Sky Slow to Fix Bug in Routers

Sky Slow to Fix Bug in Routers

Entertainment company Sky took more than 17 months to fix a security flaw that impacted roughly six million routers belonging to its customers. 

The DNS rebinding vulnerability was discovered in May 2020 by Raf Fini, a researcher at British cybersecurity company Pen Test Partners

Six router models were affected by the flaw: Sky Hub 3, Sky Hub 3.5, Booster 3, Sky Hub, Sky Hub 4, and Booster 4. 

“It affected users with the default router’s admin password (admin:sky), which was the case for a high percentage of routers,” wrote Pen Test Partners in a blog post

The flaw could have exposed a victim’s home network to the internet, allowing a cyber-criminal to gain direct access to the victim’s computers and devices.

Pen Test Partners criticized Sky’s snail-paced approach to fixing the vulnerability.

“Sky did not prioritize fixing the issue, taking nearly 18 months to fully resolve it, failing to meet numerous deadlines they set themselves,” said Pen Test Partners.

They added: “Despite having a published vulnerability disclosure program, Sky’s communications were particularly poor and had to be chased multiple times for responses.”

Pen Test Partners grew so frustrated with the entertainment company’s apparent lack of action that it eventually reached out to the BBC on August 6 over the matter. 

“Only after we had involved a trusted journalist was the remediation program accelerated,” wrote Pen Test Partners. 

Sky said in an email on October 22 that 99% of the affected routers had been updated. The company has offered to replace affected routers free of charge for its customers. 

“After being alerted to the risk, we began work on finding a remedy for the problem and we can confirm that a fix has been delivered to all Sky-manufactured products,” said Sky.

Commenting on the news, Burak Agca, security engineer at Lookout said: “This situation shows why there has never been a greater need for zero trust networking strategies to be implemented by companies. 

“Understanding whether a network connection has been compromised is critical for data in transit. Zero Trust Network Access (ZTNA) and Cloud Access Security Broker (CASB) services ensure that data and resources are only presented to registered and authenticated users, depending on the type of device and location, and the level of threat exposure.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Brit Admits Role in International Movie Piracy Ring

Brit Admits Role in International Movie Piracy Ring

A British man has admitted being a member of an international video piracy ring that illegally distributed “nearly every movie released by major production studios.”

On Thursday, before United States District Judge Richard M. Berman, George Bridi pleaded guilty to conspiracy to commit copyright infringement, which carries a maximum sentence of five years in prison.

Bridi, who is 52 years old, has been part of Sparks Group – described by Europol as “one of the biggest online piracy groups in the world” – since 2011. 

Sparks Group compromised the copyright protections of TV shows and movies then illegally shared the content online prior to its retail release date.

After lying to DVD and Blu-Ray disc wholesale distributors to obtain copyrighted content ahead of its release, Sparks Group members used specialized software to crack the hardware then reproduce and encode the content in a format that could be easily copied and shared online.

Sparks Group’s piracy operation was dismantled in August 2020 in a coordinated effort by law enforcement authorities in nearly 20 countries that was supported by Eurojust and Europol.

The US Attorney’s Office for the Southern District of New York said that the Group’s activities had “caused tens of millions of dollars in losses to film production studios.”

Bridi was charged along with his alleged co-conspirators Umar Ahmad and Jonatan Correa in an indictment unsealed on August 26 last year.

Bridi’s role in the conspiracy was to arrange for discs to be picked up, mailed, or delivered from distributors located in Manhattan, Brooklyn, and New Jersey to other members of the Sparks Group prior to their official release date.

The Brit also admitted reproducing the discs using computer software that circumvented copyright protections on the discs, and reproducing the copyrighted content for further distribution on the Internet. 

“As he admitted in court today, George Bridi participated in an international video piracy ring that illegally distributed worldwide on the Internet nearly every movie released by major production studios, as well as television shows,” said US Attorney Damian Williams.

“Bridi circumvented copyright protections on DVDs and Blu-Ray discs to illegally share movies online, but he and his crew could not evade law enforcement scrutiny, and Bridi now awaits sentencing for his crime.”

Bridi’s sentencing is scheduled for January 20, 2022.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Charges Two Iranians with Cyber-based Electoral Interference

US Charges Two Iranians with Cyber-based Electoral Interference

The United States has charged two Iranian computer hackers in connection with a cyber-campaign intended to influence the outcome of America’s 2020 presidential election.

An indictment unsealed in New York on Thursday alleges that 24-year-old Seyyed Mohammad Hosein Musa Kazemi and 27-year-old Sajjad Kashian conspired with others to intimidate and influence American voters, undermine voter confidence, and create societal discord.

Starting in approximately August 2020, Kazemi, Kashian, and other co-conspirators allegedly began a four-pronged campaign that included sending threatening emails to voters, hacking into the computer networks of an American media company, and impersonating a far-right organization to cast doubt over the integrity of electoral ballots.

According to court documents, members of the conspiracy exploited a misconfiguration error to gain unauthorized access to one US state’s computer system and download data belonging to more than 100,000 voters. Attempts were allegedly made by the conspirators to compromise 11 state voter websites in total. 

In October, the conspirators allegedly posed as a “group of Proud Boys volunteers” to send Facebook messages and emails to Republican senators, Republican members of Congress, individuals associated with the presidential campaign of Donald J. Trump, White House advisors, and members of the media. 

The message contained claims that the Democratic Party was planning to exploit “serious security vulnerabilities” in state voter registration websites to “edit mail-in ballots or even register non-existent voters.”

It is alleged that the conspirators also impersonated the Proud Boys to send threatening messages to tens of thousands of voters. 

“The emails were sent to registered Democrats and threatened the recipients with physical injury if they did not change their party affiliation and vote for President Trump,” said the Department of Justice’s Office of Public Affairs in a statement released Thursday. 

Kazemi and Kashian are both charged with one count of conspiracy to commit computer fraud and abuse, intimidate voters, and transmit interstate threats, one count of voter intimidation, and one count of transmission of interstate threats.

Kazemi is additionally charged with one count of unauthorized computer intrusion and one count of computer fraud.

Both defendants worked as contractors for Iran-based cybersecurity company Emennet Pasargad, formerly known as Eeleyanet Gostar. Eeleyanet Gostar has provided services to the Iranian government.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#IRISSCON: 12 Ways to Defend and Respond to Cyber-Attacks Effectively

#IRISSCON: 12 Ways to Defend and Respond to Cyber-Attacks Effectively

Best practices to defend and respond to cyber-attacks, drawing on analogies with the COVID-19 pandemic, were set out by Brian Honan, CEO, BH Consulting, during this week’s IRISSCON 2021.

Honan began by warning organizations: “What you put in place to defend or secure your network won’t stop the attackers. It will delay the attackers, but a sophisticated attacker will get by your systems eventually, so what you need to do is design your security to delay them long enough to detect them, so you can respond and kick them back out.”

With this principle in mind, Honan set out the following best security practices for organizations to follow:

  1. Identify Your Key Assets

    In the same way certain products and services were picked out as essential during the COVID-19 pandemic, organizations need to understand what parts of their business are most in need of protection. Then, “make sure you’ve got effective patch management and good cybersecurity hygiene in place to keep everything as secure as can be” in these areas.

  2. Have Effective Anti-Virus

    Honan noted that many organizations he has helped following a cyber-incident “haven’t had effective anti-virus solutions in place,” which in many cases would have prevented the attack. He added that there are many good products out there that can fulfill this function.

  3. Keep Good User Engagement 

    Organizations should look at government messaging around COVID-19 restrictions for inspiration about how to communicate cybersecurity best practices, according to Honan. Examples relating to COVID-19 include ‘stay at home’ and ‘get vaccinated’ – “messages that were repeated over and over again.” As a result, “there are very few people at this stage who don’t know what they should be doing in regard to COVID-19.” However, this is often not the case for cybersecurity, and organizations should educate their user base on how to act securely through simple, repeatable messages.

  4. Good Communication During a Breach

    When an organization falls victim to a cyber-attack, it should strive to be as open and transparent as possible. Honan said a good example of how to communicate clearly was during the ransomware attack on HSE Ireland earlier this year. Here, the CEO gave a TV interview as early as the following morning, “explaining exactly what was going on” in regard to the impact and response. This prevents panic and speculation about what’s happening.

  5. Have Good Filtering in Place

    In another analogy with COVID-19, where the importance of ventilation is well-recognized in helping prevent the virus’ spread, Honan noted that effective filtering at organizations’ endpoints and perimeters are critical in keeping them secure. These include email filtering and web filtering.

  6. Have Good Segmentation 

    Honan acknowledged this is easier said than done, “particularly as many organizations’’ environments have evolved over time.” Nevertheless, he believes it is time to work out how to isolate systems. “If one part of your environment gets compromised, you can lock it down,” he added.

  7. Have Appropriate Incident Response

    Having a practiced plan and processes in place ahead of a cyber-incident underpins an organizations’ ability to deal with it properly. This includes going through the different scenarios that may occur and doing regular exercises to make sure it works. For example, “have you got a press statement ready if you get hit by ransom?” Honan asked. Another aspect is ensuring the organization can respond effectively if an attack takes place during an evening or weekend.

  8. Detect Anomalies and Compromise

    Honan noted that unusual activity in your environment could be a sign of an attack. For example, “is somebody logging in from China at 2.00 am on a Sunday night when they should be logging in from Dublin?” Therefore, having these capabilities is crucial in being able to respond quickly to an attack.

  9. Manage Your Network Traffic

    Organizations should ensure their traffic is going where it should be going. Honan advised analyzing DNS logs for this purpose, as they “will provide you with huge amounts of data, intel and insights into how your network is working and behaving.”

  10. Build Resilience

    Given attacks can still be successful, no matter how secure an environment is, businesses should be asking themselves: “If you get hit by a ransomware attack tomorrow, can your organization stay in business?” Honan gave the example of the attack on Norsk Hydro in 2019, who were able to fall back on old paper-based instructions to keep the aluminum plant functioning while their systems were down.

  11. Apply Patches

    Processes must be in place to apply security patches as soon as they are available, similarly to how vaccines should be taken once offered, commented Honan. While this sounds simple, too often, patches are not applied promptly by organizations.

  12. Business Restoration

    Honan emphasized that organizations must have their own strategy in place to get their business back up and running after an attack and certainly not rely on the attackers to enable this after a ransom payment. For example, Colonial Pipeline paid $4.4m for a recovery key after suffering a ransomware attack earlier this year, yet “ended up using their own backups anyway because the decryption key was badly written.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#IRISSCON: Transition from Cybersecurity to Cyber-Immunity, Says Eugene Kaspersky

#IRISSCON: Transition from Cybersecurity to Cyber-Immunity, Says Eugene Kaspersky

Cyber veteran Eugene Kaspersky outlined the need to transition from cybersecurity to cyber-immunity during a session at this week’s IRISSCON 2021.

Kaspersky, CEO of the Russian-headquartered IT security vendor of the same name, said humanity is entering a new stage of its evolution – the cyber age. In this era, we will become increasingly reliant on digital technology, which will offer huge benefits to individuals and society at large.

However, there are significant barriers to this age. “Unfortunately, we have problems – cybercrime,” stated Kaspersky. He split the types of cybercrime into two main categories: mass cybercrime and targeted attacks.

Mass Cybercrime

Kaspersky described the levels of general cybercrime as “off the scale.” Incredibly, he revealed that Kaspersky detects around 360,000 unique, malicious attacks daily, comprising a mix of automated and “handwoven” attempts. Regarding where the attacks are coming from, Kaspersky noted the most spoken language among cyber-criminals is Chinese, followed by Russian and Spanish/Portuguese.

He added that the perpetrators of these day-to-day threats are junior or mid-level threat actors. This means most threats are not particularly sophisticated and can be prevented by following good cyber-hygiene and security technologies.

However, some of these threat actors are of particular concern. “They are learning, they are exchanging technologies, they’re buying new technologies, and they’re joining cyber-criminal gangs,” explained Kaspersky.

Targeted Attacks

These attacks are generally perpetrated by professional cyber-criminal gangs, of which there are thought to be around 900 in operation throughout the world, according to Kaspersky. “They’re able to develop very sophisticated technologies,” which are deployed on high-value targets. He said the first attack of this nature was undertaken by the Carbanak gang in 2013/14, who infiltrated around 100 banks worldwide, making off with up to $1bn over two years.

Now, we’re seeing “many more gangs who are on the same level or even worse.” Kaspersky said most of these groups are Russian-speaking, and they tend to have the best technical expertise compared to gangs based in other parts of the world. As a result, “it requires more skilled technologists to protect us from these types of attacks.”

Worryingly, as numerous incidents in the past year have demonstrated, these attackers are “slowly shifting to industrial systems.” Kaspersky expects these cyber-criminal gangs to ramp up their targeting of critical infrastructure, and for these systems, “cybersecurity simply doesn’t work.” This is because cybersecurity is a form of risk management, which requires the ability to predict the damage caused by attacks to balance security investment with risks. While this approach works for individuals and ordinary businesses, for critical infrastructures like power grids, healthcare and transport, “the damage is unpredictable,” meaning “cybersecurity doesn’t compensate the risks.”

Transitioning to Cyber-Immunity

Therefore, in respect of critical infrastructure, Kaspersky believes we need to move to a cyber-immunity approach. Describing the difference between the two concepts, he said that while cybersecurity “is a mask over your face,” immunity means developing systems that are secure by design. He added that a system can be defined as immune “if the cost of an attack must be more than the possible damage.”

While acknowledging there are many different ways to build security by design, Kaspersky believes the best approach is an ‘immune platform,’ which his company is developing. Under this concept, all applications and parts of a system are split into micro modules, each of which can only interact through the ‘security layer.’ This security layer checks all permissions. “So it’s kind of a prison for permissions, and every cell is untrusted, but the system itself is trusted,” explained Kaspersky. As a result, if one part of a system is compromised, “it can’t get to the rest of the system,” creating immunity.

Kaspersky admitted the system is less flexible than traditional security systems, but such a strict approach will be essential for protecting critical infrastructure as humanity enters the cyber age. He concluded by saying: “I dream we will get there before I retire!”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Suspected EncroChat Drug Trafficker Faces Trial

Suspected EncroChat Drug Trafficker Faces Trial

A suspected prolific drug trafficker is set to face trial following an international operation to crack a popular encrypted chat network used by criminals, according to the National Crime Agency (NCA).

The UK agency for serious and organized crime revealed that 44-year-old Kamran Butt had been extradited to Germany, where he is now remanded in custody of the Bundeskriminalamt (federal police) awaiting trial.

A Hamburg judge issued a European arrest warrant for Butt in October 2020. He was subsequently found to be living in Woolwich, south-east London

He’s believed to have used the EncroChat platform for several years to arrange “multi-tonne” cocaine shipments from South America to Europe, working with an organized crime gang based in Albania and Germany, according to the NCA.

“Kamran Butt went to great lengths to avoid the attention of law enforcement in Germany and the UK, and is believed to have been using EncroChat to communicate with other members of the crime group,” said NCA deputy director, Andrea Wilson.

“We are determined to do all we can to tackle criminal drugs smuggling networks impacting on the UK, no matter where they are, and this case is a great example of collaborative work between the NCA and our colleagues in the BKA.”

The developers of EncroChat went to great lengths to protect the privacy of their criminal userbase before the network was busted last year.

Operating from servers in France, it was thought to be one of the largest such encrypted comms services around – with 60,000 global users, including 10,000 in the UK, who used it to smuggle contraband, coordinate money-laundering operations and even plan hits on rivals.

It required its own bespoke devices, with camera, mic, GPS and USB ports removed. Devices didn’t require users to link a SIM with their account, and users could remotely wipe the entire handset with a kill code.

Police in the UK arrested hundreds last year after cracking EncroChat. This August, two drug runners were sentenced to a combined 27 years after officers monitored their encrypted communications as part of Operation Venetic.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Malicious PyPl Packages Downloaded 40,000+ Times

Malicious PyPl Packages Downloaded 40,000+ Times

Researchers have discovered 11 new malicious open-source packages using various advanced techniques to avoid detection on the popular PyPl repository.

Python’s official third-party software repository is home to over half a million developers, who typically use pre-built open-source packages to accelerate time-to-market.

However, threat actors are increasingly infiltrating these upstream sources for their own ends.

The JFrog Security research team yesterday revealed it had discovered 11 new malware packages with over 40,000 downloads from PyPl. Their authors used a range of techniques to stay hidden and therefore infect as many users as possible.

These included using the Fastly CDN to disguise traffic sent to their command and control (C2) server as a legitimate communication with pypi.org.

Another technique was to use the TrevorC2 framework to make client-server communications look similar to regular website browsing. According to JFrog, the client sends requests at random intervals and hides the malicious payload into normal-looking HTTP GET requests.

They were also observed using DNS tunneling, a popular technique that uses DNS requests – not normally inspected by security tools – as a communication channel between the victim machine and the C2 server.

In some cases, the malicious packages were split into two – a malicious element designed to steal Discord authentication tokens and a ‘legitimate’ package that doesn’t contain harmful functionality. The latter can be installed through typosquatting or “dependency confusion,” according to the report.

The discovery comes months after the same research team found eight malicious packages that had already been downloaded 30,000 times.

“While this set of malicious packages may not have the same ‘teeth’ as our previous discoveries, what’s notable is the increasing level of sophistication with which they are executed,” they said of the latest find.

“It’s not reaching for your wallet in broad daylight – but there is a lot more subterfuge going on with these packages, and some of them may even be setting up for a follow-up attack after the initial reconnaissance, instead of running a highly-compromising payload to start.”

According to a September Sonatype report, attacks on the upstream software supply chain surged 650% year-on-year.

The PyPl maintainers have now removed the offending packages, according to JFrog.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Less than Half of Consumers Change Passwords Post-Breach

Less than Half of Consumers Change Passwords Post-Breach

There’s a “shockingly high” disconnect between awareness of best practices following a data breach and actions taken, according to a new study from the Identity Theft Resource Center (ITRC).

The non-profit polled over 1000 US consumers to gauge their understanding of and response to breach incidents involving personal information.

The report found that more than half (55%) of social media users have had their accounts compromised in the past, so there’s generally a high level of awareness about what can be done to enhance personal security.

However, nearly a fifth (16%) of respondents said they took no action following a breach. Less than half (48%) changed affected passwords, and only a fifth (22%) changed all of their passwords.

That’s particularly worrying when 85% admitted to reusing log-ins across multiple accounts, putting them at risk of credential stuffing.

“When asked why they don’t use unique passwords, 52% said it’s too difficult to remember their passwords, 48% don’t trust or know how to use password managers, and 46% don’t think it’s important or believe their password practices are good enough,” the report noted.

Just 3% followed best practice advice following a breach notice and put a credit freeze in place to prevent fraudsters running up debts on new lines of credit taken out in victims’ names. Some 11% said they used free credit monitoring services, even though these are of limited use as they don’t block new account fraud, the report revealed.

A quarter (26%) of respondents claimed that they took no action after a breach notice as they believed “my data is already out there,” while slightly more (29%) naively thought third-party organizations would handle the issue.

Nearly a fifth (17%) claimed they didn’t know what to do, while 14% thought the notice itself was a scam.

“Organizations need to review how they notify consumers of data breaches to reduce the level of inaction and improve the credit freeze adoption rates,” argued ITRC president Eva Velasquez. “Also, businesses should recommend to consumers that they reset any passwords that are not unique and offer multi-factor authentication with an app.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

6M Sky Routers Left Exposed to Attack for Nearly 1.5 Years

Pen Test Partners didn’t disclose the vulnerability after 90 days because it knew ISPs were struggling with a pandemic-increased network load as work from home became the new norm.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains