Ubiquiti Developer Charged With Extortion, Causing 2020 “Breach”

In January 2021, technology vendor Ubiquiti Inc. [NYSE:UI] disclosed that a breach at a third party cloud provider had exposed customer account credentials. In March, a Ubiquiti employee warned that the company had drastically understated the scope of the incident, and that the third-party cloud provider claim was a fabrication. On Wednesday, a former Ubiquiti developer was arrested and charged with stealing data and trying to extort his employer while pretending to be a whistleblower.

Federal prosecutors say Nickolas Sharp, a senior developer at Ubiquiti, actually caused the “breach” that forced Ubiquiti to disclose a cybersecurity incident in January. They allege that in late December 2020, Sharp applied for a job at another technology company, and then abused his privileged access to Ubiquiti’s systems at Amazon’s AWS cloud service and the company’s GitHub accounts to download large amounts of proprietary data.

Sharp’s indictment doesn’t specify how much data he allegedly downloaded, but it says some of the downloads took hours, and that he cloned approximately 155 Ubiquiti data repositories via multiple downloads over nearly two weeks.

On Dec. 28, other Ubiquiti employees spotted the unusual downloads, which had leveraged internal company credentials and a Surfshark VPN connection to hide the downloader’s true Internet address. Assuming an external attacker had breached its security, Ubiquiti quickly launched an investigation.

But Sharp was a member of the team doing the forensic investigation, the indictment alleges.

“At the time the defendant was part of a team working to assess the scope and damage caused by the incident and remediate its effects, all while concealing his role in committing the incident,” wrote prosecutors with the Southern District of New York.

According to the indictment, on January 7 a senior Ubiquiti employee received a ransom email. The message was sent through an IP address associated with the same Surfshark VPN. The ransom message warned that internal Ubiquiti data had been stolen, and that the information would not be used or published online as long as Ubiquiti agreed to pay 25 Bitcoin.

The ransom email also offered to identify a purportedly still unblocked “backdoor” used by the attacker for the sum of another 25 Bitcoin (the total amount requested was equivalent to approximately $1.9 million at the time). Ubiquiti did not pay the ransom demands.

Investigators say they were able to tie the downloads to Sharp and his work-issued laptop because his Internet connection briefly failed on several occasions while he was downloading the Ubiquiti data. Those outages were enough to prevent Sharp’s Surfshark VPN connection from functioning properly — thus exposing his Internet address as the source of the downloads.

When FBI agents raided Sharp’s residence on Mar. 24, he reportedly maintained his innocence and told agents someone else must have used his Paypal account to purchase the Surfshark VPN subscription.

Several days after the FBI executed its search warrant, Sharp “caused false or misleading news stories to be published about the incident,” prosecutors say. Among the claims made in those news stories was that Ubiquiti had neglected to keep access logs that would allow the company to understand the full scope of the intrusion. In reality, the indictment alleges, Sharp had shortened to one day the amount of time Ubiquiti’s systems kept certain logs of user activity in AWS.

“Following the publication of these articles, between Tuesday, March 30, 2021 and Wednesday March 31, [Ubiquiti’s] stock price fell approximately 20 percent, losing over four billion dollars in market capitalization,” the indictment states.

Sharp faces four criminal counts, including wire fraud, intentionally damaging protected computers, transmission of interstate communications with intent to extort, and making false statements to the FBI.

News of Sharp’s arrest was first reported by BleepingComputer, which wrote that while the Justice Department didn’t name Sharp’s employer in its press release or indictment, all of the details align with previous reporting on the Ubiquiti incident and information presented in Sharp’s LinkedIn account. A link to the indictment is here (PDF).

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Final Member of ‘The Community’ Sentenced

Final Member of ‘The Community’ Sentenced

The United States has sent a fourth member of the international hacking group known as The Community to prison.

Garrett Endicott, of Warrensburg, Missouri, was the last of six defendants to be sentenced in connection with a multi-million-dollar SIM-swapping conspiracy that claimed victims across the country, including in California, Missouri, Michigan, Utah, Texas, New York and Illinois.

Endicott, along with 22-year-old Conor Freeman of Dublin, Ireland; Ricky Handschumacher, 28, of Pasco County, Florida; Colton Jurisic, 22, of Dubuque, Iowa; Reyad Gafar Abbas, 22, of Rochester, New York; and Ryan Stevenson, 29, of West Haven, Connecticut, was charged with conspiracy to commit wire fraud, wire fraud, and aggravated identity theft in a 15-count indictment unsealed on May 9, 2019.  

After pleading guilty to the charges, 22-year-old Endicott was yesterday ordered to pay restitution in the amount of $121,549.37 and serve 10 months behind bars by United States District Judge Denise Page Hood.

Members of The Community would gain control of a victim’s cell phone number, then use it to access the victim’s email accounts, crypto-currency wallets, and cloud storage. By resetting passwords and requesting two-factor authentication codes, the hackers were able to bypass security measures and steal tens of millions of dollars’ worth of crypto-currency.

“Individual victims lost crypto-currency valued, at the time of theft, ranging from under $2,000 to over $5m. The sentenced defendants were involved in total thefts ranging from approximately $50,000 to over $9m,” said the US Attorney’s Office for the Eastern District of Michigan. 

Three of Endicott’s co-conspirators have already been handed custodial sentences in the United States. Handschumacher was sentenced to 48 months in prison and ordered to pay restitution in the amount of $7,681,570.03. 

Jurisic was sentenced to 42 months in prison and ordered to pay restitution in the amount of $9,517,129.29, and Abbas was ordered to pay restitution in the amount of $310,791.90 and sentenced to 24 months in prison. Stevenson pleaded guilty and was sentenced to probation in the District of Connecticut.

In January, the United States withdrew its extradition request for Freeman after the hacker was sentenced to three years in prison in Ireland in November for stealing crypto-currency, dishonestly operating a computer to make a gain, and knowingly engaging in the possession of the proceeds of crime.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Twitter to Remove Private Media

Twitter to Remove Private Media

Twitter has altered its privacy rules so that images of individuals that were posted without the subject’s consent can be taken down from its online platform. 

The social media company said it was expanding its existing private information policy to include “private media” in a bid to combat cyber-harassment. 

News of the policy change came the day after Twitter co-founder Jack Dorsey announced that he is stepping down as the company’s chief executive officer. Parag Agrawal, a 37-year-old Twitter engineer who was appointed as the company’s chief technology officer in 2017, will take over the helm.

Under the new policy, which was announced by the company in a blog post on Tuesday, images do not need to be considered abusive to be removed.

“While our existing policies and Twitter Rules cover explicit instances of abusive behavior, this update will allow us to take action on media that is shared without any explicit abusive content, provided it’s posted without the consent of the person depicted,” stated Twitter. 

“This is a part of our ongoing work to align our safety policies with human rights standards, and it will be enforced globally starting today.”

The company said that it will take action in line with its “range of enforcement options” whenever it receives a report that a tweet features unauthorized private media.

Reports must be sent in from the individual depicted in the image or from their authorized representative before the company will determine whether its private media rule has been infringed.

Twitter said that the new policy “is not applicable to media featuring public figures or individuals when media and accompanying Tweet text are shared in the public interest or add value to public discourse.”

Current privacy rules put in place by Twitter ban users from publishing other people’s private data, such as phone numbers, addresses, and IDs. Users are also barred from threatening to share private information or encouraging other people to expose it.

In May, Twitter introduced a prompt feature to encourage users wishing to Tweet abusive language to think harder about what they are posting before they post it.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

SANS Institute Founder Dies

SANS Institute Founder Dies

American cybersecurity training advocate, technologist, and entrepreneur Alan Terry Paller has died at the age of 76. 

Paller’s death occurred on November 9 at his home in Bethesda, Maryland. His passing was announced by the Bethesda-based SANS Institute, which Paller and his wife, Marsha Mann Paller, founded in 1989.

The Institute went on to become one of the world’s leading nongovernment cybersecurity training programs. 

Paller was born in Indianapolis on September 17, 1945, to an engineer and a high school English teacher. In 1967, he graduated from Cornell University with a bachelor’s degree in mechanical engineering. Paller completed a master’s degree in engineering from the Massachusetts Institute of Technology in 1968. 

He began his career in the United States Navy, using computers to design ships. He went on to co-found a computer timeshare business in Hawaii, run a consultancy in applied computer graphics technology, and work for the Institute for Defense Analysis on missile-defense issues.

Cybersecurity was described by Paller as an “existential issue.” He was a firm believer in the use of regulation to improve America’s cybersecurity posture and earned a reputation as one of cybersecurity’s earliest cheerleaders. 

Speaking to the Washington Post in 2012, Paller said of cybersecurity: “Our future economic well-being and future national security are at stake if we don’t mandate it.”

In addition to championing cybersecurity and raising awareness of the importance of training cybersecurity professionals, Paller was an advocate for increasing the diversity of the cybersecurity workforce and actively sought ways to reach out to veterans, community colleges, communities of color, teens, and women. 

To attract more young people into pursuing a career in cybersecurity, Paller established game-based competitions that introduced teens to cybersecurity in a fun way.

Haya Arfat, a 20-year-old student at Texas A&M University, became interested in cybersecurity after joining the GirlsGoCyberStart program for high-schoolers that Paller set up. She later received a SANS Institute scholarship in 2019. 

“Alan was really encouraging and passionate,” said Arfat. “That’s what opened my eyes to the possibility of a career in cybersecurity.”

Paller is survived by his wife of 53 years, his daughters, Channing Paller and Brooke Paller, his two grandsons, and other family members.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Organizations Now Have 76 Security Tools to Manage

Organizations Now Have 76 Security Tools to Manage

Organizations are presenting their attackers with an open goal because of tool bloat, a lack of visibility into key assets, and misplaced confidence in their security controls, according to Panaseer.

The security vendor polled 1,200 US and UK enterprise security decision-makers from various industries to compile its Panaseer 2022 Security Leaders Peer Report.

It found that the shift to cloud and remote working has driven a 19% increase over the past two years in the number of security tools organizations must manage – from 64 to 76.

This can increase reporting requirements and generate visibility and security controls gaps that are difficult to close.

Only a third (36%) of respondents said they feel very confident in their ability to prove controls were working as intended. In comparison, the vast majority (82%) claimed to have been surprised by a security event, incident or breach that evaded controls thought to be in place.

According to a Gartner poll of senior executives, security controls failures were the number one cited risk in Q1 2021.

Panaseer also found that just two-fifths of security leaders can confidently understand and remediate underperforming controls and track improvement. A majority (60%) of respondents admitted to not being confident in their ability to measure security controls designed to mitigate ransomware continuously.

Part of the challenge is a lack of insight into key assets such as databases (27%), devices (17%) and IoT endpoints (16%).

The amount of time the average security decision-maker spends on generating manual reports for the board has also surged in the past two years – from 40% to 54%

Panaseer CEO, Jonathan Gill, argued that tool overload has created a major data integration headache for security teams.

“Many organizations try to resolve this with spreadsheets and other in-house solutions that simply increase the reporting and administration burden on precious cybersecurity resources,” he added.

“It’s almost impossible to understand an organization’s assets, the status of controls relating to those assets, and the business context or ownership of the associated vulnerabilities. Most attacks happen despite organizations having invested in controls to defend themselves, but finding those controls were not deployed across all assets as intended.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

HP Printer Hijack Bugs Impact 150 Models

HP Printer Hijack Bugs Impact 150 Models

Security researchers have discovered two vulnerabilities in multi-function printers (MFPs) which impacted 150 product models.

F-Secure security consultants Timo Hirvonen and Alexander Bolshev have written up their findings in a detailed report, Printing Shellz.

Specifically, they found a physical access port vulnerability (CVE-2021-39237) and a font parsing bug (CVE-2021-39238) in HP’s MFP M725z device. They turned out to affect scores more products in the FutureSmart line dating back to 2013.

CVE-2021-3928 is the more dangerous of the two as it can be exploited remotely, potentially by tricking an employee into visiting a malicious website, to conduct a “cross-site printing” attack. Here, the website would automatically print a document containing a maliciously crafted font on a vulnerable MFP, said F-Secure.

This would allow an attacker to execute arbitrary code on the machine to steal any printed, scanned or faxed information, including device passwords.

The report claimed that it could also enable attackers to launch deeper attacks into the corporate network to spread ransomware, steal data from more sensitive data stores and achieve other goals.

The bugs are also wormable, meaning multiple MFPs on the same network could be automatically impacted.

“It’s easy to forget that modern MFPs are fully-functional computers that threat actors can compromise just like other workstations and endpoints. And just like other endpoints, attackers can leverage a compromised device to damage an organization’s infrastructure and operations,” explained F-Secure’s Hirvonen.

“Experienced threat actors see unsecured devices as opportunities, so organizations that don’t prioritize securing their MFPs like other endpoints leave themselves exposed to attacks like the ones documented in our research.”

HP has issued patches for the vulnerabilities, which are described as “medium” (CVE-2021-39237) and critical severity (CVE-2021-39238).

Although they’re only thought to be exploitable by advanced targeted attackers, enterprises were urged to patch them as soon as possible.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

MI6 Boss: Digital Attack Surface Growing “Exponentially”

MI6 Boss: Digital Attack Surface Growing “Exponentially”

One of the UK’s top spymasters has revealed that MI6 is pursuing partnerships with the technology industry to tackle the challenges posed by nation-states, cyber-criminals and global terrorists.

Head of the Secret Intelligence Service (SIS), Richard Moore, explained in a rare speech yesterday that, unlike the character Q from the James Bond films, the service cannot source all of its tech capabilities in-house.

“Through the National Security Strategic Investment Fund we are opening up our mission problems to those with talent in organizations that wouldn’t normally work with national security,” he added.

“I cannot stress enough what a sea-change this is in MI6’s culture, ethos and way of working, since we have traditionally relied primarily on our own capabilities to develop the world class technologies we need to stay secret and deliver against our mission.”

These partnerships will increasingly be needed in areas such as artificial intelligence (AI), quantum computing and synthetic biology, into which adversaries are “pouring money and ambition” to gain leverage, Moore warned.

New tech capabilities will help address MI6’s four key priorities: Russia, China, Iran and global terrorism. It’s a challenge made more acute as technology rapidly advances, he said.

“The ‘digital attack surface’ that criminals, terrorists and hostile states threats seek to exploit against us is growing exponentially. We may experience more technological progress in the next ten years than in the last century, with a disruptive impact equal to the industrial revolution,” Moore argued.

Much of his speech was focused on China, whose intelligence services Moore claimed were “highly capable” and both monitor foreign targets and aim to influence the Chinese diaspora.

Moore called out China’s growing disinformation operations via social media and its attempts to draw smaller nations into its sphere of influence via “debt traps” and “data exposure.”

He also warned that the country was increasingly exporting “Made in China” surveillance technology to create a “web of authoritarian control” around the planet.

James Griffiths, technical director of consultancy Cyber Security Associates, argued that technology like big data analytics could be a “force multiplier” in helping to automate key tasks and make intelligence analysts more productive.

“MI6 is very good at what it does within its own intelligence remit. It has also positively identified that to be the best across the board it needs to leverage the skillset of other organizations that are specialists in key areas, for example AI, machine learning quantum cryptography,” he added.

“By leveraging and working in partnership with these organizations MI6 will increase its overall effectiveness and the wider intelligence community as a whole.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains