Most UK Firms Admit #COVID19 Cloud Security Threat

Most UK Firms Admit #COVID19 Cloud Security Threat

Most UK firms are set to increase digital adoption after admitting that the cloud saved their business from collapse during the early months of the COVID-19 crisis, but security remains a persistent challenge, according to new research.

Identity management vendor Centrify surveyed 200 business decision makers in large and medium-sized UK firms in September, in order to assess the impact of the pandemic on IT organizations.

It found that 51% claimed that transitioning to a cloud-based business model helped to keep the business afloat after the government mandated mass remote working during the first lockdown.

However, in so doing, the shift also exposed major gaps in their cybersecurity posture: although 61% said they were ready for this challenge, 39% agreed that security risks increased.

This chimes with a separate study from Tanium which found that although 85% of global CXOs felt ready to shift to a fully remote workforce, almost all (98%) were then caught off guard by the security challenges they faced within the first two months.

Over half (56%) of the UK business leaders polled by Centrify claimed that remote working has made it harder to identify attempts to impersonate staff, presumably via BEC attacks and phishing emails.

An additional 51% said the new model of distributed working has led to an increase in ‘insider’ threats, such as employee accounts that are hijacked by attackers.

Fortunately, 60% of respondents said they are now more aware of the risks facing their organization following the spike in phishing attacks over the past few months. They will need to be, as the same number (60%) said they’re planning to increase their use of cloud-based IT as the pandemic continues.

A range of security experts over the first half of the year have warned that employees working from home may be more distracted and therefore likely to click on phishing links. The threat is amplified further by the fact that their laptops or devices may be less well secured than corporate equivalents, missing vital patches, and/or used to download non-approved applications.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Gaming Industry Subjected to Surge in Attacks Over Last Two Years

Gaming Industry Subjected to Surge in Attacks Over Last Two Years

Video game companies and players have been subjected to a high volume of attacks in the period from July 2018 to June 2020, a new report published by Akamai has found. This included 152 million web application attacks and 10 billion credential attacks targeting the gaming industry recorded during this period.

To execute credential stuffing attacks, malicious actors attempt to gain access to gamers online accounts by using lists of username and password combinations that are often available on nefarious websites and services.

In regard to the web application attacks carried out, a substantial majority were SQL injection attacks. These are designed to exploit data stored in the targeted server’s database, such as user login credentials and personal data. Another significant attack vector in this space was local file inclusion, which can expose player and game details that can ultimately be used for exploiting or cheating.

Akamai said that gamers were also heavily targeted by phishing attempts, in which criminals attempt to trick players into revealing their login credentials by creating legitimate-looking websites related to a game or gaming platform.

The security firm added that in the period from July 2019 to July 2020, gaming was the sector most targeted by DDoS attacks, on the receiving end of 3000 out of 5600 attacks of this kind.

A spike in attacks against the industry was additionally recorded during COVID-19 lockdowns earlier this year, when video games offered an important source of entertainment and social interaction.

The gaming industry has become an increasingly lucrative target for cyber-criminals due to its rise in popularity over recent years, according to the report; the sector was worth $159 billion in 2019 and is predicted to reach $200 billion by 2023.

Steve Ragan, Akamai security researcher and author of the report, commented: “The fine line between virtual fighting and real world attacks is gone. Criminals are launching relentless waves of attacks against games and players alike in order to compromise accounts, steal and profit from personal information and in-game assets, and gain competitive advantages. It’s vital that gamers, game publishers, and game services work in concert to combat these malicious activities through a combination of technology, vigilance, and good security hygiene.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Iranian Government Hacking Android

The New York Times wrote about a still-unreleased report from Chckpoint and the Miaan Group:

The reports, which were reviewed by The New York Times in advance of their release, say that the hackers have successfully infiltrated what were thought to be secure mobile phones and computers belonging to the targets, overcoming obstacles created by encrypted applications such as Telegram and, according to Miaan, even gaining access to information on WhatsApp. Both are popular messaging tools in Iran. The hackers also have created malware disguised as Android applications, the reports said.

It looks like the standard technique of getting the victim to open a document or application.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft: Attackers Exploiting ‘ZeroLogon’ Windows Flaw

Microsoft warned on Wednesday that malicious hackers are exploiting a particularly dangerous flaw in Windows Server systems that could be used to give attackers the keys to the kingdom inside a vulnerable corporate network. Microsoft’s warning comes just days after the U.S. Department of Homeland Security issued an emergency directive instructing all federal agencies to patch the vulnerability by Sept. 21 at the latest.

DHS’s Cybersecurity and Infrastructure Agency (CISA) said in the directive that it expected imminent exploitation of the flaw — CVE-2020-1472 and dubbed “ZeroLogon” — because exploit code which can be used to take advantage of it was circulating online.

Last night, Microsoft’s Security Intelligence unit tweeted that the company is “tracking threat actor activity using exploits for the CVE-2020-1472 Netlogon vulnerability.”

“We have observed attacks where public exploits have been incorporated into attacker playbooks,” Microsoft said. “We strongly recommend customers to immediately apply security updates.”

Microsoft released a patch for the vulnerability in August, but it is not uncommon for businesses to delay deploying updates for days or weeks while testing to ensure the fixes do not interfere with or disrupt specific applications and software.

CVE-2020-1472 earned Microsoft’s most-dire “critical” severity rating, meaning attackers can exploit it with little or no help from users. The flaw is present in most supported versions of Windows Server, from Server 2008 through Server 2019.

The vulnerability could let an unauthenticated attacker gain administrative access to a Windows domain controller and run an application of their choosing. A domain controller is a server that responds to security authentication requests in a Windows environment, and a compromised domain controller can give attackers the keys to the kingdom inside a corporate network.

Scott Caveza, research engineering manager at security firm Tenable, said several samples of malicious .NET executables with the filename ‘SharpZeroLogon.exe’ have been uploaded to VirusTotal, a service owned by Google that scans suspicious files against dozens of antivirus products.

“Given the flaw is easily exploitable and would allow an attacker to completely take over a Windows domain, it should come as no surprise that we’re seeing attacks in the wild,” Caveza said. “Administrators should prioritize patching this flaw as soon as possible. Based on the rapid speed of exploitation already, we anticipate this flaw will be a popular choice amongst attackers and integrated into malicious campaigns.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Thieves Fail to Auction Bruce Springsteen’s Legal Documents

Thieves Fail to Auction Bruce Springsteen’s Legal Documents

Cyber-criminals hoping to profit from the theft of Bruce Springsteen’s legal documents were left disappointed when an online auction of the data attracted no buyers.

The singer’s documents were among a 756GB cache of data swiped from New York City law firm Grubman Shire Meiselas & Sacks in a cyber-attack carried out in May this year. 

Other high-profile entertainers believed to have been impacted by the incident included Lady Gaga, Madonna, Jessica Simpson, Nicki Minaj, Priyanka Chopra, Mariah Carey, Outkast, and Mary J. Blige.

Sensitive information stolen in the incident included contracts, telephone numbers, email addresses, personal correspondence, and non-disclosure agreements.

Responsibility for the attack was claimed by the criminal gang behind REvil ransomware (also known as Sodinokobi), who demanded, but failed to get, a ransom to return the files. 

Following the attack in May, the gang threatened to auction off data relating to Grubman Shire Meiselas & Sacks client Madonna, demanding a starting bid of $1m for the information. However, the gang reneged on their threat. 

Yesterday, the gang staged an auction on its Dark Web “Happy Blog” of “All Bruce Springsteen legal documents from Grubman office” in which interested buyers were invited to start with a more modest opening bid of $600,000. A blitz price option of $1,500,000 was also offered.

When no bidders came forward, the gang published the message “No one paid for this lot in time. So the data is published.” However, the gang did not share a link to where the allegedly published stolen data could be found, suggesting that the auction may have been nothing more than a bluff. 

In another feint, played out earlier this year, the gang claimed to have stolen “a ton of dirty laundry” on US president Donald Trump in the ransomware attack on Grubman.

The gang is yet to provide any evidence of data that is damaging to Trump, who was never a client of the media and entertainment law firm. 

The FBI has advised victims not to pay any ransom demands, as doing so doesn’t guarantee the return and security of the encrypted files and encourages further attacks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk