NCSC CEO: Ransomware the “Most Immediate Threat” Facing UK Businesses

NCSC CEO: Ransomware the “Most Immediate Threat” Facing UK Businesses

NCSC CEO Lindy Cameron has warned UK businesses that ransomware “is the most immediate cyber threat” they face.

During a speech at Chatham House’s cyber conference, Cameron made the remarks, marking one year since she was appointed head of the UK government agency. She cited numerous examples of the real-world damage caused by ransomware attacks in the past year. This includes the attack on Ireland’s Health Service Executive, which led to “months of disrupted appointments and services” and the disruption to vital services at Hackney Borough Council in the UK due to its IT systems being forced offline for months. In addition, she highlighted the notorious attack on Colonial Pipeline in the US, leading to significant fuel shortages across the East Coast.

These examples show why ransomware is the most immediate threat to UK businesses and most other organizations, “from FTSE 100 companies to schools; from national infrastructure to local councils.”

It is the latest in several warnings made by Cameron about the recent threat of ransomware.

Cameron said many organizations “have no incident response plans, or ever test their cyber defenses.”

This needs to change, with the NCSC expecting ransomware attacks to continue growing for the foreseeable future. This issue is exacerbated by increasingly sophisticated methods being employed by some groups, such as multi-extortion attacks, which in addition to closing down an organization’s systems and data, the attackers threaten to publish exfiltrated data on the dark web.

Unfortunately, “we expect ransomware will continue to be an attractive route for criminals as long as organizations remain vulnerable and continue to pay,” continued Cameron, who warned that “paying ransoms emboldens these criminal groups – and it also does not guarantee your data will be returned intact, or indeed returned at all.”

“Paying ransoms emboldens these criminal groups – and it also does not guarantee your data will be returned intact, or indeed returned at all”

She acknowledged the role of governments in tackling ransomware gangs, but noted how challenging it is for law enforcement is in this area due to criminals being able to operate “beyond our borders.” Therefore, organizations need to do much more to enhance their cybersecurity and incident response measures. “Do you know what you would do if it happened to you? Have you rehearsed this? Have you taken steps to ensure your systems are the hardest target in your market or sector to compromise? And if you’d even contemplate paying a ransom, are you comfortable that you are investing enough to stop that conversation ever happening in the first place?” Cameron asked.

In the speech, Cameron also pointed the finger at the Russian state’s “cyber aggression,” and for harboring ransomware gangs. “In addition to the direct cyber security threats that the Russian state poses, we – along with the NCA – assess that cyber-criminals based in Russia and neighboring countries are responsible for most of the devastating ransomware attacks against UK targets,” she outlined.

Commenting on Cameron’s words, Chris Ross, SVP, International, Barracuda Networks comments: “It’s right for the NCSC to identify ransomware as the biggest threat facing UK business, these attacks have the potential to completely paralyze any organization, hijacking critical data and forcing many to handover large sums of money to break free.

“The days of businesses hoping for the best and assuming they won’t fall victim to a ransomware attack are well and truly over, and urgent action needs to be taken to prevent such threats and ensure the necessary backup support is in place to protect compromised data.”

Torsten George, cybersecurity evangelist, Absolute Software, said: “Ransomware is without doubt the biggest threat facing UK businesses and remains a frighteningly effective tool for leaving organisations of all sizes completely at the mercy of cyber-criminals. The risks have dramatically increased with the rise of remote working, with millions of people mixing home and work devices to answer emails and share company data, making it easier for employees to fall victim to scam emails which contain hostile threats.”

During Cameron’s address, she also discussed the threat posed by China in the digital space and the growing danger of supply chain attacks.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Over 90% of Firms Suffered Supply Chain Breaches Last Year

Over 90% of Firms Suffered Supply Chain Breaches Last Year

Some 93% of global organizations have suffered a direct breach due to weaknesses in their supply chains over the past year, according to BlueVoyant.

The cybersecurity services company polled 1200 IT and procurement leaders responsible for supply chain and cyber-risk management from global companies with 1,000+ employees to compile its report: Managing Cyber Risk Across the Extended Vendor Ecosystem.

It revealed the average number of breaches experienced in the past 12 months grew from 2.7 in 2020 to 3.7 in 2021 – a 37% year-on-year increase.

Although the percentage of companies that don’t consider third-party risk a priority has fallen from 31% last year to 13% in 2021, the number who admit they have no way of knowing if an incident has occurred in their supply chain rose from 31% to 38%.

In addition, while 91% of respondents said budgets were increasing this year to help tackle the risk, investments don’t seem to be making an impact.

Typical pain points highlighted by the report include:

  • Managing false positives and large data volumes.
  • Prioritizing risk.
  • Understanding the company’s own risk position.

“Budget increases demonstrate that firms are recognizing the need to invest in cybersecurity and vendor risk management. However, the wide yet consistent array of pain points suggests that this investment is not as effective as it needs to be,” argued BlueVoyant global head of third-party cyber-risk management, Adam Bixler.

“This, tied to the lack of visibility, monitoring and senior-level reporting, underscores a need for further improvement when approaching third-party cyber risk, in order to reduce the exposure of data before attackers take advantage of this.”

Supply chain risk has been abundantly evident over the past year, with big-name campaigns such as the SolarWinds breaches and the ransomware attacks on Kaseya customers highlighting the threat to organizations.

Organizations must evolve their third-party risk management from static questionnaires to continuous monitoring and rapid action to tackle critical new vulnerabilities, BlueVoyant claimed.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Euro Police Disrupt $17m Fake Investment Scheme

Euro Police Disrupt $17m Fake Investment Scheme

European police have disrupted a significant financial crime organization said to have made at least €15m ($17m) by tricking investors.

Between May 2019 and September 2021, the criminal network reportedly lured German investors via adverts on social media and elsewhere, supported by over 250 newly registered domain names.

As part of the scam, two call centers were reportedly set up in the Bulgarian capital of Sofia, where around 100 employees were required to pose as financial advisors and try to sell fake binary options — a type of financial betting.

Working from scripts, the call center operatives used pre-written messaging to nudge their victims into releasing more funds. However, most were not aware they were involved in a scam, according to Europol.

The criminal gang behind the scam took the money invested by these ‘clients’ and pocketed it, so that they didn’t receive any payment of winnings or credit balance updates following their investment.

It’s unclear where the scam’s ringleaders were based, but the criminal network is said to have been connected to a Ukrainian company.

An action day on October 6 saw involvement from law enforcement and judicial authorities in Bulgaria, Cyprus, Germany, the Netherlands and Ukraine, supported by Europol and Eurojust.

It resulted in eight house searches in Ukraine, Bulgaria and Cyprus, the questioning of 17 individuals in Bulgaria, the arrest of one “high-value target” in Cyprus and the seizure of important assets including phones, electronic equipment, bank accounts and data back-ups.

The investigation has also so far led to 246 criminal proceedings across 15 German federal states.

Investment fraud was the third-highest money-maker for cyber-criminals last year, according to data from the FBI.

It revealed that these scams made them over $336m, on the back of just 8700 victims.

Cryptocurrency fraud is typically a big driver of this criminal activity. Earlier this year, the founder of two crypto hedge funds pleaded guilty to defrauding investors out of around $100m.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ukraine Police Cuff Botnet Herder Who Controlled 100K Machines

Ukraine Police Cuff Botnet Herder Who Controlled 100K Machines

Ukrainian law enforcers have arrested a suspected botnet herder responsible for controlling an automated network of around 100,000 compromised machines to launch DDoS and other attacks.

The Security Service of Ukraine (SSU) claimed the resident of Ivano-Frankivsk also used the botnet to launch spam campaigns, scan for vulnerabilities in websites to exploit, and brute-force users’ email passwords.

He’s said to have found and communicated with customers for his services on encrypted channels like Telegram and closed underground forums, and received the payment through platforms banned in Ukraine like WebMoney.

The National Security and Defence Council of Ukraine imposed sanctions on the Russian firm back in 2018.

Unfortunately for the individual, he registered his real address with WebMoney, enabling SSU officers to find him pretty easily.

He now faces charges under Part 2 of Article 361-1 of the Criminal Code of Ukraine, which relates to the creation, distribution, or sale of malicious software or hardware; and interference with the work of computers, automated systems, and computer or telecoms networks.

Police are currently looking through the equipment seized at the property to find out more.

Ukrainian law enforcers have had a busy time over recent years, as the country continues to harbor more than its fair share of threat actors.

In February last year, police arrested suspected members of the Egregor ransomware group. A few months later, in June, six suspected members of the notorious Clop ransomware gang were cuffed in Ukraine.

Then in October, two “prolific ransomware operators” were arrested in the country after an international law enforcement operation.

Those arrests come in stark contrast to law enforcement activity in Russia, where the state appears to give its blessing to cybercrime activity as long as it is targeted at victims outside the country.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Microsoft Kills Bug Being Exploited in MysterySnail Espionage Campaign

Microsoft’s October 2021 Patch Tuesday included security fixes for 74 vulnerabilities, one of which is a zero-day being used to deliver the MysterySnail RAT to Windows servers.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Apple Releases Urgent iOS Updates to Patch New Zero-Day Bug

The bug is under attack. Within hours of the patch release, a researcher published POC code, calling it a “great” flaw that can be used for jailbreaks and local privilege escalation.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Airline Passenger Mistakes Vintage Camera for a Bomb

I feel sorry for the accused:

The “security incident” that forced a New-York bound flight to make an emergency landing at LaGuardia Airport on Saturday turned out to be a misunderstanding — after an airline passenger mistook another traveler’s camera for a bomb, sources said Sunday.

American Airlines Flight 4817 from Indianapolis — operated by Republic Airways — made an emergency landing at LaGuardia just after 3 p.m., and authorities took a suspicious passenger into custody for several hours.

It turns out the would-be “bomber” was just a vintage camera aficionado and the woman who reported him made a mistake, sources said.

Why in the world was the passenger in custody for “several hours”? They didn’t do anything wrong.

Back in 2007, I called this the “war on the unexpected.” It’s why “see something, say something” doesn’t work. If you put amateurs in the front lines of security, don’t be surprised when you get amateur security. I have lots of examples.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

2021 Hispanic Heritage Month Pt. 5: A Celebration of Hispanic Heritage and Hope

We’re closing McAfee Enterprise’s Hispanic Heritage Month with Solutions Architect, Gus Arias. Read the full interview below to see how his heritage impacted his life and career in technology.

What do you enjoy most about your heritage and what is one of your favorite memories growing up?

I love the food and music.  To this day I never get tired of eating Arepas, a staple of my Venezuelan heritage.

Tell us about your journey to a career in technology and how your heritage played a role to where you are today?

I’ve always liked technology and I took a leap into IT from the Mortgage Industry. I stayed hungry for knowledge and am always eager to learn which transformed my cybersecurity career to where it is today.

What do you hope to pass on to future generations?

I want future generations to know that it is never too late to learn something new, and you should strive to learn something new every day.

What are the three most important things that people should know about your culture?

  1. Family oriented (Family takes care of family)
  2. We are very festive (any chance we get we will throw a party)
  3. A night of having family and friends over will turn out into a cookout and game night of playing dominos

What types of foods were cooked for special occasions when you were growing up?

Arepas, Mandocas, Hayacas, and Paella

Is there a tradition or celebration that you hope that your descendants maintain?

I would have to say our Christmas celebrations throughout the month of December.

As the country continues to grow more diverse, what advice would you give to young Hispanic/LatinX individuals interested in starting a career in cybersecurity?

Do not let anything hold you back and when it comes to change, have an open and positive view. Learn from those changes to improve, also work on soft skills. From a technology perspective – keep up with the times. Meaning, stay informed on the evolution of technology and threats.

What are some of your ideas on how to attract more Hispanic/LatinX individuals to cybersecurity?

Educate and promote early by engaging with local schools. Also, provide internships at the High School/College levels as a summer program.

The post 2021 Hispanic Heritage Month Pt. 5: A Celebration of Hispanic Heritage and Hope appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains