Sentar Awarded $164m Cybersecurity Task Order by US Defense Health Agency

Sentar Awarded $164m Cybersecurity Task Order by US Defense Health Agency

Women-owned small business (WOSB) Sentar Inc. has been awarded a potential $164m task order to provide cybersecurity support to the Defense Health Agency.

Sentar announced yesterday that it had won the task order from the Naval Information Warfare Center (NIWC) to provide the Defense Health Agency (DHA) with cybersecurity risk management operations support (RMOPS) services. 

Under the terms of the contract, Sentar will support the DHA in efforts to protect military information technology platforms from cyber-threats. The company will also assist the DHA to address various cybersecurity initiatives, processes, and compliance requirements.

The newly awarded task order is the largest of its kind to be received by Sentar. If fully executed, this contract will extend the company’s support to the DHA through the next four years. 

Work under this contract will be conducted at NIWC Atlantic in Charleston, South Carolina, as well as at DHA facilities in San Antonio, Texas, the National Capital Region (NCR), and at many other Military Health System (MHS) locations around the world.

“We are incredibly excited to assist NIWC and the DHA under this effort,” said April Nadeau, Sentar’s senior vice president of Navy, Marine Corps, and Health IT. 

“This achievement would not have been possible without the hard work of our team. It’s an exciting time to be at Sentar!”

Under the new task order, Sentar will provide assistance to NIWC Atlantic in cybersecurity execution efforts across the MHS. The company’s efforts will impact military treatment facilities (MTFs), programs of record (PORs), and medical devices within locations both inside and outside the continental United States.

“Our enduring support to the DHA and its military services stands among our proudest engagements, both for the mission itself, and for those we get to work with and support in achieving its objectives,” commented Sentar’s vice president for health information technology, Joseph Sabin.

“With this latest award, we look forward to maintaining these relationships in addressing the challenges and opportunities to come.”

Sentar was founded in 1990 with a mission to provide advanced Intel and cybersecurity services and products. The company has offices in Huntsville, Alabama; Charleston, South Carolina; Columbia, Maryland; and San Antonio, Texas.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Governments Are Soft Targets for Cyber-criminals

Governments Are Soft Targets for Cyber-criminals

New research by AI-driven commercial insurance products provider Corvus has found that governments are more vulnerable to cyber-attacks than other organizations.

A report on the security of municipal governments and agencies identified three key factors that made governments particularly soft targets. Researchers found that governments had larger attack surfaces, lower usage rates of even the most basic email authentication schemes, and much higher rates of internal hosting than other organizations.

Government attack surfaces, consisting of open ports and applications, were found to be on average 33% larger than those risked by other organizations. 

Researchers wrote: “Greater attack surface is harder to defend (due to sheer scale) and presents attackers with more opportunities for a range of different attack types.”

When compared to other organizations, governments were found to be more likely to use enhanced email security software but not as likely to protect themselves with basic email authentication schemes. On average, 15% of governments went for enhanced while 74% stuck with basic, compared to 12% and 80% of other organizations, respectively. 

Researchers noted that protecting the security of email “is an important step in preventing phishing exploits (the origin of 91% of all cyberattacks), and the majority of organizations of all types do not take it.”

Governments were found to be 350% more likely to host internally than other organizations, making them much more reliant on their in-house IT teams to keep security measures updated.

Staying on top of security is tough when your software is older than a US presidential candidate. Researchers found that 29% of governments are running older versions of software, which are more likely to harbor vulnerabilities.

“In general, we’d expect municipalities to have better security than average, given their size and scale,” wrote researchers, “but with more attack surface for potential exploits on vulnerable ports, lower usage rates of even the most basic email authentication schemes to protect against phishing, much higher rates of internal hosting (meaning it’s up to the often under-staffed and under-funded IT departments to keep up with security trends), and old software versions in use, governments are a soft target.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Iranian Phishers Use Journalist’s Identity to Steal Info

Iranian Phishers Use Journalist’s Identity to Steal Info

Security researchers have discovered a new phishing campaign from Iranian state-linked hackers which uses the lure of an interview with a noted journalist to trick recipients into clicking.

The latest operation is the work of the Charming Kitten group, which was identified by London security vendor Certfa through the servers and settings it used in previous attacks, alongside other techniques.

It’s primarily designed to harvest email account info from journalists and political and human rights activists, as well as information about their contacts and networks.

The campaign is notable for spoofing the identity of a former Wall Street Journal writer, Farnaz Fassihi, to set up a non-existent interview with the recipient. However, the phishers made a glaring mistake: Fassihi is now at the New York Times, rendering the WSJ masthead on the email more than a little incongruous. The email also comes from a Gmail account.

The attackers use shortened links to legitimate sources in the footnotes of the email, enabling them to gain valuable basic information about the victim’s device, including IP address, type of operating system and browser.

“After communication and relative trust are established through the initial email, hackers send their victim an exclusive link as a file that contains the interview questions. According to our samples, Charming Kitten has been using a page that is hosted on Google Sites,” Certfa explained.

“This method is a relatively new tactic that has been widely used in phishing attacks by hackers in the past year in order to make the targets trust the destination domain. After clicking the download button on the Google Site page the target is sent to another fake page in two-step-checkup site domain where login credential details of his/her email such as the password and two-factor authentication (2FA) code are requested by phishing kits.”

The researchers also uncovered a new piece of backdoor malware, pdfreader.exe, which changes Windows’ Firewall and Registry settings to run automatically, gather device information and run new malware remotely on the machine.

Stay up-to-date with the latest information security trends and topics by registering for Infosecurity Magazine’s next Online Summit. Find out more here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

90% of UK Data Breaches Due to Human Error in 2019

90% of UK Data Breaches Due to Human Error in 2019

Human error caused 90% of cyber data breaches in 2019, according to a CybSafe analysis of data from the UK Information Commissioner’s Office (ICO).

According to the cybersecurity awareness and data analysis firm, nine out of 10 of the 2376 cyber-breaches reported to the ICO last year were caused by mistakes made by end-users. This marked an increase from the previous two years, when respectively, 61% and 87% of cyber-breaches were ascribed to user error.

CybSafe cited phishing as the primary cause of breaches in 2019, accounting for 45% of all reports to the ICO. ‘Unauthorized access’ was the next most common cause of cyber-breaches in 2019, with reports relating to malware or ransomware, hardware/software misconfiguration and brute force password attacks also noted.

Oz Alashe, CEO of CybSafe, said: “As this analysis shows, it’s almost always human error that enables attackers to access encrypted channels and sensitive information. Staff can make a variety of mistakes that put their company’s data or systems at risk, often because they lack the knowledge or motivation to act securely, or simply because they accidentally slip up.”

However, Alashe was quick to argue that the statistics should not provoke a negative reaction.

“Employees of course pose a certain level of cyber-risk to their employers, as seen in our findings thus far. Nevertheless, people also have an important role to play in helping to protect the companies they work for, and human cyber-risk can almost always be significantly reduced by encouraging changes in staff cyber-awareness, behavior and culture.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft: We Detect 77,000 Web Shells Each Month

Microsoft: We Detect 77,000 Web Shells Each Month

Microsoft has warned that inadequate security on web applications and internet-facing servers is allowing hackers to use web shells in their tens of thousands each month to launch attacks.

Web shells are pieces of malicious code typically implanted onto web servers to execute commands, steal data and help hackers launch additional raids on the victim organization, such as watering hole attacks.

Microsoft claimed in a new blog this week that thanks to poor IT security hygiene, the use of these tools is rocketing: the tech giant detects around 77,000 each month on an average of 46,000 machines.

“Aside from exploiting vulnerabilities in web applications or web servers, attackers take advantage of other weaknesses in internet-facing servers. These include the lack of the latest security updates, anti-virus tools, network protection, proper security configuration and informed security monitoring,” it continued.

“Interestingly, we observed that attacks usually occur on weekends or during off-hours, when attacks are likely not immediately spotted and responded to.”

Multi-layered protection is needed to mitigate the threat of web shells, beginning with gaining visibility into internet-facing servers by monitoring web application directories for web script file writes, the firm advised.

Regular audits of web server logs, prompt patching, intrusion prevention to stop C&C communications, limiting privileged accounts and closing non-standard ports can also help, said Microsoft.

Ilia Kolochenko, founder & CEO of web security company ImmuniWeb, explained that web shells have existed for over a decade and are often automated by hackers, but finding them should not be difficult.

“Usually, once a web shell is uploaded, it is fairly simple to root the server by exploiting unpatched vulnerabilities or its insecure configuration,” he added.

“Detection of web shells is a fairly routine operation, moreover, such attacks are usually attributable to junior hackers unskilled or careless enough to upload a web shell without obfuscation and proper removal after backdooring the server.”

Stay up-to-date with the latest information security trends and topics by registering for Infosecurity Magazine’s next Online Summit. Find out more here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Twitter Confirms it Will Only Ban “Harmful” Deepfakes

Twitter Confirms it Will Only Ban “Harmful” Deepfakes

Twitter has become the latest major social platform to articulate its deepfake policy, claiming it will remove “manipulated media” only if it causes harm.

In a blog post earlier this week, head of site integrity, Yoel Roth, and group product manager, Ashita Achuthan, explained that the site’s new policy was distilled from responses to its draft rule by academics, civil society and thousands of Twitter users.

The new rule is that if synthetic or manipulated content like deepfakes is deliberately intended to deceive users then it will be clearly labelled. If it’s also deemed likely to cause harm then it is “very likely” to be removed.

By harm, Twitter means threats to physical safety, the risk of mass violence or civil unrest, and threats to privacy or free expression of an individual or group. This includes voter suppression or intimidation, but it doesn’t mention attempts to influence voters in other ways.

Twitter said it “may” also remove manipulated content that causes harm but has not been shared in a manner intended to deceive.

The firm added that it might also show a warning to users before they retweet such content, reduce its visibility on Twitter and/or prevent it from being recommended, and provide a landing page with more context.

Twitter’s policy would, at first sight, appear more liberal than Facebook, which earlier this year effectively stated its intent to ban any deepfake content designed to mislead users, whether it’s harmful or not.

YouTube also recently reminded users that any deepfakes related to the upcoming US Presidential elections would be banned from the site.

The challenge for such platforms is that their attempts to police such content at present are largely reactive in nature, and that harm can still be done to candidates if a deepfake goes viral, even if it is subsequently removed and confirmed as a hoax.

Stay up-to-date with the latest information security trends and topics by registering for Infosecurity Magazine’s next Online Summit. Find out more here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk