—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Author: admin
Critical Cisco Contact Center Bug Threatens Customer-Service Havoc
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
‘Be Afraid:’ Massive Cyberattack Downs Ukrainian Gov’t Sites
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Russian Security Takes Down REvil Ransomware Gang
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Three Plugins with Same Bug Put 84K WordPress Sites at Risk
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
DigiCert Acquires Mocana
DigiCert Acquires Mocana

American technology company DigiCert has announced the acquisition of Mocana, a cybersecurity firm based in California.
Mocana was founded in 2002 and is headquartered in Sunnyvale. The focus of the company is on embedded system security for industrial control systems and the internet of things (IoT).
DigiCert said the acquisition will allow it to offer an end-to-end IoT platform and provide customers with a way to manage device identity, secure connections, prevent device tampering, and update firmware and settings remotely and securely.
“IoT security has been a challenge for device manufactures and operators,” said DigiCert chief executive officer John Merrill.
“With the addition of Mocana, DigiCert is building on its vision for delivering digital trust, a growing necessity in the IoT market as smart devices become ubiquitous in every corner of our personal and professional lives.”
The deal was executed with the backing of Clearlake Capital Group, Crosspoint Capital, and TA Associates. The financial terms of the transaction were not disclosed.
Mocana’s chief technology officer, Srinivas Kumar, said his colleagues are excited to be joining the DigiCert team.
He added: “Together, our solutions uniquely solve the challenges of IoT security, from embedding security protections on-chip or at device manufacturing to on-device secure communications and firmware updates once in the field.”
Mocana’s list of clients includes ABB Ltd., Ciena Corp, Citrix Systems Inc., Eaton Corp. PLC, General Atomics, General Electric Company, HP Inc., International Business Machines Corp., Lenovo Group Ltd., Schneider Electric SE, Siemens AG, and VMware Inc.
Mocana hit the headlines in August 2020 when the company won a $1.5m contract to provide cybersecurity support to the United States Air Force (USAF). Under the Phase II Small Business Innovation Research (SBIR) contract, Mocana agreed to work with USAF to deliver advanced cyber-protection for military systems, establishing end-to-end digital supply chain security.
DigiCert specializes in authorizing and issuing TLS/SSL (transport layer security/secure sockets layer) certificates, public key infrastructure (PKI), and IoT security and digital trust solutions.
Four years ago, Symantec’s SSL certificate authority was purchased by DigiCert for $950m.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Flaw Found in Biometric ID Devices
Flaw Found in Biometric ID Devices

A critical vulnerability has been discovered in more than ten devices that use biometric identification to control access to protected areas.
The flaw can be exploited to unlock doors and open turnstiles, giving attackers a way to bypass biometric ID checks and physically enter controlled spaces. Acting remotely, threat actors could use the vulnerability to run commands without authentication to unlock a door or turnstile or trigger a terminal reboot so as to cause a denial of service.
Positive Technologies researchers Natalya Tlyapova, Sergey Fedonin, Vladimir Kononovich, and Vyacheslav Moskvin found the flaw, which impacts 11 biometric identification devices made by IDEMIA.
The team said that the impacted devices are in use in the “world’s largest financial institutions, universities, healthcare organizations, and critical infrastructure facilities.”
The critical vulnerability (VU-2021-004) has received a score of 9.1 out of 10 on the CVSS v3 scale, with 10 being the most severe.
“The vulnerability has been identified in several lines of biometric readers for the IDEMIA ACS [access control system] equipped with fingerprint scanners and combined devices that analyze fingerprints and vein patterns,” said Vladimir Nazarov, head of ICS Security at Positive Technologies.
He added: “An attacker can potentially exploit the flaw to enter a protected area or disable access control systems.”
The IDEMIA devices affected by the vulnerability are MorphoWave Compact MD, MorphoWave Compact MDPI, MorphoWave Compact MDPI-M, VisionPass MD, VisionPass MDPI, VisionPass MDPI-M, SIGMA Lite (all versions), SIGMA Lite+ (all versions), SIGMA Wide (all versions), SIGMA Extreme, and MA VP MD.
Enabling and correctly configuring the TLS protocol according to Section 7 of the IDEMIA Secure Installation Guidelines will eliminate the vulnerability.
IDEMIA has said it will make TLS activation mandatory by default in future firmware versions.
This isn’t the first time Positive Technologies researchers have discovered a flaw in IDEMIA devices. In July 2021, IDEMIA fixed three buffer overflow and path traversal vulnerabilities identified by the cybersecurity company’s team.
Under certain conditions, these prior vulnerabilities allowed an attacker to execute code, or to gain read and write access to any file from the device. IDEMIA released firmware updates to mitigate the security vulnerabilities.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Ukrainian Government Websites Forced Offline in “Massive” Cyber-Attack
Ukrainian Government Websites Forced Offline in “Massive” Cyber-Attack

Ukraine has been hit by a “massive” cyber-attack, forcing more than a dozen government websites offline, it has been reported today.
The attack, which also targeted the UK, US and Swedish embassies in Ukraine, is suspected to have been perpetrated by Russian threat actors amid significant tensions between the two nations.
The websites taken offline include the Ukrainian ministry of foreign affairs and the education ministry. Before going down, a sinister message appeared stating: “Ukrainians! … All information about you has become public. Be afraid and expect worse. It’s your past, present and future.”
The message also reproduced the Ukrainian flag and map crossed out and referenced “historical land.” This appeared in three languages: Ukrainian, Russian and Polish.
The Guardian quoted the Ukrainian foreign ministry’s spokesperson, Oleg Nikolenko, who said: “As a result of a massive cyber-attack, the website of the ministry of foreign affairs and other government agencies are temporarily down.
“Our specialists have already started restoring the work of IT systems, and the cyber-police has opened an investigation.”
Ukraine’s SBU security service said that no personal data was leaked in the attack.
The incident has come amid heightened tensions in the region, with the Kremlin demanding assurances that Ukraine will not join Nato. Russia has deployed 100,000 troops to the border with Ukraine.
The EU’s top diplomat, Josep Borrell, condemned the attacks, stating: “We are going to mobilize all our resources to help Ukraine to tackle this. Sadly, we knew it could happen.”
He added: “I can’t blame anybody as I have no proof. But we can imagine.”
Commenting on the story, Anthony Gilbert, cyber threat intelligence lead at Bridewell Consulting, said: “At the moment it’s unclear how the attack occurred or who is behind it, but given the current situation, it’s highly likely it was politically charged as there appears to be no financial motivation. The attackers probably wanted to give a warning or ignite civil unrest and spread further undercurrents of no confidence in the government.”
Toby Lewis, global head of threat analysis at Darktrace, said it was too early to jump to conclusions about the nature of the attack and its perpetrators. “We should be cautious around labeling this as a ‘sophisticated’ attack. Some cyber-attacks are more successful than others; some are advanced and others less so. A distributed denial of service (DDoS) attack, for example, which is an attempt to bring down websites or networks by overwhelming the webserver with internet traffic, is not particularly sophisticated and relatively easy to mitigate.
“Some of the website defacements, such as those left on the education website and the ministry of foreign affairs, are designed to mimic ‘nationalist/separatist groups’ with claims that the attack was done in the name of the UPA (Ukrainian Separatist Army), which has not existed for over 50 years. Attribution is impossible to do with digital data alone, and it is not unlikely that this is a false flag to divert attention away from the true perpetrators, to stir up unrest or simply impact the credibility of the website owners.”
Russia has previously been blamed for cyber-attacks on Ukraine in recent years. These include attacks in 2015 and 2016 that took out large parts of the country’s power grids.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
North Korean Hackers Stole $400m in Cryptocurrency Last Year
North Korean Hackers Stole $400m in Cryptocurrency Last Year

North Korean cyber-criminals stole nearly $400m worth of cryptocurrency in 2021, according to a new report by blockchain analysis firm Chainalysis.
The researchers said hackers from the rogue state extracted the funds following at least seven attacks on cryptocurrency platforms, primarily targeting investment firms and centralized exchanges. This represents a significant rise from four hacks recorded in 2020, with the value extracted from heists in 2021 up by 40%.
According to the study, the attackers used various techniques to siphon the funds out of the victims’ internet-controlled “hot” wallets into Democratic People’s Republic of Korea (DPRK)-controlled addresses. These included phishing lures, code exploits, malware and advanced social engineering.
“Once North Korea gained custody of the funds, they began a careful laundering process to cover up and cash out,” stated the report.
The researchers added that it is likely many of these hacks were carried out by the notorious Lazarus Group (APT 38), which is led by North Korea’s main intelligence agency, Reconnaissance General Bureau. Lazarus has been blamed for high-profile attacks in recent years, including Wannacry. However, the authors observed that since 2018, the group has focused its efforts on cryptocurrency crime, “a strategy that has proven immensely profitable.”
Indeed, North Korean hackers have been linked to a number of major crypto heists in recent years, and a report last year by Venafi found that cybercrime is now the primary means by which the authoritarian state is funded.
Interestingly, the report noted that Bitcoin represented just 20% of the stolen funds last year, with Ether accounting for the majority (58%) and ERC-20 tokens or altcoins making up 22%.
Chainalysis also revealed that it has identified $170m worth of stolen cryptocurrency controlled by the East Asian state, which has yet to be laundered. This is a result of separate hacks spanning from 2017-2021.
Commenting, Erich Kron, security awareness advocate at KnowBe4, said: “Cryptocurrency is a heavily targeted sector when it comes to cybercrime due to the decentralized nature of the currencies and the fact that, unlike with credit card or bank transfers, the transaction happens quickly and is impossible to reverse. Nation-states, especially those under strict tariffs or other financial restrictions, can benefit greatly by stealing and manipulating cryptocurrency. Many times, a cryptocurrency wallet can contain multiple types of cryptocurrency, making them a very appealing target.”
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
AWS Patches Glue Bug That Put Customer Data at Risk
AWS Patches Glue Bug That Put Customer Data at Risk

Researchers have discovered a critical vulnerability in the AWS Glue service, which could allow remote attackers to access sensitive data owned by large numbers of customers.
Dubbed “Superglue” by the Orca Security Research Team, the bug was made possible by an internal misconfiguration within the service.
AWS Glue is a serverless data integration service that allows customers to discover and combine data for machine learning, analytics and app development. Given that it can access large volumes of potentially sensitive data, it could be an attractive target for hackers.
“During our research, we were able to identify a feature in AWS Glue that could be exploited to obtain credentials to a role within the AWS service’s own account, which provided us full access to the internal service API,” Orca Security explained.
“In combination with an internal misconfiguration in the Glue internal service API, we were able to further escalate privileges within the account to the point where we had unrestricted access to all resources for the service in the region, including full administrative privileges.”
The vendor claimed to have been able to assume roles in AWS customer accounts that are trusted by Glue and query and modify AWS Glue service-related resources in a region. These included Glue jobs, dev endpoints, workflows, crawlers and triggers.
The research team was at pains to point out that it only used its own accounts for this project and that no AWS Glue customers were compromised as a result.
AWS worked swiftly with the team to fix the problem.
“Today, Orca Security, a valued AWS partner, helped us detect and mitigate a misconfiguration before it could impact any customers,” explained AWS principal engineer Anthony Virtuoso.
“We greatly appreciate their talent and vigilance, and we would like to thank them for the shared passion of protecting AWS customers through their findings.”
The same research team revealed a second vulnerability in AWS this week dubbed “BreakingFormation.”
Also now fixed by AWS, this zero-day bug could have allowed attackers to leak sensitive files on targeted service machines and grab credentials related to internal AWS infrastructure services.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains