SolarWinds APT Targets Tech Resellers in Latest Supply-Chain Cyberattacks

The Nobelium group, linked to Russia’s spy agency, is looking to use resellers as a path to infiltrate their valuable downstream customers – and it’s working.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

New York Times Journalist Hacked with NSO Spyware

Citizen Lab is reporting that a New York Times journalist was hacked with the NSO Group’s spyware Pegasus, probably by the Saudis.

The world needs to do something about these cyberweapons arms manufacturers. This kind of thing isn’t enough; NSO Group is an Israeli company.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Staying Cyber Aware and Safer from Ransomware

Ransomware – A truly frightening cyber security topic

It’s October, and at McAfee we love celebrating spooky season. As McAfee’s Chief Technology Officer, I’m also excited that it’s Cyber Security Awareness Month. And while there are no fun-size candy bars, we do talk about some truly bone-chilling stuff when it comes to cyber safety. So gather round, as I tell you all about one of the scariest threats online, ransomware. 

What is Ransomware?

Ransomware is a form of extortion that happens when cyber criminals demand payment. Recently some high-profile companies have been in the news as victims of major ransomware attacks. However, ransomware also impacts individuals, just like you and me. In the individual’s case, a cybercriminal may demand payment to restore access to your device or data or even to prevent them from dumping sensitive or embarrassing information onto the internet. McAfee defends consumers from tens of thousands of ransomware attacks every month. 

What should I do if I’m a victim of ransomware? 

If the worst should happen, take a deep breath and don’t panic. Calmly assessing the situation now can save you a lot of stress later. Ask yourself: 

What data has been compromised?  

  • Look for things like encrypted files on your computer that you can no longer open. 
  • Did the hacker show you an email you don’t believe they should have access to? 

How valuable is the data?  

  • Can you afford to lose this data? 
  • Ideally, your data is backed up on another device or in the cloud so you can regain anything that the criminals have stolen. 
  • Would this data be publicly damaging to you? 

How to avoid making the problem worse 

  • Never accept unsolicited help. This may be the hacker. 
  • Don’t click on pop-ups, links, or emails offering help, as these may also be affiliated with the ransomware. 

Taking action 

Now that you’ve assessed the situation, we can do something about it. 

  • Update all your passwords to lock criminals out of your online accounts. 
  • Make sure all your system software is up to date. 
  • Check that McAfee security is installed and active on all your devices. 

Don’t negotiate with terrorists   

If you can afford to lose your data, and the personal impact is minimal, we always recommend you don’t pay the criminal. There’s no guarantee that if you pay the ransom, you’ll get your data back, and ultimately, you’re incentivizing the cybercriminal to do it again. The best defense against ransomware is to have great cybersecurity habits that prevent the attack from occurring in the first place. 

So, whether you’re enjoying some creepy lawn decorations, or just surfing the web, remember to stay safe out there this Halloween. 

The post Staying Cyber Aware and Safer from Ransomware appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Why an Ounce of Cybersecurity Prevention is Worth a Pound of Detection

Cybersecurity detection is a criminal investigation. Cybercrime investigators are experts who are in limited supply.  Sometimes their hunt begins while an intrusion is in process, but more often than not, it occurs after the attack when a crime has occurred. The investigation is taunting and less glamorous, realizing that it can take an average of 228 days even to identify the breach[i].

At that point, you’re looking to find out what your adversaries have seen or stolen, you want to plug the holes that enabled the hack and kick out or remove the adversary completely. Figure on an average of 80 days to resolve and contain a breach. Meanwhile, your adversary spends the epic dwell time in your environment to monitor your traffic and behavior before determining their next move.

Do the math on that exercise and, unless you have generous funding, you may conclude that your resources stretch further by focusing on prevention rather than detection. While eliminating detection may not be practical, you can at least realign your spending and shore up your prevention efforts with enhanced actionable information.

Several things have happened to make this shift possible. First, detection is now often automated and highly productive. Second, advance warning is better than ever. You can apply predictive analytics to leverage in-depth threat intelligence sources to produce real-time, automated assessments of your security posture risks from device to cloud.

Proactive Threat Hunting

Making the shift from detection to prevention didn’t happen overnight for the Service public de Wallonie (SPW), the public administration arm of the French-speaking regional government of Wallonia in Belgium. SPW’s endpoint security team oversees 9,000 desktops, 1,300 servers, and 1,000 applications used by more than 8,000 employees.

When SPW implemented MVISION Insights, the security team sought to identify potential threats lurking outside the agency’s perimeter. Using data gathered from one billion sensors globally that have been distilled and analyzed by artificial intelligence and human experts, MVISION Insights provides comprehensive risk intelligence filtered for a specific industry and geography. It helps SPW’s security team to prioritize which threats and campaigns are most likely to target them.

Before making this shift, SPW’s team regularly spent hours checking out various security sites, lab reports, and news articles to track the latest threat campaigns. After deploying MVISION Insights, the same result arrived in seconds or minutes. Now they’re engaging in more proactive threat hunting and attack prevention by tapping into predictive assessments and adjusting their posture accordingly.

A Change of Posture

Organizations such as SPW illustrate that playing both offense and defense becomes necessary to reduce time-to-detect and dwell time. Detection is difficult for several reasons, most notably the deluge of advanced persistent threats (APTs). And it’s also complicated by the cost of threat hunting talent, given the current shortage of cybersecurity expertise.

These days there’s such an overwhelming amount of security data pouring into data lakes that manually aggregating and analyzing it to make sense of anything requires a fair amount of threat expertise. Then there’s the time it takes to triage and determine the following steps to thwart an attack. By the time you’re analyzing this data, at best, you’re in a reactive state with limited visibility and understanding of your local environment.

One effective way to streamline that process is to apply the proven MITRE ATT&CK® framework, which provides an excellent knowledge base to help with threat hunting and detection. We use that framework to better inform MVISION XDR powered by MVISION Insights, for example. As we mentioned in March, we align XDR with MITRE to greatly expand the depth of our investigation, threat detection, and prevention capabilities to prevent the attack chain with relevant insights.

Meet the Proactive Evolution Series to Help Become More Preventive

In our leading role in the cybersecurity community, we gather a lot of intelligence and invest considerable time curating content to ensure that what we share is timely, accurate, and valuable. This is reflected in MVISION Insights with over 1000 threat campaign profiles. If you place MVISION Insights in your environment it goes beyond threat intelligence.  You also gain prioritized threat insights on a likely attack targeting you, where your gaps are and what you can do. Introducing our new Proactive Evolution series to get regular information on how to become more preventive and protective with LinkedIn Live discussions, blog posts, and other intelligence from our cybersecurity expert contributors highlighting the power of MVISION Insights.

This new Proactive Evolution Series features helpful content intended for managing or building security operations to be more effective and preventive or for a CISO who wants to stay on top of changing best practices.

Detection is often done in reaction to an attack or a looming threat. Not every organization can do both detection and prevention equally well. That’s usually because they lack dedicated or experienced threat hunters or suitable detection technologies. By shifting your efforts to a proactive prevention strategy, you’re boosting your chances to harden your systems before an attack.

Click here to access McAfee Enterprise’s new Proactive Evolution Series content.

Event Replay

The Proactive Evolution is Now

Understand how the adversary is working and how you stack up against them. Together, Raj and Brett dig into how MVISION Insights helps you determine which active threat campaigns you need to worry about, if you’re a target, and what you can do.

View Now

[1] Ponemon & IBM Research, Cost of Data Breach 2020

The post Why an Ounce of Cybersecurity Prevention is Worth a Pound of Detection appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Conti Ransom Gang Starts Selling Access to Victims

The Conti ransomware affiliate program appears to have altered its business plan recently. Organizations infected with Conti’s malware who refuse to negotiate a ransom payment are added to Conti’s victim shaming blog, where confidential files stolen from victims may be published or sold. But sometime over the past 48 hours, the cybercriminal syndicate updated its victim shaming blog to indicate that it is now selling access to many of the organizations it has hacked.

A redacted screenshot of the Conti News victim shaming blog.

“We are looking for a buyer to access the network of this organization and sell data from their network,” reads the confusingly worded message inserted into multiple recent victim listings on Conti’s shaming blog.

It’s unclear what prompted the changes, or what Conti hopes to gain from the move. It’s also not obvious why they would advertise having hacked into companies if they plan on selling that access to extract sensitive data going forward. Conti did not respond to requests for comment.

“I wonder if they are about to close down their operation and want to sell data or access from an in-progress breach before they do,” said Fabian Wosar, chief technology officer at computer security firm Emsisoft. “But it’s somewhat stupid to do it that way as you will alert the companies that they have a breach going on.”

The unexplained shift comes as policymakers in the United States and Europe are moving forward on efforts to disrupt some of the top ransomware gangs. Reuters recently reported that the U.S. government was behind an ongoing hacking operation that penetrated the computer systems of REvil, a ransomware affiliate group that experts say is about as aggressive and ruthless as Conti in dealing with victims. What’s more, REvil was among the first ransomware groups to start selling its victims’ data.

REvil’s darknet victim shaming site remains offline. In response, a representative for the Conti gang posted a long screed on Oct. 22 to a Russian language hacking forum denouncing the attack on REvil as the “unilateral, extraterritorial, and bandit-mugging behavior of the United States in world affairs.”

“Is there a law, even an American one, even a local one in any county of any of the 50 states, that legitimize such indiscriminate offensive action?” reads the Conti diatribe. “Is server hacking suddenly legal in the United States or in any of the US jurisdictions? Suppose there is such an outrageous law that allows you to hack servers in a foreign country. How legal is this from the point of view of the country whose servers were attacked? Infrastructure is not flying there in space or floating in neutral waters. It is a part of someone’s sovereignty.”

Conti’s apparent new direction may be little more than another ploy to bring victim companies to the negotiating table, as in “pay up or someone will pay for your data or long-term misery if you don’t.”

Or maybe something just got lost in the translation from Russian (Conti’s blog is published in English). But by shifting from the deployment of ransomware malware toward the sale of stolen data and network access, Conti could be aligning its operations with many competing ransomware affiliate programs that have recently focused on extorting companies in exchange for a promise not to publish or sell stolen data.

However, as Digital Shadows points out in a recent ransomware roundup, many ransomware groups are finding it difficult to manage data-leak sites, or hosting stolen data on the dark web for download.

After all, when it takes weeks to download one victim’s data via Tor — if indeed the download succeeds at all — the threat of leaking sensitive data as a negotiation tactic loses some of its menace. It’s also a crappy user experience. This has resulted in some ransomware groups exposing data using public file-sharing websites, which are faster and more reliable but can be taken down through legal means quite quickly.

Data leak sites also can offer investigators a potential way to infiltrate ransomware gangs, as evidenced by the recent reported compromise of the REvil gang by U.S. authorities.

“On 17 Oct 2021, a representative of the REvil ransomware gang took it to a Russian-speaking criminal forum to reveal that their data-leak sites had been ‘hijacked’,” Digital Shadows’ Ivan Righi wrote. “The REvil member explained that an unknown individual accessed the hidden services of REvil’s website’s landing page and blog using the same key owned by the developers. The user believed that the ransomware gang’s servers had been compromised and the individual responsible for the compromise was ‘looking for’ him.”

A recent report by Mandiant revealed that FIN12 — the group believed to be responsible for both Conti and the Ryuk ransomware operation — has managed to conduct ransomware attacks in less than 3 days, compared to more than 12 days for attacks involving data exfiltration.

Seen through those figures, perhaps Conti is merely seeking to outsource more of the data exfiltration side of the business (for a fee, of course) so that it can focus on the less time-intensive but equally profitable racket of deploying ransomware.

“As Q4 comes near, it will be interesting to see if issues relating to managing data leak sites will discourage new ransomware groups [from pursuing] the path of data-leak sites, or what creative solutions they will create to work around these issues,” Righi concluded. “The Ryuk ransomware group has proven itself to remain effective and a top player in the ransomware threat landscape without the need for a data-leak site. In fact, Ryuk has thrived by not needing a data leak site and data exfiltration.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

New Cybersecurity World Record Set

New Cybersecurity World Record Set

A new Guinness World Record in cybersecurity training has been set by a cloud-based identity and access management (IAM) provider, a security awareness training platform, and a PR firm. 

The first-of-its-kind record was for the most views of a virtual cybersecurity lesson in 24 hours, and it was achieved on October 14 through the joint efforts of OneLoginKnowBe4, and Eskenzi PR.

Security expert and global data protection officer at OneLogin, Niamh Muldoon, and Javvad Malik, lead security awareness advocate at KnowBe4, presented the record-breaking lesson about ransomware prevention. 

“Niamh and Javvad provided their expertise on ransomware prevention and table-top exercises before opening the session for Q&A with the viewers,” said Eskenzi PR’s Paula Brici. 

She added: “The objective of the training was to bridge the gap between security professionals and the rest of the workforce.”

The hour-long lesson was hosted and recorded via Zoom and made accessible to the public via YouTube Live for 23 hours. Guinness World Records stipulated that a minimum of 1,500 views were needed at the end of the 24 hours for a new record to be officially recorded. 

Within the timeframe set for the world-record attempt, the educational content comfortably earned its place in history, logging a total of 2,136 views. Guinness World Records adjudicator Richard Stenning was present to validate the record attempt and gave his seal of approval that a new record had been achieved.

“I’m delighted to have the opportunity to share my knowledge of security incident response with such a large audience, and to have an opportunity to shine a much-needed light on cybersecurity, and the devastating impact these incidents can have on an organization,” said Muldoon. 

Malik said: “Security awareness is an essential skill for today’s digitally connected world. And what better way to help spread the message than delivering a free session and setting a world record at the same time.” 

He added: “Having followed Guinness World Records from a young age, being involved in a record-setting attempt is something I never imagined I would be part of.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Nebraska Issues First Federal Cyber-stalking Sentence

Nebraska Issues First Federal Cyber-stalking Sentence

The first ever person to be convicted of cyber-stalking in the District of Nebraska has been sentenced to federal prison.

Dennis Sryniawski, a 48-year-old resident of Bellevue, was charged with intent to extort and cyber-stalking his former girlfriend, Diane Parris, in an attempt to prevent her husband, Jeff Parris, from being elected to the Nebraska legislature. 

A jury convicted Sryniawski on only the cyber-stalking charge in June 2021, after a three-day jury trial. Evidence presented at trial showed that Sryniawski had used two different email accounts to send six emails on two different days to the legislature candidate.

One email was sent under Sryniawski’s name, but the others were delivered under names that the cyber-stalker had invented. 

“The initial email contained personal details about the candidate’s wife and accusations concerning the candidate’s stepdaughter, and a later email included explicit photos purportedly of each,” said the US Attorney’s Office for the District of Nebraska in a statement issued Thursday.

The explicit photographs of Diane Parris had been taken with her consent more than two decades ago, when she and Sryniawski were romantically involved. But Parris never consented to the images’ being shared. 

In the emails, Sryniawski threatened the candidate and told him to quit the electoral race. The victim was told that the personal details and explicit photos of his wife and stepdaughter would be released if he did not withdraw his candidacy.

Jeff Parris refused to comply with the demands; however, his bid to join the Nebraska legislature was ultimately unsuccessful. 

Sryniawski asked to receive probation for his crime, citing his voluntary work and prior military service. However, on October 21, United States District Judge Brian Buescher sentenced the cyber-stalker to twelve months and one day in prison, to be followed by three years of supervised release. 

The offender was also ordered to pay a fine of $10,000 out of a possible maximum of $250,000. 

“The egregious nature of that conduct, its effect on the victims, the need to deter others and the defendant’s lack of remorse overcome any mitigation and support a sentence within the advisory guidelines,” said US Attorney Jan Sharp.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Secret Service Announces Cyber Games Winner

US Secret Service Announces Cyber Games Winner

A team of law enforcement officials from South Carolina has seized first place in a nationwide cybersecurity contest.

More than 200 teams from across the United States participated in the National Computer Forensics Institute’s (NCFI’s) Training and Cyber Games competition, which took place earlier this month.

During the event, teams of NCFI-trained local law enforcement officials joined forces with Secret Service investigators to form integrated response units. 

The units were tasked with solving a simulated cyber-attack using the specialized cybersecurity training they had received at the institute. 

“Beginning October 18, participants were presented with the simulated scenario of a ransomware attack on a hospital and charged with executing a series of technical actions to disrupt and hunt the cyber threat actors,” said a Secret Service spokesperson.

“The teams were stationed across the country within Secret Service field office locations for the competition and charged with objectives to recover and examine network evidence in an immersive virtual ransomware investigation experience.”

In a news release issued October 21, the United States Secret Service announced that first place had been awarded to a team from South Carolina’s state capital, Columbia. 

The winning group comprised representatives from the Secret Service, the 125th Cyber Protection Battalion for the South Carolina Army National Guard, the FBI Columbia field office, the South Carolina Law Enforcement Division (SLED), and the Lexington County Sheriff’s Department. 

Over the three days of the competition, this victorious blend of federal and state talent completed all 39 of the challenge’s objectives in a combined time of six hours and 15 minutes. 

“One of the hallmarks of our success as an agency in investigating complex criminal activity in cyberspace is our law enforcement partnerships that span the entire country,” said Secret Service Office of Investigations Assistant Director Jeremy Sheridan. 

“I am grateful to and proud of the integrated federal and state teams who participated in standing with us in this important and ever critical fight and remain thankful four our partners in Alabama and especially the City of Hoover who continue to make these efforts possible by hosting the NCFI facility.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

FOI Request Reveals Scale of Data Breaches at UK Councils

FOI Request Reveals Scale of Data Breaches at UK Councils

UK councils have been hit by a staggering 33,645 data breaches caused by human error in the past five years, according to official figures.

The data, which was obtained following a Freedom of Information (FoI) request sent by VPNOverview to 103 county councils in the UK, also broke down the number of breaches suffered by each body. The local authority with the worst record for human-caused data breaches was Hampshire County Council, with 3759 incidents since 2016. This included 902 breaches in the year 2018/19.

Gloucestershire County Council had the next worst record, suffering 2723 breaches in this period. It also experienced the largest increase from 2016/17 (90) to 2020/21 (1004) of any UK council, a rise of 1016%.

Gloucestershire was followed by Lancashire (1260), Warwickshire (1252), East Sussex (1250) and Norfolk (1226). It was also noted that Lancashire did not have figures available for the year 2016/17.

In contrast, several councils experienced an extremely low number of data breaches caused by human error, with Armagh, Banbridge and Craigavon Borough (4) and Mid and East Antrim Borough (6) recording single digits. Derry City and Strabane District Council and Mid Ulster District Council – Dungannon recorded 10 data breaches over the five years.

The local authority with the most improved record over the period was Essex County Council, which achieved an 86% reduction in breaches from 2017/18 to 2020/21.

The figures are worrisome considering the highly sensitive data local authorities hold on citizens. This point has been raised by David Janssen, a cybersecurity analyst at VPNOverview: “Next time you’re thinking of applying for planning permission or even just asking for a second recycling bin – be aware of who you’re giving your data to and how it’s going to be handled.”

Several UK local authorities have experienced damaging cyber-attacks recently. These include Redcar & Cleveland Borough Council, which caused online public services to be unavailable for 135,000 locals for over a week, and Hackney Borough Council in London, after which sensitive data about staff and citizens was allegedly published on the dark web.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains