Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
WordPress Pushes Out Multiple Flawed Security Updates
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Survey: Cybersecurity Skills Shortage is ‘Bad,’ But There’s Hope
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Texas Gold-Dealer Mined for Payment Details in Months-Long Data Breach
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Unpatched Windows Zero-Day Exploited in the Wild for Sandbox Escape
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Scammers Abuse Google Drive to Send Malicious Links
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
New Windows Zero-Day
Google’s Project Zero has discovered and published a buffer overflow vulnerability in the Windows Kernel Cryptography Driver. The exploit doesn’t affect the cryptography, but allows attackers to escalate system privileges:
Attackers were combining an exploit for it with a separate one targeting a recently fixed flaw in Chrome. The former allowed the latter to escape a security sandbox so the latter could execute code on vulnerable machines.
The vulnerability is being exploited in the wild, although Microsoft says it’s not being exploited widely. Everyone expects a fix in the next Patch Tuesday cycle.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Marriott Fined £18.4m Over Data Breach
Marriott Fined £18.4m Over Data Breach

The Information Commissioner’s Office (ICO) has fined hotel chain Marriott International £18.4m over a data breach that exposed the information of millions of guests worldwide.
The UK’s independent body set up to uphold information rights imposed the financial penalty on Marriott for “failing to keep millions of customers’ personal data secure.”
In November 2018, Marriott reported a data breach that saw an estimated 339 million guest records exposed globally, of which around seven million related to UK residents. An investigation into the incident revealed that an unauthorized party had been accessing the network of Starwood Hotels and Resorts Worldwide Inc. since 2014, copying and encrypting information.
The attack remained undetected until September 2018, by which time Starwood had been acquired by Marriott.
The personal data involved in the breach differed between individuals, but the ICO said that it may have included names, email addresses, phone numbers, unencrypted passport numbers, arrival/departure information, guests’ VIP status, and loyalty program membership number.
An investigation into the incident by the ICO found that Marriott “failed to put appropriate technical or organizational measures in place to protect the personal data being processed on its systems, as required by the General Data Protection Regulation (GDPR).”
However, the ICO recognized that Marriott was swift to act once the breach had been discovered, contacting customers and the ICO promptly.
“It also acted quickly to mitigate the risk of damage suffered by customers, and has since instigated a number of measures to improve the security of its systems,” said the commissioner’s office.
In July last year, the ICO announced an intention to fine Marriott £99m over the data breach for “infringements of the GDPR.”
In a statement released yesterday, the ICO said: “As part of the regulatory process, the ICO considered representations from Marriott, the steps Marriott took to mitigate the effects of the incident and the economic impact of COVID-19 on their business before setting a final penalty.”
Although the breach dates back to 2014, the GDPR regulations only came into effect in May 2018, two years before the UK left the European Union.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US Sanctions Russian Institute Linked to TRITON
US Sanctions Russian Institute Linked to TRITON

The United States Treasury has imposed sanctions on a Russian state-funded research institute that was linked to malware used in an attack on a Middle East petrochemical facility.
In October 2018, researchers at FireEye attributed industrial control system (ICS) intrusion activity known as TRITON to a professor at the Moscow-based Central Scientific Research Institute of Chemistry and Mechanics (CNIIHM). The malware is known also as TRISIS and HatMan in open source reporting.
TRITON was deployed against a Saudi Arabian petrochemical facility in August 2017, where it was observed targeting emergency shutdown capabilities for industrial processes.
Researchers who investigated the cyber-attack reported that the malware was designed to give the attackers complete control of infected systems and had the capability to cause significant physical damage and loss of life.
The Treasury Department said that CNIIHM built customized tools that enabled the assault, producing malware designed to tamper with the facility’s critical safety mechanisms.
“The Russian Government continues to engage in dangerous cyber activities aimed at the United States and our allies,” said Secretary Steven Mnuchin. “This Administration will continue to aggressively defend the critical infrastructure of the United States from anyone attempting to disrupt it.”
In a designation released October 23, the department said that the institute is “connected to the destructive TRITON malware” which “was designed specifically to target and manipulate industrial safety systems.”
According to the department, TRITON’s operators had turned their attention to targets in the United States.
“In 2019, the attackers behind the Triton malware were also reported to be scanning and probing at least 20 electric utilities in the United States for vulnerabilities,” said the department.
As a result of the sanctions on CNIIHM, people in the United States are prohibited from engaging in transactions with the institute.
“While the Russian government claims to be a responsible actor in cyberspace, it continues to engage in dangerous and malicious activities that threaten the security of the United States and our allies,” said US Secretary of State Mike Pompeo.
“We will not relent in our efforts to respond to these activities using all the tools at our disposal, including sanctions.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Montreal Metro Hacker Demands $2.8m Ransom
Montreal Metro Hacker Demands $2.8m Ransom

A malicious hacker that attacked Montreal’s transit agency with malware has demanded a ransom of US $2.8m to restore normal network operations.
The Société de transport de Montréal (STM) was targeted with ransomware on October 19. The attack knocked the agency’s reservation system for adapted transit offline and caused an outage that affected around 1,000 of STM’s 1,600 servers, 624 of which are considered operationally sensitive.
No data was exfiltrated by the hacker, and the incident did not impact the city’s bus and metro services.
After more than a week of silence, the hacker finally contacted STM to issue a ransom demand that the agency says it will not comply with.
In a statement published Thursday, STM said: “Following communication with the hacker, a ransom demand of US $2.8 million was made. The STM maintains its decision not to act on this request.”
STM’s paratransit reservation system was restored on October 25. The agency said that as of yesterday, around 77% of servers impacted by the attack had been restored.
Payments to STM’s 11,000 employees were completed in what the agency described as an “almost normal manner.” Payments to suppliers were not affected by the incident.
An investigation into the incident is ongoing. Details revealed so far indicate that the attacker used a phishing email to gain access to STM’s network. While describing the attack as similar to RansomExx, STM said it would not share any further details until the investigation had been completed.
A week after the cyber-strike on Montreal’s transit agency, a second attack was carried out on a health agency in the city’s west end.
The CIUSSS du Centre-Ouest-de-l’Île-de-Montréal blocked remote access and disconnected from the internet after the attack in an attempt to minimize any damage.
Dr. Lawrence Rosenberg, head of the CIUSSS, said that no personal information belonging to staff or patients had been compromised as a result of the security incident.
The CIUSSS run the city’s Jewish General Hospital and several long-term care facilities. Rosenberg said that while problems had been experienced with the telephone system, patient care had not been affected by the attack.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk