Determining What Video Conference Participants Are Typing from Watching Shoulder Movements

Accuracy isn’t great, but that it can be done at all is impressive.

Murtuza Jadiwala, a computer science professor heading the research project, said his team was able to identify the contents of texts by examining body movement of the participants. Specifically, they focused on the movement of their shoulders and arms to extrapolate the actions of their fingers as they typed.

Given the widespread use of high-resolution web cams during conference calls, Jadiwala was able to record and analyze slight pixel shifts around users’ shoulders to determine if they were moving left or right, forward or backward. He then created a software program that linked the movements to a list of commonly used words. He says the “text inference framework that uses the keystrokes detected from the video … predict[s] words that were most likely typed by the target user. We then comprehensively evaluate[d] both the keystroke/typing detection and text inference frameworks using data collected from a large number of participants.”

In a controlled setting, with specific chairs, keyboards and webcam, Jadiwala said he achieved an accuracy rate of 75 percent. However, in uncontrolled environments, accuracy dropped to only one out of every five words being correctly identified.

Other factors contribute to lower accuracy levels, he said, including whether long sleeve or short sleeve shirts were worn, and the length of a user’s hair. With long hair obstructing a clear view of the shoulders, accuracy plummeted.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Why Paying to Delete Stolen Data is Bonkers

Companies hit by ransomware often face a dual threat: Even if they avoid paying the ransom and can restore things from scratch, about half the time the attackers also threaten to release sensitive stolen data unless the victim pays for a promise to have the data deleted. Leaving aside the notion that victims might have any real expectation the attackers will actually destroy the stolen data, new research suggests a fair number of victims who do pay up may see some or all of the stolen data published anyway.

The findings come in a report today from Coveware, a company that specializes in helping firms recover from ransomware attacks. Coveware says nearly half of all ransomware cases now include the threat to release exfiltrated data.

“Previously, when a victim of ransomware had adequate backups, they would just restore and go on with life; there was zero reason to even engage with the threat actor,” the report observes. “Now, when a threat actor steals data, a company with perfectly restorable backups is often compelled to at least engage with the threat actor to determine what data was taken.”

Coveware said it has seen ample evidence of victims seeing some or all of their stolen data published after paying to have it deleted; in other cases, the data gets published online before the victim is even given a chance to negotiate a data deletion agreement.

“Unlike negotiating for a decryption key, negotiating for the suppression of stolen data has no finite end,” the report continues. “Once a victim receives a decryption key, it can’t be taken away and does not degrade with time. With stolen data, a threat actor can return for a second payment at any point in the future. The track records are too short and evidence that defaults are selectively occurring is already collecting.”

Image: Coveware Q3 2020 report.

The company said it advises clients never to pay a data deletion ransom, but rather to engage competent privacy attorneys, perform an investigation into what data was stolen, and notify any affected customers according to the advice of counsel and application data breach notification laws.

Fabian Wosar, chief technology officer at computer security firm Emsisoft, said ransomware victims often acquiesce to data publication extortion demands when they are trying to prevent the public from learning about the breach.

“The bottom line is, ransomware is a business of hope,” Wosar said. “The company doesn’t want the data to be dumped or sold. So they pay for it hoping the threat actor deletes the data. Technically speaking, whether they delete the data or not doesn’t matter from a legal point of view. The data was lost at the point when it was exfiltrated.”

Ransomware victims who pay for a digital key to unlock servers and desktop systems encrypted by the malware also are relying on hope, Wosar said, because it’s also not uncommon that a decryption key fails to unlock some or all of the infected machines.

“When you look at a lot of ransom notes, you can actually see groups address this very directly and have texts that say stuff along the lines of, Yeah, you are fucked now. But if you pay us, everything can go back to before we fucked you.’”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Wakefern and ShopRite Settle Slapdash Data Disposal Claim

Wakefern and ShopRite Settle Slapdash Data Disposal Claim

ShopRite and its parent company Wakefern have agreed to pay New Jersey $235,000 over a lapse in data disposal security.

The companies agreed to the substantial settlement to resolve claims that they failed to protect the personal information of more than 9,700 New Jersey residents who shopped at ShopRite supermarkets in Millville, New Jersey, and Kingston, New York. 

According to the allegations, the companies violated Health Insurance Portability and Accountability Act (HIPAA) regulations and the New Jersey Consumer Fraud Act (CFA) by failing to properly dispose of electronic devices used to collect the signatures and purchase information of pharmacy customers. 

After the devices were replaced with newer technology by Wakefern in 2016, it is alleged that the old machines were simply tossed into dumpsters. Under HIPAA, any protected health information that may have been stored on the devices should have been removed prior to their disposal. 

Data that may have been exposed in the security breach included names, phone numbers, birthdates, driver’s license numbers, prescription numbers, medication names, dates and times of pick-up or delivery, and customer zip codes.

“Pharmacies have a legal obligation to protect the privacy and security of the patient information they collect, and to properly dispose of that information when the time comes,” said Attorney General Gurbir Grewal. 

“Those who compromise consumers’ private health information face serious consequences.”

As part of the settlement, Wakefern must implement specific data-protection measures aimed at safeguarding Protected Health Information (PHI) and Electronic Protected Health Information (ePHI) collected at ShopRite supermarkets that operate in-store pharmacies.

The company, which is based in Kasbey, New Jersey, has agreed to appoint a chief privacy officer and to ensure that all ShopRite stores with pharmacies in the Wakefern cooperative designate a HIPAA privacy officer and HIPAA security officer. Wakefern will then provide those officers with online training on HIPAA security and privacy rules.

“This settlement ensures that ShopRite supermarket pharmacies will be trained and monitored for HIPAA compliance to avoid future conduct that places consumers at risk for privacy invasion and identity theft,” said Paul Rodríguez, acting director of the Division of Consumer Affairs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Prison for Russian Player in $100m Botnet Conspiracy

Prison for Russian Player in $100m Botnet Conspiracy

A Russian cyber-criminal will spend the next eight years in an American prison for his role in a sophisticated multi-million-dollar Botnet conspiracy.

Skilled computer programmer Aleksandr Brovko admitted being involved in a scheme to steal sensitive personal and financial data and traffic it on the darknet that caused estimated losses of over $100m.

From 2007 through 2019, Brovko collaborated with other cyber-criminals to monetize huge quantities of data that had been stolen by networks of infected computers. Documents submitted to the court state that Brovko wrote software scripts to parse Botnet logs and performed extensive manual searches of the data to extract personally identifiable information and online banking credentials that could be exploited for financial gain.  

Other roles played by the 36-year-old included verifying the validity of stolen account credentials and assessing whether compromised financial accounts contained enough funds to make using them to conduct fraudulent transactions worthwhile. 

Court documents also pegged Brovko as an active member of multiple elite online forums in which Russian-speaking cyber-criminals gather to exchange criminal tools and services. During the course of the conspiracy, Brovko possessed and trafficked over 200,000 unauthorized access devices. 

In February 2020, Brovko pleaded guilty to committing bank and wire fraud. On October 30, he was sentenced to an 8-year period of incarceration by senior US district judge T.S. Ellis III.

“For over a decade, Brovko participated in a scheme to gain access to Americans’ personal and financial information, causing more than $100 million in intended loss,” said Acting Assistant Attorney General Brian Rabbitt of the Justice Department’s Criminal Division.  

“This prosecution and the sentence imposed show the department’s commitment to work with our international and state counterparts to bring cybercriminals to justice no matter where they are located.”

News of Brovko’s sentencing was announced today by Rabbitt, US Attorney General Zachary Terwilliger for the Eastern District of Virginia, and Special Agent in Charge Matthew Miller of the US Secret Service’s Washington Field Office.

Miller said: “This investigation is a prime example of the Secret Service’s investigative mission; to protect the U.S. financial infrastructure by pursuing counterfeit and financial crimes investigations.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

IT Pro Salaries Decline in Value

IT Pro Salaries Decline in Value

New research has revealed that the value of salaried professional IT jobs has declined over the past 12 months.

According to the “IT Skills Demand and Pay Trends Report” – 4Q 2020 edition, released October 31 by research group Foote Partners, more than 40% of job titles in IT have been impacted. 

Data for the report was gathered from Foote Partners’ IT Skills and Certifications Pay Index (ITSCPI) based on compensation data provided by 3,640 public-sector employers in 83 US and Canadian cities who partner with Foote to report pay for their 330,340 technology professionals in the Canada and the United States. 

Findings show that the fall in value varies from role to role, ranging from a small decline to a fall to a sizable decrease. 

“That’s never happened in the 26-year history of this salary survey, so clearly the X factor is COVID-19 impacts,” said a Foote Partners spokesperson.

Researchers found that cash pay premiums (extra pay) awarded by employers to tech professionals for 594 non-certified tech skills remained unchanged on average in 2020’s third quarter at 9.6%.

“Currently averaging the equivalent of 9.6 percent of base salary on average for a single non-certified skill, this is the highest average premium in 20 years,” noted researchers.  

Conversely, average market values for 516 tech certifications decreased from July to September, sinking by 1.5% overall, currently earning the equivalent of 6.8% of base salary on average for a single certification. 

Researchers said: “That’s the lowest average pay premium for IT certifications in seven years and the widest gap between certified and non-certified tech skills pay since mid-2000s.”

Among the non-certified skills that declined 10% or more in market value in the three months ending October 1, 2020, were BusinessObjects, Backbone.js, Azure Data Factory, SAP Oil & Gas, SNA, CoreOS, and TIBCO Enterprise Message Service.

Cash pay for information/cybersecurity tech certifications lost 8.8% of value over the past 12 months, with a 3.2% drop in the last three months alone. The value of web development certifications and of system administration/engineering certifications declined by 10.8% and 9.3% respectively.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Florida Invests in Security Controls Ahead of #Election2020

Florida Invests in Security Controls Ahead of #Election2020

Florida has invested $14.6m in securing its county election offices

Pinellas county supervisor of elections, Julie Marcus, told ABC Action News it is putting resources into detecting, monitoring and responding to cyber-threats, after it was determined by the Mueller investigation that, in 2016, the Russian military intelligence agency sent spear-phishing emails to over 120 email accounts used by Florida county officials.

This led to two Florida counties being attacked, but state officials did not reveal which. Guy Garrett, assistant director of University of West Florida’s Center for Cybersecurity, which helped state election officials identify and fix vulnerabilities, said “what the bad guys were after at that point was actually the voter database. Fortunately, we were able to get dollars through grants in the legislature to address those problems.”

This led to the $14.6m investment in Florida’s 67 counties, although election supervisors were required to sign confidentiality agreements regarding exactly how that money would be spent.

Marcus said the tabulation system, which counts votes, cannot be hacked as the system is unconnected to the internet, “and it’s protected under multiple layers of security.”

Jake Moore, cybersecurity specialist at ESET, said: “I would be extremely surprised if we go through the election without a security or technical hitch. Even if the system can handle the deluge of information all on one day, there will be multiple attempts to knock it over to even cast the smallest of doubt on the outcome.

“At least Florida has learned from its previous mistakes which cannot be said for all organizations after an attack. Proactive defense works as a far better insurance and there is no space for error with this election which will undoubtedly be targeted with an array of different attacks looking for the weakest links.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Remote Working Exposing Businesses to Unforeseen Threats

Remote Working Exposing Businesses to Unforeseen Threats

The sudden shift to remote working this year as a result of COVID-19 has left businesses at far higher risk of cyber-attacks, largely due to their corporate infrastructure being exposed to attack vectors and threats that would not have been considered a year ago.

This is according to Bitdefender’s The ‘New Normal’ State of Cybersecurity report, which showed that businesses are particularly at risk of attacks exploiting unpatched vulnerabilities that are under a year old, with 36.37% of all unpatched vulnerabilities involving CVEs that were assigned in 2019 in the first half of 2020.

The report also found that, of the network-level attacks recorded in this period, 46.84% involved the exploitation of a vulnerability in the SMB protocol, while 41.63% were bruteforce attempts on RDP and FTP.

The increasing use of Internet of Things (IoT) devices by remote employees was another major source of concern for security professionals, with 45% believing them to pose serious security risks as they can be easily controlled by remote hackers and compromise corporate infrastructure. This was supported by Bitdefender’s data, which revealed that suspicious IoT incidents in households surged by 46% from January to June.

Additionally, the researchers further highlighted the extent to which malicious actors have been using the topic of COVID-19 to launch business email compromise (BEC) attacks. They said that four in 10 coronavirus-themed emails have been classified as spam, phishing or malware, which suggests remote employees have been “constantly at risk” of opening malicious emails.

Bitdefender CTO Bogdan Dumitru commented: “In the wake of 2020, 50% of organizations were unprepared to face a scenario in which they would have to migrate their entire workforce in a work-from-home environment. The global COVID-19 pandemic may have been a respiratory illness that affected people around the world, but it also impaired the way organizations and business conducted normal operations.

“The lack of forward planning for such a scenario left many organizations open to potential vulnerabilities and misconfigurations that threat actors could have easily leveraged to score breaches, exfiltrate data or even generate additional profit by extorting vulnerable companies.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Adobe Chooses Blizzard Entertainment’s Adams as New CSO

Adobe Chooses Blizzard Entertainment’s Adams as New CSO

Former Blizzard Entertainment chief security officer (CSO) Mark Adams has joined Adobe as its new CSO and SVP, where he will play a key role in shaping the future of the firm after Flash.

Adams replaces former CSO, Brad Arkin, who joined Cisco as its new chief security and trust officer recently.

Before a four-year stint as CISO and then combined CIO and CSO at entertainment software developer, Blizzard, Adams had CIO and head of security stints at WFG National Title Insurance Company and SaaS developer HireRight.

Having graduated from California State University-Fullerton with a computer science degree in 2002, Adams spent the first four years of his career as VP of IT and security at Lending Tree, before moving on to gaming start-up Red 5 Studios and then the Automobile Club of Southern California.

Reporting to Adobe CTO, Abhay Parasnis, he will work closely with IT, product and legal to ensure Adobe systems and customers are protected, according to a statement from the firm.

“Going forward, I’ll be focused on security-related decisions across the company, leading the teams responsible for the security of Adobe’s infrastructure, products and services, as well as teams dedicated to security incident response and communications,” Adams said in a LinkedIn update.

“Suffice it to say that I feel hugely honored to take on this role. Adobe products have been enabling creativity in my life for so long that it feels like coming home.”

Adams joins Adobe at an exciting time for the firm, with its venerable but notoriously buggy Flash product about to be retired.

After December 31 2020, Adobe will no longer be providing updates for Flash Player, with support already removed from all major browsers.

That leaves Adobe free to focus on its line-up of cloud-based products and services, where Adam’s industry experience is likely to stand him in good stead.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Alert as Emotet Detections Surge 1200%

Ransomware Alert as Emotet Detections Surge 1200%

Detected attacks using the Emotet Trojan soared by over 1200% from Q2 to the third quarter of this year, supporting a surge in ransomware campaigns, according to the latest data from HP Inc.

Powered by its acquisition of Bromium, the firm’s HP Sure Click unit captures malware at the endpoint and runs it inside secure containers.

These installations picked out a “large and sustained increase in malicious spam campaigns” spreading Emotet, especially in August. Emotet is often used as a loader, providing access to third-party threat groups to deploy secondary TrickBot and QakBot infections as well as human-operated ransomware.

In the case of the latter threat, actors often use access to victim networks provided by Emotet to perform reconnaissance as the first stage in attacks.

HP Inc senior malware analyst, Alex Holland, warned that according to current patterns, Emotet is likely to appear in weekly spam runs until early 2021.

“The targeting of enterprises is consistent with the objectives of Emotet’s operators, many of whom are keen to broker access to compromised systems to ransomware actors. Within underground forums and marketplaces, access brokers often advertise characteristics about organizations they have breached — such as size and revenue — to appeal to buyers,” he added.

“Ransomware operators in particular are becoming increasingly targeted in their approach to maximize potential payments, moving away from their usual spray-and-pray tactics. This has contributed to the rise in average ransomware payments, which has increased by 60%.”

Japan and Australia were hit particularly hard by this uptick in Emotet activity, accounting for 32% and 20% of recipients, according to an analysis of the TLDs the malware was sent to.

Attackers typically used “thread hijacking” techniques, where a user’s inbox is compromised and monitored so that Emotet can reply to a legitimate email with malicious attachments or links. This makes success more likely, according to HP Inc.

The recent surge in ransomware infections at US hospitals was closely linked to the activity of another notorious Trojan, TrickBot, which is often used in concert with Emotet.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NCSC Report Highlights #COVID19 Threat Surge

NCSC Report Highlights #COVID19 Threat Surge

Over a quarter of cyber-threats handled by the UK’s National Cyber Security Centre (NCSC) over the past year were COVID-19 related, the GCHQ branch has revealed in its annual report.

The security agency said it defended the UK from an average of 60 attacks per month from September 2019 to August 2020, with the number of incidents climbing from an average of around 600 over the past three years to 723.

This reflects a more proactive approach from the NCSC rather than more malicious cyber-activity, it said.

The NHS in particular was handed significant help after giving the center its consent to check security. The NCSC shared information on over 160 high-risk and critical vulnerabilities with trusts, as well as 51,000 indicators of compromise (IOCs).

The NCSC also performed threat hunting on 1.4 million NHS endpoints, scanned over one million IP addresses to detect weaknesses and rolled out its Active Cyber Defense services to 235 frontline health bodies, offering them web, email and DNS protection.

In total, over 15,000 COVID-related malicious campaigns were taken down by the NCSC over the year and 260 Sender IDs blocked for sending malicious SMS messages.

Elsewhere, the center said it was instrumental in ensuring the seven new emergency Nightingale hospitals were built with cybersecurity in mind, and it also engaged with more than 1200 “essential service providers” in public and private sectors to support their work in tackling COVID-19.

Away from the pandemic, the NCSC took down over 166,000 phishing URLs, most (65%) within 24 hours, while 2.3 million suspect emails were forwarded to its new Suspicious Email Reporting Service (SERS).

The NCSC’s annual report also listed myriad ways the organization has helped protect elections, parliament, critical infrastructure and businesses, and shared its expertise globally, such as via an “Exercise in a Box” tool, which allows businesses to test their cyber-defenses against realistic attack scenarios.

“From handling hundreds of incidents to protecting our democratic institutions and keeping people safe while working remotely, our expertise has delivered across multiple frontiers,” said new CEO, Lindy Cameron.

“This has all been achieved with the fantastic support of government, businesses and citizens and I would urge them to continue contributing to our collective cybersecurity.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk