudhouse said the move will help enable its customers to find, manage and resolve configuration and compliance issues throughout their IT infrastructure.

UpGuard Core will now be renamed Cloudhouse Guardian and will form part of Cloudhouse’s application compatibility packaging solutions. Cloudhouse Guardian can identify what businesses have in their infrastructure estate as well as pinpoint anything that’s out of date and non-compliant. Additionally, compliance can be automatically achieved by aligning with best practice configuration.

A number of major global organizations are currently using Cloudhouse Guardian to monitor and manage their IT infrastructure, including The New York Stock Exchange and NASA.

Cloudhouse added that the acquisition will help it scale its existing operations in the US as well expand its presence in Europe and APAC regions.

Cloudhouse founder and CEO, Mat Clothier commented: “The launch of Cloudhouse Guardian is an important step in our development, allowing us to offer our customers a wider set of capabilities that build on our core skills. This is a hugely exciting time for Cloudhouse. Having just been named the 13th Fastest Growing Technology Company in the UK by Deloitte, we are eager to build on that and Cloudhouse Guardian will be important to our continued growth.”

Alan Sharp-Paul, co-founder and co-CEO of UpGuard said: “With the rapid growth of our security offerings we are pleased to have found a great home for Core and are looking forward to the development of this product under Cloudhouse, while we continue to cement our position as leaders in the third-party risk management space.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Society at Increasingly High Risk of Cyber-Attacks

Society at Increasingly High Risk of Cyber-Attacks

Cyber-attacks are becoming easier to conduct while conversely security is getting increasingly difficult, according to Kevin Curran, senior IEEE member and professor of cybersecurity, Ulster University, during a virtual media roundtable.

“Any company you can think of has had a data breach,” he commented. “Whenever a data breach happens it weakens our credentials because our passwords are often reused on different websites.”

He observed that the art of hacking doesn’t necessarily require a significant amount of technical expertise anymore, and bad actors can receive substantial help from numerous and readily accessible tools online. “You don’t have to spend seven years in college to learn how to hack, you just have to know about these sites and what terms to use,” noted Curran.

A number of legitimate online mechanisms that can help damaging attacks to be launched by hackers were highlighted by Curran in his presentation. These include Google Dorks, which are “search strings which point to website vulnerabilities.” This means vulnerable accounts can be identified simply via Google searches.

Another are free penetration testing toolkits online such as Metasploit, which can enable hackers to undertake exploits very easily. He said that “with a bit of training you can do a lot of damage with this one tool.”

Curran also demonstrated the free online tool Shodan, which scans the internet and categorizes publicly accessible devices, such as webcams. As with Metasploit, the primary users are cybersecurity professionals, but can be utilized by those with malicious intent as well to hack such devices.

Denial of Service (DoS) attacks, whereby websites can be brought down through sending too many packets, can also be conducted relatively easily nowadays, according to Curran. “If you have a complete collection of compromised webcams, you can have them all point to Microsoft.com and bring it to its knees,” he said.

As attacks get easier to conduct, cybersecurity is becoming more complex due to the growing reliance on digital technology and internet connections; something that has been exacerbated by the COVID-19 pandemic.

The security issues associated with IoT devices, such as watches, doorbells and webcams are well documented, but reliance on internet connections is going much wider than this, including even cars and aeroplanes. Curran cited a recent IEEE survey, which showed that the top security concern for chief information officers and chief technology officers was employees bringing their own devices to work and securing IoT.

“We’re moving towards a world where we’re increasingly relying on technology,” he said, outlining recent examples where essential services have been disrupted as a result of this growing connectivity, including the power outage in Ukraine in 2016. This is an issue that countries must be prepared to for in the future.

Curran added: “Everything seems to be moving towards smart cities, but what happens when they crash?”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Set to Block SolarWinds Orion Binaries

Microsoft Set to Block SolarWinds Orion Binaries

Microsoft is preparing to quarantine malicious versions of the SolarWinds Orion application used in recent nation state attacks, in a move that may crash systems.

The computing giant had previously released detections to alert customers of its Windows Defender security product if they were running the malicious updates. Although it was recommended that such customers isolate and investigate any such devices, the decision was down to them.

However, in an update yesterday Microsoft effectively said it was taking the decision out of the hands of its customers.

“Starting on Wednesday, December 16 at 8:00 AM PST, Microsoft Defender Antivirus will begin blocking the known malicious SolarWinds binaries,” it said.

“This will quarantine the binary even if the process is running. We also realize this is a server product running in customer environments, so it may not be simple to remove the product from service.”

Over the weekend reports emerged that a previous attack on FireEye was part of a much larger Russian intelligence plot to steal sensitive information from US government and countless other unnamed organizations.

The vector was Orion updates which the attackers managed to seed with malicious binaries used to install the Sunburst (aka Solarigate) backdoor malware. SolarWinds confirmed to the SEC that 18,000 customers were affected.

However, as the product performs crucial network management operations, Microsoft’s decision could theoretically cause some disruption.

“It is important to understand that these binaries represent a significant threat to customer environments,” it argued. “Customers should consider any device with the binary as compromised and should already be investigating devices with this alert.”

Microsoft urged victim organizations to immediately isolate affected devices, identify accounts used on the device and assume they have been compromised, reset passwords, look for lateral movement tools and more.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NCSC Names Academic Centers of Excellence in Cybersecurity Education

NCSC Names Academic Centers of Excellence in Cybersecurity Education

Abertay University has been named among the first eight UK universities to be awarded Academic Centre of Excellence in Cyber Security Education by the National Cyber Security Centre (NCSC).

Abertay University is the first university in Scotland to receive the Academic Centre of Excellence in Cyber Security Education Gold Award, along with Lancaster University, University of Southampton, University of South Wales, University of Surrey, University of the West of England and University of Warwick.

The announcement comes as the region receives £11.7m of UK and Scottish Government funding through the Tay Cities Region Deal, which will unlock major investment in Dundee’s cyberQuarter project which brings a new research and development center to Abertay’s campus in Dundee.

In granting Abertay Academic Centre of Excellence recognition, the NCSC recognized the plans for the Dundee cyberQuarter, which is designed to attract existing cybersecurity firms to Dundee, support the creation of new companies and boost the security and resilience of the Scottish business community, as well as the high quality of the University’s degree programs.

The Academic Centre of Excellence will become the pathway for Abertay students to interact with and benefit from the research and knowledge exchange activities of the cyberQuarter and its business links.

Professor Nigel Seaton, principal of Abertay University said: “Being named a UK Academic Centre of Excellence in Cyber Security Education and the launch of the cyberQuarter project will place the University and the city of Dundee at the heart of Scotland’s cybersecurity sector.

“We are confident that by combining academic expertise, student talent, enterprise support and industry knowledge in this way, we have all the ingredients for significant sectoral growth and new job opportunities, as well as innovation in research and business development.”

UK Government Minister Iain Stewart said: “Congratulations to Abertay University on this important and prestigious accolade from the UK’s National Cyber Security Centre. I am delighted that we are seeing Tayside go from strength to strength as a national hotbed of cyber research and innovation. The UK Government is supporting this through its £150 million investment in the Tay Cities Region Deal, which will create thousands of jobs and support our economic recovery from coronavirus.”

Chris Ensor, NCSC deputy director for Cyber Growth, said the first tranche of universities as Academic Centres of Excellence in Cyber Security Education complement its existing programs which recognize high quality cybersecurity research and degree courses.

“It is a testament to the continual efforts of academics, support staff and senior management that cybersecurity remains high on their agenda,” Ensor said. “We very much look forward to working with them over the coming years and strongly encourage other universities to work towards achieving similar recognition in the future.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Account Fraud Surges 28% in the UK as Global Rates Drop

New Account Fraud Surges 28% in the UK as Global Rates Drop

New account fraud surged by 28% year-on-year in the UK as global rates fell by nearly the same amount, according to new data from Jumio.

The online verification firm analyzed tens of millions of global transactions over the past year up to November, to compile its annual Holiday Fraud Report.

It revealed that while the global average for new account fraud rates dropped 23% year-on-year, it increased by over a quarter in the UK. The country has the second-highest fraud levels in Europe after Spain, which recorded a 25% increase in ID-based fraud in 2020.

The report recorded attempts to bypass fraud checks using both government-issued IDs and selfies. Fraud rates in the UK based on ID documents almost doubled from 2017 levels, and fraud levels in November were a third higher than those from January to October in 2020, it revealed.

Jumio claimed the relatively high rates of fraud in the UK could be attributed to the large number of financial services customers based there.

The industry is by far the most affected by fraud of any surveyed globally, although it did manage to record a drop in rates from 2019. However, in the UK it was the online gaming and cryptocurrency verticals that had the highest levels of new account fraud during the year; an indication of ongoing money laundering activity, Jumio claimed.

Interestingly, the global drop in new account fraud came during a year in which many experts have been claiming fraud rates have risen.

“One possible explanation is that more legitimate customers were opening accounts through online channels instead of in person, so the percentage of bad actors in the total transactions we processed dropped as a result,” the report noted.

“Another possibility is that fraudsters redirected their efforts to easier targets where security was more lax and they did not have to divulge personal information about themselves, such as providing a selfie, which is self-incriminating.”

The firm argued that by adding selfie-based authentication to government ID uploads, organizations have the best chance of weeding out scammers. It claimed to have seen 80% less fraud using this method compared to customers who only require a government-issued ID.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Total Published CVEs Hits Record High for Fourth Year

Total Published CVEs Hits Record High for Fourth Year

The past 12 months have seen a record number of CVEs published by the US authorities, the fourth year in a row volumes have risen.

As of December 15, the number of vulnerabilities in production code discovered and assigned a CVE number by the US-CERT Vulnerability Database, topped the 2019 figure.

Last year there were 17,306 CVEs published, including 4337 high-risk, 10,956 medium-risk and 2013 low-risk flaws. As of yesterday, 17,447 were recorded in total, including 4168 high-risk, 10,710 medium-risk and 2569 low-risk bugs.

Between 2005-16 numbers ranged from around 4000 to 8000 vulnerabilities each year, according to the official figures from the National Institute of Standards and Technology (NIST)’s National Vulnerability Database.

However, in 2017 the number skyrocketed to over 14,000, and each year since published volumes have hit a record high.

K2 Cyber Security, which noticed the recent record spike, argued that the pandemic may have had an impact on disclosures this year.

“Companies still struggle to find the balance between getting applications to market quickly, and securing their code. The COVID-19 pandemic is a major factor this year,” argued the vendor’s co-founder and CEO, Pravin Madhani.

“It’s pushed many organizations to rush getting their applications to production; they run less QA cycles, and use more third-party, legacy, and open source code, which is a key risk factor for increased vulnerabilities.”

To mitigate these risks, DevOps teams should shift security as far left in the lifecycle as possible, while sysadmins should patch as soon as they can to ensure operating systems and critical software are up-to-date, he said.

“Finally, it’s important to have a security framework that offers a defense-in-depth architecture. It’s time to take a hint from the recent finalization of NIST’s SP800-53 that was just released on September 23,” said Madhani.

“The new security and privacy framework standard now requires Runtime Application Self-Protection (RASP) as an added layer of security in the framework.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Zodiac Killer Cipher Solved

The SF Chronicle is reporting (more details here), and the FBI is confirming, that a Melbourne mathematician and team has decrypted the 1969 message sent by the Zodiac Killer to the newspaper.

There’s no paper yet, but there are a bunch of details in the news articles.

Here’s an interview with one of the researchers:

Cryptologist David Oranchak, who has been trying to crack the notorious “340 cipher” (it contains 340 characters) for more than a decade, made a crucial breakthrough earlier this year when applied mathematician Sam Blake came up with about 650,000 different possible ways in which the code could be read. From there, using code-breaking software designed by Jarl Van Eycke, the team’s third member, they came up with a small number of valuable clues that helped them piece together a message in the cipher

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk