Space ISAC and NY InfraGard to Collaborate on Cybersecurity in Space

Space ISAC and NY InfraGard to Collaborate on Cybersecurity in Space

The Space Information Sharing and Analysis Center (Space ISAC) and the New York Metro InfraGard Members Alliance (NYM-IMA) have agreed to work together to advance the mission of cybersecurity in space. 

A Memorandum of Understanding (MOU) enabling collaboration between the two organizations was signed earlier this month. In a statement released to announce the news, the organizations said that the aim of the partnership was to promote broad-based participation by members of both organizations.

This participation will take the form of enhanced educational initiatives, training of both users and operators, and intelligence-sharing activities in the space domain.

Space ISAC serves to facilitate collaboration across the global space industry. The organization defines its mission as “to enhance the ability to prepare for and respond to vulnerabilities, incidents, and threats; to disseminate timely and actionable information among member entities; and to be the primary communications channel for the space sector with respect to this information.”

To date, Space ISAC has teamed up with a broad range of organizations that spans the entire horizon of the space industry. Collaborations have been set up with organizations in space missions, education and research, space business systems, launch, space systems engineering, payload design, space vehicles, cybersecurity, space communications, intelligence, cloud, the space supply chain, data processing, and more.

“We are delighted to collaborate with the NY Metro InfraGard Members Alliance as a partner in our global space community,” said Erin Miller, Space ISAC executive director.

“We can work together to increase security and resilience in the space sector and anticipate this collaboration will assist with long-term space security.”

Non-profit organization InfraGard is a proactive collaboration between the FBI and the private sector for the protection of United States critical infrastructure. 

“All the Critical Infrastructure sectors are reliant upon the services within space, such as the Global Positioning System (GPS), modern communication networks, and satellite technologies,” said Jennifer Gold, vice president and IT sector chief of NY Metro InfraGard. “The data collected and transmitted in space informs all sectors. 

“In the best interest of our nation, we must secure the vulnerable technology in space to defend against the most consequential cyber-threats.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Data Breach Could Cost Missouri $50M

Data Breach Could Cost Missouri $50M

A data breach that may have exposed the Social Security numbers of tens of thousands of teachers, administrators, and counselors across Missouri could end up costing the Show-Me State $50m. 

The security incident was caused by a flaw in a search tool on a website maintained by the state’s Department of Elementary and Secondary Education. 

A reporter at the St. Louis Post-Dispatch discovered the vulnerability. The newspaper said that while no private information was clearly visible or searchable, teachers’ Social Security numbers were contained in the HTML source code of certain web pages. 

After being notified of the data breach on October 12, the department removed the page that included the search tool. 

Department spokeswoman Mallory McGowin said: “We have worked with our data team and the Office of Administration Information Technology Services Division to get that search tool pulled down immediately, so we can dig into the situation and learn more about what has happened.”

The newspaper estimated that more than 100,000 Social Security numbers were made vulnerable by the flaw. However, the Missouri Commissioner’s Office, in a statement released October 12, said that the personally identifiable information of only three Missouri educators was potentially compromised.

Shaji Khan, a cybersecurity professor at the University of Missouri–St. Louis, described the vulnerability as “a serious flaw” that the cybersecurity industry has known about “for at least 10–12 years, if not more.”

“The fact that this type of vulnerability is still present in the DESE web application is mind boggling!” wrote Khan in an email to the Post-Dispatch.

Speaking at a press conference held on October 14, Missouri Governor Mike Parson said that the journalist who discovered the flaw should face criminal hacking charges.

“Not only are we going to hold this individual accountable, but we will also be holding accountable all those who aided this individual and the media corporation that employs them,” said Parson.

News of how much money it might take to recover from the breach was announced by the governor’s office. The $50m estimate includes the cost of credit monitoring for breach victims and the creation of a call center to handle related inquiries.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Twitter Pulls Account After Argentinian Mega Breach Claims

Twitter Pulls Account After Argentinian Mega Breach Claims

Twitter has suspended the account of an individual who claims to have obtained an ID card database covering the entire population of Argentina.

The hacker behind @aniballeaks claimed to have infiltrated the government’s Registro Nacional de las Personas, or Renaper registry, last month and took to the social media site to publish personal details on over 40 Argentinian celebrities including Lionel Messi.

According to Recorded Future, the individual also posted an ad on a well-known cybercrime forum claiming to have the details of over 45 million Argentinians – including ID card photos, full names, processing numbers and more. These could be used to create false ID cards, they said.

The Argentinian government responded last Wednesday, denying it had been breached and saying the individual was able to obtain access to the 44 celebrities by obtaining a staff member’s VPN password.

“After this preliminary analysis, the specialists confirmed, an unauthorized entry into the systems or a massive leak of data from the agency was ruled out outright,” it concluded.

However, the threat actor told Recorded Future that they do indeed have the full database and plan to release data on a million or two Argentinians to prove it over the coming days.

It remains to be seen whether they have the entire trove or are simply trying to drum up publicity and interest from potential buyers.

In related news, Twitter was also forced this week to suspend several accounts linked to North Korean hackers who have been posing as security researchers.

Google Threat Analysis Group analyst Adam Weidermann claimed that accounts @lagal1990 and @shiftrows13 were “leaning on the hype of zero days to gain followers and build credibility.”

In April, the North Korean group was observed creating a new fake company, website and social media accounts to lure victims interested in collaborating with the fake ‘researchers.’

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

81% of UK Healthcare Organizations Hit by Ransomware in Last Year

81% of UK Healthcare Organizations Hit by Ransomware in Last Year

More than four-fifths (81%) of UK healthcare organizations suffered a ransomware attack in the last year, according to a new study by Obrela Security Industries.

The survey of 100 cybersecurity managers in the health sector found that 38% of UK healthcare organizations have elected to pay a ransom demand to get their files back. However, 44% revealed they had refused to pay a demand but lost their healthcare data as a result.

The study also examined the broader consequences of cyber-attacks on healthcare organizations. Close to two-thirds (64%) of respondents admitted their organization has had to cancel in-person appointments because of a cyber-attack. Even more worryingly, 65% believe that a cyber-attack on their systems could lead to loss of life.

The study comes shortly after it was reported that the death of an infant in the US could be the first recorded fatality caused by ransomware.

George Patsis, CEO of Obrela, commented: “Healthcare organizations hold some of the world’s most sensitive data and our study shows many are completely unprepared for cyber-attacks. Threat actors target valuable confidential data, making healthcare a growing target, and ransomware is steadily picking up pace as today’s cyber-weapon of choice. However, most organizations will not be able to identify a data leakage or a security compromise before it is too late. The security community and the UK Government should use this data as a call to action to step in and assist.”

The survey coincided with Obrela’s Q3 Digital Universe Study, which found there was a 30% increase in attacks on healthcare industry IT infrastructure in Q3 compared to Q2 2021. A significant rise was observed across multiple attack vectors, including email security threats (36%), insider attacks (24%) and perimeter breaches (20%).

Patsis added: “Technology has been evolving very rapidly, and it has become a critical element of modern healthcare, but it has also become a significant part of the attack landscape. What is worrisome is that healthcare technology is often deployed and used without security in mind. Therefore, security professionals must consider that the risk profiles of those organizations are now higher, given the complexity of the underlying infrastructure, as well as the fusion of previously physically and logically separated technologies. In short, we need to act now, otherwise we will witness the loss of human lives.”

There have been numerous high-profile examples of healthcare organizations falling victim to ransomware attacks in 2021. These include the attack on Ireland’s health service, HSE Ireland, in May, which led to a number of hospital appointments being canceled.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Microsoft, Intel and Goldman Sachs Team Up For New Supply Chain Security Initiative

Microsoft, Intel and Goldman Sachs Team Up For New Supply Chain Security Initiative

Microsoft has teamed up with Intel and Goldman Sachs to push for hardware security improvements that could help to mitigate supply chain risks.

Working under the auspices of the non-profit Trusted Computing Group (TCG), the companies have created a new Supply Chain Security work group which will aim to bring in experts from across the tech sphere.

The TCG argued that malicious and counterfeit hardware is particularly difficult to detect as most organizations don’t have the tools or in-house knowledge to do so.

With that in mind, the group will focus on two key areas: 

1) Provisioning to ensure devices can be trusted at every step of the supply chain.

2) Helping companies to recover in the event of an attack.

This is TCG’s sweet spot as it has in the past been instrumental in developing global standards for a hardware-based root of trust.

“For nearly 20 years, TCG has guided the industry in adopting technologies that enable secure computing, with specifications for IoT and embedded systems, PCs and servers, mobile, and storage,” argued Dennis Mattoon, co-chair of the work group and principal software development engineer at Microsoft.

“The supply chain is the one thing that spans all of these verticals and experts from TCG work groups are now coming together to create industry-wide guidance that seeks to make the supply chain more secure.”

A new report published by Acronis yesterday claimed that 53% of global organizations have a false sense of security when it comes to supply chain attacks and trust manufacturers and software providers when they perhaps shouldn’t.

A separate report from BlueVoyant last week claimed that 93% of global firms had suffered a supply chain-related breach over the past year. Furthermore, it said the average number of breaches increased 37% from 2020 to 2021.

Worryingly, the number who admitted they have no way of knowing if an incident has occurred in their supply chain rose from 31% to 38% over the period.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

LightBasin Operation Compromises 13 Global Telcos in Two Years

LightBasin Operation Compromises 13 Global Telcos in Two Years

Researchers have uncovered a “highly sophisticated” two-year espionage campaign against global telcos that has already compromised 13 organizations.

Dubbed “LightBasin” by CrowdStrike, the group UNC1945 was actually uncovered by Mandiant in November last year. At that time, its targets were MSPs and their customers in finance and consulting.

According to CrowdStrike, LightBasin has been active since at least 2016, but the current campaign dates back to 2019.

It revealed that the group used custom tools and “in-depth knowledge” of telecoms networks to compromise its targets.

“Recent findings highlight this cluster’s extensive knowledge of telecommunications protocols, including the emulation of these protocols to facilitate command and control (C2) and utilizing scanning/packet-capture tools to retrieve highly specific information from mobile communication infrastructure, such as subscriber information and call metadata,” it claimed.

Operating with a high level of OPSEC, the group established implants on the Linux and Solaris servers popular in the telecoms sector.

At least one provider was compromised via their GPRS-supporting external DNS (eDNS) servers. The group accessed the organization via SSH from another compromised target, using password spraying techniques for initial compromise.

LightBasin then deployed its own Slapstick PAM backdoor for further access, password theft and persistence. The group used a separate custom tool in another part of the operation, an implant dubbed “PingPong.” This spawned reverse shells and communicated via TCP port 53 with compromised servers in other victim organizations — in an attempt to disguise its activity.

“The key recommendation here is for any telecommunications company to ensure that firewalls responsible for the GPRS network have rules in place to restrict network traffic to only those protocols that are expected, such as DNS or GTP,” the report urged.

If telcos believe they have already been compromised, CrowdStrike recommended a full incident response investigation that extends to all partner systems.

The report described the group not as a nation-state entity but as a “targeted intrusion actor.” However, there are some links to China, and the data it has been stealing would apparently be helpful to signal intelligence.

“Notably, data that is sent to and from the remote C2 is encrypted with the hard-coded XOR key wuxianpinggu507. This Pinyin translates to ‘unlimited evaluation 507’ or ‘wireless evaluation 507’,” it noted.

“The identification of a Pinyin artifact indicates the developer of this tool has some knowledge of the Chinese language; however, CrowdStrike Intelligence does not assert a nexus between LightBasin and China.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains