Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
COVID-19 Vaccine-Maker Hit with Cyberattack, Data Breach
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Ransomware Takes Down Network of French IT Giant
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Friday Squid Blogging: Squid-like Nebula
Pretty astronomical photo.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
New Report on Police Decryption Capabilities
There is a new report on police decryption capabilities: specifically, mobile device forensic tools (MDFTs). Short summary: it’s not just the FBI that can do it.
This report documents the widespread adoption of MDFTs by law enforcement in the United States. Based on 110 public records requests to state and local law enforcement agencies across the country, our research documents more than 2,000 agencies that have purchased these tools, in all 50 states and the District of Columbia. We found that state and local law enforcement agencies have performed hundreds of thousands of cellphone extractions since 2015, often without a warrant. To our knowledge, this is the first time that such records have been widely disclosed.
Lots of details in the report. And in this news article:
At least 49 of the 50 largest U.S. police departments have the tools, according to the records, as do the police and sheriffs in small towns and counties across the country, including Buckeye, Ariz.; Shaker Heights, Ohio; and Walla Walla, Wash. And local law enforcement agencies that don’t have such tools can often send a locked phone to a state or federal crime lab that does.
[…]
The tools mostly come from Grayshift, an Atlanta company co-founded by a former Apple engineer, and Cellebrite, an Israeli unit of Japan’s Sun Corporation. Their flagship tools cost roughly $9,000 to $18,000, plus $3,500 to $15,000 in annual licensing fees, according to invoices obtained by Upturn.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Oregon Retailer Suffers Sustained Data Breach
Oregon Retailer Suffers Sustained Data Breach

Customers of an Oregon retailer have become victims of fraud after their financial information was exposed in a sustained data breach.
Data belonging to thousands of customers of Made in Oregon was compromised in a breach that lasted six months. Made in Oregon is a regional vendor with five stores in the Portland area.
According to the gift retailer, an unauthorized party gained access to its e-commerce site between the first week of February 2020 and the last week of August 2020.
Last week, Made in Oregon sent letters to 7,800 customers who purchased gifts from its online store during the period when the breach occurred.
Customers were warned that their name, billing address, shipping address, email address, and credit card information may have been compromised.
Made in Oregon is aware of a small number of customers who have become victims of fraud after their credit card data was exposed in the breach and is working with law enforcement to investigate the security incident.
“We think the actual number of people who had their cards used fraudulently was very, very small,” company owner Verne Naito told OregonLive. “But having said that, anybody who (made a purchase) on our site was potentially compromised, which is why we immediately came forward.”
Naito said that customers who made purchases over the phone during the breach period had not been affected by the security incident.
The breach has been reported to law enforcement, and Made in Oregon have launched an internal investigation to ascertain exactly what happened and how many customers were affected. Customers have been offered complimentary credit monitoring services for a year.
Since the breach, Made in Oregon said it has “implemented additional security measures designed to prevent a recurrence of this incident.”
“With consumers around the world increasing the amount of shopping they do online, attackers have naturally gone after online shoppers with sophisticated fraud campaigns,” commented Brendan O’Conner, CEO and co-founder of https://appomni.com/. “These trends are unlikely to slow down anytime soon, and I expect that we will continue to see more attacks targeting cloud applications for business and e-commerce sites for consumers.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Attackers Spoof Microsoft Teams
Attackers Spoof Microsoft Teams

Cyber-criminals are impersonating a popular Microsoft messaging service to steal employees’ Office 365 login credentials in a newly detected attack that has hit up to 50,000 mailboxes.
The campaign, discovered by researchers at Abnormal Security, targets Office users with an automated message that appears to be sent from communication tool Microsoft Teams.
“The email is sent from the display name, ‘There’s new activity in Teams’, making it appear like an automated notification from Microsoft Teams,” said researchers.
“It appears to notify the recipient that their teammates are trying to reach them and urges the recipient to click on ‘Reply in Teams’.”
Victims who take the bait and click on any of the three links included in the message are directed to a malicious phishing page where they are asked to enter their email and password.
“The link landing page also looks convincingly like a Microsoft login page with the start of the URL containing ‘microsftteams’, lending further credence,” noted researchers.
Victims who enter their credentials risk exposing sensitive information stored on their account and giving attackers a foothold into the company’s corporate network for more sophisticated BEC attacks.
“Should recipients fall victim to this attack, their login credentials as well as any other information stored on their account will be compromised,” wrote researchers.
The attack exploits both the instantaneous nature of the communication tool and its rise in popularity triggered by the outbreak of COVID-19.
“Because Microsoft Teams is an instant messaging service, recipients of this notification might be more apt to click on it so that they can respond quickly to whatever message they think they may have missed based on the notification,” noted researchers.
News of this new attack follows the discovery of two other similar campaigns by Abnormal Security in May 2020, in which threat actors spoofed Microsoft Teams to steal credentials.
Describing the earlier campaigns, researchers noted: “These attackers crafted convincing emails that impersonate automated notification emails from Microsoft Teams. The landing pages that host both attacks look identical to the real webpages, and the imagery used is copied from actual notifications and emails from this provider.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
#InfosecurityOnline: Adapting Security Strategies to Growing Digitalization
#InfosecurityOnline: Adapting Security Strategies to Growing Digitalization

The significant challenges around ensuring cybersecurity adapts to the rapid digitalization of organizations was the topic of discussion during a panel at the Infosecurity Online event.
The panel speakers first highlighted how digitalization has fundamentally changed the ways companies operate over recent years, such as the greater use of data and offering digital products as well as the shift to remote working brought about by COVID-19. “The journey to digital transformation has been happening for quite some time now,” noted Amitabh Singh, chief information security officer and chief data officer at Swisscard AECS GmbH.
Ledum Maeba, head of information security, Avanti Communications, said that it is important to have a very cautious security approach when it comes to digitalization. “We are digitalizing everything we do, but we are very cautious in what we do; we take every process very seriously and we make sure all security concerns are addressed before we do anything.”
Before specific digital projects begin, Simon Cole, global security architecture and solutions director at Dentsu, outlined how security should become one of the key considerations: “You have to define what success looks like and that’s with many lenses, so what it means for the business, but also what it means from a security perspective.”
Very often this is not the case. Singh said: “So far when we’ve been working on security, it comes as a retrofit requirement, so we build certain things into digital transformation then security comes later on,” adding that “security needs to come by design as a de facto thing that has to be considered when we are thinking about digitalization.” He noted this should be the goal in the financial industry where he works.
Such an approach clearly requires strong collaboration between security teams and other areas of the organization. “My risk posture is going to be totally different than the executive who is about to launch a new product. What we have to do is have that honest conversation and decide what the acceptable risks are, what are the guardrails,” said Cole.
In this new environment of home working, third party sharing and use of cloud applications traditional perimeter security structures are insufficient, according to the panel. Instead, security must become tailored to the specific business needs of individual organizations and what level of risk is acceptable. Singh commented: “Security professionals have a much larger challenge of first trying to understand the environment. Once you have understood the environment you need to define exactly what security means for that, and define what is good for us.” He added the approach must be fluid, adapting to changing digitalization.
With increasing reliance on third party suppliers, including greater levels of data sharing, undertaking extra due diligence regarding their security is important. This includes assessing the chances of a data risk occurring. Maeba stated: “You need to be really sure they are able to meet your security requirements.”
The panel then discussed how organizations’ increasing shift to the cloud to facilitate digital transformation is impacting security. Singh explained there are two main elements to this, the first of which is user access and the need for a zero-trust model. “Never trust, always verify and contextualize,” he said.
The second is the overall management of the environment, where security professionals are too often caught up in the latest “fads” and simply using new patches to solve issues. This leads to the integration of the technologies becoming more challenging. Again, understanding an organization’s goal in moving to the cloud is vital for the right approach to be taken. Based on this, security professionals should “articulate what the products available in the market are that can give you a seamless picture.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Fraud Analysts Miss Dark Web Data
Fraud Analysts Miss Dark Web Data

New research into how financial crimes are investigated has found that the majority of fraud analysts at financial organizations do not gather evidence from the dark web.
Web isolation platform provider Authentic8 today released the results of its 2020 Global Financial Crimes Survey, conducted in partnership with the Association of Certified Financial Crime Specialists (ACFCS).
The survey questioned 175 fraud analysts from 150 financial organizations about how financial corporations are handling increasing risks and exposure to losses as they battle against online adversaries.
When asked “Are you / your team researching and collecting evidence from the dark web?” 75% of fraud analysts answered “no.” Nearly half (46%) said that they are not able to follow leads into the dark web but would collect more intelligence from the dark web and other toxic sources “if it could be done securely and with an audit trail.”
The need for zero exposure was recognized by 74% of fraud analysts, who agreed with the statement “We need to protect our IT infrastructure while browsing unsafe sites / malicious content.” Nearly all (91%) of respondents said that anonymity while carrying out online investigations and research was “desirable or critical.”
Over a quarter of respondents (28%) said that their biggest challenge in online investigations is completing training to keep up with evolving criminal threats and technological advances.
A key finding of the survey was that caseload productivity was an issue for many fraud analysts. Over half (57%) of those surveyed said that their productivity is the same or worse in 2020 compared to 2019.
Almost all (90%) fraud analysts said that more investment in OSINT (open source intelligence) gathering capabilities was needed “to accelerate time-to-insight” for investigations.
“Adversaries are growing in both sophistication and number, but the surveyed firms are telling us the productivity of their fraud analysts is not improving at the same rate,” said Scott Petry, co-founder and CEO of Authentic8 Inc.
“The imbalance leads to more risk exposure for financial firms and other regulated industries. They risk write-downs, legal penalties, damage to their brand reputations, and more.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
#InfosecurityOnline: Tactics for Defending Against Credential Stuffing
#InfosecurityOnline: Tactics for Defending Against Credential Stuffing

A combination of password management, bot detection and traffic visibility can aid in spotting and defeating credential stuffing attacks.
Speaking during the Infosecurity Online event, Jamie Hughes, solutions engineer at Auth0, said credential stuffing attacks are a huge industry problem at the moment and are commonly enabled by single-factor authentication, breached credential lists, password reuse, attack tools and darknet market availability.
He explained that, on many websites and applications, he is typically only offered a choice of a password to authenticate to gain access. “There are some improvements, and some do offer MFA, and I always implement it where I can” but he said someone who is less security savvy may not, and the account can be left vulnerable.
A breached credential list can contain many credentials, which may be out-of-date, and Hughes flagged one website which had over seven billion records from 370 databases. He also said some lists charge a fee to download, and this is where the credentials are more likely to be successful. He said credentials can be collected via multiple means, such as via phishing attacks or via insecure databases, while password reuse is all too common where the average user has 26 accounts and five passwords.
Hughes added: “Targets of these attacks are typically subscription services, as the attacks gain access to the accounts but are typically sold at a lower cost on dark markets.”
As for impact on a company, Hughes said a company’s reputation could be damaged, and the “negative association can last for years” leading to media coverage as well as loss of trust from your users. There can also be a financial impact of the cost to investigate, the suspension of services and the computational costs of handling attacks.
In order to mitigate credential stuffing attacks, Hughes recommended looking at the analytics of your traffic, and also to benchmark your traffic, so you know what the normal patterns are and are able to spot a spike in failed login attempts. He also recommended looking for failed logins from IP addresses, to understand where an attack comes from.
“The main way to defend is through layers,” he said, focusing on three features: multi-factor authentication, breached password detection and bot detection. “We assess all of this traffic, and feed into our engine and see attempts against a user and IP address,” he said. “You can determine in real time if something is suspicious.”
With bot detection, Hughes said you’re looking to block, or challenge, requests, and recommended adding a Captcha as with bot detection you’re looking to slow down those requests before they are processed.
With regards to breached password detection, Hughes said Auth0 keeps a database of common passwords and warns the user if they are using something that is known to be commonly used. For MFA, Hughes said this can be added as an additional step for the user to prevent the attack takeover and prevents the account value from being sold on a darknet marketplace.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk