Volvo Hit by Cyber-thieves

Volvo Hit by Cyber-thieves

Cyber-thieves hacked into the computer network of Swedish car manufacturer Volvo and exfiltrated research and development secrets.

The carmaker posted a notice on its website yesterday stating that it had suffered a cybersecurity breach in which a limited amount of data was stolen. 

Though the quantity of data swiped in the incident was small, Volvo warned that its loss may have an impact on the company’s operations. 

Volvo did not disclose the date on which the attack took place, how long it lasted, or when it was detected. The company shared only sparse information regarding the nature of the attack, describing it as involving a breach of one of its file repositories by a third party. 

In a statement released Friday, the carmaker said: “Volvo Cars has become aware that one of its file repositories has been illegally accessed by a third party. 

“Investigations so far confirm that a limited amount of the company’s R&D property has been stolen during the intrusion. Volvo Cars has earlier today concluded, based on information available, that there may be an impact on the company’s operation.”

External cybersecurity experts have been hired to investigate the attack, and the relevant authorities in Sweden have been notified of the incident. 

While the investigation into the incident is ongoing, Volvo said that no evidence had been uncovered yet to suggest that any personal data belonging to its customers had been stolen or accessed. 

“Volvo Cars is conducting its own investigation and working with third-party specialists to investigate the property theft,” said the carmaker.

“The company does not see, with currently available information, that this has an impact on the safety or security of its customers’ cars or their personal data.”

Volvo was founded in 1927 and is headquartered in Gothenburg, Sweden. The carmaker has multiple production plants scattered around the world, including at sites in the United States and the People’s Republic of China.

Volvo’s three research and development (R&D) and design centers are located in Gothenburg, in Camarillo, California, and in Shanghai, China. The company has not yet shared which of its sites was impacted by the cyber-attack.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK Court Paves Way for Julian Assange’s Extradition to the US

UK Court Paves Way for Julian Assange’s Extradition to the US

Julian Assange can be extradited from the UK to the US to face trial for leaking classified military and diplomatic documents, a UK court has ruled today.

The US won an appeal against the ruling earlier this year that the Wikileaks founder could not be extradited to the US to face charges due to concerns over his mental health. Having been offered assurances about the treatment Assange would receive when he enters the US, the UK High Court Judges decided there is no other reason in law to prevent the extradition.

These assurances include ensuring Mr Assange is not being subject to solitary confinement pre or post-trial and that he will not be detained at a maximum-security prison. In addition, lawyers for the US claimed he would be allowed to transfer to his native Australia to serve any prison sentence he is given.

Giving the judgment, Lord Chief Justice Lord Burnett said: “That risk is in our judgment excluded by the assurances which are offered.

“It follows that we are satisfied that, if the assurances had been before the judge, she would have answered the relevant question differently.”

The ruling was met with dismay by free speech campaigners. In a statement, the Freedom of the Press Foundation wrote: “Today’s ruling is an alarming setback for press freedom in the United States and around the world, and represents a notable escalation in the use of the Espionage Act in the ‘War on Whistleblowers’ that has expanded through the past several presidential administrations.”

Nils Muiznieks, Europe director of human rights organization Amnesty International, described the decision as a “travesty of justice” and said it “poses a grave threat to press freedom both in the United States and abroad.”

Muiznieks also raised doubts about assurances regarding Mr Assange’s treatment at the hands of US authorities, stating: “If extradited to the US, Julian Assange could not only face trial on charges under the Espionage Act but also a real risk of serious human rights violations due to detention conditions that could amount to torture or other ill-treatment.”

The decision therefore paves the way for Mr Assange’s extradition to the US. The judges ordered the case to be returned to Westminster Magistrates’ Court for a district judge to send it formally to Home Secretary Priti Patel.

Mr Assange’s lawyers claimed that if convicted in the US, he faces a prison sentence of up to 175 years. However, the US government said the sentence was more likely to be between four and six years.

Mr Assange’s legal team will now consider whether to appeal to the Supreme Court, the final court of appeal in the UK.

The US Department of Justice initially indicted Assange in April 2019 for conspiring with former US Army intelligence analyst Chelsea Manning to crack a password to a classified US government computer network, the Secret Internet Protocol Network (SIPRNet).

That charge was superseded in May 2019 by a new 18-count indictment alleging that beginning in late 2009, 49-year-old Assange and WikiLeaks actively solicited United States classified information, publishing a list of “Most Wanted Leaks” that sought classified documents. This information relates to the Afghanistan and Iraq wars, which Mr Assange said exposed abuses by the US military. However, The US government argued that the leaks of classified materials endangered lives.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Experts Meet to Share Info on Crypto Crimes

Experts Meet to Share Info on Crypto Crimes

Around 2000 public and private sector experts joined forces this week at a virtual conference designed to promote information sharing in the cryptocurrency and anti-money laundering space.

Participants logged on to the 5th Global Conference on Criminal Finances and Cryptocurrencies, organized by the Basel Institute on Governance, Interpol and Europol.

They met to share expertise on current trends, strategies and tactics to tackle crimes involving virtual assets — such as money laundering, cryptocurrency fraud and cryptojacking. Day two was restricted to those from law enforcement and certain public sector representatives.

Europol argued that close co-operation between governments, law enforcement, regulators and the private sector is vital to tackle crypto-enabled crimes.

“This kind of knowledge-sharing between the public and private sectors, as well as between law enforcement representatives in different countries and institutions, is crucial in global efforts to protect the virtual assets industry from malicious actors,” it explained.

“It also helps to foster the multi-disciplinary approach that is essential to tackling virtual assets-based money laundering and related crimes, by bringing together expertise in technology, financial investigation and asset recovery.”

Specific recommendations crystallized from these conversations will emerge over the coming days.

However, they will likely fall into areas such as: international and public-private cooperation; virtual asset recovery; harmonized regulations; capacity building; investigative techniques and technologies; and the use of specialized police units.

Cryptocurrency remains a major target for financially motivated threat actors and a means to launder the proceeds of cybercrime.

The US Treasury has been placing sanctions on certain Russian cryptocurrency exchanges, to send a message that such activity will not go unpunished.

Money laundering is said to be worth trillions annually, with sporadic police action such as the 1800 arrests earlier this month doing little to stem the tide.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Crypting Mastermind Gets Just Two Years for Kelihos Plot

Crypting Mastermind Gets Just Two Years for Kelihos Plot

A Russian man has been sentenced to just 24 months behind bars for his part in helping to hide the infamous Kelihos malware from global security teams.

Oleg Koshkin, 41, was convicted by a federal jury on June 15 of one count of conspiracy to commit computer fraud and abuse, and one count of computer fraud and abuse.

He’s said to have operated several crypting websites including “crypt4u.com” and “fud.bz.” Crypting services are used by threat actors to disguise their malware from anti-virus software, using encryption.

According to the Department of Justice, Koshkin and his co-conspirators claimed their services could be used to obfuscate botnet-related malware, remote access trojans, keyloggers, credential stealers and cryptocurrency miners.

Koshkin is said to have worked with Peter Levashov, who operated the Kelihos botnet, to “crypt” the malware several times each day in order to stay hidden. Levashov pleaded guilty in 2018 to fraud, identity theft, computer crime and other offenses.

Thanks to Koshkin’s work, Kelihos became a popular tool to send spam, harvest account credentials, conduct denial of service attacks, and distribute ransomware and other malware.

Kelihos used Koshkin’s crypting services from 2014 until Levashov’s arrest in 2017, which led to the demise of Kelihos. According to the DoJ, it infected 200,000 computers around the world in just the last four months of that period.

“Today’s sentencing of Oleg Koshkin serves as another example of the risk and consequences awaiting those who choose to commit cybercrimes against the American public,” said special agent in charge David Sundberg of the FBI’s New Haven Division.

“For years, Koshkin and his co-conspirators worked to evade our most basic cyber-defenses in order to spread malware on a truly global scale. While our work to bring Koshin to justice comes to a close, the FBI will continue to tirelessly defend our country from the ever-evolving cyber threats posed by criminals, terrorists and hostile nation-states.”

Another co-conspirator, Pavel Tsurkan, pleaded guilty on June 16 to one count of causing damage to a protected computer.

Although that offense that carries a maximum term of 10 years in prison, he can expect a similar stretch to Koshkin, or shorter. Koshkin’s crimes theoretically carried a maximum term of 15 years.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Three-Quarters of Firms Admit Sub-Optimal IoT Security

Three-Quarters of Firms Admit Sub-Optimal IoT Security

Global businesses have become more risk aware as they deploy IoT projects, but over three-quarters (77%) admitted that these systems could be more secure, according to Inmarsat.

The satellite communications company polled 450 individuals responsible for delivering IoT in their respective organizations around the world, to compile its report, Industrial IoT in the Time of COVID-19.

The most commonly cited security challenges were an external cyber-attack on IoT systems (50%), poor network security (49%), insecure or unencrypted edge networks (44%) and employees mishandling data (44%).

Yet elsewhere, there has been progress: nearly half (48%) of respondents claimed to have an IoT security policy in place, versus 32% in 2018.

More businesses are also plugging in new security solutions (46% versus 33% in 2018) and creating an external IoT security policy for suppliers and partners (41% compared to 29% in 2018).

Unsurprisingly, those with a formal IoT strategy in place are more likely to deploy security measures, and if projects are driven from the top-down, purchasing decisions are more likely to include upgrades to security technology, the report found.

Inmarsat claimed there has been a flurry of IoT activity over the course of the pandemic, as organizations across the globe look for new ways to manage production, distribution and delivery more efficiently across global supply chains.

“With nearly four in five respondents reporting their organization’s IoT security could be more robust, many businesses clearly continue to face serious security challenges in their IoT deployments,” said Inmarsat Enterprise president, Mike Carter.

“The accelerating speed of IoT adoption over the course of the COVID-19 pandemic has brought with it a proliferation of security concerns, given the increasing number of potentially vulnerable endpoints associated with IoT projects. Comparing our latest results with our 2018 IoT survey, security risks are growing, but businesses are becoming more aware of cybersecurity threats and doing more to respond.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Next-Gen Maldocs & How to Solve the Human Vulnerability

Malicious email attachments with macros are one of the most common ways hackers get in through the door. Huntress security researcher John Hammond discusses how threat hunters can fight back.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains