Hiding Malware in Social Media Buttons

Clever tactic:

This new malware was discovered by researchers at Dutch cyber-security company Sansec that focuses on defending e-commerce websites from digital skimming (also known as Magecart) attacks.

The payment skimmer malware pulls its sleight of hand trick with the help of a double payload structure where the source code of the skimmer script that steals customers’ credit cards will be concealed in a social sharing icon loaded as an HTML ‘svg’ element with a ‘path’ element as a container.

The syntax for hiding the skimmer’s source code as a social media button perfectly mimics an ‘svg’ element named using social media platform names (e.g., facebook_full, twitter_full, instagram_full, youtube_full, pinterest_full, and google_full).

A separate decoder deployed separately somewhere on the e-commerce site’s server is used to extract and execute the code of the hidden credit card stealer.

This tactic increases the chances of avoiding detection even if one of the two malware components is found since the malware loader is not necessarily stored within the same location as the skimmer payload and their true purpose might evade superficial analysis.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

AI Collaborative Research Institute Launched

AI Collaborative Research Institute Launched

A trio of companies is launching a new research institute whose intended purpose is to strengthen privacy and trust for decentralized artificial intelligence (AI). 

The Private AI Collaborative Research Institute, originally established by Intel‘s University Research & Collaboration Office (URC), is launching as a joint project involving digital security and privacy products vendor Avast and AI software-defined secure computing hardware services company Borsetta.

“As AI continues to grow in strength and scope, we have reached a point where action is necessary, not just talk,” said Michal Pechoucek, CTO at Avast.

“We’re delighted to be joining forces with Intel and Borsetta to unlock AI’s full potential for keeping individuals and their data secure.’’

By decentralizing AI, the companies aim to protect privacy and security, free inaccessible data from silos, and maintain efficiency. The trio said that centralized training can be easily attacked by modifying data anywhere between collection and the cloud. 

Another security issue surrounding contemporary AI stems from the limitations of Federated Machine Learning, a technique used to train an algorithm across multiple decentralized edge devices. 

While today’s federated AI can access data at the edge, the team behind the Institute said that this technique cannot simultaneously guarantee accuracy, privacy, and security.

“Research into responsible, secure, and private AI is crucial for its true potential to be realized,” said Richard Uhlig, Intel Senior Fellow, vice president and director of Intel Labs.

Borsetta said it was inspired to join the collaboration by its strong belief in driving a privacy-preserving framework to support the future hyperconnected world empowered by AI. 

“The mission of the Private AI Collaborative Institute is aligned with our vision for future proof security where data is provably protected with edge computing services that can be trusted,” said Pamela Norton, CEO of Borsetta.

“Trust will be the currency of the future, and we need to design AI embedded edge systems with trust, transparency, and security while advancing the human-driven values they were intended to reflect.”

A call for research proposals issued earlier this year has resulted in the selection of nine research projects at eight universities in Belgium, Canada, Germany, Singapore, and the United States to receive Institute support.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Smart Sex Toy Sales Surge Poses Security Risk

Smart Sex Toy Sales Surge Poses Security Risk

A cybersecurity company has urged the rising number of smart sex toy owners to think about protection.

Sales of internet-connected sex toys, also known as teledildonics, have increased since lockdown measures were introduced to slow the spread of COVID-19. 

In March alone, sex toy revenue in France, Italy, and Spain, where lockdown measures were particularly stringent, exceeded projected figures by 94%, 124%, and 300%, respectively.

In “Cybersecurity Trends 2021: Staying secure in uncertain times,” ESET researchers Denise Giusto and Cecilia Pastorino describe how this particular tech is a potential hotbed of privacy and security concerns that may result in users’ most private information being exposed.

“With new models of smart toys for adults entering the market all the time, we might imagine that progress is being made in strengthening the mechanisms to ensure good practices in the processing of user information,” wrote the researchers. 

“However, many researchers have shown that we are a long way from being able to use smart sex toys without exposing ourselves to the risk of a cyber-attack.”

The duo said that the extremely sensitive information processed by smart sex toys could be exploited by cyber-criminals hoping to make money through sextortion or by authorities in countries whose citizens are banned from engaging in certain sexual practices. 

Smart sex toy data that could fall into the hands of an oppressive government regime or digital blackmailer include names, sexual preferences and orientations, the names of sexual partners, information about device usage, and sexually explicit images and videos.

Most of the smart sex toy devices currently on the market are controlled via Bluetooth Low Energy (BLE) from an app installed on a smartphone.

“As well as concerns about data confidentiality, we must consider the possibility that vulnerabilities in the app could allow malware to be installed on the phone, or firmware to be changed in the toys,” noted researchers.

“These situations could lead to DoS (Denial of Service) attacks that block any commands from being delivered.”

Researchers urged users to practice data-safe sex by avoiding risks where possible; for example, being careful not to use an official name or email address that could identify them when registering for sex apps.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Tech CEO Pleads Guilty to Investment Fraud

Tech CEO Pleads Guilty to Investment Fraud

The former chief executive officer of a technology startup based in Virginia has admitted conning investors out of millions of dollars. 

Danny Boice pleaded guilty yesterday to one count of securities fraud and one count of wire fraud before senior United States district judge T.S. Ellis III of the Eastern District of Virginia.    

Alexandria resident Boice held the position of CEO at the now bankrupt Trustify Inc, a privately held company that he co-founded in 2015. Headquartered in Crystal City, the business provided a digital platform that enabled customers in need of a sleuth to connect with private investigators.  

According to admissions made in connection with the plea agreement, the 41-year-old former CEO fraudulently solicited investments in Trustify from 2015 onwards by, among other things, falsely overstating the company’s financial performance.

By lying about how much money the company was really making, Boice managed to raise approximately $18.5m from over 90 investors.

After investors handed over the money, Boice siphoned off millions of dollars that he used to purchase luxury items and services for himself. 

In a statement released December 3, the Department of Justice wrote: “Despite representing to investors that their funds would go towards operating and growing Trustify’s business, Boice diverted at least $3.7 million for his own benefit and to fund his lifestyle.  

“This included the purchase of a home in Alexandria, Virginia, travel by private jet, and furnishing a seaside vacation home.”           

An indictment unsealed in federal court on July 24, 2020, charged Boice with five counts of wire fraud, one count of securities fraud, and two counts of money laundering.

Boice’s case is currently being investigated by FBI’s Washington Field Office. Trial Attorney Blake Goebel of the Criminal Division’s Fraud Section and Assistant U.S. Attorney Russell Carlberg of the Eastern District of Virginia are prosecuting the case. 

Trustify ceased operating suddenly at the tail end of 2018. Four lawsuits were later brought against the company by PR firms, private investigators, a real estate investment company, and investors who sued for malfeasance. 

Boice is scheduled to be sentenced on March 19, 2021.      

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Set for Evolution in Attack Capabilities in 2021

Ransomware Set for Evolution in Attack Capabilities in 2021

Ransomware is set to evolve into a greater threat in 2021 as service offerings and collaborations increase.

Speaking on a webinar this week, Carbon Black’s Tom Kellermann, Greg Foss and Rick McElroy said the year turned out “different than predicted” and the shift to working from home also impacted the e-crime landscape. “This created an industrialization of e-crime groups and their abilities to extend from single groups into business pipelines,” Foss said. This has led to a supply chain of one party getting access, to another selling access and another “selling access to a ransomware-as-a-service group.”

Foss explained the traditional end goal of ransomware operators is to offer up the service as that has led to the concept of “double extortion techniques” where systems were once encrypted across the network and a payment was requested, but now, as users are able to better recover from backups, attackers are changing their tactics to exfiltrate sensitive information from a company and post it online as a means of blackmail.

As well as becoming more efficient and professional, Foss also said the groups are smaller than realized and are focusing on the ransomware-as-a-service option. Also, access is gained to networks and “is more wide reaching and pivotable nowadays than we saw in years past.”

Kellerman said: “The Maginot line of cybersecurity transformation failed as the first adopters were the e-crime groups and cybercrime cartels, and we just have to pay attention now as perimeter defenses have failed and continue to fail, and visibility and hardening has become an extreme challenge. Most attacks you see today are attacks from the inside out – digital insiders using trusted ecosystems to leverage ransomware attacks and espionage and crime campaigns.”

Looking at ransomware in particular, the trio said they do not see this stopping or slowing down “and we continue to predict that this is going to extend significantly,” Foss said. He claimed ransomware groups have brought more people into their groups and are making sure they are getting trusted people, with nation state adversaries taking part as well.

“We see this reaching out to additional operating systems; traditionally this has only impacted Windows primarily, but with MacOS having such a market reach in the professional ecosystem of most organizations, we predict it will be targeted as well,” Foss said. “Linux is one we have started to see more campaigns begin to target, and a lot are looking at defacing webpages in addition to taking over core components of ecosystems that these companies operate.”

Foss also explained that there is greater collaboration between ransomware groups, and in 2021, he predicts that we will see more ransomware and the variants “will be re-factored and turned into purely destructive attacks.”

He said there have been attacks on large databases where everything is wiped and replaced with fake data, and he predicted that the destructive attacks will be used more in the future.

McElroy said this is a case of the attacker thinking about what else they can do with ransomware, as they are using it to conduct Denial of Service attacks too. “I expect to see a large increase in that as the adversaries collect more data on what is actually critical to the inside of these organizations,” he said.

Asked by Infosecurity about how attackers are using ransomware for more than the initial encrypt and extortion, McElroy said the idea is that extortion is big business, but now access is being sold on the dark web “and that becomes really dangerous as you have a bunch of guys on the dark web who execute attacks for cryptocurrency.” However, he also said there is a “trickle down effect” where there are innovators at the top of the model who do innovative things.

“Innovation is occurring at the top end, but as soon as this stuff hits the wild, the cyber-groups learn from that and scale it out as well,” McElroy said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#WebSummit: Nick Clegg Claims Internet Needs Accountability, Not Rules

#WebSummit: Nick Clegg Claims Internet Needs Accountability, Not Rules

Speaking as part of the online Web Summit in conversation with John Micklethwait, editor-in-chief of Bloomberg News, former deputy Prime Minister and leader of the Liberal Democrats Nick Clegg said there is a concern where technology is blamed for everything from the results of elections to climate change.

Now VP of global affairs at Facebook, Clegg said the ability to use data at scale “is considered to be suspicious or dodgy” and his conversations with politicians and policy makers globally suggest a “deep seated imprecise antagonism to the idea that data can be held safely, and at scale, to provide free tools.” He claimed that data has to be used in an inventive and ingenious way, as it will be the “lifeblood of medicine, health and education for years to come.”

Speaking on privacy, Micklethwait said there is a need to “grow up with new laws” especially as debates about Section 230 continue and Facebook makes “editorial decisions on what to show.” Clegg said there is a legitimate societal and political debate to be had on the role of technology in society, “and I think Section 230 is one of the things that should be revisited if there is the political consensus to do so in DC.”

Section 230 was passed into law in 1996, and provides immunity from liability for any “provider or user of an interactive computer service” for the content provided by a third party. It has come into focus as US President-elect Joe Biden has called for it to be revoked.

Clegg said there is a need for updated rules for the internet, as Section 230 exempts the likes of Facebook and YouTube from liability over content “that those companies themselves do not generate.” He argued that as Facebook is not a conventional publisher, it doesn’t have the requirement to spot malicious content, but Section 230 allows Facebook, YouTube and Twitter to “aggressively intervene on that content where it breaks the law or our own other standards.”

He added that Facebook had removed 2.5 million pieces of hate speech from its platform, degrading and labelling content and allowing fact checkers to do their work. “All of that is permitted under Section 230.” Clegg said that Section 230 allows these companies to do content moderation that people want to be done.

“The truth is Facebook is not like a conventional publisher, as billions of ordinary people post whatever they like and it is an amazing freedom that these technologies give, which is why I remain so enthusiastic as not withstanding the controversies, you’re empowering billions of people for free,” he said. Whilst Facebook doesn’t commission content, it does have a responsibility to “police the guardrails within which that content appears on our platform.” He said these can be guardrails set by law or its own content, while there is diversity of opinion on what is legal.

Asked by Micklethwait about what steps he would take if he were still in politics, Clegg said “as an old fashioned liberal who is not good when states start to interfere on what citizens can and cannot say,” governments should not get into legislation to determine what legal speech can be used on a platform, “as that is the route to very worrying state censorship.” However, what government should and will do is say to the likes of Facebook that it is their legal duty to show they have policies and practices in place to keep users safe and secure on the platform.

Also, systems need to be shown to be auditable and transparent, and if they are not operating like that, or fail, there will be penalties and sanctions attached.

“We need a systems-based form of accountability” and this is why Facebook publishes a transparency report every 12 weeks. He said this will be audited not to ensure government needs to step in, but to say to big companies “you have got to show that you have got all of your arrangements in place and do this as best as you can using content moderators, machine learning tools and by having accountable standards.”

Clegg concluded by saying you have to have these in place and if you do not “the law will come down hard on you, and that is the kind of accountability and transparency, in my own view, that would work best.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NCSC Warns of Multimillion Pound Christmas Fraud Bonanza

NCSC Warns of Multimillion Pound Christmas Fraud Bonanza

The UK’s National Cyber Security Centre (NCSC) is urging Christmas shoppers to exercise caution online this holiday season.

The GCHQ offshoot rolled out its updated Cyber Aware campaign today alongside the Home Office, the Cabinet Office and the Department for Digital, Culture, Media and Sport (DCMS).

According to the NCSC, there were over 17,400 reports of online retail fraud last Christmas shopping period, which runs from the start of November until the end of January. They amounted to total losses of £13.5m, or £775 per incident.

The truth is that the real size of online fraud could be many times higher, as cases are often not reported to the authorities.

With consumers expected to surge online this year due to government-imposed lockdowns and social distancing rules, fraudsters and cyber-criminals will be geared up for a bumper season.

NCSC CEO, Lindy Cameron, argued that technology will play a key role in the Christmas season this year.

“Scammers stole millions from internet shoppers last Christmas – but by following our advice, you can protect yourself from the majority of their crimes,” she added.

“We hope the Cyber Aware campaign helps people to shop confidently online and enjoy their Christmas.”

It focuses on six key steps that consumers can take to help them steer clear of online threats.

These are: using strong and unique passwords for email and other online accounts, saved in the browser for ease of use. The NCSC recommended creating passwords using three random words to make them harder to crack or guess. Two-factor authentication (2FA) should also be switched on wherever possible to further bolster access security.

The campaign also urged consumers to backup their data in case ransomware strikes and to update all devices and apps in case attackers look to exploit vulnerabilities to gain remote access.

“If you are shopping online this year, spend the time you would have spent wrapping up warm to head out to the shops on checking your online security,” urged Microsoft chief security advisor, Sian John.

“Let’s make sure the gifts we give this Christmas go to the people we love, not to the fraudsters who just want to steal your money.”

The campaign is set to run across TV, radio and online — the first time the NCSC has produced adverts for media.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

ACLU Sues Government Over Secret Purchasing of GPS Data

ACLU Sues Government Over Secret Purchasing of GPS Data

A rights group is suing the US government over what it claims to be the latter’s secret purchasing of mobile phone location data to track individuals.

The GPS data used by many apps is regularly sold to other companies for marketing and other purposes.

However, the American Civil Liberties Union (ACLU) this week claimed that, according to reports earlier in the year, some of these companies are selling it on to government agencies.

That raises a constitutional issue, as it appears as if the federal government is trying to bypass the Fourth Amendment, which protects people from unreasonable searches and seizures by the government. The ACLU argued that, instead, the agencies involved should be seeking legitimate court warrants to track individuals.

According to those reports, a company known as Venntel has been selling access to a massive database of GPS info to the US Department of Homeland Security, Customs and Border Protection (CBP) and Immigration and Customs Enforcement (ICE) so they can track and arrest immigrants.

“There’s even more reason for alarm when those agencies evade requests for information — including from US senators — about such practices,” the ACLU argued.

“That’s why today we asked a federal court to intervene and order DHS, CBP and ICE to release information about their purchase and use of precise cell phone location information. Transparency is the first step to accountability.”

Specifically, the ACLU wants to see all of the agencies’ records of purchase for the location data, including contracts, policies and procedures for use, communications with selling companies, legal documents and more.

It argued that a 2018 Supreme Court ruling, Carpenter vs United States, affirmed that government agencies cannot request personal location information from a phone company without first obtaining a search warrant from a judge.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Aerospace Giant Embraer Downed by Suspected Ransomware

Aerospace Giant Embraer Downed by Suspected Ransomware

Brazilian aerospace giant Embraer has revealed it suffered a data breach last week, although local reports suggest ransomware was involved.

The aircraft-maker, the world’s third largest after Boeing and Airbus, claimed in a brief statement on Monday that it suffered a cyber-attack resulting in the disclosure of data “attributed to the company” in the early hours of November 30.

Confusingly, the announcement also notes that the actual incident was identified on November 25, last Wednesday.

According to the statement, the attack “made access to only a single environment of the company’s files unavailable.”

The firm said it is now working to “normalize” its operations, which would indicate that at least some disruption had occurred.

“As a result of this occurrence, the company immediately initiated its procedures of investigation and resolution of the event, as well as proceeding with the proactive isolation of some of its systems to protect the systems environment, thus causing temporary impact on some of its operations,” it continued.

“The company continues to operate with the use of contingency systems, with no material impact to its activities.”

Although Embraer itself is being coy about the cause of the attack, local reports in Brazil were more revealing.

News site Globo confirmed that the cause was indeed ransomware, with sources claiming on Tuesday that the firm had not yet restored all its systems.

It was also claimed that a large number of Embraer servers were forced offline by the firm and that attackers managed to encrypt some backups. All remote workers were apparently affected for some time, although the IT department told them it was down to a system problem rather than cyber-attack.

Tripwire VP of strategy, Tim Erlin, argued that every organization today needs to be prepared for a ransomware attack.

“While we tend to focus on the response to ransomware, prevention is still the best way to deal with the threat,” he added.

“Ransomware doesn’t magically appear on systems, and the methods by which it’s introduced into an environment are generally well understood: phishing, vulnerability exploits and misconfigurations. Identifying and addressing the weak points in your security posture can help prevent ransomware, as well as other attacks, from being successful.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk