Securonix Announces New C-Suite Appointments to Bolster Growth

Securonix Announces New C-Suite Appointments to Bolster Growth

Security information and event management (SIEM) company Securonix has announced two new C-suite appointments to bolster its growth.

Brett Bowman joins Securonix as chief financial officer and Dilshan Ratnayake as chief people officer.

Bowman brings previous experience in defining and executing growth strategy within tech startups and will lead Securonix’s finance and accounting operations, whilst Ratnayake, with a 25-year background in human resources leadership, will head up the people and talent functions across the company’s global footprint and scale growth and expansion plans.

Bowman said: “It’s clear from recent company trajectory that Securonix provides a platform solution that is purpose built for today’s enterprise security needs and holds unlimited growth potential, which is why joining Securonix is so exciting.”

Ratnayake added: “Coming from several publicly-traded organizations, I recognize the promise Securonix holds and am fully committed to helping it achieve its goals as one of cybersecurity’s next great companies.”

Securonix also announced that has added product engineering leadership from companies including Amazon, Microsoft and IBM.

“Securonix has experienced unprecedented market traction by allowing customers to cut the cord on traditional security monitoring and leverage the cloud-based SaaS model of the Securonix Next-Gen SIEM platform,” said Dave Colesante, COO of Securonix. “In order to capitalise on recent success and take the next step in our company lifecycle, we must continue to enhance our offerings with the best people, process and technology.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Universities Face Increase in Ransomware Attacks as Students Return

Universities Face Increase in Ransomware Attacks as Students Return

Academia has faced fresh warnings of cyber-attacks after a rise was recorded in August when students returned.

According to an alert issued by the National Cyber Security Centre (NCSC) there has been a recent spike in ransomware attacks against UK schools, colleges and universities. It claimed that, in recent incidents, it has observed remote desktop protocols and unpatched software and hardware being utilized, as well as attackers using phishing emails to deploy ransomware.

Attackers have also sabotaged backup or auditing devices to make recovery more difficult, encrypted entire virtual servers and used scripting environments (including PowerShell) to deploy tooling or ransomware.

Paul Chichester, director of operations at the NCSC, called the targeting of the education sector “utterly reprehensible” at such a challenging time.

“While these have been isolated incidents, I would strongly urge all academic institutions to take heed of our alert and put in place the steps we suggest, to help ensure young people are able to return to education undisrupted,” he said. ““We are absolutely committed to ensuring UK academia is as safe as possible from cyber-threats, and will not hesitate to act when that threat evolves.”

David Corke, director of education and skills policy at the Association of Colleges, said: “As the last six months have shown us, it has never been more important for colleges to have the right digital infrastructure in order to be able to protect their systems and keep learning happening, whatever the circumstance.”

Corke called for a “whole college approach and for a focus wider than just systems” to include supporting leaders, teachers and students to recognize threats, mitigate against them and act decisively when something goes wrong.

The NCSC recommended a number of actions to better disrupt ransomware attacks, such as having effective vulnerability management and patching procedures, secure remote desktop protocols with multi-factor authentication, enabling anti-virus and phishing preventions.

Dr Jamie Collier, intelligence analyst at Mandiant Threat Intelligence, said the influx of attacks against universities at the beginning of term “is indicative of threat actors’ ultimate aim with ransomware attacks – to maximize leverage and increase the chance of being paid.”

Collier said the start of term is a critical time for universities trying to onboard students, and their IT infrastructure being held to ransom will cause major operational issues, especially this year. “The issue for universities is compounded by the fact that they have a large and complicated network – which has to account for many departments, students using their own devices and sophisticated computing systems for research – making it difficult to enforce blanket security controls,” he said.

“The attack surface is large and constantly evolving, which means there are more opportunities for attackers to exploit it. Moreover, the data universities hold, including valuable or sensitive research and intellectual property, as well as thousands of students’ personal information, means that there is a lot at stake.”

He echoed the NCSC’s recommendations on patching and authentication, and also recommended universities use threat intelligence to identify the most likely ransomware attacks they will face to put the correct protection measures in place.

Collier said: “Ransomware groups are increasing and diversifying, which is why we are seeing more attacks. Only by identifying the techniques and methods of the most likely ransomware families for their region or the types of data they hold can universities be better prepared for the attacks they may face.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DDoS Attacks Hit 1 Tbps in 2020

DDoS Attacks Hit 1 Tbps in 2020

There has been a 151% increase in the number of DDoS attacks in the first half of 2020, compared to the same period in 2019.

According to Neustar’s latest CyberThreats and Trends Report, these attacks include the largest that Neustar has ever mitigated at 1.17 Tbps.

As reports of the number of detected DDoS attacks increase, Neustar said the number of attacks sized 100 Gbps and above grew by 275%, and the number of “small attacks,” sized 5 Gbps and below, increased by more than 200%. These small 5 Gbps and below attacks represented 70% of all attacks mitigated by Neustar between January and June 2020.

Michael Kaczmarek, Neustar vice-president of security products, said: “These shifts put every organization with an internet presence at risk of a DDoS attack – a threat that is particularly critical with global workforces reliant on VPNs for remote login. VPN servers are often left vulnerable, making it simple for cyber-criminals to take an entire workforce offline with a targeted DDoS attack.” 

There was also evidence of 52% of mitigated threats leveraging three vectors or more, with the number of attacks featuring a single vector essentially non-existent. Neustar tracked new amplification methods and attacks of higher intensity targeted at critical pieces of web infrastructure. The previous high-water mark of 500 millions-of-packets-per-second (Mpps) was topped this year, with an attack of over 800 Mpps recorded.

In an email to Infosecurity, Rory Duncan, security GtM Leader at NTT Ltd, said: “DDoS attacks are increasing in size partly because it is easier: cyber-criminals are now able to compromise more end points with commercialized DDoS services. In addition, organizations have more capacity than ever before to “absorb” or mitigate DDoS attacks, which means that basic volumetric DDoS attacks need to be bigger to overwhelm defenses. In response, our adversaries are also constantly evolving their techniques – and automation is a tool used on both sides of the battle.”

Duncan recommended utilizing incident response and digital forensics capabilities when hit by a DDoS attack, as “having awareness of whether the organization’s infrastructure is compromised and contributing to the botnets that are launching the DDoS attacks is key.” That forensic investigation will involve reviewing and monitoring what every endpoint is doing.

“DDoS attacks can cripple employee productivity, damage brand reputation and eat into sales and profits,” he said. “DDoS protection is therefore an insurance policy against this worst-case scenario. It can be a significant investment with plenty of variables — so it pays for an organization to plan ahead to find the right option. We recommend a hybrid approach which combines on-premise inline devices, to protect against application layer attacks and signal to the cloud if a volumetric attack is detected and cloud-based scrubbing solutions which allow sanitized business traffic to pass.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#GartnerSEC: How Midsized Enterprises Can Recover from Ransomware

#GartnerSEC: How Midsized Enterprises Can Recover from Ransomware

A ransomware attack need not be tragic for midsized enterprises.

That is according to Paul Furtado, senior director, midsized enterprise security at Gartner, speaking  at the Gartner Security and Risk Virtual Summit. He said a midsized enterprise is defined as a company with up to 1001 employees, with revenues of $50m to $1bn. Furtado said these businesses typically have an IT budget of less than $20m, and under three people working in IT with no cybersecurity leader.

Furtado explained the issue of ransomware is continuing to be a problem as costs go up, and ransomware can sit dormant on your network for around three days and often executes outside of working hours. In terms of what businesses can do, Furtado said ransomware can be handled in the same way as malware, as it comes into the network in the same way, propagates in the same “and we can defend against it in the same way.”

Looking at steps for ransomware response, Furtado recommended the following:

  • Isolate the System(s) – Unplug but do not power it down, as you may need the device, but make sure it cannot connect to other devices on the network
  • Identify Port of Entry – Identify how it got in, and close that method, so it is not moving around
  • Prepare a New Device From Image – Do a restore from a gold standard image, you don’t want to risk something sitting on the system that you may miss
  • Scan Backups to Ensure No Infection – Scan backups so ransomware is not part of the backup set
  • Restore Files to a Time Prior to Infection
  • Investigate all Systems in Contact with the Impacted Resource – What other devices did that machine connect to, as we need to go through exercise on all devices
  • Conduct a Post-Incident Review – This is not about a pass or fail, but identifying gaps and how you can tackle the problem, and what you can do to further improve your security moving forward

Furtado also recommended keeping third parties close for when this does happen, as you will need guidance from legal counsel and bring them in early in the discussion. He also recommended bringing in a managed security services provider or a managed detection partner as part of your security team, as they can help contain and minimize the impact.

He also recommended keeping incident response partners, a cyber insurance provider and law enforcement informed too.

“Keep in mind ransomware prevention is both doable, and manageable, yes it is scary, but you can handle it,” he said. “Stick to doing the fundamentals well and it is very important to go back and not over complicate the process, do the basics right.”

Commenting on the debate on if a ransom should be paid or not, Furtado said it is up to the company, and it depends on your ability and the impact to the business, and to pay and get the decryption key or to try and recover from backups. “When you do pay, there is no guarantee you’re going to get all of your data back,” he warned. “Also, you’ll be a target for future attacks, and keep in mind any cryptocurrency transaction you do is part of public record.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Former Aussie PM’s Passport Details and Phone Number Obtained by Hacker Following Social Media Post

Former Aussie PM’s Passport Details and Phone Number Obtained by Hacker Following Social Media Post

Former Australian Prime Minister Tony Abbott’s passport details and personal phone number were obtained by a hacker, it has been reported.

Writing on his personal blog, Australian hacker Alex Hope outlined that he was able to gain this sensitive information after Abbott posted a picture of his boarding pass back in March 2020 on the social media site Instagram. Hope said he was able to log in to Abbott’s online booking page with Australia’s national airline carrier Qantus, by typing in the reference number displayed on the boarding pass.

He then gained Abbott’s passport and phone number, as well as staff comments about the former Prime Minister’s seat requests, by using the page’s HTML code. 

However, Hope did not reveal these details, and instead took steps to firstly inform the Australian government of what he had done and then Qantus regarding the flaw on the booking page that enabled these details to be accessed. Following initial correspondence, the latter informed Hope five months later that the bug in question had been fixed.

Hope was eventually also able to contact Abbott’s staff, who informed him that they were aware of the situation and were in the process of getting a new passport for the former PM.

Abbott himself, who has recently been appointed as an official UK trade advisor, then phoned Hope to discuss the incident, requesting more information about how it occurred.

Quoted in The Guardian, a spokesman for Abbott said: “Mr Hope brought this to the attention of relevant bodies earlier this year, and it has since been resolved.”

Commenting on the story, Jake Moore, cybersecurity specialist at ESET, said: “Few people realize the dangers of photographing seemingly innocuous information such as plane tickets and then posting it on social networks. Yet, as we have seen here, the internet can easily carve up personal details after a little trawling. Many airlines now require information such as a username and password to obtain more personal details, but there are still a number of providers where only the ticket reference from the boarding pass is needed to unravel the more private details on anyone who flies with them.

“Many people now live their whole lives through social media and give little thought to the consequences of what might happen should personal data get into the wrong hands. We need to educate those users and remind them to think twice when posting sensitive information. Furthermore, information that seems trivial to them could just be the missing piece in the jigsaw to a cyber-criminal.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk