Missouri Vows to Prosecute ‘Hacker’ Who Informed State About Data Leak

Missouri Gov. Mike Parson launched a criminal investigation of a reporter who flagged a state website that exposed 100K+ Social-Security numbers for teachers and other state employees.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Friday Squid Blogging: New Giant Squid Video

New video of a large squid in the Red Sea at about 2,800 feet.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Security Risks of Client-Side Scanning

Even before Apple made its announcement, law enforcement shifted their battle for backdoors to client-side scanning. The idea is that they wouldn’t touch the cryptography, but instead eavesdrop on communications and systems before encryption or after decryption. It’s not a cryptographic backdoor, but it’s still a backdoor — and brings with it all the insecurities of a backdoor.

I’m part of a group of cryptographers that has just published a paper discussing the security risks of such a system. (It’s substantially the same group that wrote a similar paper about key escrow in 1997, and other “exceptional access” proposals in 2015. We seem to have to do this every decade or so.) In our paper, we examine both the efficacy of such a system and its potential security failures, and conclude that it’s a really bad idea.

We had been working on the paper well before Apple’s announcement. And while we do talk about Apple’s system, our focus is really on the idea in general.

Ross Anderson wrote a blog post on the paper. (It’s always great when Ross writes something. It means I don’t have to.) So did Susan Landau. And there’s press coverage in the New York Times, the Guardian, Computer Weekly, the Financial Times, Forbes, El Pais (English translation), NRK (English translation), and — this is the best article of them all — the Register. See also this analysis of the law and politics of client-side scanning from last year.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Olympus Investigates Potential Cyber-attack

Olympus Investigates Potential Cyber-attack

Olympus has launched an investigation after detecting a potential cybersecurity incident in part of its IT system. 

The Japanese manufacturer of optics and reprography products said that suspicious activity was spotted on October 10. The possible threat is affecting the company’s systems in the United States, Canada, and Latin America. 

Digital forensics experts are looking into the security issue, which Olympus said it is “working with the highest priority to resolve.”

While the specific nature of the cybersecurity incident has not been confirmed by the company, Olympus said it was working to contain the threat. Part of the company’s response has been to shut down the systems that were affected.

“As part of the investigation and containment, we have suspended affected systems and have informed the relevant external partners,” said the company in a statement published October 12. 

Olympus said that it is “working with appropriate third parties on this situation and will continue to take all necessary measures to serve our customers and business partners in a secure way,” then apologized for any inconvenience caused by the incident.

The investigation into the incident is ongoing. However, Olympus has stated: “The current results of our investigation indicate the incident was contained to the Americas with no known impact to other regions.”

“If this is another ransomware case, it points to an alarming trend,” said Heather Gantt-Evans, CISO at SailPoint.

“Organizations are at risk of repeat attacks, whether that’s from the threat actor that breached their systems the first time, or one of their affiliates. They may also employ double extortion tactics where even after the ransom is paid to unencrypt the data, the threat actor will request more money later on to not release the victim’s stolen data publicly.”

Commenting on action Olympus should take, Gantt-Evans said: “A focus on understanding root-cause and bolstering data recovery capabilities is paramount once the effort of containment and eradication is complete. 

“Threat actors will walk right back into the front door they used the first time if you continue to leave it open. They will also leave footholds in the network for re-entry if you do not investigate and eradicate properly.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Facebook to Shield Public Figures from Cyber-harassment

Facebook to Shield Public Figures from Cyber-harassment

Social media company Facebook has announced plans to selectively protect some of its better-known users from being harassed on its platform.

Updates to the company’s bullying and harassment policies were announced yesterday by Facebook’s global head of safety, Antigone Davis. The announcement coincided with National Bullying Prevention and Awareness Day in the United States. 

Davis said Facebook is introducing a policy “to help protect people from mass harassment and intimidation.” Under the new rules, “harmful content” that attacks public figures only will be removed. 

This digital courtesy will not be extended to all public figures. Facebook said it will remove harmful content that impacts only certain notable personages. 

Decisions over who will be left with abusive content on their profile will be made on a case-by-case basis by Facebook.

“The policy team will assess an involuntary public figure’s engagement with fame on a case-by-case basis, conducting analysis of social media presence (which may include things like high fan count, verification), or the person’s engagement with their fame through ongoing media engagements and public speaking,” a Facebook spokesperson told Fox News

Davis said that Facebook is also going to start deleting sexualized content about some public figures, “based on feedback from a large number of global stakeholders.”

This newly banned content includes “attacks through negative physical descriptions that are tagged to, mention or posted on the public figure’s account,” and “Profiles, Pages, groups or events dedicated to sexualizing the public figure.”

All coordinated harassment, in which a group of individuals work together to bully another user, will also be banned under the new policy. That change will apply to all users.

Davis said: “It’s important that everyone on our apps feels safe to engage and connect with their communities.”

News of the policy change comes after former Facebook data scientist Frances Haugen told the United States Congress that the California-based company had not made a big enough effort to address its responsibility for spreading harmful content.

Haugen also said that Facebook had repeatedly prioritized its profits over the welfare of its users.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Acer Confirms Second Security Breach

Acer Confirms Second Security Breach

Another cybersecurity breach has occurred at Taiwanese computer manufacturer Acer.

Earlier this year, the company suffered a $50m ransomware extortion attempt after falling prey to the REvil ransomware group in May.

In this latest incident, the computer maker initiated its security protocols after detecting an attack on the section of its after-sales service system that is based in India. 

Prior to Acer’s confirmation of the breach, hackers claimed to have stolen more than 60 GB of the company’s data. On the underground cybercrime forum RAID, threat actors calling themselves Desorden posted a sample of the allegedly stolen data that appeared to show information belonging to 10,000 Acer customers.

Desorden also posted a video showing more files and databases that the group claims to have exfiltrated from Acer.

The threat actors wrote that the stolen data includes “customer, corporate accounts and financial data,” and that “affected customer data are in the millions.”

Desorden claims to have stolen the login details of at least 3,000 Acer retailers or distributors.  

“We have recently detected an isolated attack on our local after-sales service system in India,” said Steven Chung, Acer Corporate Communications, in a statement to the media. 

“Upon detection, we immediately initiated our security protocols and conducted a full scan of our systems. We are notifying all potentially affected customers in India.” 

Acer added that the incident had been reported to local law enforcement and the Indian Computer Emergency Response Team.

The company said that the incident “has no material impact to our operations and business continuity.”

The breach isn’t the first to hit Acer’s India operations. In 2012, Maxney from the Turkish hacker group known as Ajan breached six Acer India sub-domains, defacing landing pages and stealing 15,000 user credentials.

“Ransomware attacks are evolving, targeting next-gen applications like Kubernetes and Microsoft 365,” said Andy Fernandez, senior manager, product marketing, Zerto. “As the adoption of cloud applications grows, so will exploits and attacks and in turn the importance of restoring data.” 

He added: “Modern organizations that are responsible for that data will need to have native data protection solutions that can help them protect internal applications and applications shipped using containers.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Met Police Loses 2280 Electronic Devices in Last Two Years

Met Police Loses 2280 Electronic Devices in Last Two Years

The Metropolitan Police has lost or had stolen 2280 electronic devices over the past two years, official figures have revealed.

The data obtained under a Freedom of Information (FoI) by law firm Griffin law has raised fears that substantial personal and government data, including that of crime victims, has been accessed by nefarious actors.

In total, 1245 electronic devices were lost or stolen in 2019, while in 2020, it was 1101. Tablet computers and iPads were the most common items that went missing over the two years, with 1561 reported as lost and 59 registered as stolen.

These were followed by mobile phones, with 366 lost and 18 stolen during the period.

Many laptops also went missing over both years: 132 in 2019 and 136 in 2020. Notably, a very high proportion of the laptops missing in 2020 were stolen (40), representing a 60% rise compared to 2019.

London’s police service is now facing calls for an inquiry into the data loss revelation.

Donal Blaney, founder, Griffin Law, said: “The Home Secretary and the Information Commissioner need to investigate this catastrophic loss of data urgently. This irresponsible attitude by the Met to electronic devices full of sensitive data relating to criminal investigations should be the last straw.

“Who knows what was on these devices? More evidence of misogyny, boorish behavior and criminal wrongdoing among officers, conveniently destroyed to cover it up?

“And who now has these devices? The very criminals under investigation by the police who now know who gave confidential information about them that led to their arrests? How can anyone have confidence in the Met anymore? The Commissioner needs to get her house in order, immediately.”

Torsten George, cybersecurity evangelist, Absolute Software, further emphasized the potential dangers of police data going astray: “Large organizations like the Met will inevitably experience device losses, particularly with officers engaged in complex operations in the fight against crime. However, such high volumes of lost or stolen items like police laptops and tablets could pose serious risks to victims and witnesses if the data falls into the wrong hands.

“The reality is that regardless of security procedures, misplaced endpoint devices represent a significant cyber threat to organizations, as they might contain sensitive data that could result in a significant data leak or breach.”

The figures represent a new source of embarrassment to the Met, which has been rocked by recent controversies such as the murder of Sarah Everard by serving officer Wayne Cousins.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

New “Yanluowang” Ransomware Variant Discovered

New “Yanluowang” Ransomware Variant Discovered

Security researchers are warning of a newly discovered ransomware variant currently being used in targeted attacks.

Dubbed “Yanluowang” after the .yanluowang extension it adds to encrypted files, the new ransomware was discovered by Symantec during its investigation into an attack against an unnamed “large organization.”

It appears that the group using the variant first deployed legitimate command-line Active Directory query tool AdFind for reconnaissance and to help with lateral movement.

Before Yanluowang is downloaded, an additional tool creates a .txt file with the number of remote machines to check in the command line and uses WMI to get a list of processes running on these machines.

It also logs all the processes and remote machine names, Symantec said.

Then, following deployment, the malware stops all hypervisor machines running on the targeted machine, ends the processes listed in the .txt file, encrypts the files and drops a ransom note named README.txt.

The note purpotedly warns victims not to contact the police or any specialized ransomware negotiation firms.

“If the attackers’ rules are broken the ransomware operators say they will conduct distributed denial of service (DDoS) attacks against the victim, as well as make ‘calls to employees and business partners.’ The criminals also threaten to repeat the attack ‘in a few weeks’ and delete the victim’s data,” Symantec revealed in a blog post.

“While the Yanluowang ransomware appears to be still under development it should by no means be underestimated. Targeted ransomware is one of the biggest cyber-threats faced by organizations today and, as such, all new ransomware threats should be taken equally seriously.”

The volume of ransomware attacks surged by 288% between the first and second quarters of 2021, according to the most recent data from the NCC Group.

Yanluowang refers to a Chinese deity linked to the underworld, although Symantec had no confirmation about the origin of the threat group.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Financial Regulator Warns of Hybrid Working Security Risks

Financial Regulator Warns of Hybrid Working Security Risks

The UK’s financial regulator, The Financial Conduct Authority (FCA), has released new guidance for organizations in the sector to help them transition securely to hybrid working practices.

The regulator warned that financial sector firms must prove that “the lack of a centralized location or remote working” doesn’t increase the risk of financial crime.

It also demanded that firms prove there is “satisfactory planning” in several areas. These include regular reviews of hybrid working plans to identify new risks and proof that firms “can cascade policies and procedures to reduce any potential for financial crime arising from its working arrangements.”

Specific “control functions” including risk, compliance and audit must also be able to prove they can carry out their work unaffected by the new working patterns.

The FCA also requires firms to consider any data and cybersecurity risks, “particularly as staff may transport confidential material and laptops more frequently in a hybrid arrangement.”

Security experts welcomed the extra guidance offered by the FCA.

“As well as ensuring the right security systems are in place, it’s essential that staff are fully trained about the risks posed in terms of data security around incorrectly addressed email correspondence as well as external threats like phishing emails, ransomware attacks,” argued Tessian CEO, Tim Sadler.

“Financial services organizations manage valuable and critical data, and it’s so important that they do not allow flexible working practices to put them at risk of a breach.”

Zoho Europe managing director, Sridhar Iyengar, added that while the crisis had forced many positive changes in working practices, many organizations still lack the processes and infrastructure to drive compliance.

“The FCA is right to warn financial services firms about the risks associated with hybrid working, particularly around challenges such as regulatory requirements, data compliance and accountability,” he argued.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains