UK in Cyber-War Against Anti-vaccine Propaganda

UK in Cyber-War Against Anti-vaccine Propaganda

British spies are on a cyber-mission to disrupt the spread of anti-vaccine disinformation online by hostile states and terrorist groups, according to The Times.

The paper reported today that GCHQ has begun a digital offensive operation to prevent the circulation of propaganda that could put people off the idea of receiving inoculations against diseases. 

The Times says it has been informed by sources that GCHQ is “using a toolkit developed to tackle disinformation and recruitment material peddled by Islamic State” to detect and disrupt the activities of antivaxxers. 

Ensuring the public is open to such medical procedures is a rising priority for the UK government as the prospect of an effective vaccine’s being developed for Covid-19 becomes increasingly likely.

A government source told The Times: “GCHQ has been told to take out antivaxxers online and on social media. There are ways they have used to monitor and disrupt terrorist propaganda.”

GCHQ’s cyber-spies are said to be focusing on taking down state-linked content and making life difficult for those who posted it by encrypting their data and preventing them from communicating with other cyber-actors.

Regular social media users who post anti-vaccination sentiments will not be targeted by GCHQ, which is not legally allowed to take down disinformation spouted by private individuals. 

“You wouldn’t get authorization to go after cranks. People have a right to say batshit stuff online,” the government source told The Times.

Another restriction placed on GCHQ’s cyber-operation is the whereabouts of servers used by propagandists. Currently, servers located in Australia, Canada, New Zealand, and the United States are beyond their reach because those countries are members of the intelligence-sharing agreement, the Five Eyes Alliance. 

In October, fake news media outlets in Russia posted memes and social media posts that indicated a coronavirus vaccine currently being developed in Oxford by AstraZeneca could turn people into monkeys.

Foreign Secretary Dominic Raab described the propaganda as a serious attempt to disrupt the discovery of a safe vaccine.

Speaking on BBC Radio 4’s Today program, Raab said that “any attempt to spread lies about Covid-19, and the vaccine in particular, when we’re trying to come together as an international community to resolve a global pandemic is utterly deplorable.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Mashable Customer Data Leaked Online

Mashable Customer Data Leaked Online

Data belonging to users of American culture and technology news website Mashable has been leaked on the internet.

In a statement released Sunday, November 8, Mashable confirmed that a hacker had obtained a copy of one of its databases and published it online. 

The site launched an investigation after learning of the attack on November 4. Mashable has temporarily disabled access to all accounts impacted by the security breach as a cautionary measure.

The exposed data is linked to a sign-in feature that is no longer in use on the Mashable website. Information leaked included first and last names, location data, email addresses, gender, date of registration, IP addresses, links to social media profiles, expired OAuth tokens, and the days and months on which users’ birthdays fall. 

“This past Wednesday evening, November 4th, we learned that a hacker known for targeting websites and apps had posted a copy of a Mashable database to the internet,” said Mashable.

“Based on our review, the database related to a feature that, in the past, had allowed readers to use their social media account sign-in (such as Facebook or Twitter) to make sharing content from Mashable easier.”

Mashable stated that it does not require or store any financial data belonging to any of its registered users. 

The site said that their ongoing investigation into the attack had so far found no evidence that user password data had been accessed by an unauthorized party.

The site asked users to be wary of any emails they receive that contain links to unfamiliar sites and to send any suspicious emails to them for investigation. 

Users were also advised to confirm the authenticity of the emails they receive by other means such as over the phone. 

“We appreciate your attention to this important topic and sincerely apologize for any concern or inconvenience this incident may cause,” said Mashable. 

“Protecting our users’ data is one of our highest priorities. We are working hard to investigate the issue and prevent it from happening again.”

Mashable has not disclosed the identity of their attacker, but states that the hacker is “known for targeting websites and apps.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Open University Targeted With Over a Million Malicious Email Attacks So Far This Year

Open University Targeted With Over a Million Malicious Email Attacks So Far This Year

The UK’s Open University has been targeted with over 1 million malicious email attacks from January to September this year, according to official figures obtained by the think tank Parliament Street following a Freedom of Information (FoI) request.

The data revealed that attacks on the higher education institution, which offers flexible undergraduate and postgraduate courses for adults of all ages, was evenly spread throughout the nine-month period, averaging 132,368 attacks and spam messages per month.

Encouragingly, each one the 1,191,312 malicious emails, which included spam, malware and phishing attacks, were successfully blocked by the Open University’s servers.

Overall, 6804 messages were blocked due to suspicion of malware while 16,452 phishing emails were detected and prevented from reaching their intended targets.

Education institutions have been heavily targeted by cyber-attacks since the start of the COVID-19 crisis, with threat actors exploiting to growth in online learning methods due to social distancing measures. For instance, a study in September found that distributed denial of service (DDoS) attacks against online educational resources are over three times more prevalent in 2020 than they were last year.

Chris Ross, SVP sales, international at Barracuda Networks commented: “The nature of the Open University, and the fact that a majority of its courses take place online, means cyber-attackers will inevitably attempt to target the abundance of data stored in its servers, hence the significant quantity of scam attacks facing the institution.

“To add to this, our recent research revealed that spear-phishing attacks are disproportionately targeting educational institutions across the world, with over 3.5 million phishing emails hitting over 1,000 global schools and universities from June through to September of this year.”

Ross went on to say whilst it is certainly a good thing that the Open University has, so far, managed to successfully protect itself from a data breach, it is important that security standards are maintained, and the right software and training is constantly updated, to keep pace with the rapidly changing cyber threat-scape.

“Furthermore, due to the sensitivity of information stored in its servers, education institutions must ensure that all data is backed up in a third-party, encrypted cloud backup solution, which will also enable protection from the growing trend in ransomware attacks facing universities.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Paul Collyer to Join HTB as New Chief Risk Officer

Paul Collyer to Join HTB as New Chief Risk Officer

Specialist lender Hampshire Trust Bank (HTB) has announced the appointment of Paul Collyer as its new chief risk officer (CRO). Subject to regulatory approval, Collyer will assume the role in December 2020, with HTB’s current CRO Clive Gavin set to retire.

Collyer is currently the risk director for Virgin Money having previously held various risk-focused roles at GE Capital and served as senior manager at HSBC.

Matthew Wyles, CEO of HTB, said: “HTB’s ongoing success is underpinned by a strong risk culture. Paul Collyer has an impressive track record with a broad palette of experience across the whole waterfront of risk disciplines. Having spent the last 20 years working with global banks, challenger banks and leading non-bank financial institutions, he has deep knowledge of HTB’s key lending classes and is a perfect fit for us. I’m really looking forward to working with him.”

Collyer added: “The specialist lending sector is the most dynamic segment of the UK banking market and HTB is an outstanding player in that market. I am really looking forward to joining the strong team in place and contributing to the achievement of HTB’s exciting growth plans.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Emotet and TrickBot Top the Malware Charts Yet Again

Emotet and TrickBot Top the Malware Charts Yet Again

TrickBot and Emotet topped the list of most prolific malware strains in October, helping in the process to drive a surge in ransomware infections, according to new analysis from Check Point Software.

The Tel Aviv-headquartered security vendor compiled its Global Threat Index for October 2020 from data flowing through its ThreatCloud threat intelligence system, which is said to inspect over 2.5 billion websites and 500 million files daily.

Emotet emerged as the most prevalent malware last month, accounting for 12% of infected organizations. TrickBot and Android malware Hiddad came next, with a global impact of 4% each.

Both Emotet and TrickBot started life as banking Trojans, but have evolved significantly in recent years and now feature advanced modular functionality to enable everything from crytojacking and ransomware to sophisticated data theft.

Increasingly, they’re being used to provide access for attackers and maintain persistence in victim networks as a precursor to additional malware downloads such as ransomware.

This has led to a 71% increase in ransomware attacks on US healthcare organizations last month versus September, whilst the figures jumped 36% in EMEA and 33% in APAC, according to Check Point.

“We’ve seen ransomware attacks increasing since the start of the coronavirus pandemic, to try and take advantage of security gaps as organizations scrambled to support remote workforces. These have surged alarmingly over the past three months, especially against the healthcare sector, and are driven by pre-existing TrickBot and Emotet infections,” explained Maya Horowitz, director of threat intelligence and research, products at Check Point.

“We strongly urge healthcare organizations everywhere to be extra vigilant about this risk, and scan for these infections before they can cause real damage by being the gateway to a ransomware attack.”

The findings chime with those of HP Inc, which revealed last week that attacks using the Emotet Trojan soared by over 1200% from Q2 to the third quarter of this year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Price Dropped on Hacked Educational RDP Details

Price Dropped on Hacked Educational RDP Details

Hackers selling network access to 7500 educational establishments have reportedly dropped their asking price.

Reports emerged last week that access was being sold by a threat actor on multiple Russian hacker forums and as well as educational organizations. The package also included access to corporate networks from other verticals, such as entertainment and the bar industry.

In particular, access to the networks via remote desktop protocol was being sold, with the initial bid for the entire package starting at 25 BTC (roughly $330,000) and the buy now option at 75 BTC (about $1,000,000).

In an email to Infosecurity, Kacey Clark, security researcher at Digital Shadows, said these were posted on the Russian-language cyber-criminal forums Exploit and XSS; however, they are yet to receive any responses from other forum users on either platform.

“There are no indications yet as to which entities/organizations are involved, and this will likely remain the case to keep the offering available,” Clark said.

Digital Shadows also confirmed that the threat actor reduced the asking price to BTC 10 (USD 155,300) from BTC 25 (USD 387,000) on November 4, “but this is still a significant amount of money even on these forums, hence why it might be taking longer to sell,” Clark said.

Clark also made the point that whilst the user only registered on the forums relatively recently, they have deposited significant funds into both of their forum accounts, likely in an effort to substantiate their credibility on these forums and justify the legitimacy of their presence.

“Interestingly, they have even sponsored the most recent articles competition on XSS, which indicates they have developed an effective relationship with the administrator on this platform and again highlights their potential prowess,” she said. “Although this does not provide insight into the actual legitimacy of the offering, it likely indicates the vendor is legitimate and credible in their offering.”

Mark Kerrison, CEO at New Net Technologies, said: “Educational establishments could be a particularly tantalizing target for research and intellectual property theft, especially if linked to COVID-19 research. Cyber-criminals are economically rational in their behavior and will price their ‘offer’ of credentials to maximize returns, in the shortest time, for the smallest of efforts.”

Commenting, Matt Walmsley, EMEA director at Vectra, said, as we move to a world of zero trust, identity is the new perimeter, and so access to live credentials makes an attacker’s task significantly easier. “Whether captured from data dumps of inadvertently public repositories, gained through social engineering or through more traditional vulnerability exploitation and network penetration, these credentials offer an open door through which attackers will pay to walk through then move and expand their influence and establish the privileged access needed to meet their nefarious goals,” he said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Housing Group Struck by Sodinokibi Data Thieves

Housing Group Struck by Sodinokibi Data Thieves

A housing association in East Anglia has suffered a ransomware attack, leading to the compromise of an unknown volume of employee and customer data.

Norwich-headquartered Flagship Group put out a statement last week that it was forced to take most of its IT systems offline after the Sodinokibi strain entered the company via a phishing attack.

Although these efforts were described as “successful,” the association admitted that “there has been some data encryption, and some personal customer and staff data has been compromised.

“Having completed the containment stage of our remediation process, detailed forensic analysis is fully underway, and we are now working towards recovery of all our systems,” the statement continued. “We have been able to restore several internal systems and are now working towards resuming normal operations as quickly as possible.”

The police and regulator the Information Commissioner’s Office (ICO) have been notified.

It remains unclear how many individuals have been affected by the data theft, although Flagship Group claims to be a landlord for over 30,000 homes in the east of England.

Sodinokibi (REvil) is one of the more prolific strains out there, spotted in attacks targeting hospital VPNs earlier this year. It was the number one variant in Q1 2020, accounting for 27% of attacks analyzed by Coveware.

This latest victim may not be as high profile as many over recent weeks, but it is increasingly common for SMBs to be struck by ransomware, the security vendor said last week. In fact, it revealed that organizations with up to 100 employees accounted for 32% of attacks in Q3, while those with up to 1000 workers accounted for 73%.

“Over the past few days, the incident has caused considerable disruption to our staff and customer services and we are concentrating on emergency situations, to ensure our customers are safe,” said Flagship Group’s CEO, David McQuade.

“Our teams are working tirelessly around the clock to bring our systems back online, and we apologize for any inconvenience this may have caused.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hotel Booking Firm Leaks Data on Millions of Guests

Hotel Booking Firm Leaks Data on Millions of Guests

A hotel software provider has exposed the personal data of millions of guests around the world after misconfiguring an AWS bucket, according to a new report from Website Planet.

The tech site’s security team discovered an exposed cloud database belonging to Spanish developer Prestige Software, whose platform enables hotels to automate their availability on booking websites like Expedia.

The misconfigured S3 bucket contained over 10 million individual log files, dating back to 2013. Website Planet researcher, Mark Holden, warned that the total number of affected individuals could be even greater than this, as some logs contained personally identifiable information (PII) for multiple members of a single booking.

Among the leaked data were full names, email addresses, national ID numbers and the phone numbers of hotel guests. For hundreds of thousands of individuals card booking details including card number, cardholder’s name, CVV and expiration date were also exposed.

Prestige’s Cloud Hospitality platform appears to be used by many of the top online travel agent (OTA) sites out there including Agoda, Expedia, Booking.com and Hotels.com.

Website Planet reached out to AWS directly to disclose the incident, which was fixed the day after. Prestige Software also confirmed to it that it is the owner of the data.

The leaked information could have offered malicious third parties a trove of data to commit identity fraud, launch follow-on phishing attacks and even hijack and change booking details.

As a result, the Spanish developer may face questions from GDPR and PCI DSS investigators over the incident.

“Millions of people were potentially exposed in the data breach, from all over the world. We can’t guarantee that somebody hasn’t already accessed the S3 bucket and stolen the data before we found it,” argued Holden.

“So far, there is no evidence of this happening. However, if it did, there would be enormous implications for the privacy, security and financial wellbeing of those exposed.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

San Francisco Police Seek Cybercrime Victims

San Francisco Police Seek Cybercrime Victims

Police in San Francisco have asked the unidentified victims of two men charged with cyber-stalking and child sexual exploitation to come forward. 

East Bay residents Delaney Tang and Vincenz Sison were taken into custody on November 3 on suspicion of extorting sexually explicit videos and images from dozens of underage minors.

Appearing yesterday in federal court in front of US Magistrate Judge Jacqueline Scott Corley, Tang, of Oakland, was charged in a criminal complaint with Solicitation of Child Pornography and with Conspiracy to Commit Cyberstalking. 

His alleged co-conspirator, Sison, of Concord, was charged with Conspiracy to Commit Cyberstalking. 

Police began investigating the defendants last fall after the dean of students at a San Francisco high school told officers that several students had been extorted for sexually explicit videos and images through online social media platforms.

The SFPD Internet Crimes Against Children (ICAC) Unit determined that Tang had created dozens of accounts on various social media platforms using false names and false profile photos.

Tang then allegedly used these accounts to start chats with victims aged between 11 and 14 years old, often while pretending to be a minor himself. Tang would then allegedly ask for indecent images and videos.

Tang is accused of using two methods to extort victims who refused to comply. First, he allegedly used social media platforms to learn the approximate home addresses of his victims, then threatened to physically harm them.

Second, he allegedly obtained photos of the victims via their friends or acquaintances and tricked them into believing he had other more-compromising images that he threatened to make public.

Victims who sent explicit images and videos to Tang were allegedly threatened with exposure unless they supplied additional content. 

“In several cases, Tang actually posted the victims’ sexually explicit images and videos, which were then circulated at the victims’ schools,” said San Francisco Police

Sison was allegedly deployed by Tang to contact and harass victims into producing more images and videos, sometimes tormenting them for months.

Investigators have identified eight underage minor victims located in the San Francisco Bay Area, Northern California, and in Utah. Police are appealing for unidentified victims to contact the SFPD Special Victims Unit.

The social media usernames used by Tang and Sison were: thedrunkg1raffe, jimmynguyen0950, anthonytran800, bobbychao5150, davidnguyen850, kevin_luong5150, brianchao0150, and delaneyytang.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Brazil Seizes Sites Pirating US TV Shows

Brazil Seizes Sites Pirating US TV Shows

The United States and Brazil have teamed up to take down multiple websites and apps that were selling pirated versions of American-made movies and TV shows.

In a joint effort dubbed “Operation 404,” seizure warrants were executed against three domain names of commercial websites engaged in the illegal reproduction and distribution of copyrighted works. 

The federal law enforcement operation targeted online services that provided illegal copies of television shows and movies owned by American rights holders to audiences in Brazil and beyond. 

According to the affidavit in support of the warrants, each of the three domains—megatorrentshd.biz, comandotorrentshd.tv, and bludv.tv—offered “free access to copyrighted content to website visitors all over the world, including released and pre-release feature-length movies and television shows.”

Megatorrentshd.biz featured roughly 335 different television series and approximately 84 navigation pages, with around 20 film titles per page. 

While Comandotorrentshd.tv displayed movies and television shows, with approximately 10 titles per page, distributed throughout around 124 navigation pages, Bludv.tv offered users a choice of around 9,500 different entertainment titles.

Operation 404 was coordinated with Brazil’s Secretariat of Integrated Operations (SEOPI) at Brazil’s Ministry of Justice and Public Security (MoJPS). 

“By seizing these domain names, law enforcement has disrupted the unlawful reproduction and distribution of thousands of pirated television shows and movies, while also cutting off the profits to unlawful actors willing to exploit the hard work of others for their own personal gain,” said Acting Assistant Attorney General Brian Rabbitt of the Justice Department’s Criminal Division. 

“The Justice Department, together with our international law enforcement partners, will continue to take enforcement actions to identify, seize, and disable these sites wherever they exist around the globe.”

The federal government now has custody of the domains. Users who attempt to access the seized sites will now be confronted with a seizure banner and a notice that informs them that willful copyright infringement is a federal crime.

“Illegal streaming is not a victimless crime,” said Derek Benner, executive associate director for US Immigration and Customs Enforcement’s Homeland Security Investigations (HSI).  “It harms the content creators of the shows that you know and love, and feeds a criminal enterprise whose profits support organized criminal endeavors.” 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk