US Senate Approves New Deepfake Bill

US Senate Approves New Deepfake Bill

US legislation mandating government research into deepfakes took a step closer to becoming law this week after it passed the Senate by unanimous consent.

Sponsored by Democrat senator for Nevada, Catherine Cortez Masto, the Identifying Outputs of Generative Adversarial Networks (IOGAN) Act recognizes the need for such research as nation states and cyber-criminals hone their tools.

“This bill directs the National Science Foundation (NSF) and the National Institute of Standards and Technology (NIST) to support research on generative adversarial networks. A generative adversarial network is a software system designed to be trained with authentic inputs (e.g. photographs) to generate similar, but artificial, outputs (e.g. deepfakes),” noted a summary of the bill.

“Specifically, the NSF must support research on manipulated or synthesized content and information authenticity and NIST must support research for the development of measurements and standards necessary to accelerate the development of the technological tools to examine the function and outputs of generative adversarial networks or other technologies that synthesize or manipulate content.”

Just this week, Europol, the UN and Trend Micro warned in a new report of the malicious use of deepfakes.

The tech offers cyber-criminals and state actors opportunities to extort high profile figures through pornographic and other content with their faces superimposed, undermine governments through misinformation and could also be used in quasi-BEC attempts to persuade corporate victims to make large wire transfers.

The latter technique has already been used by attackers with an audio clip, in which a British CEO was tricked into sending £200,000 to his attackers.

The potential for political disruption perhaps accounts for the Senate’s unanimous approval of IOGAN.

“In 2019, a deepfake video that went viral in Malaysia involved a political aide who appeared to confess to having had homosexual relations with a cabinet minister,” noted the Europol report.

“Additionally, the video included a call to have the minister investigated for alleged corruption. While the motive behind the video (beyond character defamation) remains unclear, it succeeded to wreak havoc politically and destabilize the coalition government.”

The US bill must now pass through the House of Representatives.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Black Friday Alert as E-Commerce Attacks Surge in 2020

Black Friday Alert as E-Commerce Attacks Surge in 2020

Security researchers are warning of a spike in cyber-attacks against retailers this year which may impact the coming Black Friday and holiday season shopping spree.

Imperva’s State of Security Within e-Commerce report was compiled using data from its various security products.

It noted several attack trends this year likely to have been influenced by the greater numbers of shoppers heading online during COVID-19 lockdowns.

First, it claimed that e-retailers experienced more than twice as many account takeover (ATO) attempts than any other industry this year — 62% of login pages were hit versus 25%. Nearly 79% of retailers suffered credential stuffing, where previously breached credentials are used in automated attacks across large numbers of sites.

This chimes with an Akamai study which found that retail accounted for over 90% of the 64 billion credential stuffing attempts detected over 2018-2020.

Bots are used to power such attempts, and indeed 98% of the attacks featured in Imperva’s report originate from automated bot activity. While many are used by cyber-criminals, bots can also be deployed by retailers for price scraping and inventory tracking of competitors, the report claimed.

Elsewhere, API attacks have surged past usual levels this year, with cross-site scripting (42%) and SQLi (40%) together accounting for the majority as attackers sought to access customer databases.

However, XSS only accounted for 16% of the total volume of attacks on retailer websites this year: more common were remote code execution (21%) and data leakage (20%) raids, with 49% aimed at US sites by attackers using anonymizing tools.

DDoS attacks have also increased in volume and intensity this year. Imperva monitored an average of eight application layer attacks per month against online retail sites, with a significant peak occurring in April 2020, when major lockdowns came into force.

Imperva also warned that retailers are particularly exposed to Magecart and similar attacks, given that on average the industry uses 31 JavaScript resources per site.

This all bodes ill for e-commerce players this Black Friday, when traffic is expected to be higher than ever.

“The holiday shopping season is a crucial revenue period for retailers every year, but in 2020, they face a two-pronged threat: managing unprecedented levels of human and attack traffic to their websites and APIs,” said Edward Roberts, application security strategist at Imperva.

“Amid this historic holiday shopping season, the retail industry is likely to experience a peak in human traffic that exceeds anything measured this year and unlike anything in recent memory. The question is, how many attackers are going to hide within this expected traffic spike?”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Symantec Reports on Cicada APT Attacks against Japan

Symantec is reporting on an APT group linked to China, named Cicada. They have been attacking organizations in Japan and elsewhere.

Cicada has historically been known to target Japan-linked organizations, and has also targeted MSPs in the past. The group is using living-off-the-land tools as well as custom malware in this attack campaign, including a custom malware — Backdoor.Hartip — that Symantec has not seen being used by the group before. Among the machines compromised during this attack campaign were domain controllers and file servers, and there was evidence of files being exfiltrated from some of the compromised machines.

The attackers extensively use DLL side-loading in this campaign, and were also seen leveraging the ZeroLogon vulnerability that was patched in August 2020.

Interesting details about the group’s tactics.

News article.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk