Cyber-Criminals Target #COVID19 Vaccine

Cyber-Criminals Target #COVID19 Vaccine

Cybersecurity analysts at IBM are urging cold-chain companies to be “on high alert” after discovering a spear-phishing scheme that targets global COVID-19 vaccine supply chains.

IBM Security X-Force created a threat intelligence task force dedicated to tracking down COVID-19 cyber-threats back when the current coronavirus outbreak exploded into a full-blown pandemic.  

Today the team announced that they had detected a global phishing campaign targeting organizations associated with the task of keeping coronavirus vaccines safely preserved at the correct temperature during storage and transportation.

The malicious campaign was launched in September 2020, striking at organizations in six different countries. Targeted organizations are likely associated with Gavi, the Vaccine Alliance’s Cold Chain Equipment Optimization Platform (CCEOP) program.

While IBM’s team was unable to definitively say who was behind the campaign, researchers observed the lack of an obvious cash-out from the scheme and said the precision targeting of executives and key global organizations “hold the potential hallmarks of nation-state tradecraft.”

Threat actors impersonated a business executive from Chinese company Haier Biomedical that is purportedly the only complete cold chain provider in the entire world. Haier, which is based in Qingdao, is a qualified supplier for the CCEOP program and a member company of the COVID-19 vaccine supply chain.

“Disguised as this employee, the adversary sent phishing emails to organizations believed to be providers of material support to meet transportation needs within the COVID-19 cold chain,” wrote researchers. 

“We assess that the purpose of this COVID-19 phishing campaign may have been to harvest credentials, possibly to gain future unauthorized access to corporate networks and sensitive information relating to the COVID-19 vaccine distribution.”

The campaign struck at global organizations headquartered in Germany, Italy, South Korea, Czech Republic, greater Europe, and Taiwan. Targets included the European Commission’s Directorate-General for Taxation and Customs Union, as well as organizations within the energy, manufacturing, website creation, and software and internet security solutions sectors. 

Spear-phishing emails were sent to hand-picked executives in sales, procurement, information technology, and finance positions using subjects regarding quotations (RFQ) related to the CCEOP program. 

Commenting on who might be responsible for the campaign, Sam Curry, chief security officer at Cybereason, told Infosecurity Magazine: “The list of candidates goes beyond the usual suspects and the truly suspect actors are those who don’t care about the long term relationships with the US and the civilized world. 

“Word to the wise: denying anyone access to the vaccine will be remembered.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#WebSummit: Companies of the Future Should Focus on Data Privacy Rather than Data Collection

#WebSummit: Companies of the Future Should Focus on Data Privacy Rather than Data Collection

New business getting set to launch have a strong opportunity to take an emphasis on allowing customers to bring their data to the company willingly, rather than insisting on owning it.

Speaking as part of the online Web Summit, the EFF’s Cindy Cohn, in conversation with David Gilbert from Vice News, said that since the launch of the EFF 30 years ago, the conversations around data and privacy ownership have changed as most people do not control their data.

“You own your data, but you don’t control it as you click it away for most of the services you use,” she said. “I like to think about controlling your data, that means we can put it beyond the scope of a simple click agreement and there are some situations where control cannot be taken from you and sometimes not at all.”

Cohn said that you need to think about the data you have and when law enforcement has it, and the EFF has set the rules on when the police have access, and now it is the time to focus on when companies have your data “as it has become something that you don’t control and is used against you.”

Asked by Gilbert what she thought about the actions of big companies that claim they have to obey the law but also protect consumers, Cohn said they could do better, but admitted they are in a difficult position. “We need to change some of the laws, and we need to change some of the ways technologies are structured and built,” she said.

In the context of the US, the EFF has been fighting the third party doctrine which stipulates that, when a consumer gives their data to a mobile phone company or ISP, “you’ve waived your constitutional protections as you’ve given them to a third party.”

Gilbert cited the GDPR as an example of how consumers in Europe have had the chance to take control of their data, and Cohn agreed that it is a good thing, although she mentioned that it does not contain anything on the law enforcement factor. “There is a broad understanding in Washington DC that this stuff matters, but the ‘what we do about it’ is widely different,” she said. “The part where everybody recognizes that we need to change is an important part, but I would say there is nothing like a widespread agreement on what needs to change.”

Asked by Gilbert about new companies starting up and the issue of data privacy and control, Cohn said there are companies emerging who have this principle “and there are fledging efforts to do this in almost everything.”

She recommended companies to “think about striking out in a different direction if they cannot compete with the big companies” as users should be able to find a way to move their data “as the general environment is getting in the way of doing this.

“If you’re a young start p now, you should really be looking for and supporting ways that people can actually bring their data to you and bring their networks to you and use your services in ways that really empower them and offer them a better choice,” she said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Orgs Told to Prepare for New Wave of Brexit-Related Scams

UK Orgs Told to Prepare for New Wave of Brexit-Related Scams

Barclays has warned UK businesses that cyber-criminals will target them with scams relating to changing rules at the end of the Brexit transition period.

The UK remains locked in negotiations about its relationship with the EU from the start of next year, and there is a lack of clarity over the new rules many businesses will be operating under.

The bank urged companies to stay extra vigilant as the deadline for the UK’s full departure from the EU approaches, with fraudsters likely to try and capitalize on this period of uncertainty in a similar way to how it has during the COVID-19 pandemic. It said it is vital that businesses ensure their fraud and scam prevention practices are up-to-date in areas such as receiving unexpected calls, protecting against malicious messages and on confirming the identity of new suppliers.

The warning came as Barclays published new research showing there has been a 20% rise in business scams during the last five months, many of which have exploited the uncertainty posed by COVID-19 . It noted “an uptick in the number and cost of scams to small businesses” as a result.

Impersonation of genuine organizations to gain personal or banking information was the technique most commonly employed by fraudsters according to the analysis, representing 42% of all attempts since January. In the last five months, use of this method went up by 79%.

This was followed by purchase scams, in which victims are tricked into purchasing non-existing products through a fake website. This made up 25% of all fraud attempts this year. In third place was invoice and mandate scams at 18%, whereby suppliers are impersonated in emails that request an update in bank details, potentially leading to large sums of money being transferred into the scammers account.

Jim Winters, Barclays head of fraud, said: “Many businesses across the UK are busy preparing ahead of the Brexit transition deadline. However, they need to be on their guard as fraudsters will often ramp up their efforts during uncertain periods. Business owners, perhaps not used to the new rules following our departure from the EU, may find it more difficult to differentiate between genuine and fake claims.

“It’s important that business owners and their staff are aware of the different type of scams that can occur and if they’re ever in doubt, they should always double check with their bank or a source they know is genuine.”

Commenting on Barclay’s statement, John Dobson, CEO of SmartSearch, said: “Criminals will take advantage of any opportunity, whether it’s the crisis caused by coronavirus, or uncertainty about new rules for businesses when we leave the EU at the end of December.

“The latest data from Barclays really does highlight how crucial it is for businesses to be sure about who they are dealing with when entering into a commercial relationship with another business. The fact is fraudsters are not just posing as individuals or customers looking to use a fake ID to launder money. They are organized and posing as businesses, CEOs, suppliers etc.

“Regulated businesses in the UK not only need to make sure they are compliant with Know Your Customer (KYC) legislation but also Know Your Business (KYB). Otherwise, they are seriously exposed to fraud and also to financial penalties from the Financial Conduct Authority (FCA).”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Quarter of Firms Suffered 7+ Serious Cyber-Attacks in 2020

Quarter of Firms Suffered 7+ Serious Cyber-Attacks in 2020

Nearly a quarter (23%) of global organizations suffered seven or more attacks that infiltrated their networks over the past year, and a majority believe it will happen in the coming 12 months, according to Trend Micro.

The security giant commissioned the Ponemon Institute to calculate its biannual Cyber Risk Index (CRI), which measures the gap between responding organizations’ current security posture and their likelihood of being attacked.

This edition features information from Europe and APAC for the first time to offer a global perspective.

Some 83% of respondents claimed that the chances of attacks gaining a foothold inside networks or IT systems over the next year are “somewhat” or “very” likely.

The CRI is based on a numerical scale of -10 to 10, with -10 representing the highest level of risk. The current global index stands at -0.41, representing “elevated” risk, although it is highest globally in the US (-1.07) due to a perceived lack of cyber-preparedness versus other regions. 

Responding organizations claimed their top cyber-risks globally are: phishing and social engineering, clickjacking, ransomware, fileless attacks, botnets and man-in-the-middle attacks. They’re most concerned about loss of customer data, IP and financial information, customer churn, and stolen or damaged equipment.

However, there were differences between certain countries. US respondents were unique in also listing the cost of outside consultants as a top negative consequence of attack, while in APAC, damage to critical infrastructure concerned organizations.

The top security risks within IT infrastructure highlighted by respondents were: organizational complexity and misalignment, negligent insiders, cloud infrastructure and providers, skills shortages and malicious insiders.

Trend Micro’s global threat communications director, Jon Clay, described the CRI as a useful resource for organizations keen to better understand their risk postures.

“It will help organizations across the world find better ways to cut through complexity, mitigate insider threats and skills shortages, and enhance cloud security to minimize cyber-risk and drive post-pandemic success,” he argued.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#WebSummit: Balancing Security, Privacy and Free Speech in the Digital Age

#WebSummit: Balancing Security, Privacy and Free Speech in the Digital Age

Resolving the conflicts between security and issues such as privacy and free speech next year and beyond in the US was discussed by a panel during the online Web Summit 2020.

One issue highlighted was the growing levels of disinformation across the internet, a problem that is particularly difficult to resolve in countries like the US where the principle of freedom of speech is so engrained. Susan Landau, professor at Tufts University, explained: “The disinformation problem is a unique one to the US; we’re such firm believers in our first amendment that we find it very hard to prescript what kind of information can be easily available.”

Nevertheless, there is the potential for solutions that can tackle the scourge of fake news without necessarily impinging free speech rights. Landau highlighted the approach taken by Baltic countries, largely in response to misinformation campaigns emanating from nearby Russia. They focused on educating their citizens to be much more analytic and careful not to take things they see and hear at face value. “Long-term, that’s part of a solution if we’re going to keep the first amendment,” she added.

However, such an approach is unlikely to be by itself adequate, with Paul Syverson, mathematician at US Naval Research Laboratory, noting that “if all the information you’re getting is only framed by one perspective and it’s a distorted one, or one that is full of misinformation, it’s going to be very hard for you to practice this judgement.”

It is therefore important to place more emphasis on large tech firms to frame misleading content in a certain way, without actually preventing its availability on their platforms. An example of this is labelling certain claims as disputed, as was seen from the Twitter response to some of President Trump’s allegations about voter fraud during this year’s election. Syverson pointed out that “while section 230 [of the Communications Act] does protect your ability to put up content produced by others with impunity, you are free to make this available and police it yourself as best you can.”

Adapting the section 230 legislation to disincentivize tech firms to stop targeting individuals with only certain types of information and perspectives based on their interests could be another consideration going forward, according to Landau.

The need to recognize that physical safety and cybersecurity are becoming increasingly interlinked was also highlighted by the panel. Bruce Schneier, founder and security expert at Schneier on Security, noted that the growing reliance on digital technologies for critical services, ranging from medical devices to electricity plants, is likely to be an increasing target for cyber-villains. “There are a lot of laws and regulation around things that are physically dangerous and computers are going that way,” he said.

This year, the response to the COVID-19 pandemic by government has thrown up a number of new issues in the security-privacy debate, including the use of contact tracing apps and the potential for immunity passports when vaccines are introduced. Schneier acknowledged that most people are appreciative that such measures are justifiable in a time of emergency, “as long as we recognize that it is temporary.”

Syverson concluded on a positive note, expressing hope that the COVID-19 pandemic would serve as a “wake-up call” for people about the extent of misinformation out there, with many of the claims made so contrary to reality that it is impossible to ignore.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Law to Crack Down on Fraudulent Foreign Firms Listed in US

New Law to Crack Down on Fraudulent Foreign Firms Listed in US

The House of Representatives has passed a new bill designed to prevent fraudulent foreign companies listed on US stock markets from escaping scrutiny by the Securities and Exchange Commission (SEC).

The bipartisan Holding Foreign Companies Accountable Act will prohibit foreign firms from listing any of their securities on US exchanges if they fail to comply with the Public Company Accounting Oversight Board’s (PCAOB) audits for three years in a row.

The PCAOB’s role is to establish whether the information presented by listed firms is accurate, independent and trustworthy.

The law will also require public companies to disclose whether they’re owned or controlled by a foreign government.

It’s therefore not hard to see where the bill is primarily aimed. Beijing currently refuses to allow PCAOB audits of homegrown companies despite having been in negotiations with US authorities for over a decade. Vague national security concerns are often cited as an obstacle to progress.

This lack of scrutiny resulted in US investors in Chinese firm Luckin Coffee losing significant sums after the Starbucks rival was found to have fabricated sales by hundreds of millions of dollars.

The bill, sponsored by US senators Chris Van Hollen and John Kennedy, was presented as a way to protect ordinary US investors and their families.

“Millions of American families rely on modest investments to retire, send their kids to college and weather financial emergencies. but many have been cheated out of their money after investing in seemingly legitimate Chinese companies that are not held to the same standards as other publicly listed companies,” argued Van Hollen.

“This bill rights that wrong, ensuring that all companies on US exchanges abide by the same rules. I’ve been proud to work with senator Kennedy on this bipartisan legislation, and I’m glad to see it pass the House with such strong support. I urge the President to sign this bill into law immediately.”

The bill will not only target Chinese firms, although their number has surged significantly on US exchanges in recent years as they seek to raise capital abroad.

According to the SEC, 224 US-listed companies are located in countries where there are obstacles to PCAOB inspections, with a combined market capitalization of more than $1.8tn.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Philly Food Bank Loses $1m in BEC Scam

Philly Food Bank Loses $1m in BEC Scam

A Philadelphia food bank has been scammed out of nearly $1m following a classic business email compromise (BEC) attack, it has emerged.

Philabundance is the region’s largest hunger-relief organization and receives tens of millions of dollars in donations every year.

Earlier this year, it was in the process of completing a new $12m community kitchen, which is when it was sent an invoice by what managers thought was a construction company supplier.

However, the email was in fact spoofed by attackers and the $923,533 was lost, according to The Philadelphia Inquirer. To make matters worse, the firm then had to find the same amount to pay the legitimate supplier.

It appears as if the non-profit was hit by a classic BEC scam, where attackers compromise an employee’s email account and then silently monitor messages sent back and forth.

They then step in to send a spoofed invoice from a legitimate supplier at the time one was expected to come in, so as not to raise an alarm at the victim organization. Certain emails are deleted to hide their tracks.

The FBI issued a warning last week that organizations should switch off automatic email forwarding to external addresses, as these rules are often deployed by attackers to send messages from compromised inboxes to their own.

It added that in some cases, web and desktop email clients are not synced by IT administrators, meaning security teams can’t see when remote workers, or attackers, make rule changes.

BEC made scammers $1.8bn in 2019, over half the $3.5bn total for all reported cybercrime, according to the FBI.

Colin Bastable, CEO of Lucy Security, argued that policies for supplier payments should be updated to limit the number of individuals authorized to make them, and to require additional authorizations from senior managers and the supplier itself for large sums.

“The Philabundance attack checks all the boxes of a successful BEC scam: in-depth research to identify the target, social engineering exploits to penetrate the network, creation of a fake invoice from a known email address and the request to wire funds to a phony bank account,” he said.

“BEC scams cleverly play on two glaring human vulnerabilities: an employee’s susceptibility to social engineering, and their unquestioning trust in the chain of command. The best way to help prevent these types of attacks is to provide regular security training for employees, and establish specific business and financial policies for company payments.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#WebSummit: Growing Acceptance of Ethical Hacking

#WebSummit: Growing Acceptance of Ethical Hacking

There should be a re-evaluation of what hacking is and how it is viewed, according to Michiel Prins, co-founder at HackerOne, speaking during the online Web Summit 2020.

“When people think of the word hacker they often think of a bad person,” he explained, adding that “for us at HackerOne, if you use your hacking skill to find vulnerabilities, and then report those vulnerabilities to the companies affected so they can fix them, that is an ethical hacker.”

He stated that those who undertake hacking for nefarious purposes should simply be labelled “criminal.”

HackerOne is a company that works with the global hacker community to uncover security vulnerabilities in organizations throughout the world. Prins revealed it now has over 2000 customers on its platform with 900,000 hackers signed up to it, who together have so far discovered around 200,000 vulnerabilities.

He explained that it was much trickier starting out back in 2012, however, with limited response from many organizations when it contacted them about security weaknesses it had uncovered. It was those companies “born on the internet” such as tech firms in Silicon Valley that were far and away the most receptive to the concept of ethical hacking.

This is now changing, according to Prins. “Over the years, we’ve seen more traditional companies start to embrace it, from big banks like Goldman Sachs all the way to government institutions like the US Department of Defense,” he said.

Working with these more conventional organizations has meant that as well as finding vulnerabilities, it is also important for an ethical hacking service such as HackerOne to help provide the solutions. Prins commented: “You definitely need a process in place that allows you to remediate vulnerabilities, and typically those have to happen fast because if you find a critical vulnerability you can’t wait a couple of weeks to start fixing it.”

He outlined that the types of vulnerabilities discovered vary significantly, ranging from gaining access to sensitive data to being able to open a bridge.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Sectigo Acquires SSL247 and Xolphin

Sectigo Acquires SSL247 and Xolphin

Web security firm Sectigo has announced the acquisition of two companies to expand its enterprise and IoT solution offerings. These are SSL247, a SSL certificate and web security provider operating across 18 countries in Europe and Latin America and Xolphin, which provides SSL certificates and digital signatures in the Netherlands.

Sectigo said the move was in response to the growing demand, particularly in Europe, for identity management and web security solutions. It will also enable the US-based company to extend its reach to thousands of additional organizations throughout Europe and Latin America, supporting its growth goals.

SSL247 sells and supports SSL certificates, as well as offering vulnerability assessments, digital IDs, penetration tests and more, while Xolphin has issued over a million certificates to more than 50,000 customers in Europe. Both companies will maintain their brands as Sectigo subsidiaries.

Bill Holtz, CEO of Sectigo, commented: “Acquiring SSL247 and Xolphin is an early milestone in Sectigo’s next chapter of growth, expanding our reach across Europe and Latin America. Sectigo has partnered with SSL247 and Xolphin for many years. Both organizations are known for rapid and reliable SSL certificate delivery and world-class expertise and support. We proudly welcome them to Sectigo.”

Benjamin Tack, commercial director at SSL247, added: “As digital security experts, SSL247 is driven to help secure the value of businesses online and offline, through a range of specifically tailored services. Joining the global Sectigo organization will enable our team to offer a broader set of resources and solutions to our more than 10,000 satisfied clients, spanning micro businesses to large enterprises.”

The announcement means Sectigo has undertaken four acquisitions during the past three years, following the purchase of Codeguard in 2018 and Icon Labs last year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk