More Log4j News

Log4j is being exploited by all sorts of attackers, all over the Internet:

At that point it was reported that there were over 100 attempts to exploit the vulnerability every minute. “Since we started to implement our protection we prevented over 1,272,000 attempts to allocate the vulnerability, over 46% of those attempts were made by known malicious groups,” said cybersecurity company Check Point.

And according to Check Point, attackers have now attempted to exploit the flaw on over 40% of global networks.

And a second vulnerability was found, in the patch for the first vulnerability. This is likely not to be the last.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Privacy, Identity, and Device Protection: Why You Need to Invest in All Three

Cybercriminals make people uneasy about the safety of their identity and online accounts. McAfee is your partner who’ll work tirelessly to restore your confidence in your online activities. Check out this roundup of privacy protection, identity protection, and device security best practices to boost your confidence in the safety of your personal information and technology. 

Privacy Protection 

Privacy protection means keeping the information you’d rather keep to yourself from getting in the hands of advertisers, cybercriminals, and nefarious groups seeking to use your personal details for their benefit. To boost your online privacy, all it takes is a few thoughtful additions to your daily browsing, email, and social media routine.  

First, think carefully about your social media habits. Do you post everything about your day and childhood, pin your location, and share photos of documents that include your full name, birthday, or address? You may want to consider cutting back on what you broadcast on the internet, especially if your account is public for anyone to view. Unfortunately, while your friends and family may love your status updates, cybercriminals love them more. After only minutes of snooping, cybercriminals can glean enough personal details about you to impersonate you or target a social engineering attempt at you. To keep your private information private, limit what you share on social media and pare down your follower and friend lists to only people you know in real life. 

Another way to protect your privacy is to use a virtual private network (VPN). A VPN allows you to remain completely anonymous online, scrambling your location and your connection. Some users may swear by incognito mode for safe browsing; however, only a VPN can ensure your privacy is protected. Incognito mode, also known as private mode, deletes your browsing history, cookies, and site data on your device once you log out of a session. While incognito mode prevents someone from snooping on your browsing history if they gain access to your device, you’re still vulnerable to cyber criminals intruding on your sensitive transactions.   

A VPN is especially important when you’re logged on to a public network, like those in coffee shops, libraries, and transportation hubs. Cybercriminals often lurk on non-password-protected Wi-Fi networks and eavesdrop on people paying bills or online shopping to steal their credentials. 

You should also invest in antivirus software, and turn on automatic updates so you can be confident that you are always running the most secure, recent version. McAfee Total Protection Ultimate is an all-in-one service that protects your personal information and privacy. It also includes premium antivirus software, safe browsing, and a VPN. 

Identity Protection 

Another type of online security you need is protection against identity theft. Identity theft is a broad term that can apply to the following unfortunate situations: 

  • Synthetic identity fraud. This most common type of identity theft occurs when a criminal steals a Social Security Number and ascribes it to a totally new identity. 
  • New account fraud. New account fraud happens when a criminal successfully steals personal identifiable information (PII) and financial information and uses a victim’s excellent credit score to open new credit cards, utility accounts, cellphone accounts, etc. 
  • Account takeover fraud. Account takeover fraud means that a cybercriminal steals banking credentials and then adds themselves as authorized users, meaning that they get a credit card tied to the victim’s banking account. Luckily, this type of fraud is on the way out, thanks to the prevalence of EMV chip readers. 
  • Medical identity theft. Medical identity thieves impersonate patients to gain access to their prescription medications and have their medical treatments paid for by the identity theft victim. 
  • Business identity theft. Often targeted at small business owners, business identity theft is when a cybercriminal attempts to open new credit lines in the business’ name or sends customers phony bills and collects the payments themselves. 

In each case, the consequences can be a hassle to deal with and may even affect your finances, credit score, and ability to secure loans, a mortgage, or future credit cards. One way to keep your identity secure is to guard your PII carefully. Never give out your Social Security Number unless it’s absolutely necessary and never share it over email. Also, stay on top of the news and take action immediately if a company that houses your PII is breached by a cybersecurity attack. That way you can quickly take action to hopefully protect your account. 

Sometimes, you do everything right and a cybercriminal still gets their hands on your PII, like through a breach at a company with which you have an account. You may want to invest in an identity protection service that provides dark web monitoring and alerts you to unusual activity that could indicate identity theft.  

McAfee Identity Protection Service is easy to set up and offers extensive monitoring of over 60 types of PII. McAfee notifies identity theft victims up to 10 months sooner than similar identity monitoring services and grants $1 million in ID theft coverage to help you get back on your feet if a cybercriminal steals your identity. 

Device Security 

Device security covers the actions you take to keep your physical devices safe from thieves and harmful software, like viruses and malware.  

The first step to keeping your laptops, tablets, and smartphones safe is to know where your devices are at all times and never let anyone you don’t know to use them. Password-protect your devices, so in the case, you leave your laptop in a taxi or forget your phone at a coffee shop, you know that your information stored within is inaccessible. Back up your files frequently so if you do lose a device and have to wipe it remotely, you don’t lose all your photos or work documents. 

Another component of device security is defending against malicious software. Viruses and malware can make their way onto your devices through several avenues, including sketchy websites, dishonest downloads, phishing schemes, and clicking on ads. Be careful on what you click on and use common sense when visiting websites that look untrustworthy. 

McAfee Total Protection prevents, scans, detects, and deletes viruses and malware from your devices. McAfee antivirus provides real-time, 24/7 threat protection plus a 100% guarantee that it’ll remove viruses from your devices. Additionally, McAfee Web Advisor is a free option that alerts you when you visit potentially risky sites, so you can be more confident in your browsing and downloading. 

The post Privacy, Identity, and Device Protection: Why You Need to Invest in All Three appeared first on McAfee Blogs.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

NY Man Pleads Guilty in $20 Million SIM Swap Theft

A 24-year-old New York man who bragged about helping to steal more than $20 million worth of cryptocurrency from a technology executive has pleaded guilty to conspiracy to commit wire fraud. Nicholas Truglia was part of a group alleged to have stolen more than $100 million from cryptocurrency investors using fraudulent “SIM swaps,” scams in which identity thieves hijack a target’s mobile phone number and use that to wrest control over the victim’s online identities.

Truglia admitted to a New York federal court that he let a friend use his account at crypto-trading platform Binance in 2018 to launder more than $20 million worth of virtual currency stolen from Michael Terpin, a cryptocurrency investor who co-founded the first angel investor group for bitcoin enthusiasts.

Following the theft, Terpin filed a civil lawsuit against Truglia with the Los Angeles Superior court. In May 2019, the jury awarded Terpin a $75.8 million judgment against Truglia. In January 2020, a New York grand jury criminally indicted Truglia (PDF) for his part in the crypto theft from Terpin.

A SIM card is the tiny, removable chip in a mobile device that allows it to connect to the provider’s network. Customers can legitimately request a SIM swap when their mobile device has been damaged or lost, or when they are switching to a different phone that requires a SIM card of another size.

Nicholas Truglia, holding bottle. Image: twitter.com/erupts

But fraudulent SIM swaps are frequently abused by scam artists who trick mobile providers into tying a target’s service to a new SIM card and mobile phone controlled by the scammers. Unauthorized SIM swaps often are perpetrated by fraudsters who have already stolen or phished a target’s password, as many financial institutions and online services rely on text messages to send users a one-time code for multi-factor authentication.

Compounding the threat, many websites let customers reset their passwords merely by clicking a link sent via SMS to the mobile phone number tied to the account, meaning anyone who controls that phone number can reset the passwords for those accounts.

Reached for comment, Terpin said his assailant got off easy.

“I am outraged that after nearly four years and hundreds of pages of evidence that the best the prosecutors could recommend was a plea bargain for a single, relatively minor count of the unauthorized use of a Binance exchange account, when all the evidence points toward Truglia being one of two masterminds of a wide-ranging criminal conspiracy to steal crypto from me and others,” Terpin told KrebsOnSecurity.

Terpin said public court records already show Truglia bragging about stealing his funds and using it to finance a lavish lifestyle.

“He at the very least withdrew 100 bitcoin (worth $1.6 million at the time and nearly $5 million today) from my theft into his wallet at a separate, US-based exchange, and then moved or spent it,” Terpin said. “The fact is that the intentional theft of $24 million, whether taken at the point of a gun in a bank or through a SIM card swap, is a major felony. Truglia should be prosecuted to the fullest extent of the law.”

Nicholas Truglia, showing off a diamond-studded Piaget watch while aboard a private jet. Image: twitter.com/erupts.

Terpin also is waging an ongoing civil lawsuit against 18-year-old Ellis Pinsky, who’s accused of working with Truglia as part of a SIM swapping crew that has stolen more than $100 million in cryptocurrency. According to Terpin, Pinsky was 15 when he took part in the $24 million 2018 SIM swap, but he returned $2 million worth of cryptocurrency after being confronted by Terpin’s investigators.

“On the surface, Pinsky is an ‘All American Boy,’” Terpin’s civil suit charges. “The son of privilege, he is active in extracurricular activities and lives a suburban life with a doting mother who is a prominent doctor.”

“Despite their wholesome appearances, Pinsky and his other cohorts are in fact evil computer geniuses with sociopathic traits who heartlessly ruin their innocent victims’ lives and gleefully boast of their multi-million-dollar heists,” the lawsuit continues. “Pinsky is reputed to have used his ill-gotten gains to purchase multi-million-dollar watches and is known to go on nightclub sprees at high end clubs in New York City, and Truglia rented private jets and played the part of a dashing playboy with young women pampering him.”

Pinksy could not be immediately reached for comment. But a review of the latest filings in the lawsuit show that Pinsky’s attorneys stopped representing him because he no longer had the funds to pay for their services. The most recent entry in the New York Southern District’s docket asks the court to give Pinsky additional time to seek counsel, and hints that barring that he may end up representing himself.

Ellis Pinsky, in a photo uploaded to his social media profile.

Truglia is still being criminally prosecuted in Santa Clara, Calif., the home of the REACT task force, which pursues SIM-swapping cases nationwide. In November 2018, REACT investigators and New York authorities arrested Truglia on suspicion of using SIM swaps to steal approximately $1 million worth of cryptocurrencies from Robert Ross, a San Francisco father of two who later went on to found the victim advocacy website stopsimcrime.org.

According to published reports, Truglia and his accomplices also perpetrated SIM swaps against the CEO of the blockchain storage service 0Chain; hedge-funder Myles Danielson, vice president of Hall Capital Partners; and Gabrielle Katsnelson, the co-founder of the startup SMBX.

Truglia is currently slated to be sentenced in April 2022 for his guilty plea in New York. He faces a maximum sentence of up to 20 years in prison.

Erin West, deputy district attorney for Santa Clara County, told KrebsOnSecurity that SIM swapping remains a major problem. But she said many of the victims they’re now assisting are relatively new cryptocurrency investors for whom a SIM swapping attack can be financially devastating.

“Originally, the SIM swap targets were the early adopters of crypto,” West said. “Now we’re seeing a lot more of what I would call normal people trying their hand at crypto, and that makes a lot more people a target. It makes people who are unfamiliar with their personal security online vulnerable to hackers whose entire job is to figure out how to part people from their money.”

West said REACT continues to train state and local law enforcement officials across the country on how to successfully investigate and prosecute SIM swapping cases.

“The good news is our partners across the nation are learning how to conduct these cases,” she said. “Where this was a relatively new phenomenon three years ago, other smaller jurisdictions around the country are now learning how to prosecute this crime.”

All of the major wireless carriers let customers add security against SIM swaps and related schemes by setting a PIN that needs to be provided over the phone or in person at a store before account changes should be made. But these security features can be bypassed by incompetent or corrupt mobile store employees.

For some tips on how to minimize your chances of becoming the next SIM swapping victim, check out the “What Can You Do?” section at the conclusion of this story.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

DHS Launches Bug Bounty Program

DHS Launches Bug Bounty Program

The United States Department of Homeland Security has launched a new bug bounty program to identify potential cybersecurity vulnerabilities and increase the department’s cybersecurity resilience. 

When announcing the “Hack DHS” program in a statement shared yesterday, the department said its aim was to uncover weaknesses within certain DHS systems so that they can be patched.

In exchange for pointing out flaws, successful bug hunters will receive a cash payment. How much they earn will be decided by a sliding scale, with the highest bounties going to hackers who catch the most severe bugs.

The DHS bug bounty program is by invitation only. Program participants will be selected from a list of vetted cybersecurity researchers.

“As the federal government’s cybersecurity quarterback, DHS must lead by example and constantly seek to strengthen the security of our own systems,” said Secretary Alejandro Mayorkas.

“The Hack DHS program incentivizes highly skilled hackers to identify cybersecurity weaknesses in our systems before they can be exploited by bad actors.”

Mayorkas added that the new program is an example of how the DHS is partnering with the community to help protect America’s national cybersecurity.

Hack DHS is a three-phase program that will run throughout the fiscal year 2022. 

The DHS said: “During phase one, hackers will conduct virtual assessments on certain DHS external systems. During the second phase, hackers will participate in a live, in-person hacking event. 

“During the third and final phase, DHS will identify and review lessons learned, and plan for future bug bounties.”

The DHS is partnering with crowdsourced cybersecurity company Bugcrowd to deliver the program. 

Bugcrowd founder and CTO Casey Ellis commented: “We’ve been advising a variety of government agencies for many years including the DHS, and we’ll be the platform partner for this program.”

He added: “In the spirit of crowdsourcing, they’ve also drawn from the existing experience of running successful programs within the US government, including from those who’ve worked on the CISA program, and veterans of the Hack the Pentagon series of programs. 

“Good planning is an excellent predictor of success in this space, and they’ve definitely put that work in.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Grindr Fined €6.5m for Selling User Data Without Explicit Consent

Grindr Fined €6.5m for Selling User Data Without Explicit Consent

Dating app Grindr has been fined €6.5m (£5.5m) for selling user data to advertisers without their explicit consent.

The fine was issued by the Norwegian Data Protection Authority (DPA) for “grave” infringements of GDPR rules. This was because Grindr shared highly sensitive ‘special category’ data with third parties without users’ explicit consent, which is a requirement under the regulation. This includes GPS location, IP address, advertising ID, age and gender. Additionally, the third parties knew the user was on Grindr, a dating app for gay, bi, trans and queer people, meaning their sexual orientation data was exposed.

Users were forced to agree to the company’s privacy policy without being asked specifically if they consented to the sharing of their data for behavioral purposes.

Tobias Judin, head of the Norwegian DPA’s international department, explained: “Our conclusion is that Grindr has disclosed user data to third parties for behavioral advertisement without a legal basis.”

The €6.5m penalty is the largest fine issued by the Norwegian data protection authority. However, this figure was reduced from £8.6m after Grindr provided details about its financial situation and had changed permissions on its app. However, the regulator added that it has not assessed whether this new consent mechanism complied with GDPR.

Grindr now has three weeks to decide whether to launch an appeal.

The Norwegian DPA’s decision was welcomed by consumer rights group the European Consumer Organisation (BEUC). Ursula Pachl, deputy director general of the BEUC, outlined: “Grindr illegally exploited and shared its users’ information for targeted advertising, including sensitive information about their sexual orientation. It is high time the behavioral advertising industry stops tracking and profiling consumers 24/7. It is a business model which clearly breaches the EU’s data protection rules and harms consumers. Let’s now hope this is the first domino to fall and that authorities start imposing fines on other companies as the infringements identified in this decision are standard surveillance ad-tech industry practices.”

The case is another example of the stricter approach regulators are taking to GDPR enforcement in the past year or so. In September, WhatsApp was fined €225m by Ireland’s Data Protection Commission (DPC) for failing to discharge GDPR transparency obligations, while Amazon was hit with a $886.6m fine for allegedly failing to process personal data in accordance with the law in July.

Commenting on the story, Jamie Akhtar, CEO and co-founder of CyberSmart, said: “Although GDPR has been around for a while now, it’s only in the last few years that we’ve seen regulators take a hard-line approach. With legislators all over the world beginning to follow the EU’s lead and draft their own regulations, there’s never been a better time to make sure your business is processing data responsibly.”

Reflecting on the case in the context of current trends around GDPR enforcement, Jonathan Armstrong, partner at legal firm Cordery Compliance stated: “I think the case confirms a couple of trends we are seeing. Firstly, regulators are getting more aggressive in enforcing data protection laws. GDPR fines alone are now over €1.3bn and we know there is at least another €100m coming through the system in the next few weeks. Secondly, transparency is a key theme of data protection enforcement. When GDPR was coming in some people said it was all about security – this proves that that’s just wrong. Organizations need to be clear about the data they are collecting, how they are using it and who they are sharing it with. Thirdly, it also shows the power of the activist. One of the people behind the original complaint, Max Schrems has a real track record of privacy campaigns that get results. Activists and litigants are becoming more prominent and this trend will continue too.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

UK’s New Cyber Strategy Designed to Boost Position as “Global Cyber Power”

UK’s New Cyber Strategy Designed to Boost Position as “Global Cyber Power”

The UK government has published a new national cyber strategy to bolster the nation’s defensive and offensive capabilities amid rising attacks from criminal gangs and nation-state actors.

The government wants its wide-ranging strategy to solidify the UK’s “position as a global cyber power.” Plans to enhance the nation’s cyber-defenses include implementing the recently announced Product Security and Telecommunications Infrastructure (PSTI) that imposes minimum security standards on smart device manufacturers and increased funding in public sector cybersecurity. Additionally, the government said there will be an expansion of the National Cyber Security Centre (NCSC)’s research capabilities.

There is also a strong emphasis on promoting offensive measures in the policy to better equip the military and police to take the fight to cyber-threat actors. For this, there will be increased funding for the UK’s recently established National Cyber Force and for law enforcement to help disrupt and target cybercrime groups.

Home Secretary Priti Patel commented: “Cybercrime ruins lives and facilitates further crimes such as fraud, stalking and domestic abuse. Billions of pounds are lost each year to cyber-criminals who steal or hold personal data to ransom and who disrupt key public services or vital sectors of the national economy.

“This strategy will significantly improve the Government’s response to the ever-changing threat from cybercrime and strengthen law enforcement’s response in partnership with NCSC and the National Cyber Force. We all have a part to play in protecting ourselves from cybercrime. It is important that as a society, we take this threat seriously.”

“It is important that as a society, we take this threat seriously”

Another major aspect of the policy is growing the UK’s cyber talent pool and calling for “all parts of society to play their part in reinforcing the UK’s economic and strategic strengths in cyberspace.” Among the measures outlined in this area, the government announced a new ‘Cyber Explorers’ online training platform to enable young people to learn cyber skills in classrooms and a new scheme to help adults from all backgrounds access jobs in this sector. In addition, a new Royal Charter will be brought in to bring cybersecurity in line with other professional occupations like engineering.

It will also continue to support cyber start-up companies through programs like the Cyber Runway scheme. The government said that these initiatives will build on the considerable growth in the UK’s cyber sector over recent years, with over 1400 businesses generating revenues of £8.9bn last year. These initiatives also aim to ‘level up’ the cyber sector across all UK regions.

Sir Jeremy Fleming, director of GCHQ, said: “The National Cyber Strategy builds on the country’s strong foundations in cyber security that GCHQ’s work has been part of, particularly through the NCSC. But it goes beyond that. It brings together the full range of cyber activities, from skills to communities, and to the use of offensive cyber capabilities through the newly established National Cyber Force.

“It shows how the UK can build capacity across the country to continue to prosper from the opportunities of cyberspace.” With the UK being a leading responsible cyber power, it “can build alliances with democratic partners around the world to protect a free, open and peaceful cyberspace.”

The strategy is supported by a £2.6bn investment in cyber that the government announced in its spending review this year.

Commenting on the announcement, Jude McCorry, CEO of SBRC, said: “The number of cyber-attacks has been on the rise since the start of the pandemic, with both international and domestic cyber-criminals taking advantage of our increased reliance on technology. We welcome the new National Cyber Strategy, particularly with its emphasis on a ‘whole of society’ approach. From a business perspective, the public and private sectors alone cannot drive the change needed to level up cyber security in the UK and keep us safe from cyber-criminals both here and abroad; we must work in partnership.”

Adrian Nish, head of cyber propositions at BAE Applied Intelligence, stated: “We welcome any overarching strategy as long as it is joined up and includes details on implementation, leadership, accountabilities and enables different bodies to carry out their missions.”

Saj Huq, head of innovation at Plexal, the innovation center helping deliver the Cyber Runway scheme, said: “Cybersecurity is relevant to everyone and today’s newly announced National Cyber Strategy recognizes this – and discusses how the government wishes to take a whole-of-society approach to the UK’s cybersecurity.”

“The sheer growth of cyber incidents, the increasing geopolitical relevance of cyber and our growing dependence on technology as a society has further underlined how critical effective cybersecurity is for our country’s future prosperity and national security. This view is cemented in today’s strategy, with the government highlighting how all of us – be that public, private, big or small – must play our part in this important sector.

“The new National Cyber Strategy recognizes that horizontal technology areas such as cyber – with their potential to influence and shape the fabric of how our society interacts and engages with technology – requires targeted government intervention. We need to harness the power of the government to bring together stakeholders from across the ecosystem and create the conditions that enable them to share information an unlock opportunities.

“This strategy places cybersecurity at the heart of all future national decision-making on emerging technologies, with a specific focus on building ecosystems around key technologies that are critical to the UK’s strategic direction and embedding security into the next generation of breakthrough technologies that will shape our digital and physical worlds.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Web App Attacks Surge 251% in Two Years

Web App Attacks Surge 251% in Two Years

Web application attacks on UK businesses have soared by over 250% since October 2019, driving a surge in data breaches, according to Imperva.

The security vendor analyzed nearly 4.7 million web application-related cybersecurity incidents over the period to find that attacks are increasing, on average, by 22% each quarter.

This is likely to be fuelling a vast increase in data breaches. Remote code execution (RCE) and remote file inclusion (RFI) attacks, often used to steal information and hijack websites, surged by 271% over the two years.

In fact, previous research from Imperva Research Labs found that half (50%) of all data breaches begin with web applications. The research estimated that around 20 billion compromised records would stem from web app attacks this year.

More concerning still is that recorded web app attacks increased by 68% from Q2 to Q3 2021, as threat actors sought to flood underground sites with stolen data ahead of the Christmas shopping period.

Fraudsters often use busy shopping times to disguise their activity, as retailers sometimes relax their checks to process larger sales volumes.

“The pandemic placed immense urgency on businesses to get all kinds of digital transformation projects live as quickly as possible, and that is almost certainly a driving factor behind this surge in attacks,” said Peter Klimek, director of technology at Imperva.

“The changing nature of application development itself is also hugely significant. Developments like the rapid proliferation of APIs and the shift to cloud-native computing is beneficial from a DevOps standpoint, but for security teams, these changes in application architecture and the accompanying increased attack surface is making their jobs much harder.”

According to official figures, fraud costs UK businesses and consumers an estimated £1.3bn in the first half of 2021, a three-fold year-on-year increase.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains