New Jersey Keylogger Hacker Jailed

New Jersey Keylogger Hacker Jailed

A New Jersey man who physically installed keyloggers onto the computer networks of his rivals to steal trade secrets has been sent to prison for nearly eight years. 

Ankur Agarwal, of Montville, pleaded guilty to two counts of obtaining information from computers and one count of aggravated identity theft in federal court in Newark back in October 2019. The 45-year-old admitted stealing 15,000 files relating to emerging technology from two different companies. 

According to court documents, Agarwal trespassed on the New Jersey premises of a Texas-based tech company in February 2017. The cyber-criminal then illegally installed hardware keylogger devices on the company’s computers to capture the keystrokes of its employees.

From the data provided by the keyloggers, Agarwal was able to extract the usernames and passwords of the employees and gain access to the company’s computer system. 

Once inside the company’s network, Agarwal installed his personal computer and a hard drive. Prosecutors said that Agarwal then stole data relating to the development of an emerging technology from the company’s computers.

To exfiltrate the data, Agarwal used a computer code that he had made specifically for that purpose. He executed the exfil script against multiple computers and on more than one occasion. 

Agarwal confessed to hacking into a second company based in New York. He was able to enter the company’s premises in New Jersey after fraudulently creating an access card for himself.

The Justice Department said: “This fraudulently obtained access badge, bearing another individual’s name, allowed Agarwal to physically trespass onto Company Two’s premises.”

While trespassing at the second company, Agarwal again targeted data relating to emerging technology and stole it. His criminal activities were detected by employees at the company in April 2018.

On September 1, 2020, US District Judge Susan Wigenton sentenced Agarwal to 94 months behind bars. He was further sentenced to three years of supervised release and ordered to pay a fine of $25,000.

Agarwal consented to a forfeiture judgment that required him to forfeit his computers, storage devices, and related equipment.

US Attorney Craig Carpenito credited special agents of the FBI’s Cyber Division with the investigation that lead to the conviction of Agarwal.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

St. Louis County Fends Off Cyber-Attack

St. Louis County Fends Off Cyber-Attack

An attempt to infect a Missouri county’s website with malware has been foiled. 

Threat actors deployed Trojan horse malware in an attempt to gain access to the website of St. Louis County earlier this month. 

Staff in the IT department took down the county website on September 1 after detecting multiple attacks on the county’s server. 

Recently appointed IT director Charles Henderson said on Monday that the unsuccessful attack had been an attempt to take control of the website. According to Henderson, none of the county’s data was compromised, lost, stolen, or corrupted as a result of the cyber-attack. 

Threat actors were observed mimicking legitimate traffic in an effort to exploit a vulnerability in the website’s management system. Henderson said the incident was a close call, with the attackers managing to bypass all but one of the county’s cyber-defenses.

“All that it would have taken is for a single Trojan to get past . . . and the server would have been compromised,” Henderson told the Saint Louis Dispatch.

Rather than risk the attackers penetrating that final layer of defense, Henderson’s team opted to take the site down and install a new site that was in development, ready to be launched in a few months’ time.

“We took the web server down for maintenance with the intent of closing the security vulnerability and bringing the site back up,” Henderson said. 

“After examining their attack method and the options available to us, we determined that we could not, with confidence, defend the server against further attacks and with only a single layer of defense available we recommended that we not bring the system back online.”

Operations in Camden County, Missouri, were disrupted in April this year following a “sophisticated encryption attack.” 

Elsewhere in the Show-Me State, around 360, 212 patients of Kansas City–based Saint Luke’s Foundation (SLF) were affected by the recent ransomware attack on Blackbaud, a third-party vendor.

public notice issued last month by Saint Luke’s stated that the cyber-criminal who carried out the ransomware attack removed a copy of SLF’s backup file for the purpose of extorting funds from Blackbaud.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CISA Issues Chinese Hacking Groups Warning

CISA Issues Chinese Hacking Groups Warning

US government agencies and private-sector companies have been warned to be on high alert for cyber-attacks by threat actors affiliated with the Chinese Ministry of State Security (MSS).

A joint security advisory on the cyber-threat was issued yesterday by the Cybersecurity and Infrastructure Security Agency (CISA) and the United States Department of Justice.

CISA said that it had observed MSS-affiliated cyber-threat actors “using publicly available information sources and common, well-known tactics, techniques, and procedures (TTPs) to target US Government agencies.” 

Publicly available information and open source exploit tools leveraged in the attacks have included China Chopper, Mimikatz, and Cobalt Strike.

The attacks have been going on for over a year, often targeting vulnerabilities in popular networking devices such as Microsoft Exchange email servers, Citrix and Pulse Secure VPN appliances, and F5 Big-IP load balancers.

CISA said that the best defense against the most frequently used attacks was to maintain a rigorous patching cycle. 

“If critical vulnerabilities remain unpatched, cyber threat actors can carry out attacks without the need to develop custom malware and exploits or use previously unknown vulnerabilities to target a network,” states the advisory.

Victims of the attacks described by CISA had usually neglected to take every possible step to protect their digital assets.

“In most cases, cyber operations are successful because misconfigurations and immature patch management programs allow actors to plan and execute attacks using existing vulnerabilities and known exploits,” read the advisory. 

“Widespread implementation of robust configuration and patch management programs would greatly increase network security.”

CISA added that companies that made an effort to stay up-to-date with their cybersecurity could reduce the speed and frequency of cyber-attacks “by forcing threat actors to dedicate time and funding to research unknown vulnerabilities and develop custom exploitation tools.”

According to a recent US Department of Justice indictment, MSS-affiliated actors have targeted various industries across the United States and other countries in a campaign that lasted over a decade. Industries affected by the attacks include the high-tech manufacturers of medical devices, civil and industrial engineering, business, education, gaming, solar energy, pharmaceuticals, and defense.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#GartnerSEC: Phased Passwordless Authentication Can Enhance Productivity and Security

#GartnerSEC: Phased Passwordless Authentication Can Enhance Productivity and Security

Passwordless authentication “is an aspiration and not necessarily a destination,” said David Mahdi, senior director analyst at Gartner during the Gartner Security and Risk Virtual Summit. This is because many organizations are still reliant on legacy technology that does not necessarily support passwordless authentication.

Nevertheless, a gradual move in this direction as new technologies like SAAS-based applications are rolled out is something that organizations should be looking at in order to reduce the risk of breaches occurring. Mahdi noted: “Bad actors keep going after passwords and it continues to be problematic,” adding that “in breach after breach, identity is being leveraged as one of the main surfaces to get in and target a vulnerability, or conduct attacks like phishing.”

The poor usability often associated with traditional passwords also “leads users to cut corners,” according to Mahdi.

So what alternatives should organizations look to introduce that offer greater usability and security?

In regard to single-factor options, Mahdi outlined the importance of ensuring such methods provide the same flexibility as usernames and passwords, which can be used on any device. One important method that can be used in this category are tokens: these include QR code scans via a mobile app, out of band SMS and FIDO2 security keys. “These tokens are handy in that they are portable, so whether it’s contactless or the right USB interface, I can interface to the multiple devices I have and under the hood it’s using public key cryptography to achieve that authentication and security,” explained Mahdi.

Biometric authentication technology has grown in significance over recent years, ranging from face, to voice and retina scanning. Mahdi highlighted that attempts are ongoing to enhance the convenience of this form of authentication further, such as ensuring it can work even when part of your face is covered. “Certainly biometric methods have really increased and they’re quite ubiquitous,” he added. “They will help in that fight against passwords – they really are an enabling mechanism.”

There are also a number of multi-factorial authentication (MFA) options that organizations should be considering, which are particularly secure but continue to provide usability. A major type is PIN protected and biometric-enabled smart cards, often utilized across highly sensitive organizations like government departments. “These cards really bring together what you have, because of the card, what you know, because of the PIN, and sometimes you can have biometrics tied in, so what you are as well,” said Mahdi.

Finally, Mahdi discussed zero-factor alternatives, which are based on multiple recognition signals that people use such as geo-location, instead of requesting that a user actively does something. He commented: “These can be really passive and can help in balancing usability and security.”

While not impenetrable, Mahdi believes these passwordless forms of authentication have the potential to substantially enhance security and productivity in organizations in the future. “If employees can access their services faster with higher security, it means they’ll be able to access more content, more services and do it in a very effective and seamless way,” he concluded.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#GartnerSEC: #COVID19 Created New Roles, More Data Collection and Flexible Businesses

#GartnerSEC: #COVID19 Created New Roles, More Data Collection and Flexible Businesses

The impact of the COVID-19 pandemic has led to uncertainly and anxiety in society, but also sweeping changes in the way businesses operate and plan for the future.

Speaking during the Gartner Security and Risk Virtual Summit, research VP Roberta Witty called the impact of COVID-19 life changing and stated it has pushed resilience to be a board-level discussion, acting as  “an industry refresh to reshape business for at least the next decade.”

Witty said that many organizations did not have the time to undertake due diligence for the rapid transition, and supply chain was impacted “as China shut down for a few months” and employees reported being stressed, tired and anxious. “Business leaders need to respond rapidly to ensure their organizations remain secure and resilient,” she said.

Citing Gartner research, Witty said 73% of board of directors considered economic slowdown as the top threat shaping their business strategy, but the focus has shifted to resilience, providing essential services that the business requires and “coping with the unexpected in how we work and deliver our products and services.”

She explained that resilience must be at the heart of any project, as “we are in this for the long haul” and this can be achieved by understanding where you are. “Many [businesses] were prepared for traditional business disruption, but few were prepared for a crisis of a global scale lasting months if not years,” Witty said. “We’re living our lives and running businesses with the pandemic all around us, impacting everything we do.”

Adding that “business continuity management is at the heart of every resilience program,” Witty said the biggest change Gartner sees is organizations realizing that monitoring risk and managing operations on day to day basis “must be tightly coupled with crisis planning.”

Among the changes being made, Witty said decisions that would have taken months are now being done in an afternoon, as organizations are “flatter and faster” and layers of the business are compressed. She also said more critical roles are being developed and “work being reworked” as more agile teams are launched and talent reallocated.

“We’re also seeing a shift from design for efficiency to design for resilience,” which Witty said could be a challenge. “We’re also seeing more technology being used, the rapid move to remote work and collaboration tools that go along with that, plus the rapid deployment of digital systems to support these interactions has been substantial.”

Also, there is a growth in data collection in all areas of business “to make better strategic and operational decisions about our businesses.”

Witty also claimed the remote working trend will continue, as we see the emergence of new top tier employees, while the supply chain is pressure-tested and strengthened. “Lastly there will be an increase in organizational complexity over the next few months because of more mergers and acquisitions, nationalization and as big companies get bigger.”

Concluding, Witty said the pandemic has “shaken us personally and organizations to the core” and we need to decide if we lean into the change, or stay stuck in the past. “We cannot rely on the same old habits, so be creative and imaginative,” she said. “So what will you do to move the world forward, and how will you make changes to make someone else’s dreams come true?”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NCSC Launches New Vulnerability Reporting Toolkit

NCSC Launches New Vulnerability Reporting Toolkit

The UK’s National Cyber Security Centre (NCSC) has released a new Vulnerability Reporting Toolkit, designed to help organizations manage vulnerability disclosure in a streamlined, process-driven manner.

The government-backed GCHQ unit explained in a blog post yesterday that the new toolkit was built with knowledge distilled from two years of running the NCSC’s Vulnerability Co-ordination Pilot and Vulnerability Reporting Service.

It was built according to the three best practices of vulnerability disclosure: good communication, a clear policy and ease-of-use. On the latter, the NCSC advocated the proposed IETF standard security.txt, also supported by the US Department of Homeland Security and NZ CERT, as an easy way for individuals to find all the information they need. 

“The toolkit is not an all-encompassing answer to vulnerability disclosure, but it is a great start. If you don’t have a vulnerability disclosure process, then the toolkit can help you create one. We believe it’s worth establishing a process in advance (that is, before you need to create a process when responding to a vulnerability disclosure),” the NCSC’s “Ollie N” said.

“The toolkit is deliberately easy to implement, so you can adopt it at short notice. Even if you already have a process in place, please take a look at the toolkit as it may help you to improve on what you’ve already set up.”

As the first edition of the toolkit, the current iteration is designed to cover just the basics. However, over time it will be adapted to include details on how to build an internal process that can triage and fully manage a vulnerability disclosure.

The NCSC’s advice comes ahead of new IoT laws being drawn up by the government which will compel all manufacturers of consumer smart gadgets to run vulnerability disclosure programs.

Earlier this month, the US Cybersecurity and Infrastructure Security Agency (CISA) issued new requirements for all government agencies to develop and publish vulnerability disclosure policies (VDPs).

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#GartnerSEC: Five Steps to Ensuring Board Engagement

#GartnerSEC: Five Steps to Ensuring Board Engagement

Security professionals are still making a poor job of getting business leaders to understand strategies.

Speaking during the Gartner Security and Risk Virtual Summit, VP analyst Jeffrey Wheatman claimed security professionals are “fighting a battle with ourselves and our business stakeholders” as security does a poor job of articulating strategies and getting stakeholders to understand “why the things we do are important.”

He claimed that even during the COVID-19 pandemic, this is still the case, and security needs to know how to take steps to create a cybersecurity strategy that resonates with stakeholders. He also claimed that everyone is seeking to create a one-page strategy, which management understand but which does resonate with the technical team, or the strategy can be more technical and granular, where technology team knows what to do, but the management team does not.

“Clearly we need to figure out how we can bring these two extremes together and articulate what we are doing and why; to tell a simple story,” he said. Wheatman said this involves five steps:

  • Start with your business goals
  • Identify your risks
  • Make the risks real
  • Articulate the program objectives
  • Map strategy to tactics

As part of this, Wheatman recommended focusing on what the company does, what risks it faces and how they are addressed. “That construct is very important, this is not us in security, it is not you in the business, it is we working together to achieve a common set of goals and objectives,” he said.

He advised the best way to get company engagement is to focus on what business stakeholders care about, namely: growing revenue, managing costs, focusing on customer retention, growing the sales force, being number one in the market and being the best in class. “If you cannot use these, where can you get your business goals from? Look at the annual report executive summary of what the company is going to accomplish this year, what are the core values and initiatives?” he said. “Essentially, this is what the board and C-level executives get measured on at the end of the year, so focus on those.”

To identify risks, Wheatman said a common question Gartner receives is “tell us what our risks are.” He said there may be commonality in your vertical, but “your risks are your risks” and so identify them by doing a risk assessment, focus on the executive summary, look for published reports, talk to your peers and ISAC, if you have one.

He also recommended keeping risks to between eight and 10, as many more will not be digestible and you’ll be shifting to threats and vulnerabilities.

Wheatman also recommended mapping your strategy to a framework which others use as this will give you a justification for expenditure.

“If you think about the five elements of the story, it is how we’re going to do it, how we’re going to invest, the time and human capital and tooling, here’s how we’re going to measure our success, and here’s the process for continuous improvement,” he said. “So think about these things as the next step, once you’ve gone through the initial five steps to build this out.”

He recommended linking back to business goals, particularly in growing revenue, and to link actions to goals. “You must target your audience and target what they care about and the things they are compensated on and measured on at the end of the year,” he concluded. “Identify your risks and make those risks real for your audience.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Data Breach Hits 46,000 US Veterans

Data Breach Hits 46,000 US Veterans

Tens of thousands of US veterans have had their personal information illegally accessed in a data breach incident announced on Monday.

The US Department of Veterans Affairs (VA) Office of Management revealed that 46,000 veterans had been affected by the incident.

“The Financial Services Center (FSC) determined one of its online applications was accessed by unauthorized users to divert payments to community health care providers for the medical treatment of veterans. The FSC took the application offline and reported the breach to VA’s Privacy Office,” it continued.

“A preliminary review indicates these unauthorized users gained access to the application to change financial information and divert payments from VA by using social engineering techniques and exploiting authentication protocols.”

The VA Office of IT is conducting a comprehensive security review before system access is allowed again, it added.

To protect these veterans, the FSC is alerting the affected individuals, including the next-of-kin of those who are deceased, of the potential risk to their personal information,” the statement concluded.

“The department is also offering access to credit monitoring services, at no cost, to those whose social security numbers may have been compromised.”

Thomas Richards, principal security consultant at Synopsys, argued that social engineering is a common tactic to gain unauthorized access to applications and systems.

“If, for business reasons, these applications must be public facing they should be secured with multi-factor authentication to prevent any compromised credentials from being used,” he added. “Organizations should also conduct regular assessments against their staff to raise awareness around social engineering threats, thus reducing the chance of a successful attack.”

Back in September last year, security researchers discovered a spoofed VA recruitment site crafted to deploy spyware on visitors’ computers.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Largest Ever Magecart Campaign Hits 2000 E-Stores

Largest Ever Magecart Campaign Hits 2000 E-Stores

Around 2000 e-commerce stores running the popular Magento software were attacked over the weekend, in the largest recorded campaign of its kind, according to researchers.

Sansec’s Threat Research Team warned that the 1904 Magecart attacks it detected targeted e-stores running the now out-of-date Magento version 1. A total of 10 stores were infected on Friday, followed by 1058 on Saturday, 603 on Sunday and 233 on Monday, it said.

The security firm estimates that tens of thousands of customers unwittingly had their payment details stolen over the weekend in the attacks.

“This automated campaign is by far the largest one that Sansec has identified since it started monitoring in 2015. The previous record was 962 hacked stores in a single day in July last year,” it added.

“The massive scope of this weekend’s incident illustrates increased sophistication and profitability of web skimming. Criminals have been increasingly automating their hacking operations to run web skimming schemes on as a many stores as possible.”

Sansec suggested that, as many of the sites had no previous history of security incidents, the attackers may have found a new way to compromise their servers — potentially exploiting a zero-day in Magento 1 that was advertised online.

The firm warned that, if this is the case, 95,000 stores could also be exposed to the exploit, as they’re running Magento 1 and no more patches are being produced by developer Adobe.

“Official PCI requirements are to use a malware and vulnerability scanner on the server, such as Sansec’s eComscan,” it said. “Sansec also recommends to subscribe to alternative Magento 1 patch support, such as provided by Mage One.”

Back in June, Sansec spotted a spate of new Magecart infections on e-commerce sites like Claire’s. It’s possible that those groups behind these digital skimming attacks feel there are rich pickings to be had as shoppers under lockdown flood online stores and IT teams struggle to support business-critical infrastructure, leaving security gaps to exploit.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Privacy Issues Found in Vote Joe App

Privacy Issues Found in Vote Joe App

Privacy issues have been detected in an official application of the Joe Biden campaign.

The Vote Joe app uses relational organizing to allow users to share data about themselves and their contacts with a voter database run by Target Smart, a service claiming to have over 191 million voter records.  

A user who syncs their contacts with the Vote Joe app will be presented with a corresponding voter entry from the Biden campaign’s voter database. The user’s contact data is then harvested and used to enrich the database entry. 

The App Analyst noted: “An issue occurs when the contact in the phone does not correspond with the voter, but the data continues to enrich the voter database entry. By adding fake contacts to the device, a user is able to sync these with real voters.” 

Commenting on the relational organizing employed by the app, Brandon Hoffman, CISO at Netenrich, said: “An influencer could easily just sync their phone loaded with a list of pre-planted fake social media ‘contacts’ and ‘profiles’ that will be used to further their information campaign.”

Anyone who signs up for the app with an unverified email can query the voter database using a first and last name, and state. The returned information includes which elections the voter has participated in with either a checkmark to signify their participation or an X to denote that they did not vote. 

The App Analyst found that more information about each individual voter was revealed in the voter-returned JSON (JavaScript Object Notation) object.

“The returned object appears to contain ‘Y’ to signify ‘Yes they voted,’ but there are other values such as ‘B’ and ‘R.’ These values may represent how Target Smart suspects the user voted, using an ‘R’ value to potentially represent ‘Red’ or ‘Republican’ and the ‘B’ value to represent ‘Blue’ or ‘Democrat,'” they wrote.

Additional voter data revealed included specific date of birth, “voterbase_id” (a value unique to Target Smart and not an official voter ID), and some Target Smart fields corresponding to the voter’s Senate, congressional, and House districts.

The app states: “We’ll let you know which of your friends and family members could use that extra touch to help make sure they vote in 2020.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk