Reimagining mobile security for the way we live our lives today, tomorrow, and beyond.

Online is a little different for everyone

How do you connect online these days? I’ll give you an example from my own life: From my 15-year old son to my 80-year-old mother, not one of us leaves the house without our phone. And today, there isn’t a single thing you can’t do on your phone. It’s the minicomputer that goes where you go. 

This trend in the way we connect is reflected in recent data too. In fact, we’ve found that the average consumer spends 6 hours and 55 min online per day, split between mobile (52%) and desktop (48%). Whether you’re a Boomer, Gen X, a Millennial, or Gen Z, the way you connect online is diverse and specific to you. 

As for what we’re doing online? It’s just about everything. After all, we spend an average of 7 hours per day on connected devices and the pandemic has forced us to do even more online. The downside to this rapid change in the way we live is that we are opening ourselves up to more risk which leaves consumers feeling highly concerned about their ability to keep their personal info secure or private. We need new protection for this new normal. 

For the new normal, a new approach to protection with mobile security 

What all these changes mean is that you’re able to have the same online experience regardless of where you are, what you’re doing, or what device you’re using. Your favorite streaming service is a great example – you can just as easily find a movie on a tablet as you can on your laptop. In fact, you can pause the movie you’re watching on that tablet and pick up where you left off on your laptop. Your experience with online security should offer the same convenience and familiarity. More importantly, online protection should give you a feeling of confidence however or wherever you choose to connect. 

 This means knowing your personal info is secure even when accessing an unsecured network, your browsing habits remain private, and you can take necessary actions should your information be compromised. To put it another way, YOU are what we’re focused on protecting and we do that by making sure everything you connect with is also secure. 

Introducing the new McAfee Security mobile app 

A phone is the remote control for your life. From the palm of your hand, you’re able to shop, browse, stream, and create – everything you do online you can now do from your phone. So, it’s crucial that your phone be a major focus of our online protection. The new mobile app makes it easier to get robust protection for your identity, privacy, and phone. Let’s look at a few of the capabilities offered by the new mobile app. 

Identity Protection Service

Think about all the online accounts you’ve created in the past year. How many of them do you use regularly? Sometimes I think I have more food delivery apps on my phone than I do restaurants to use them on. Regardless of how often you use an account (or if you no longer use it at all!), any personal information (like emails, addresses, credit cards) added to it is available online and vulnerable to breaches. McAfee Security comes with identity protection, a feature that monitors your personal information and then notifies you when there’s a risk of your data being compromised. What this means is that if we detect that your data was stolen, you’ll be alerted an average of 10 months earlier than similar services, so you can act before your data is used illegally or shows up on the dark web. 

Privacy protection with Secure VPN

Let’s say you’re about to use the free internet at your favorite café for a speedier connection. Time to flip on your virtual private network (VPN). Forget about digging through a sea of menus to find your VPN. The new mobile app offers a seamless VPN experience so you can keep your activity hidden on less-than-secure Wi-Fi. Or, better yet, you can set up a Secure VPN to automatically turn on for unsecured Wi-Fi networks. Whatever you choose, Secure VPN keeps your personal data and location private anywhere you go with unlimited data and bank-grade Wi-Fi encryption. 

Device protection 

At the end of the day, phones are devices and they’re vulnerable to viruses, malware, and, increasingly, malicious apps. The new McAfee Mobile app offers an antivirus scan for Android phones and system scans to see if your passcode is strong enough and that your OS is up to date on iOS devices. 

Most importantly, the app is part of McAfee’s total online protection, so the experience on your phone is the same as on your PC. It’s protection that goes where you go – at home on your PC, or on the go with your mobile. 

The mobile app is available right now – here’s how to get it 

If you’re an existing McAfee subscriber using McAfee Total Protection or McAfee LiveSafe, you can get the app right now. And, if you’ve already got the app installed, just make sure it’s up-to-date and you’ll be all set with the new look and features. 

Interested in trying the app out? You can buy or get a free trial of McAfee Total Protection here and get started today. 

The post Reimagining mobile security for the way we live our lives today, tomorrow, and beyond. appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

What Is SIM Swapping? 3 Ways to Protect Your Smartphone

You consider yourself a responsible person when it comes to taking care of your physical possessions. You’ve never left your wallet in a taxi or lost an expensive ring down the drain. You never let your smartphone out of your sight, yet one day you notice it’s acting oddly.  

Did you know that your device can fall into cybercriminals’ hands without ever leaving yours? SIM swapping is a method that allows criminals to take control of your smartphone and break into your online accounts. 

Don’t worry: there are a few easy steps you can take to safeguard your smartphone from prying eyes and get back to using your devices confidently. 

What Is a SIM Card? 

First off, what exactly is a SIM card? SIM stands for subscriber identity module, and it is a memory chip that makes your phone truly yours. It stores your phone plan and phone number, as well as all your photos, texts, contacts, and apps. In most cases, you can pop your SIM card out of an old phone and into a new one to transfer your photos, apps, etc. 

What Is SIM Swapping? 

Unlike what the name suggests, SIM swapping doesn’t require a cybercriminal to get access to your physical phone and steal your SIM card. SIM swapping can happen remotely. A cybercriminal, with a few important details about your life in hand, can answer security questions correctly, impersonate you, and convince your mobile carrier to reassign your phone number to a new SIM card. At that point, the criminal can get access to your phone’s data and start changing your account passwords to lock you out of your online banking profile, email, and more. 

SIM swapping was especially relevant right after the T-Mobile data breach.1 Cybercriminals stole millions of phone numbers and the users’ associated personal details. Criminals could later use these details to SIM swap, allowing them to receive users’ text or email two-factor authentication codes and gain access to their personal accounts. 

How Can You Tell If You’ve Been SIM Swapped? 

The most glaring sign that your phone number was reassigned to a new SIM card is that your current phone no longer connects to the cell network. That means you won’t be able to make calls, send texts, or surf the internet when you’re not connected to Wi-Fi. Since most people use their smartphones every day, you’ll likely find out quickly that your phone isn’t functioning as it should.  

Additionally, when a SIM card is no longer active, the carrier will often send a notification text. If you receive one of these texts but didn’t deactivate your SIM card, use someone else’s phone or landline to contact your wireless provider. 

How to Prevent SIM Swapping 

Check out these tips to keep your device and personal information safe from SIM swapping.  

  1. Set up two-factor authentication using authentication apps. Two-factor authentication is always a great idea; however, in the case of SIM swapping, the most secure way to access authentication codes is through authentication apps, versus emailed or texted codes. It’s also a great idea to add additional security measures to authentication apps, such as protecting them with a PIN code, fingerprint, or face ID. Choose pin codes that are not associated with birthdays, anniversaries, or addresses. Opt for a random assortment of numbers.  
  2. Watch out for phishing attempts. Cybercriminals often gain fodder for their identity-thieving attempts through phishing. Phishing is a method cyber criminals use to fish for sensitive personal information that they can use to impersonate you or gain access to your financial accounts. Phishing emails, texts, and phone calls often use fear, excitement, or urgency to trick people into giving up valuable details, such as Social Insurance Numbers, birthdays, passwords, and PINs. Be wary of messages from people and organizations you don’t know. Even if the sender looks familiar, there could be typos in the sender’s name, logo, and throughout the message that are a good tipoff that you should delete the message immediately. Never click on links in suspicious messages. 
  3. Use a password manager. Your internet browser likely asks you if you’d like the sites you visit to remember your password. Always say no! While password best practices can make it difficult to remember all your unique, long, and complex passwords and passphrases, do not set up autofill as a shortcut. Instead, entrust your passwords and phrases to a secure password manager, such as True Key. A secure password manager makes it so you only have to remember one password. The rest of them are encrypted and protected by two-factor authentication. A password manager makes it very difficult for a cybercriminal to gain entry to your accounts, thus keeping them safe. 

Boost Your Smartphone Confidence 

With just a few simple steps, you can feel better about the security of your smartphone, cellphone number, and online accounts. If you’d like extra peace of mind, consider signing up for an identity theft protection service like McAfee Identity Protection Service. McAfee, on average, detects suspicious activity ten months earlier than similar monitoring services. Time is of the essence in cases of SIM swapping and other identity theft schemes. An identity protection partner can restore your confidence in your online activities. 

1T-Mobile data breach and SIM-swap scam: How to protect your identity 

The post What Is SIM Swapping? 3 Ways to Protect Your Smartphone appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

The Bug Report – November Edition

Your Cybersecurity Comic Relief 

CVE-2021-20322: Of all the words of mice and men, the saddest are, “it was DNS again.” 

Why am I here? 

For all our newcomers, welcome to the Advanced Threat Research team’s monthly bug report – a digest of all the latest and greatest vulnerabilities from the last 30-ish days based on merits just a tad more nuanced than sorting NVD by “CVSS > 9.0.” Instead, we focus on qualitative and experience-based analysis, relying on over 100 years of combined industry experience within our team. 

To those who are returning after having read last month’s issue, I would like to congratulate you for being a Bug Report fan before it was cool – which it now most assuredly is, thanks in no small part to a litany of fascinating vulnerabilities. We encourage our veterans to stick around as long as possible, so that a year from now you can complain about how we’re washed up and how much better our early editions were. 

PAN GlobalProtect VPN: CVE-2021-3064 

What is it? 

Palo Alto Networks (PAN) firewalls that use its GlobalProtect Portal VPN running PAN-OS versions older than 8.1.17 are vulnerable to a cutting-edge, state-of-the-art style of vulnerability known as a “stack-based buffer overflow.” Although the vulnerable code is normally not reachable, when combined with an HTTP smuggling vulnerability, CVE-2021-3064 can be used to gain remote code execution, a remote shell, and even access to sensitive configuration data according to Randori Attack Team researchers. Randori discovered the vulnerability over a year ago but chose not to disclose it to PAN until September of this year, using it as part of its “continuous and automated red team platform” during the interim – I suppose we should be thankful that PAN has claimed in its security advisory that no evidence of exploitation of this vuln has been discovered, despite its age. 

Who cares? 

Absence of “in-the-wild” exploitation aside, we should also be grateful that the number of people who should care is rapidly dwindling (an ever-present theme of 2021). Randori initially reported over 70,000 internet-accessible PAN firewalls running vulnerable versions of PAN-OS according to Shodan, which it later amended to 10,000. As of this writing, that number has fallen to around 7,000. Even so, 7,000 vulnerable firewalls mean an even larger number of vulnerable clients at risk of an over-the-internet attack vector requiring zero authentication. Those connecting to PAN firewalls running on VMs have even greater cause for concern as these lack ASLR, a factoid I have chosen to add to my ever-growing “why is that a thing” list, right next to the Ghostbusters remake. 

What can I do? 

We suggest an experiment: open the Shodan search linked above and note the total number of devices running a vulnerable version of PAN-OS. Next, call up whoever manages your firewall and demand they power it down immediately – use threats if you must. Check the Shodan scan again: has the number gone down? If so, it’s probably time to update. If you’re an Arch user and the prospect of updating terrifies you, Palo Alto has also indicated that its signatures for Unique Threat IDs 91820 and 91855 should block exploitation of CVE-2021-3064. 

The Gold Standard 

Be sure to stay up to date on the latest CVEs – our security bulletins are a great resource for finding product information for all kinds of critical vulnerabilities. 

Linux Kernel: CVE-2021-20322 

What is it? 

Researchers at the University of California, Riverside have discovered a flaw in the way the Linux kernel handles “ICMP fragment needed” and “ICMP redirect” errors, allowing an attacker to quickly learn the randomized port number assigned to a UDP socket. What this description fails to convey is the big picture impact of this vulnerability, which is its use as a side-channel for the now-prehistoric DNS cache poisoning attack, in which an off-path malicious actor ‘poisons’ a DNS resolver’s cache with a false record, mapping a known domain (google.com) to an IP address of their choosing (98.136.144.138). Truly nefarious. 

Who cares? 

To be frank, just about everyone should be at least raising an eyebrow at this one. Although the researchers have indicated in their whitepaper that this particular side-channel only affects about 13.85% of open resolvers on the internet, it’s important to note that various security services rely on proof of domain ownership, including even the issuing of certificates, making the impact tremendous. Users of popular DNS service Quad9 have particular cause for concern, as the paper claims it falls under the vulnerable 13.85%. Linux users should also be concerned, and not just because their drivers refuse to work – DNS software such as BIND, Unbound, and dnsmasq running on their platform of choice are also vulnerable. 

What can I do? 

This is where things get tricky. DNS extensions that were standardized over two decades ago, such as DNSSEC and DNS cookies, should successfully mitigate this and all other DNS cache poisoning attack side channels. The unfortunate reality is that these features see very limited adoption due to backwards-compatibility concerns. While we wait for these dinosaurs holding back progress to die out, the authors of the aforementioned whitepaper have suggested some alternative mitigations, including enabling the IP_PMTUDISC_OMIT socket option, introducing additional randomization to the structure of the DNS exception cache, and configuring DNS servers with a singular default gateway to outright reject ICMP redirects. Further details can be found in section 8.4 of their paper. 

The Gold Standard 

Unfortunately, not every vulnerability can be adequately addressed by network security products, and this vulnerability happens to be one of those cases. Your best bet is to follow the mitigations mentioned above and keep your servers up to date. 

Just About All DRAM: CVE-2021-42114 aka Blacksmith 

What is it? 

Blacksmith, a name referring to both the vulnerability and the fuzzer created to exercise it, is a new implementation of the Rowhammer DRAM hardware vulnerability from 2014. The crux of Rowhammer is the use of high frequency read operations to induce bit flips in neighboring regions of physical memory, which can lead to the crossing of any security barrier if the attacker can massage memory so that critical data is stored in a vulnerable physical page. Modern DRAM hardware uses a technology called Target Row Refresh (TRR) to prematurely refresh regions of physical memory targeted by common Rowhammer attacks. Researchers at ETH Zurich and their associates discovered that TRR exploits the uniform nature of memory accesses used by existing Rowhammer attacks to “catch” them, and so devised a Rowhammer attack that used non-uniform accesses, arriving at CVE-2021-42114, which bypasses TRR and all other modern Rowhammer mitigations. 

Who cares? 

Everyone. Just about every common electronic device you can think of uses DRAM and of the DIMMs (RAM sticks) testedthe researchers did not find a single one that was completely safe. It might be easy to presume that hardware vulnerabilities such as this are academically fascinating but have little real-world impact, but research published since 2014 has shown Rowhammer attacks successfully escape JavaScript containers in the browsercross VM boundaries in the cloud, and even achieve RCE across networks with high enough throughput. Perhaps the greatest tragedy of Blacksmith is that it arrived a month too late – it would have fit in perfectly with Halloween monsters like Freddy Krueger or Jason Voorhees who also see new iterations every few years and refuse to stay dead. 

What can I do? 

Hide your PC, hide your tablet, and hide your phone, ‘cause they’re hammerin’ everybody out there. Beyond that, there’s not much to be done besides wait for JEDEC to develop a fix and for DRAM manufacturers to begin supplying hardware with the new standard. 

The Gold Standard 

We at McAfee Enterprise are doing everything in our power to address this critical vulnerability. In other words, we’ll be waiting for that JEDEC fix right along with you. 

The post The Bug Report – November Edition appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Business School Dean Guilty of Data Conspiracy

Business School Dean Guilty of Data Conspiracy

The former dean of a business school in Philadelphia has been found guilty of involvement in a fraudulent scheme to doctor program rankings using false data.

Moshe Porat, of Bala Cynwyd, Pennsylvania, was dean of Temple University’s Richard J. Fox School of Business and Management for more than two decades, from 1996 until 2018.

On Monday, a jury found 74-year-old Porat guilty of scheming to deceive the school’s applicants, students, and donors into believing that the school offered top-ranked business degree programs, so that they would pay tuition and make donations to Temple.

“This case was certainly unusual, but at its foundation it is just a case of fraud and underlying greed,” said US Attorney Jennifer Arbittier Williams.

From 2014 to 2018, Porat colluded with Fox professor Isaac Gottlieb and a Fox employee named Marjorie O’Neill to give false data to US News & World Report about the school’s online MBA (OMBA) and part-time MBA (PMBA) programs.

Among other things, the conspirators lied about the number of Fox’s OMBA and PMBA students who had taken the Graduate Management Admission Test, the average work experience of Fox’s PMBA students, and the percentage of students who were enrolled part time.

Based on the false data, US News ranked Fox’s OMBA program number one in the country four years in a row (2015–2018) and upped the school’s PMBA program ranking from 53 in 2014 to 20 in 2015, to 16 in 2016, and to 7 in 2017.

“Porat boasted about these rankings in marketing materials directed at potential Fox students and donors. Enrollment in Fox’s OMBA and PMBA programs grew dramatically in a few short years, which led to millions of dollars a year in increased tuition revenues,” said the US Attorney’s Office for the Eastern District of Pennsylvania. 

Porat was charged in April with one count of conspiracy to commit wire fraud and one count of wire fraud. He was convicted of both counts on Monday. Porat now faces a fine of $500K and a maximum custodial sentence of 25 years.

Gottlieb and O’Neill are each charged with one count of conspiracy to commit wire fraud. 

Stephen Orbanek, a university spokesperson, said in a statement to The Temple News: “The evidence presented at the trial speaks for itself but is not representative of Temple or the overwhelming majority of the thousands of educational professionals serving our students.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Texas School District to Scan Children’s Devices

Texas School District to Scan Children’s Devices

A school district in East Texas is going to start scanning the digital devices used by its students to find out what they have been saying to and about one another. 

Longview Independent School District (Longview ISD) has partnered with technology and web-hosting company Gaggle to scour district-issued devices and student emails for a particular set of keywords. With Gaggle’s software, the keywords can be detected and reported to school administrators. 

The district says that the purpose of the virtual searches is to whittle out cyber-bullies and identify students with mental health issues. 

Francisco Rojas, public information officer for Longview ISD, told CBS: “Mental health issues are on the rise. And we have to keep up with it, we have to be proactive instead of reactive.”

An expenditure of $60,000 for the Gaggle software system was approved by the Longview Independent School District Board of Trustees during a meeting held on November 8. Funding for the software was gathered from the administrative and pupil services budget. 

In a statement released November 8, the Longview ISD trustees said: “The software protects students and ensures their well-being by informing administrators of incidents of cyber-bullying, self-harm, threats, or any inappropriate behavior taking place on district-issued devices and student emails.”

Gaggle scanning will begin in the Longview ISD middle and high schools on December 9. The company says its software scanning system is in use in over 1,500 districts. 

“We expect this to be a tool available to help our students and staff 24/7 who might be dealing or battling with mental health issues,” said Rojas. “We expect this to be an extra pair of eyes, an extra pair of ears and hands for our school district.”

According to a 2018 study by the Pew Research Center, more than 59% of teenagers in the United States have experienced bullying or harassment online. Name-calling was the most common type of harassment, and it was experienced by 42% of teens.

Around a quarter of teens said that they had been sent unrequested sexually explicit images, while around a third said that false rumors had been started about them online. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Clearview AI to be Fined $22.6M for Breaching UK Data Protection Laws

Clearview AI to be Fined $22.6M for Breaching UK Data Protection Laws

American facial recognition company Clearview AI is facing a fine of just over £17m ($22.6m) for alleged “serious breaches” of the UK’s data protection laws. 

The UK’s Information Commissioner’s Office (ICO) announced the planned penalty yesterday and issued a provisional notice to Clearview to stop processing personal data taken from UK residents and to delete any such data in its possession.

The announcement follows a joint investigation by the ICO and the Office of the Australian Information Commissioner (OAIC), which found Clearview AI in breach of Australian privacy laws.

Clearview claims to have the largest known database of facial images, with more than 10 billion images sourced from public-only web sources, including news media, mugshot websites, public social media, and other open sources. ​

The company pitches its web-based intelligence platform, powered by facial recognition technology, as a tool that helps law enforcement “generate high-quality investigative leads.”

Users can upload an image of a suspect’s face and search for matching images that appear online. 

“The images in Clearview AI Inc’s database are likely to include the data of a substantial number of people from the UK and may have been gathered without people’s knowledge from publicly available information online, including social media platforms,” stated the ICO. 

In its preliminary findings, the ICO accuses Clearview of multiple failures to comply with UK data protection laws. The company’s alleged crimes include failing to process the information of people in the UK in a way they are likely to expect or that is fair; failing to have a process in place to stop the data’s being retained indefinitely; and failing to have a lawful reason for collecting the information.

Clearview’s service was used on a free-trial basis by several UK law enforcement agencies, but it is no longer offered in the country.

“UK data protection legislation does not stop the effective use of technology to fight crime, but to enjoy public trust and confidence in their products technology providers must ensure people’s legal protections are respected and complied with,” said the UK’s information commissioner, Elizabeth Denham.

Clearview dismissed the ICO’s allegations as “factually and legally incorrect.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Accenture to Create 3000 Tech and Cyber Jobs in the UK

Accenture to Create 3000 Tech and Cyber Jobs in the UK

Accenture has unveiled plans to create 3000 new tech roles in the UK over the next three years. Many of these will be related to information security, with the consulting firm confirming that the new jobs are being driven by increased demand for services in platforms, cloud engineering, cybersecurity, data and intelligent operations.

It is hoped that Accenture’s announcement will encourage more people to enter the cybersecurity sector and help close the cyber skills gap, which has risen by more than a third in the past 12 months in the UK, according to a recent study. Commenting on the news, John Fokker, head of cyber investigations for McAfee Enterprise’s Advanced Threat Research team, said: “It’s promising to see Accenture’s initiative to create thousands of new cybersecurity roles over the next three years. Not only will this help to raise awareness of the skills needed to succeed in a cybersecurity role, it will also help the industry take a step towards closing the cybersecurity skills gap. This will be particularly important in bolstering security teams when things get busy, with our research telling us that 75% of organizations struggle to maintain a fully staffed security team during peak periods.

“As well as creating new jobs, we can strive to close the skills gap by encouraging those interested in IT or cybersecurity as early as possible and provide a school pathway into the industry.”

The new positions will add to Accenture’s current UK workforce, which stands at around 11,000 people. Encouragingly for the UK government’s ‘leveling up’ agenda, half of these roles will be based outside of London, in Newcastle, Manchester, Leeds, Edinburgh and Glasgow.

UK Business Secretary Kwasi Kwarteng commented: “Today’s announcement is a huge vote of confidence in UK plc and shows that, backed up by a skilled workforce, the UK remains one of the best locations to expand and grow a business. This expansion by Accenture is a great example of the kind of digitally focused, high-skilled jobs that will help level up economic growth across the whole of the UK and help us build back better.”

Digital Secretary Nadine Dorries added: “It’s fantastic to see Accenture creating thousands of new high-skilled jobs in a number of our regional tech hubs. This investment is testament to the UK’s global reputation for innovation and talent. We’re determined to level up opportunity across the country and are investing in people’s digital skills and digital infrastructure so businesses can thrive.”

The announcement has followed a number of recent acquisitions by Accenture that have added to its cybersecurity portfolio. These include Symantec’s Cyber Security Services business and Context Information Security in 2020 and Sentor in June 2021.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK and Israel Pledge Greater Cooperation in Cybersecurity

UK and Israel Pledge Greater Cooperation in Cybersecurity

The UK and Israel have signed a new agreement promising increased cooperation in cybersecurity.

The 10-year ‘memorandum of understanding’ was signed yesterday (November 29) in London by UK Foreign Secretary Liz Truss and Israeli Foreign Minister Yair Lapid. Among the provisions is a pledge to forge a closer alliance on cyber and tech, to “help to ensure that future standards on new technology are shaped by democratic nations.”

In a joint article published in the Daily Telegraph, Truss and Lapid said the two countries will “work closer” to defend themselves in cyberspace. In addition, Israel will become a tier one cyber partner for the UK, enabling them greater access to the UK’s market. The pair added that “our partnership will keep us at the forefront of the technological revolution.”

The pact follows numerous warnings from Western government officials that liberal democracies need to work together to ensure the internet is open and secure, countering attempts by countries like China and Russia to limit access and maximize control.

However, the UK and Israel agreement has drawn criticism due to controversies surrounding Israeli spyware developer NSO Group. Last week, Apple announced it is the latest tech giant to sue the company following allegations that its Pegasus spyware was installed on the devices of targeted journalists, activists, dissidents, academics and government officials. Earlier this month, NSO Group was added to a US export blacklist designed to prevent it from buying components from American companies.

The joint statement by Truss and Lapid also emphasized that the two countries would work “night and day to prevent the Iranian regime from ever becoming a nuclear power.” Yesterday, Infosecurity reported that last month’s cyber-attack that paralyzed Iran’s gas stations has been attributed to Israel by two unnamed US defense officials.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cyber Essentials Set for Major Update in 2022

Cyber Essentials Set for Major Update in 2022

The UK government’s best practice cybersecurity framework is set to undergo the “biggest overhaul” of its technical controls since it was introduced in 2014, the National Cyber Security Centre (NCSC) has warned.

Cyber Essentials offers a simple set of steps that organizations can sign-up to and be certified against to prevent the most common cyber-threats. It’s available in a basic self-assessment version and a Cyber Essentials Plus scheme requiring hands-on technical verification by a third-party.

It covers areas such as firewalls, secure configuration, access controls and malware protection.

The new version of the program’s technical requirements will be officially released on January 24 2022.

“Any assessments already underway, or that begin before that date, will continue to use the current technical standard, meaning that in-progress certifications will not be affected. Organizations using the current standard will have six months from January 24 to complete the assessment,” the NCSC said.

“All Cyber Essentials applications starting on or after January 24 will use the updated version of requirements. We recognize that some organizations may need to make extra efforts when assessed against the new standards, so there will be a grace period of up to 12 months for some of the requirements.”

After consultation with assessors, applicants and the Cloud Industry Forum, the changes were brought in and are deemed essential to ensuring the program remains relevant amidst a fast-moving technology and threat landscape.

It also signals a more regular review process for the controls in the future, the NCSC claimed.

Among the new requirements are updates in areas such as home working, cloud services, BYOD, think clients and multi-factor authentication.

There’s also a new FAQs page and a technical blog from delivery partner IASME for further information

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ransomware Group Rebrands Multiple Times to Evade Detection

Ransomware Group Rebrands Multiple Times to Evade Detection

A mid-sized ransomware group known for targeting healthcare and education sector organizations has repeatedly rebranded over the past year to avoid scrutiny, according to Mandiant.

The “54BB47h” (Sabbath) group first appeared on the radar in September when it advertised for affiliate partners, the threat intelligence firm said.

Unusually for a ransomware group, it provides these affiliates with their own pre-configured Cobalt Strike Beacon backdoor payloads. While this posed a challenge for Mandiant’s attribution efforts, it also offered a starting point for its investigation.

“Mandiant Advanced Practices began proactively identifying similar Beacon infrastructure across past Mandiant Consulting engagements, Advanced Practices external adversary discovery programs, and commercially available malware repositories,” it explained.

“Through this analysis, Advanced Practices linked the new Sabbath group to ransom activity under previously used names including Arcane and Eruption.”

Further investigation revealed that the Sabbath public disclosure/extortion blog was virtually identical to one associated with Arcane, right down to the same grammatical errors. Affiliate Beacon samples and infrastructure also remained unchanged after the rebrand.

Sabbath, Arcane and Eruption were traced to threat group UNC2190, which “uses a multifaceted extortion model where ransomware deployment may be quite limited in scope, bulk data is stolen as leverage, and the threat actor actively attempts to destroy backups.”

The group has in the past even emailed staff, students and parents of a US school district it targeted in order to force a payment.

Interestingly, among the system languages the code checks for to avoid infecting victims from certain countries are not only former Soviet states but also Swedish, Thai, Turkish, Urdu, Indonesian, Vietnamese and Yiddish.

It seems to indicate the ransomware operators are going to extreme lengths to avoid unwanted police attention.

“UNC2190 has continued to operate over the past year while making only minor changes to their strategies and tooling, including the introduction of a commercial packer and the rebranding of their service offering,” Mandiant concluded.

“This highlights how well-known tools, such as Beacon, can lead to impactful and lucrative incidents even when leveraged by lesser-known groups.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains