—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Author: admin
Ransomware Threats Affecting the Public Sector
In the October 2021 Threat Report, McAfee Enterprise ATR provides a global view of the top threats, especially those ransomware attacks that affected most countries and sectors in Q2 2021, especially in the Public Sector (Government).
In June 2021 the G7 economies urged countries that may harbor criminal ransomware groups to take accountability for tracking them down and disrupting their operations. Let’s review the high severity campaigns and threat profiles added to MVISION Insights recently.
Threat Profile Conti Ransomware & BazarLoader to Conti Ransomware in 32hrs
Conti has been one of the top Ransomware groups in 2021, including a new campaign reported in September 2021. As mentioned earlier in this report, the public sector seems to be the sector most affected by Ransomware attacks. McAfee Enterprise provides regular publications on the strategies to defend against ransomware, such as this blog.
Other Recent Threats Affecting the Public Sector
CVE-2021-40444 Microsoft MSHTML Remote Code Execution Vulnerability
This is a serious Microsoft Office vulnerability reported in September 2021 by Microsoft, McAfee Enterprise and other sources. The MVISION Insights heat map shows the prevalence of the Indicators of Compromise (IOCs) associated with this threat in the first half of October 2021.
Although Microsoft has provided guidance on a workaround, it can be challenging for many public sector organizations to deploy these patches quickly. To help you be more agile, McAfee Enterprise has released its own guidance leveraging ENS, EDR and NSP.
Microsoft Office vulnerabilities are commonly exploited in the early phases of the attack lifecycle. BazarLoader, mentioned earlier with the Conti Ransomware, has also been used with Word and Excel documents. In the MITRE Enterprise ATT&CK framework this technique is known as T1203, which we can find in 177 campaigns and threat profiles in MVISION Insights.
Threat Profile APT41 & APT41 Malware Identified Doing the ChaCha at SAS21
APT41 is a state sponsored threat group linked to China and associated with multiple campaigns, including a new campaign reported in September 2021. Although Ransomware is currently the main cyber threat type which hits the news, state sponsored threat groups are equally concerning, especially in the public sector for organizations with sensitive government and citizen data, which could be potentially exploited by a foreign nation like China.
In the second part of this report, we highlight how you can leverage the data from MVISION Insights to find traces of these attacks to enhance your level of protection.
Cloud Threats Affecting the Public Sector
In the October 2021 Threat Report, McAfee Enterprise ATR also assessed the prevalence of Cloud Threats, identifying the US Government sector as one of the top 10 verticals affected.
Many governments are moving quickly to adopt cloud technologies to bring services for their citizens, for collaboration and cost savings.
Inadequate readiness to address cloud security has been the primary contributor of these threats. Several cloud-native controls exist to protect sensitive data from loss or theft in real time, such as:
- Cloud Native Application Protection Platform (CNAPP) to secure your cloud services
- Secure Access Service Edge (SASE) to secure access to all cloud services
Operationalize Threat Intelligence
In the second part of this report, we want to give you some guidance on how you can operationalize this threat intelligence data to better protect your networks. MVISION Insights can help operationalize McAfee Enterprise Threat Intelligence data by providing risk assessment against threats affecting you, protective guidance and integrating with other tools to share threat data.
Let’s take the previous example of the Conti Ransomware Threat Profile. Below you can see how MVISION Insights provides:
1. A short description with the list of CVEs linked to this threat profile, the minimum version of McAfee Enterprise ENS AMcore content to be correctly protected against this threat, detections in your environment and on which device.
2. The list of related campaigns, the devices with unresolved detections related to these campaigns or those with insufficient protections.
3. The list of MITRE techniques and tools, which provide a universal and agnostic overlay of the threats, as well as details on the observables specific to this threat profile for each MITRE technique.
4. The list of IOCs with filters, IOC attributes, and IOC export features which you can use to share them with your other solutions, such as your SIEM, and which you can also share with other public sector entities. We also provide a direct integration with MVISION EDR. Alternatively, you can leverage the APIs to automate the exchange of IOCs.
If you find devices with these IOCs in MVISION EDR you can take immediate remote actions such as quarantine the device, kill the process, remove the files, or run custom scripts.
You can also use MVISION EDR for more advanced threat hunting such as searching for specific MITRE techniques in all MVISION EDR alerts …
… or in the MVISION EDR monitoring view which automatically groups the alerts.
5. MVISION Insights also provides hunting rules created by McAfee Enterprise Threat Intelligence experts using Yara, Sigma and McAfee Enterprise ENS expert rules.
6. A proactive assessment of your Endpoint and Cloud security posture score with guidance on the configuration changes which you should follow to ensure that your McAfee Enterprise Endpoint and Cloud solutions are protecting you with their full capabilities.
7. And all this, with more than 1,200 threat campaigns and threat profiles
MVISION APIs give you the ability to integrate and to exchange this extensive Threat Intelligence data with your SOC tools, including Threat Intelligence Platforms (TIPs) and Security Orchestration Automation and Response (SOAR).
These integrations can be used both in Internet-facing and closed networks. For advanced Threat Intelligence teams, our Advanced Program Group (APG) provides “Threat Intelligence as a Service” (INTAAS) including:
- Access to the unaggregated raw data behind MVISION Insights
- Access to McAfee Private Global Threat Intelligence (GTI)
- Threat Assessments
- Adversary Monitoring and Attribution
- IOC enrichment
- Reverse Engineering
Summary
To conclude, here is a summary of the use cases you can achieve with MVISION Insights in the public sector:
- Start your threat intelligence program despite a lack of time and expertise
- Improve your existing Threat Intelligence program
- Check whether you have been breached by leveraging McAfee Enterprise ENS and NPS
- Predict threats, including ransomwares, that are most likely going to hit you
- Prioritize threat hunting using the most relevant indicators
- Enrich investigations with MVISION EDR/XDR
- Integrate with your other SOC solutions
- Deliver on-premise Threat Intelligence for restricted networks
- Proactively assess your protection status with McAfee Enterprise ENS and MVISION Cloud
- Improve Zero Trust with Threat Intelligence
If you want to learn more on our Threat Intelligence capabilities and participate in Architecture or Incident Response Workshops, contact your local McAfee Enterprise representative.
The post Ransomware Threats Affecting the Public Sector appeared first on McAfee Blogs.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Digital Transformation Needs to (Re)Start with Security
In life, regret tends to take on many shapes and forms. We often do not heed the guidance of the common anecdotes we hear throughout our days and years. From “look before you leap” to “an apple a day keeps the doctor away” – we take these sayings in stride, especially when we cannot necessarily provide proof of their veracity!
One particular trope that may incite ire, frustration, or regret when applied to enterprise security is – “once bitten, twice shy.”
In its very literal sense, we’re taught that if we’re bitten by something once – whether that be dog or security breach – we’re innately cautious or fearful of falling into a similar scenario. With dogs or any animal, we may pivot our behavior to avoid sharp teeth. However, with security breaches, many enterprises continue to be blindsided by “bites” – despite believing they’ve taken the utmost of caution to protect against them.
There is a clear disconnect between enterprise-preparedness and the severity of today’s threat landscape. We continue to see that no enterprise is immune to threats and breaches, with ransomware campaigns continuing to get more sophisticated and prevalent. We’re also seeing cyber criminals work together, banding as an enterprise themselves sharing common tools and knowledge. This means, as cyber criminals become more business-savvy, operational, and efficient – the enterprises they look to attack need to consistently be one step ahead to anticipate and prevent breaches.
Safety First, Now More Than Ever
The term digital transformation is not new by any means, but it needs to be newly approached through a security-first lens. For successful digital transformation to occur today, major industries need to focus on superior prevention against threats.
It’s time for business leaders to stop focusing on the “breach of the month” and more on building security into the fabric of their organizations so they’re not the next victims. For this to happen, it is imperative to break down silos of threat and information intelligence across the organization, enabling a collaborative, holistic, and strategic approach to securing the business.
Additionally, as we’re seeing more prevalent and sophisticated attacks, enterprises need to lean into the transformative technologies that can keep up with evolving techniques. AI provides for personalization of security – a key advantage as it can prioritize detection and response to allow organizations to focus on growth outcomes instead of spending time recouping lost data, customers, revenue, efficiencies, or more that can come at the expense of a threat or breach.
Placing security at the forefront of strategies can unleash the full potential of what digital transformation can make possible. With this approach and a mindset focused on prevention and cyber-readiness as the catalyst aiding true digital and business transformation, we have the power to turn the headlines around. It is time for enterprises to bite back, and the criminals to shy away.
The post Digital Transformation Needs to (Re)Start with Security appeared first on McAfee Blogs.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
US to Sell $56M in Seized Crypto-currency
US to Sell $56M in Seized Crypto-currency

The United States has announced plans to sell tens of millions of dollars’ worth of seized crypto-currency to compensate victims of fraud.
On Friday, US District Judge Todd Robinson granted a request from the US Department of Justice and the US Attorney’s Office for the Southern District of California for authority to liquidate BitConnect crypto-currency worth approximately $56m.
The digital fortune was amassed by BitConnect’s self-described “number one promoter,” 44-year-old Glenn Arcaro of Los Angeles. United States authorities seized the crypto-currency as the proceeds of crime after Arcaro admitted being involved in an international fraud scheme.
On September 1, Arcaro pleaded guilty to participating in a massive conspiracy to defraud BitConnect investors in the United States and abroad.
Under the scheme, Arcaro and others conned victims out of $2bn. By concealing and misrepresenting the truth on social media, the fraudsters made it appear to investors that BitConnect’s purported proprietary technology (BitConnect Trading Bot and Volatility Software) could generate substantial profits and guaranteed returns, trading on the volatility of crypto-currency exchange markets.
“In truth, BitConnect operated a textbook Ponzi scheme by paying earlier BitConnect investors with money from later investors,” stated the Office of the US Attorney for the Southern District of California.
Special Agent in Charge Eric Smith of the FBI’s Cleveland Field Office said Arcaro had defrauded thousands of individuals worldwide.
The BitConnect case is still actively being investigated by the Federal Bureau of Investigation and the Internal Revenue Service – Criminal Investigation.
Arcaro is scheduled to be sentenced by a federal district court judge in the new year, on January 7. The self-confessed fraudster could receive a maximum prison sentence of 20 years.
Plans to liquidate the crypto-currency to benefit victims of the BitConnect fraud were shared on Tuesday by the Department of Justice’s Office of Public Affairs.
The Office said that the BitConnect scheme is the largest crypto-currency fraud scheme ever charged criminally and the planned liquidation is “the largest single recovery of a crypto-currency fraud by the United States to date.”
All potential victims of the BitConnect scheme are advised to visit https://www.justice.gov/usao-sdca/us-v-glenn-arcaro-21cr02542-twr.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
DDoS Attacks Surge 35% in Q3 as VoIP is Targeted
DDoS Attacks Surge 35% in Q3 as VoIP is Targeted

Security experts have warned of a surge in distributed denial of service (DDoS) attacks in the third quarter, with quantity, size and complexity all increasing in the period.
The findings come from Lumen’s Q3 DDoS Report, which revealed that the firm mitigated 35% more attacks in the quarter than Q2 2021.
The vendor claimed that the largest bandwidth attack it tackled during the period was 612 Gbps — a 49% increase over Q2. The largest packet rate-based attack scrubbed was 252 Mbps — a 91% increase.
Lumen said the longest attack on a customer lasted two weeks, highlighting the potentially crippling impact DDoS can have on an organization. Among the 500 largest attacks, the most frequently attacked verticals were telecoms and software/technology, followed by retail.
For the first time, 28% of multi-vector mitigations involved a complex combination of four different attack types — DNS amplification, TCP RST, TCP SYN-ACK amplification and UDP amplification, the vendor claimed.
September marked 25 years since the first DDoS attack was recorded, with Russian provider Yandex reporting the largest volumetric attack of all time that same month.
However, according to experts, not a great deal has changed over the years in that attacks are still relatively cheap, easy and effective at disrupting victim organizations.
To that end, DDoS-ers have increasingly been using such attacks over recent years to extort ransom payments from their victims.
A report published by Neustar in August claimed that over two-fifths (44%) of organizations had been targeted or fallen victim to a ransom-related DDoS (RDDoS) attack in the previous 12 months.
Lumen director of information security and threat intelligence, Mark Dehus, revealed that attacks are also being aimed at new services such as voice.
“We want businesses to join the fight to protect themselves,” he said. “First, have a solid strategy in place to address all potential security issues. Second, work with an established DDoS mitigation partner — particularly one that can track DDoS botnets and find new sources before they launch an attack.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Organizations More Susceptible to Ransomware Attacks During Weekends and Holidays
Organizations More Susceptible to Ransomware Attacks During Weekends and Holidays

Organizations are significantly more vulnerable to ransomware attacks during weekends and holidays, according to a new study by Cybereason.
Of the 500 UK security professionals included in the survey, 37% admitted their organization does not have specific contingency plans in place to mount a prompt response to a ransomware attack during weekend and holiday periods. This is despite all the respondents being at organizations that had previously suffered a successful ransomware attack.
This lack of preparedness has a significant impact on the capabilities of security teams. For example, over two-fifths (43%) of respondents said they required more time to mount an effective response, and close to a third (31%) indicated they need more time to fully recover from an attack over weekend and holiday periods. This is despite 89% confirming they are concerned about attacks taking place during these times.
In another worrying finding from the report, 71% of security professionals surveyed admitted they have been intoxicated while responding to a ransomware attack on a weekend or holiday. Additionally, over nine in 10 (91%) reported missing a holiday or weekend activity because of a ransomware attack.
Having insufficient security tools and solutions were also blamed for successful ransomware attacks by 43% of respondents. The study found that just 69% of organizations had a next-generation antivirus (NGAV) solution deployed at the time of attack, 42% had a traditional signature-based antivirus (AV) in place and only 36% had an endpoint detection and response (EDR) solution.
Lior Div, chief executive officer and co-founder of Cybereason, commented: “Ransomware attackers don’t take time off for holidays. The most disruptive ransomware attacks in 2021 have occurred over weekends and during major holidays when attackers know they have the advantage over targeted organizations.
“This research proves out the fact that organizations are not adequately prepared and need to take additional steps to assure they have the right people, processes and technologies in place so they can effectively respond to ransomware attacks and protect their critical assets.”
The findings provide further credence to the theory that organizations are significantly more susceptible to cyber-attacks on weekends and holidays. Ahead of Labor Day in the US this year, the FBI and Cybersecurity and Infrastructure Security Agency (CISA) issued a warning that ransomware attacks are more likely to be successful over the periods, as IT incident responders will not be at their desks.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Ghostwriter Disinformation Operation Linked to Belarus
Ghostwriter Disinformation Operation Linked to Belarus

Security researchers have linked the notorious state-sponsored Ghostwriter cyber-espionage and disinformation operation to Belarus for the first time.
An extensive report published yesterday noted threat intelligence and forensics firm Mandiant linked the UNC1151 group with “high confidence” to the Belarusian government. It has been said in the past that UNC1151 provides “technical support” to Ghostwriter.
“This assessment, along with observed Ghostwriter narratives consistent with Belarusian government interests, causes us to assess with moderate confidence that Belarus is also likely at least partially responsible for the Ghostwriter campaign,” the report claimed.
“We cannot rule out Russian contributions to either UNC1151 or Ghostwriter. However, at this time, we have not uncovered direct evidence of such contributions.”
It was thought previously that Ghostwriter was a Russian-sponsored entity. However, joint collaboration on the long-running campaign is possible, given the two countries’ shared goals and close ties, Mandiant said.
The Ghostwriter group had focused its efforts up until 2020 on anti-NATO narratives designed to strain ties between Lithuania, Latvia and Poland. Mandiant said 22 out of the 24 disinformation campaigns it observed fell into this category — including false allegations of the deployment of nuclear weapons, NATO troops spreading COVID-19, and crimes committed by NATO troops.
“The seeming intended effect of these narratives – to erode regional support for NATO – can serve both Russian and Belarusian interests. We note, however, that the campaign has specifically targeted audiences in countries bordering Belarus, whereas Russia has long promoted anti-NATO narratives both in the region and further afield,” the report claimed.
“Specifically, observed Ghostwriter operations, in this time period and through the present, have almost completely excluded Estonia, which notably does not border Belarus but is a Baltic State, NATO member and a relevant component of any concerns about NATO’s security posture on its eastern flank.”
Since August 2020, Ghostwriter has become more obviously aligned to the goals of the Belarus government and its autocratic President Alexander Lukashenko.
These include spreading disinformation about scandals within the ruling parties in Lithuania and Poland and efforts to discredit the Belarusian opposition.
Articles published by Ghostwriter personas in August last year attempted to portray widespread popular protests at the regime as NATO or US-orchestrated in an attempt to de-legitimize them.
Mandiant also claimed that Ghostwriter narratives, especially those critical of neighboring governments, have been featured on Belarusian state television as fact.
It referred to “sensitive technical information,” which locates the UNC1151 operation in Minsk, the Belarusian capital, and links it to the country’s military. These connections have reportedly been confirmed by “separate sources.”
In September, the EU criticized Russia for ongoing attempts by Ghostwriter to steal information and spread disinformation. The group had targeted German politicians in the run-up to the country’s recent elections.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
UK Spooks Handled Record Number of Cyber-Incidents Last Year
UK Spooks Handled Record Number of Cyber-Incidents Last Year

The UK’s National Cyber Security Centre (NCSC) has hailed its world-beating cybersecurity expertise after handling hundreds of incidents and disrupting millions of cyber-attack campaigns over the past year.
The government agency, part of signals intelligence body GCHQ, said it offered wraparound support for a record 777 incidents over the period, including attacks on COVID-19 vaccine research, distribution and supply chains.
That’s an increase of over 7% on the previous year, with a fifth (20%) of cases in total linked to the healthcare and vaccine sectors.
This growth is not necessarily reflective of the volume of serious incidents impacting UK firms but also the NCSC’s increasing capacity and intent to identify threats proactively, it said.
Other wins for the agency included its relatively new Suspicious Email Reporting Service, which accrued 5.9 million reports over the year, leading to the removal of more than 53,000 scams and 96,500 malicious URLs.
The service is part of the NCSC’s Active Cyber Defence program, a mainstay of its work which took down 2.3 million cyber-enabled “commodity campaigns,” 442 phishing campaigns using NHS branding, and 80 malicious NHS apps.
Available to mainly public sector organizations, the program includes Mail Check for DMARC-enabled phishing protection and Web Check and Early Warning services to scan for exposed ports such as RDP, commonly exploited in ransomware attacks.
There’s also a Protective Domain Name System (PDNS) service that blocks connections to known malicious domains, Host-Based Capability for network scanning, and Vulnerability Disclosure Services which encourage reporting of software flaws in government.
“This year we have seen countless examples of cybersecurity threats: from state-sponsored activity to criminal ransomware attacks. It all serves to remind us that what happens online doesn’t stay online — there are real consequences of virtual activity,” said GCHQ director, Jeremy Fleming.
“In the face of rising cyber-attacks and an evolving threat, this year’s NCSC’s Annual Review shows that world-class cybersecurity, enabled by the expertise of the NCSC as part of GCHQ, continues to be vital to the UK’s safety and prosperity.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Fake Ransomware Infection Hits WordPress Sites
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Apple’s Privacy Protection feature – watch out if you have a Watch!
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains