Canada Bombarded with COVID-19-Themed Cyber-attacks

Canada Bombarded with COVID-19-Themed Cyber-attacks

More than a quarter of Canadian IT workers say their organization has suffered a COVID-19-themed cyber-attack, according to a new survey.

The “2020 Cybersecurity Report” released today by the Canadian Internet Registration Authority (CIRA) surveyed more than 500 Canadian IT security decision-makers to learn more about their experience with cyber-threats.

Key findings of the report include that one-third of respondents said their organization was targeted by a COVID-19-related cyber-attack. Among the threats recorded by the survey were fake contact-tracing apps and phishing attacks that exploited COVID-19 test results.

Around three in ten organizations reported experiencing a spike in the volume of attacks they had suffered since the pandemic started. 

Slightly more than half said that they had implemented new cybersecurity protections in response to changes triggered by the global outbreak of the novel coronavirus. 

Worryingly, one-quarter of organizations surveyed said that they had experienced a data breach of customer and/or employee data last year. Of arguably greater concern was the fact that 38% of organizations didn’t know if they had been hit by a data breach or not. 

“The plot looks to get even darker for IT in the next 12 months,” said a CIRA spokesperson. “Despite facing more attacks in a harder-to-secure scenario, only about one-third of workers anticipate an increase in human resources devoted to cybersecurity. 

“That is down from 45% anticipating more resources in 2019.”

The survey found that around one in ten workers anticipate having fewer resources to invest in cybersecurity in the coming year. 

Another key finding of the report was the emergence of what appears to be compliance fatigue. 

“More report being aware of recent changes to the Personal Information Protection and Electronic Documents Act (PIPEDA), yet they are less likely to report data breaches than last year,” noted CIRA.

In 2020, only 36% of organizations informed a regulatory body after experiencing a data breach, down from 58% in 2019. This year, just 44% of those surveyed informed customers of a breach, representing a 4% decrease compared to 2019. 

CIRA predicts that if the federal government passes stricter privacy requirements, businesses will either need to be enticed into reporting breaches or financially penalized more severely for not doing so.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

John McAfee Indicted for Tax Evasion

John McAfee Indicted for Tax Evasion

Millionaire Anglo-American software pioneer John David McAfee has been arrested and charged with failing to pay taxes for a period of four years.

An indictment was unsealed yesterday by the United States Department of Justice that charges the 75-year-old with tax evasion and willful failure to file tax returns.

According to the indictment, the Roanoke College graduate earned millions in income from promoting cryptocurrencies, consulting work, speaking engagements, and selling the rights to his life story to documentary-makers. 

But the DOJ alleges that McAfee allegedly failed to file tax returns from 2014 to 2018, “despite receiving considerable income from these sources.” 

It is alleged that the man who founded multiple companies, including Tribal Voice, QuorumEx, and Future Tense, evaded his tax liability by directing his income to be paid into bank accounts and cryptocurrency exchange accounts in the names of nominees. 

The indictment further alleges McAfee attempted to evade America’s Internal Revenue Service by placing assets he owned in the names of other people. Among the assets he is accused of concealing are real estate property, a vehicle, and a yacht.

The indictment was unsealed after the British-born resident of Lexington, Tennessee, was arrested in Spain, where he is currently awaiting extradition. 

The charges were announced shortly after the US Securities and Exchange Commission (SEC) revealed that it had brought civil charges against McAfee. 

The government regulator alleges that between 2017 and 2018, McAfee leveraged his fame to recommend seven cryptocurrency offerings that turned out to be “essentially worthless.” However, McAfee allegedly neglected to disclose that he had been paid over $23m to do so.

In 2019, McAfee tweeted that he hadn’t filed tax returns for 8 years because “taxation is illegal.” If convicted in both cases, the entrepreneur could be imprisoned for a maximum of 35 years. 

Charges have also been brought by the SEC against McAfee’s bodyguard, Jimmy Watson, who allegedly aided and abetted the sale of digital currencies. 

McAfee founded the software company McAfee Associates in 1987 and ran it until 1994, when he resigned from the company.

The indictment does not allege that McAfee received any income or had any connection with the anti-virus company bearing his name during the period when he allegedly failed to pay taxes.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Corporate Credentials on the Dark Web Up by 429% This Year

Corporate Credentials on the Dark Web Up by 429% This Year

There has been a 429% growth in the number of corporate credentials with plaintext passwords on the dark web so far this year, according to Arctic Wolf’s 2020 Security Operations Annual Report. This amounts to an average of 17 separate sets of credentials per a typical organization, leaving businesses particularly vulnerable to account takeover attacks (ATO).

This is despite a year-on-year decline in publicly disclosed data breaches, which Arctic Wolf attributes to “alert fatigue”, in which overworked IT and security professionals increase alert thresholds, leading to less reporting of incidents.

The study also found there was a 64% rise in phishing and ransomware attempts in Q2 of 2020 compared to Q1, with cyber-actors seeking to use the topic of COVID-19 as a lure as well as target remote workers. The banking sector experienced the biggest increase in these types of attacks, at 520%.

Additionally, since the start of the COVID-19 pandemic in March, critical vulnerability patch time has gone up by 40 days, which the authors said was driven by higher common vulnerabilities and exposures (CVE) volumes, more critical CVEs and the shift to remote workforces. Another major security concern is that there has been a 240% increase in unsecured Wi-Fi usage since March due to the emergence of home working.

The need for organizations to closely monitor their network, endpoint and cloud environments at all times was underscored by the finding that 35% of high risk incidents observed by Arctic Wolf took place between the hours of 8.00pm and 8.00am while 14% occurred on weekends, when many in-house security teams are not online.

Mark Manglicmot, vice-president, security services, Arctic Wolf, commented: “The cybersecurity industry has an effectiveness problem. Every year new technologies, vendors, and solutions emerge. Yet, despite this constant innovation, we continue to see breaches in the headlines. The only way to eliminate cybersecurity challenges like ransomware, account takeover attacks, and cloud misconfigurations is by embracing security operations capabilities that fully integrate people, processes, and technology.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Over Half of IT and OT Professionals in Industrial Enterprises Experiencing Rise in Cyber-Threats

Over Half of IT and OT Professionals in Industrial Enterprises Experiencing Rise in Cyber-Threats

Over half (56%) of IT and operational technology (OT) security professionals from industrial enterprises have experienced a rise in cybersecurity threats since the start of the COVID-19 pandemic in March, with 72% finding that their jobs have become more challenging.

This is according to a new report from Claroty entitled The Critical Convergence of IT and OT Security in a Global Crisis, which surveyed the concerns, attitudes and experiences of 1100 full-time IT and OT security professionals involved in critical infrastructure components within large organizations in Europe, North America and Asia Pacific.

It also found that 70% have observed cyber-criminals using new tactics to target their organizations during the crisis.

Among the 200 UK-based respondents, almost a third (32%) said that their organization’s OT environment is not properly safeguarded from potential threats, while one-fifth revealed their enterprise did not make cybersecurity a priority during this time.

Challenges around the adoption of new technologies (41%) and collaboration between siloed IT and OT teams (56%) were also highlighted by those in the UK.

There were plenty encouraging signs that organizations are adapting to the new environment, however, with 83% of UK-based IT and OT professionals saying that their organization is prepared should another major disruption occur.

In addition, globally, two-thirds (67%) believe their IT and OT networks have become more interconnected since the pandemic started while 75% expect them to be even more interconnected going forward.

The five industries considered to be most vulnerable to attack by those surveyed were ranked as pharmaceutical, oil & gas, electric utilities, manufacturing and building management systems.

Yaniv Vardi, CEO of Claroty, commented: “While we would be short-sighted to think that we won’t have more challenges as we continue to face unknowns from this pandemic, protecting critical infrastructure is especially important in a time of crisis.

“As large enterprises are trying to improve their productivity by connecting more OT and IoT devices and remotely accessing their industrial networks, they are also increasing their exposure as a result. OT security needs to be brought to the fore and made a priority for all organizations. Attackers know that IT networks are covered with cybersecurity solutions so they’re moving to exploit vulnerabilities in OT to gain access to enterprise networks. Not protecting OT is like protecting a house with state-of-the-art security and alarm systems, but then leaving the front door open.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Endpoint Security Primary Pain Point in 2020

Endpoint Security Primary Pain Point in 2020

More than half of businesses have cited scaling endpoint security as their main pain point in 2020.

According to new research of 1005 key business stakeholders including C-Suite, IT and cybersecurity leaders by Asavie, 53% cited endpoint as their number one issue, followed by protecting against vulnerabilities (44%), and provisioning for remote workers (38%).

The research also found that 44% of organizations acknowledged facing a cyber-attack during the COVID-19 pandemic, specifically due to remote working. However, the research did find organizations are pushing ahead with their digital transformation journeys, with 61% prioritizing improving customer experience and 56% improving employee experience.

Terence Jackson, CISO at Thycotic, agreed that the endpoint is one of the main problems, as the pandemic has definitely highlighted the need for robust Endpoint Detection and Response (EDR) solutions to help combat attacks against the remote workforce. “Since phishing still remains the top delivery methods of malicious payloads, EDR is all the more important,” he said.

Hank Schless, senior manager, security solutions at Lookout, said lack of visibility into endpoints is a massive issue that has only been exacerbated by remote work. “Endpoints and vulnerabilities as pain points are not mutually exclusive,” he said. “Everyone has hundreds of apps on their mobile devices. Many of these apps we rely on to stay productive and be able to access corporate infrastructure from anywhere. Apps are now so deeply integrated into mobile devices that an exploited vulnerability in a mobile app could compromise any corporate data the device has access to.”

The Asavie research also determined the top three industry sectors reporting cybersecurity attacks to be media and telecoms (62%), financial services (60%) and health and life sciences (50%).

Schless said media and telecoms are an attractive target for threat actors because of their influence. “Taking over an influential publication’s social media account to spread misinformation or share a malicious link is a common tactic,” he said.

He also said the financial services industry is consistently one of the most targeted verticals for any type of cyber-attack as they were forced into remote working too, and “threat actors know that this means those remote workers are vulnerable to attack without all of the network-based protections they had in the office.”

Also, he pointed to the fact that the health and life sciences industry is leading the charge in discovering a COVID-19 vaccine, and there is evidence of foreign adversaries actively targeting the US-based companies that are at the forefront of this vaccine development.

He said: “This industry has a long chain of research and development, and employees around the globe are always collaborating across various platform and devices. Without proper visibility into all endpoints, there are countless opportunities for a malicious actor to slip into the corporate infrastructure unnoticed and exfiltrate highly sensitive data without throwing any red flags.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cisco Ordered to Pay $1.9 Billion for Security Patent Infringement

Cisco Ordered to Pay $1.9 Billion for Security Patent Infringement

Cisco has been ordered to pay $1.9 billion to a little-known threat detection company who accused it of infringing several cybersecurity patents.

US District Judge Henry Morgan issued his verdict in Norfolk, Virginia after a month-long trial held without a jury due to COVID-19.

He found Cisco had infringed four patents belonging to Herndon, Virginia-headquartered Centripetal Networks, with no action take regarding a fifth, according to Reuters.

“Cisco did not advance any objectively reasonable defenses at trial,” Morgan reportedly wrote in his 167-page decision. “The infringing functionality was added to their accused products post-June 20, 2017, and resulted in a dramatic increase in sales which Cisco touted in both technical and marketing documents.”

The $756 million in actual damages suffered by Centripetal was apparently multiplied by 2.5 in light of this “wilful and egregious” conduct by Cisco, with pre-judgement interest also added.

Cisco is set to lodge an appeal with the US Federal Circuit Court of Appeals. It claimed to have provided “substantial evidence of non-infringement, invalidity and that Cisco’s innovations predate the patents by many years.”

However, the judge said the decision was “not a close call,” and that in some cases even Cisco’s own technical documents proved Centripetal’s case.

“With this judgment, the court rejected the primitive doctrine that might makes right,” Centripetal lawyer Paul Andre, said in a statement. “This is a significant win for all small, innovative companies.”

The Virginian security firm’s current product line-up is based on the RuleGate threat intelligence gateway platform, which it says offers a 1000-fold improvement on legacy offerings such as next-gen firewalls.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Europol Warning as Cybercrime Adapts Quickest to New Normal

Europol Warning as Cybercrime Adapts Quickest to New Normal

Cyber-criminals have continued to adapt and grow in sophistication over the past year, to stay hidden on the dark web and cause maximum damage with ransomware attacks, according to Europol.

Ransomware remains “the most dominant threat” today and is becoming more dangerous as cyber-criminals continue to target their attacks with sophisticated, multi-stage raids starting with reconnaissance.

Europol warned that the combination of ransomware and third-party providers is a “lethal” one as it can damage entire supply chains, with threats to wipe or auction stolen data turning the heat up further on victim organizations.

Widespread under-reporting is also hampering law enforcement efforts as victims look to limit reputational damage, it claimed in the Internet Organised Crime Threat Assessment (IOCTA) 2020 report.

“Negative publicity leading to reputational fallout may lead to re-victimization, which may prevent victims from coming forward to law enforcement authorities with information which could be crucial in identifying and catching the perpetrators,” Europol said.

“Victims prefer to engage with private sector security firms for investigating the attack or negotiating with the extortionists to manage the crises triggered by ransomware (some IT security firms hire specialist negotiators, some of whom get discounts from organized crime groups). Some of the companies that negotiate the ransom payment are working on the edge of legality, as they have developed a trusted business relationship with the ransomware actors.”

Cyber-criminals are also getting better at hiding their activity on the dark web, despite major disruption to underground marketplaces.

A series of 2019 takedowns and the recent closure of Empire Market may have appeared as if law enforcement had the upper hand, but the cybercrime community is rallying, according to Europol.

“Darkweb administrators have been observed pulling together and showing a collaborative spirit to maintain the environment under challenging circumstances,” it claimed. 

“When faced with similar challenges, forum and service administrators have been seen working more closely together over sharing code and security methodologies (i.e. anti-DDoS measures, avoiding scams, creating trust-building sites to help users navigate vendors across different marketplaces).”

These efforts have been enhanced with new security approaches including the appearance of wallet-less and user-less markets, multi-signature crypto-currency wallets, no JavaScript policies, Sonar and Elude for secure email, and Telegram, Discord and Wickr for other encrypted comms.

Surface e-commerce web sites are also being used in growing numbers to advertise their products and services, said Europol.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

PCI DSS Compliance Slumps 28% Since 2016

PCI DSS Compliance Slumps 28% Since 2016

Compliance with the Payment Card Industry Data Security Standard (PCI DSS) has declined for the third year in a row, with organizations failing in their long-term planning, according to Verizon.

The tech giant compiled its Verizon Business 2020 Payment Security Report based as usual on data gathered by its own PCI DSS qualified security assessors (QSAs) and those of other providers.

It revealed that on average only 27.9% of global organizations maintained full compliance with the PCI DSS, a drop of over 27% since compliance peaked in 2016.

The report highlighted other concerns: just half (52%) of assessed organizations successfully test security systems and processes and unmonitored system access, and around two-thirds monitor access to business-critical systems effectively. Just 71% of financial institutions maintain essential perimeter security controls, Verizon added.

PCI DSS is designed to provide a carrot-and-stick approach to improving data security for merchants that process card payments. On the one hand it offers a best practice framework to help firms mitigate the risk of data breaches, but if they don’t comply and are subsequently hit, large fines could be levied.

The threat is real: 86% of data breaches last year were financially motivated and in the retail vertical, 99% of security incidents related to the acquisition of payment data by attackers, according to the most recent Verizon Data Breach Investigations Report.

Verizon Business president of global enterprise, Sampath Sowmyanarayan, argued that many firms still lack resources and commitment from the top to drive long-term compliance strategies.

“The recent coronavirus pandemic has driven consumers away from the traditional use of cash to contactless methods of payment with payment cards as well as mobile devices. This has generated more electronic payment data and consumers trust businesses to safeguard their information,” he continued.

“Payment security has to be seen as an on-going business priority by all companies that handle any payment data, they have a fundamental responsibility to their customers, suppliers and consumers.”

The report highlighted particular challenges for SMBs in performing what is commonly perceived as an onerous and expensive PCI DSS compliance process.

Maxine Holt, senior research director at Omdia, said the report’s findings should serve as a wake-up call to businesses.

“The alignment of security strategy with organizational strategy is essential for organizations to maintain compliance, in this case with PCI DSS 3.2.1, to provide appropriate levels of payment security,” she said.

“It makes clear that long-term data security and compliance combines the responsibilities of a number of roles, including the chief information security officer, the chief risk officer, and chief compliance officer, which Omdia concurs with.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Cryptojacking Malware Variant Targeting Cloud Systems Discovered

New Cryptojacking Malware Variant Targeting Cloud Systems Discovered

A new variant of cryptojacking malware from threat group TeamTnT has been uncovered by Palo Alto Networks’ threat intelligence team, Unit 42.

The malware, named Black-T, “gives evidence of a shift in tactics, techniques and procedures (TTPs)” for operations conducted by TeamTNT, a group known for targeting AWS credential files on compromised cloud systems and mine for Monero.

While Unit 42 researchers observed that traditional TeamTNT TTPs of targeting exposed Docker daemon APIs and undertaking scanning and cryptojacking operations on vulnerable systems of affected organizations are followed by Black-T, code in the malware shows it has enhanced capabilities.

These include the targeting and stopping of cryptojacking worms such as the Crux worm, ntpd miner and a redis-bakup miner, that were previously unknown. Another is the use of memory password scraping operations via mimipy and mimipenguins, with the identification of passwords through mimipenguins exfiltrated to a TeamTNT command and control node.

In addition, the researchers found that Black T is able to extend TeamTNTs cryptojacking operations by using three different network scanning tools to identify extra Docker daemon APIs that are present in the local network of the compromised system as well as across any number of publicly accessible networks. While two of these, masscan and pnscan, have previously been used by the group, the introduction of zgrab is the first time that a GoLang tool has been seen to be included in TeamTNT’s arsenal.

Palo Alto Networks explained: “TeamTnT is a cloud-focused cryptojacking group which targets exposed Docker daemon APIs. Upon successful identification and exploitation of the Docker daemon API, TeamTnT will drop the new cryptojacking variant Black-T.”

Speaking to Infosecurity, Nathaniel Quist, senior threat researcher at Unit 42, Palo Alto Networks said: “As TeamTnT currently functions, they are very opportunistic and are indiscriminate in who they target. It seems they are more interested in exploiting services to steal as many computational processes as they can, rather than targeting specific sectors.”

He added: “COVID-19 pushed many organizations towards cloud infrastructure a bit faster, so it’s likely that we’ll see cloud focused-malware evolve to use more sophisticated techniques as a result, given the increased opportunity.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Diplomats Attacked with Firmware Bootkit

Diplomats Attacked with Firmware Bootkit

An advanced persistent threat (APT) espionage campaign that uses a rare form of malware has been observed attacking diplomats and members of NGOs. 

The campaign, which relies on a firmware bootkit, was identified by researchers at Kaspersky who were operating UEFI/BIOS scanning technology. The previously unknown malware was identified in the Unified Extensible Firmware Interface (UEFI).

UEFI firmware is used in all modern computer devices and starts running before the operating system and all the programs installed in it. This, together with the fact that the firmware resides on a flash chip separate from a device’s hard drive, makes the detection of any malware in UEFI firmware very difficult. 

“If UEFI firmware is somehow modified to contain malicious code, that code will be launched before the operating system, making its activity potentially invisible to security solutions,” said a Kaspersky spokesperson.

“The infection of the firmware essentially means that, regardless of how many times the operating system has been reinstalled, the malware planted by the bootkit will stay on the device.”

Researchers said the UEFI bootkit used with the malware is a customized version of Hacking Team’s Vector-EDK bootkit, the source code for which was leaked in 2015. It is the first in-the-wild attack leveraging a custom-made UEFI bootkit. 

“Once software—be it a bootkit, malware or something else—is leaked, threat actors gain a significant advantage,” said Igor Kuznetsov, principal security researcher at Kaspersky’s GReAT. 

“Freely available tools provide them with an opportunity to advance and customize their toolsets with less effort and lower chances of being detected.”

A sample of the bootkit malware was used in a campaign that deployed variants of a complex, multi-stage modular framework dubbed MosaicRegressor that was used for espionage and data gathering.

Based on the affiliation of the victims, researchers determined that MosaicRegressor was used in a series of targeted attacks aimed at diplomats and members of NGOs from Africa, Asia, and Europe.

Though unsure of exactly how the infections occurred, researchers found that they may have been possible through physical access to the victim’s machine, specifically with a bootable USB key, which would contain a special update utility. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk