UK Government Orders Phase Two Review into Nvidia-Arm Deal

UK Government Orders Phase Two Review into Nvidia-Arm Deal

The UK government has ordered a phase two investigation into Nvidia’s proposed acquisition of chip designer Arm, citing competition and national security concerns.

The move follows the end of a phase one review into the £40m deal by the Competitions and Markets Authority (CMA) in August, which raised significant competition concerns but did not refer to national security. The report, published in full today, cited “detailed and reasoned submissions from customers and competitors raising concerns” across the globe. This related to the potential of a “substantial lessening of competition across four key markets” – data centers, internet of things, the automotive sector and gaming applications.

Digital Secretary Nadine Dorries has now written to the CMA instructing them to conduct an in-depth phase two investigation into the deal. In addition to competition considerations, Dorries said national security continues to be a relevant consideration and should be investigated further.

Under the Enterprise Act 2002, the UK government has the power to intervene in certain mergers on public interest grounds. The issue in the Nvidia-Arms deal relates to the design and production of semiconductors, which is increasingly seen as strategically critical to countries’ national and financial security. Cambridge-based Arm licenses semiconductor intellectual property, and Arm-based chips are used in a significant proportion of connected devices within homes, cars and businesses, including the vast majority of smartphones.

Dorries commented: “I have carefully considered the CMA’s phase one report into NVIDIA’s proposed takeover of Arm and have decided to ask them to undertake a further in-depth phase two investigation.

“Arm has a unique place in the global technology supply chain, and we must make sure the implications of this transaction are fully considered. The CMA will now report to me on competition and national security grounds and provide advice on the next steps.

“The government’s commitment to our thriving tech sector is unwavering and we welcome foreign investment, but it is right that we fully consider the implications of this transaction.” 

The CMA now has 24 weeks to conduct the phase two investigation and deliver a final report to the Digital Secretary. Once this process is complete, she has two options. The first is to make an adverse public interest finding in relation to the acquisition on national security and/or competition grounds, and if so, take action to remedy any adverse effects. The other would be to make no adverse public interest finding and refer the case back to the CMA to remedy any competition concerns identified.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

China Telecom Appeals Against US Ban

China Telecom Appeals Against US Ban

China Telecom is asking a US appeals court to block regulatory moves designed to ban it from operating in the country on national security grounds.

The FCC issued an order in late October demanding that the telco giant’s American business cease its operations at the start of 2022 in a bid to “safeguard the nation’s telecommunications infrastructure from potential security threats.”

It claimed that the firm’s ownership and control by Beijing raised major security and law enforcement concerns, by potentially enabling the Chinese government to “access, store, disrupt and/or misroute US communications, which in turn allow them to engage in espionage and other harmful activities against the United States.”

The order added: “China Telecom Americas … is subject to exploitation, influence, and control by the Chinese government and is highly likely to be forced to comply with Chinese government requests without sufficient legal procedures subject to independent judicial oversight.”

The FCC also claimed that the firm’s “conduct and representations” to the commission demonstrated “a lack of candor, trustworthiness and reliability.”

However, the Chinese telco, one of the world’s largest by subscriber numbers, reportedly told the US Appeals Court for the District of Columbia on Monday that complying with the order would “irreparably” harm its business and reputation.

It appears to be arguing against the immediacy of the order, claiming that the FCC should first have held an administrative hearing.

The US government has already blocked China Mobile from operating in the country and has begun revoking authorization for China Unicom Americas, Pacific Networks and wholly-owned subsidiary ComNet.

Chinese handset maker Xiaomi has already won a similar case it brought to the US Appeals Court after the Pentagon added it to a list of Communist Chinese military companies (CCMC).

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Government Plans Regulation to Bolster Supply Chain Security

Government Plans Regulation to Bolster Supply Chain Security

Government regulation could be on the way to force improvements in supply chain security after industry feedback and new research pointed to gaps in protection.

Feedback from the government’s call for views in May 2021 confirmed several key barriers for organizations: low recognition of supplier risk; limited visibility into supply chains; insufficient tools to evaluate supplier risk; and “limitations to taking action due to structural imbalances.”

The government trailed several possible “interventions” to improve the situation, including providing more advice and guidance, improved access to a skilled workforce and the right products, and regulation — which was reportedly described as “very effective” by more respondents than any other respondents other option.

IT service providers could in the future be required to follow cybersecurity rules such as the National Cyber Security Centre’s (NCSC’s) Cyber Assessment Framework as part of possible regulation.

The NCSC offers specific Supply Chain Security and Supplier Assurance guidance at present, which could also be built into future requirements.

In addition, the government mooted the prospect of new procurement rules to ensure the public sector buys services from firms with good cybersecurity standards.

The news comes on the day that the government released a new study of chairs, CEOs and directors of Britain’s top companies. It revealed that nearly a third (31%) do not actively manage cyber risks in their supply chain.

A similar number (35%) don’t keep the board informed of such risks or include supply chain risks in written documentation (32%).

A third (34%) of respondents also called for greater awareness-raising, education and training for board members to enhance decision-making on cyber resilience issues.

A quarter (24%) suggested more engagement with third-party experts, while a fifth (21%) claimed regular updates and reports would help.

Supply chain security has become a headline risk in 2021 following significant ransomware attacks, including those on IT software company Kaseya, and state-backed operations such as the SolarWinds compromise.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cryptojackers Disable Alibaba Cloud Security Agent

Cryptojackers Disable Alibaba Cloud Security Agent

Security experts have warned that threat actors are compromising Alibaba Cloud (Aliyun) infrastructure to deploy cryptocurrency mining malware.

The Chinese tech giant is a popular choice for infrastructure-as-a-service (IaaS) in South-East Asia. Yet, cybersecurity software company Trend Micro warned that its Elastic Computing Service (ECS) instances are also an increasingly common target for financially motivated hackers.

Several features of the platform are being targeted by these groups to enhance their chances of success, according to the report.

Although Alibaba ECS comes with a security agent, some actors can uninstall or disable it on compromise. Even if it is still running and detects a malicious script, it is then the customer’s responsibility to take action, said Trend Micro. Customers must take care to configure the product properly, as the default Alibaba ECS instance provides root access.

“In this situation, the threat actor has the highest possible privilege upon compromise, including vulnerability exploitation, any misconfiguration issue, weak credentials or data leakage. Thus, advanced payloads such as kernel module rootkits and achieving persistence via running system services can be deployed,” the researchers wrote.

“Given this feature, it comes as no surprise that multiple threat actors target Alibaba Cloud ECS simply by inserting a code snippet for removing software found only in Alibaba ECS.”

Alibaba ECS also has an auto-scaling feature that automatically adjusts computing resources based on the volume of user requests. However, this can run up additional charges for customers in the background if exploited by cryptomining malware.

Trend Micro noted that such is the popularity among threat actors of Alibaba Cloud and other regional players like Huawei Cloud that it has observed attackers removing rivals from inside compromised infrastructure.

The security vendor urged customers to:

  • Enhance CSP protection with their own third-party malware-scanning and vulnerability detection tools.
  • Practice the principle of least privilege.
  • Customize the security features of cloud projects and workloads.

It claimed to have reached out to Alibaba to respond to its findings but had not heard a reply at the time of publishing.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

FBI Email Hoaxer ID’ed by the Guy He Allegedly Loves to Torment

Vinny Troia, the cybersecurity researcher mentioned in a fake alert gushed out of the FBI’s email system, says it’s just one of a string of jabs from a childish but cybercriminally talented tormentor.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Rooting Malware Is Back for Mobile. Here’s What to Look Out For.

Hank Schless, senior manager of security solutions at Lookout, discusses AbstractEmu, mobile malware found on Google Play, Amazon Appstore and the Samsung Galaxy Store.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains