ConnectWise Launches Bug Bounty Program

ConnectWise Launches Bug Bounty Program

Bug bounty hunters have been given fresh digital grounds to prowl with the launch of a new vulnerability detection rewards program by ConnectWise.

The software specialist provider announced today that it has launched a bug bounty program to supplement its own internal vulnerability management strategy. The crowdsourcing program was created with the aim of boosting efforts to quickly identify and remediate bugs and security vulnerabilities in the company’s software. 

To host the program, ConnectWise is partnering with hacker-powered security platform HackerOne. The ConnectWise Bug Bounty program is private, meaning that it is only open to invited hackers via the HackerOne platform.

ConnectWise said that it is committed to addressing all confirmed vulnerabilities that are discovered through the bug bounty program and will remediate and disclose issues “commensurate with severity.” Responsible disclosures will continue to be delivered through the ConnectWise Trust Site, which houses the company’s security bulletins and alerts, critical patches, and updates, with the ability to subscribe to proactive notifications via an RSS feed.

“Cyber criminals move fast, so we have to move faster,” said Tom Greco, director of information security at ConnectWise. “Employing a bug bounty program with the help of HackerOne, the industry leader in this space, will allow us to do just that by finding issues before bad actors get a chance to exploit them.”

Greco said that the world’s bug bounty hunters provide an extra layer of protection by seeking out and reporting vulnerabilities.

“Crowdsourcing in this way represents a solid additional layer of security, and we clearly value the community’s expertise and participation in helping us keep our products secure,” he commented. 

“As we said earlier this year, the launch of this Bug Bounty program is yet another important addition to our security arsenal—and it’s the latest piece of our overall strategy to strengthen our own security standing so that we can better protect our partners and their SMB customers.”

ConnectWise is headquartered in Tampa, Florida, but has offices across the United States and abroad in Australia, India, and the United Kingdom. The company was founded in 1982 and became a Thoma Bravo Portfolio Company on March 1, 2019.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

eBay Execs to Plead Guilty to Cyber-Stalking

eBay Execs to Plead Guilty to Cyber-Stalking

Four former eBay executives accused of cyber-stalking and intimidating a Massachusetts couple are to admit their guilt before a court next month.

The married couple, an editor and a publisher residing in Natick, were targeted with a series of terrifying deliveries after they criticized eBay in an online newsletter. 

Horrific parcels sent to the couple included a bloody pig mask, live spiders and cockroaches, a book on surviving the death of a spouse, and a wreath of funeral flowers. In addition, pornographic magazines addressed to the husband were received by one of the couple’s neighbors.

The four defendants due to plead guilty in October are among six former senior employees of the American multinational e-commerce corporation who were charged in June with carrying out the terrifying cyber-campaign. 

Court documents alleged that one member of eBay’s executive team directed the company’s former senior director of safety and security, James Baugh, to “take her down,” referring to the newsletter’s editor. 

San Jose, California, resident Baugh, along with eBay’s former director of global resiliency, David Harville, of New York City, are charged with conspiracy to tamper with witnesses and conspiracy to commit cyber-stalking. 

Other former eBay employees charged in relation to the alleged cyber-stalking are Stephanie Popp, former senior manager of global intelligence; Stephanie Stockwell, former manager of eBay’s Global Intelligence Center; Brian Gilbert, former senior manager of special operations for eBay’s Global Security Team; and Veronica Zea, a former eBay contractor who worked as an intelligence analyst in the Global Intelligence Center.

It is further alleged that the executives created fake social media accounts from which they sent the couple threatening messages and which they used to post statements about fictitious events happening at the couple’s home address. 

News of the quartet’s intention to admit culpability was shared earlier today on Twitter by the US Attorney’s Office in the district of Massachusetts. Precisely which defendants are planning to admit their part in the affair was not specified.

The office’s tweet read: “Four former employees of #eBay are scheduled to plead guilty on Oct. 8 at 2pm via zoom in federal court in #Boston. The defendants are charged w/ participating in a cyberstalking campaign that targeted a Massachusetts couple.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK’s MOD to Expand Digital Capacity Through Introduction of Oracle Cloud infrastructure

UK’s MOD to Expand Digital Capacity Through Introduction of Oracle Cloud infrastructure

The UK’s Ministry of Defence (MOD) department, Defence Digital has added the Oracle Cloud Infrastructure within its MODCLOUD Multi-Hybrid suite of secure services, it has been announced today. The move is designed to help the department meet growing demand for real-time information advantage, as well as manage vast quantities of data in an efficient and compliant way.

The Defence Digital department is “responsible for making sure that effective digital and information technology (D&IT) is put into the hands of the military and business front line”, with its remit including defensive cyber strategy, capability development and policy.

To help facilitate this, it will allow Oracle’s flexible range of technologies to be available to the wider Defence community under a pan-defence Oracle enterprise agreement, and through Oracle’s integrated suite of services under a ‘single-sign on.’ This will give the MOD access to emerging technologies such as digital assistants, data visualization, mobile hub and low code development tools, substantially expanding its technological capabilities.

Sara Sharkey, MOD Defence Digital application services and devops head, commented: “The real opportunity of digital transformation—which includes artificial intelligence, machine learning, IoT, blockchain, and human interfaces—is to embrace data on a scale we’ve never seen before. Selecting Oracle Cloud Infrastructure within our MODCLOUD Multi-Hybrid suite of services offers new technologies that are reshaping how we approach IT and using this information, allowing us to focus on innovation and outcomes for both business and importantly, people.”

Richard Petley, senior vice president and country leader at Oracle UK said: “By adopting Oracle Cloud Infrastructure, the Ministry of Defence will be one step closer to realising its wider transformation strategy.

“The MOD will capitalize on the choice and economic benefits Oracle Cloud Infrastructure can provide, all of which will help meet challenges that lie ahead. It joins a whole host of public sector organisations, such as the Home Office, Western Sussex Family Assist, Lambeth Borough Council, Croydon County Council, The Office for National Statistics and Scottish Water, which are already using Oracle Cloud.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Shopify Insiders Attempted to Steal Customer Transactional Records

Shopify Insiders Attempted to Steal Customer Transactional Records

Canadian e-commerce merchant Shopify has reported that it detected an ongoing insider threat case.

In a statement, Shopify said it had become aware of an incident involving the data of fewer than 200 merchants, and its investigation “determined that two rogue members of our support team were engaged in a scheme to obtain customer transactional records of certain merchants.”

Upon discovery, Shopify immediately terminated the individuals’ access to the Shopify network and referred the incident to law enforcement. “We are currently working with the FBI and other international agencies in their investigation of these criminal acts,” it said. “While we do not have evidence of the data being utilized, we are in the early stages of the investigation and will be updating affected merchants as relevant.”

Shopify said the incident was not caused by a technical vulnerability in the platform, and some stores may have had customer data exposed. “This data includes basic contact information, such as email, name, and address, as well as order details, like products and services purchased. Complete payment card numbers or other sensitive personal or financial information were not part of this incident.”

Shopify said it does not take these events lightly, and “we have zero tolerance for platform abuse and will take action to preserve the confidence of our community and the integrity of our product.”

Speaking to Infosecurity, Lisa Forte, partner at Red Goat Cyber Security LLP, said insiders are notoriously dangerous, and although they are rare, they yield access legitimately granted that external attackers would only dream of.

“Incidents involving insiders are also hugely damaging from a reputational standpoint,” Forte said. “Perhaps more so than other attacks. Shopify have acted quickly and apparently transparently so far. It is unclear at this point what the precise motive of these insiders was, but all insider threats fall into one of three categories: fraud, sabotage or theft. Often insiders are not working totally alone, with research evidencing the tendency of colleagues to notice but ignore suspicious behavior.” 

In August, it was reported that a Tesla employee was apparently approached by an attacker, and offered $1 million to place ransomware internally.

Warren Poschman, senior solutions architect at Comforte AG, called the incident “the perfect example of the risks many organizations face” as while it can be difficult to immediately identify a rogue employee or malicious insider, the damage they can do can be irreversible. “This can create a lot of distress on both the businesses side and on consumers as fraud is easy to commit with stolen or accessed account information,” he said.

Jake Moore, cybersecurity specialist at ESET said: “Insider threats are a constant risk that businesses have always had to take a chance with. However, an increase in remote working – alongside the consequent factor of new employees never physically meeting their employers – accelerates the risks, meaning that insider attacks may become more prevalent than ever.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cisco: How Real is a Passwordless Future?

Cisco: How Real is a Passwordless Future?

The evolution towards being able to operate without passwords is being driven by two factors: BYOD and standards.

Speaking on a Cisco webinar, advisory CISO J. Wolfgang Goerlich said while we have to wait for “robots and flying cars,” he could see a world with reduced reliance on passwords. He said the consumer typically drives the experience that they expect in the workplace, and consumerization has enabled users to become more familiar with the technology they use.

Goerlich also praised standards, in particular from the FIDO Alliance, on “what a good passwordless token looks like.” He said there is a lot of confidence in standards and development in strong factors, is still paired with a password to make it easy for people to get in. “So in a passwordless world, they throw in a username and complete a secondary factor of authentication without having to enter a password, and then they don’t have to remember things or rotate things,” he said.

Citing Cisco statistics, Goerlich said the average user has 191 passwords, “so the ability to move off of those is something we’re very excited about.” He said the “pieces have come together” and CISOs are integrating a passwordless concept with their roadmaps.

Fellow advisory CISO for Cisco EMEA, Richard Archdeacon, agreed CISOs are beginning to look at passwordless as an option, and are looking to see if this can work at an enterprise level. “It achieves two ends: it improves your security; and it makes life easier for people, and if you can make life easier when you’re in a security team, that is a real plus,” he said.

Goerlich also made the point that CISOs often think about how to increase trust in passwordless authentication, and how fraud can be combatted if passwords are disused. He recommended using targeted machine learning to enable logins, as well as zero trust strategies. He said: “I think there is a lot that has to be considered when we talk about the next step, making it scale to the enterprise and really how we secure that passwordless future.”

Wendy Nather, head of advisory CISOs, said what is making this possible is we have more secure enclaves on phones than before, and more trusted processing modules on laptops, “where cryptographic functions can be manipulated securely without any inference from the user or any attacker who might be on the laptop or the device.”

Nather said that using the FIDO standard, a “shared secret” can be created, which is a parent key, and use it to authenticate to the phone using TouchID or FaceID, and the secure enclave would log you in, without the user having to do anything. “From my perspective I wouldn’t have to put in a password, I would just log into my phone with my fingerprint, and then the phone would do the rest. This is one way we are making passwordless a reality.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Most Workers Not Interested in Switching to a Cybersecurity Role

Most Workers Not Interested in Switching to a Cybersecurity Role

Most UK and US workers now view cybersecurity professionals in a positive light, although worryingly few are considering a career in the industry, according to a new study from (ISC)2.

The certifications company polled 2500 workers in the US and UK to compile its 2020 Cybersecurity Perception Study.

It revealed that perceptions of those working in cybersecurity are now generally positive: 71% claimed they view security pros as “smart, technically skilled individuals,” while 51% described them as “good guys fighting cybercrime.”

However, more concerning is the lack of interest in pursuing a career in the industry: 69% of respondents said it’s not the right fit for them, despite admitting that objectively it seems like a good option.

Part of the reasoning behind this is that individuals believe cybersecurity roles require a significant investment of time and money in training and the accrual of technical knowledge.

Some 61% said they thought they’d need more education or a certification before getting a job in the sector, 32% believe it requires too much tech know-how or training, 27% said they don’t know how to code and 26% claimed it is “too intimidating.”

Women were more likely than men to perceive the industry as intimidating and to be put off by the lack of diversity.

These perceptions may have been formed in part because most (77%) respondents were never offered cybersecurity as part of their school or college curriculum. Partly as a result, the majority (68%) said their view of the industry is shaped by portrayals in TV shows and movies (37%) or by news coverage of security incidents (31%).

Frustratingly for those hoping to encourage more people into the industry, the report comes at a time when many are considering a career change. Further, attributes such as job stability (61%), flexible working (57%) and earning potential (56%), all of which are available in security roles, are now priorities for respondents.

Perceptions of cybersecurity matter because, with an estimated global shortfall of over four million professionals, a major recruitment drive is needed to encourage workers to switch career paths.

However, the unpalatable truth is that many of the respondents’ negative perceptions are accurate: employers still often rely too much on certifications and previous experience when selecting candidates, and diversity is a persistent problem.

A particularly acute challenge will be changing perceptions among younger professionals: Generation Z respondents were least likely to view cybersecurity professionals in a positive light.

“The reality of the situation, and what we need to do a better job of publicizing, is that a truly effective cybersecurity workforce requires a broad range of professionals who bring different skillsets to their teams,” argued (ISC)2 COO, Wesley Simpson.

“While technical skills are vital for many roles, we also need individuals with varied backgrounds in areas including communications, risk management, legal, regulatory compliance, process development and more, to bring a well-rounded perspective to cyber-defense.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FBI Issues Warning Over US Election Disinformation Campaigns

FBI Issues Warning Over US Election Disinformation Campaigns

The US government has been forced to sound the alarm over anticipated attempts by hostile nations and cyber-criminals to spread disinformation around the results of the 2020 elections.

In a new Public Service Announcement on Tuesday, the FBI and Cybersecurity and Infrastructure Security Agency (CISA) warned that “foreign actors and cyber-criminals” could use several channels to undermine confidence in the democratic process, including new and defaced websites and social media posts.

“State and local officials typically require several days to weeks to certify elections’ final results in order to ensure every legally cast vote is accurately counted. The increased use of mail-in ballots due to COVID-19 protocols could leave officials with incomplete results on election night,” it explained.

“Foreign actors and cyber-criminals could exploit the time required to certify and announce elections’ results by disseminating disinformation that includes reports of voter suppression, cyber-attacks targeting election infrastructure, voter or ballot fraud, and other problems intended to convince the public of the elections’ illegitimacy.”

The alert urged the US public to get their news only from trusted sources of verified information, such as state and local election officials.

The process of counting votes could be dragged out even longer thanks to new policies rolled out by Trump appointee and new head of the Postal Service (USPS) Louis DeJoy, which some reports have claimed are already causing major delivery delays.

Any misinformation campaigns would only have to echo the sentiments of the President himself to undermine faith in the democratic process: Trump has claimed repeatedly without evidence that mail-in voting could lead to widespread voter fraud.

The FBI/CISA urged US voters to: be more critical when reading news about the election results, verify with multiple reliable sources, including state and local government election officials and make use of social media tools designed to flag fake news if they spot anything suspicious.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CISA: Detections of LokiBot Info-Stealer Are Soaring

CISA: Detections of LokiBot Info-Stealer Are Soaring

The US government has warned of a major increase in detections of info-stealing malware LokiBot over the past couple of months.

The Cybersecurity and Infrastructure Security Agency (CISA) sounded the alarm on Tuesday, revealing that its Einstein intrusion detection system had spotted a “notable increase” in the use of the malware since July.

“LokiBot uses a credential- and information-stealing malware, often sent as a malicious attachment and known for being simple, yet effective, making it an attractive tool for a broad range of cyber-actors across a wide variety of data compromise use cases,” it added.

Also known as Loki PWS, the Trojan malware is designed to steal usernames, passwords, cryptocurrency wallets and other credentials through the use of a keylogger. It can also deploy a backdoor, enabling the installation of additional payloads.

Although it is spread most often by malicious email attachment, users could also be targeted via phishing texts and private messages, or by infected websites.

First discovered in 2016, LokiBot has mainly been used to target Windows and Android users, and in the past has even been used as a banking Trojan and mobile ransomware. Most recently, Trend Micro researchers discovered a version disguised as a launcher for popular gaming title Fortnite.

Gurucul CEO, Saryu Nayyar, argued that the CISA warning shows how cyber-criminals are successfully scaling their business model.

“The fact that LokiBot has been around for over four years and has gained in capability over time is a reflection of how much malicious actors have advanced the state of their art, leveraging the same development models we use in the commercial space,” he added. 

“Fortunately, our security tools have also improved over time. Using a combination of data sources for telemetry, it’s possible to analyze events as they happen and identify malicious user or system behaviors. This lets an organization mitigate these attacks before they can cause serious damage.”

CISA recommended a range of best practice steps to mitigate the threat including: prompt patching; use of up-to-date AV; multi-factor authentication; scanning for malicious email attachments; user monitoring; and employee awareness training.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk