Publishers Tackle Doctoring of Research Images

Publishers Tackle Doctoring of Research Images

A working group appointed by the International Association of Scientific, Technical and Medical Publishers (STM) has published a new set of guidelines to tackle the issue of doctored images in scientific research papers. 

The recommendations of the Standards and Technology Committee (STEC) include a three-tier classification system that editors can use to flag suspicious content, and detailed step-by-step instructions on how to deal with manipulated images.

STM said the guidelines provide “a structured approach that supports editors and others applying image integrity screening as part of pre-publication quality control checks or post-publication investigation of image and data integrity issues at scholarly journals, books, preprint servers, or data repositories.”

Images that fall under tier one of the classification system include pictures that have been “beautified” or altered in a way that does not change the conclusion of the research. Images that have been significantly manipulated in a way that clashes with accepted scholarly practice and change the scientific conclusions for key data are designated tier two. 

Tier three, reserved for the most serious aberrations, includes “severe image manipulation, with unequivocal evidence of obfuscation or fabrication and an intent to mislead,” such as the selective cropping or reporting of images so that they fail to represent the original data. 

Editors who suspect an image has been doctored are advised to ask authors for their source data and an explanation. If an editor receives no response to a query over a tier three offense and later sees the suspicious images published in another journal, the guidance says the editor should notify that journal of their suspicions. 

“With these recommendations, the STM Working Group aims to contribute a consistent, structured and efficient framework for handling image integrity issues both within and between journals and publishers,” said STM. 

Elisabeth Bik, a research-integrity consultant based in California, said that the new recommendations “will not prevent science misconduct, but they provide stronger scrutiny both at the submission stage, as well as after publication.”

STEC’s recommendations are open for comments until October 31, 2021. Final recommendations will be presented at the STM Innovations Seminar on December 7, 2021.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#DTX2021: How to Keep Pace with the Rising Threat Landscape

#DTX2021: How to Keep Pace with the Rising Threat Landscape

Strategies organizations should take to keep up with the evolution of cyber-attackers was the topic of a panel discussion during Digital Transformation EXPO Europe 2021.

Moderating the session, Lisa Short, director & co-founder, Hephaestus Collective & P&L Digital Edge, observed how the digital world has become more “pervasive” during the past 18 months, with organizations undergoing significant digital transformations. She then posed the question: how should industry professionals be reacting to this change?

Matt Howells, head of cyber defense, Hargreaves Lansdown, said that threat actors are broadly using the same methods they did pre-pandemic, such as ransomware, but the velocity of attacks has ramped up. He also noted that cyber-criminals are becoming more collaborative, such as utilizing ‘as-a-service’ approaches. As such, “it’s physically impossible to stay ahead of our adversaries – there are 10s of thousands of them out there across the globe.”

Amid this environment, Jack Chapman, vice president, threat intelligence at Egress, said it is vital that security teams utilize the new technologies they have adopted since COVID-19 and combine those with the human and process layers. “It’s a case of re-evaluating what the threats our organization is facing and taking a realistic approach, because if we’re honest, every layer can be overcome. What we’re doing here is mitigating these threats and by understanding them, we stand a much better chance.”

Vijay Kumar Velu, director, offensive security, BDO UK LLP, emphasized that it is not a new set of threats being facing by organizations, but rather the changing tactics. This is partly due to the surge in cryptocurrencies, providing new avenues for cyber-criminals to make money via cryptojacking. “It’s just the way they want to make money that changes,” he stated.

Short then asked the panel about the types of tools organizations should invest in to better protect their systems and data. Howells pointed out that any new technology, person or service must be carefully vetted before being rolled out. Otherwise, “you are allowing insider threats to walk straight in the front door, which a number of organizations do on a daily basis.”

Chapman emphasized that the focus should always be on creating new layers of security by design, and tools need to be tailored for that purpose. “Any organization has different risks, different employees, different objectives, and one answer fits-all doesn’t work.”

Kumar Velu was then asked whether he feels security teams are getting enough funding to spend on security given the increased threat landscape. Short outlined the context of this question — the eye-opening costs of data breaches, which are expected to reach $10.5tn by 2025. Vijay agreed that more money is required but cautioned that teams must be careful about how they spend their budget, as “the spends are going wrong sometimes.”

Building on this point, Howells stated that the best way to ensure the right decisions about security spending is to have the right CISO to communicate security risks and needs effectively to the board. “If you have somebody who is able to communicate to them in the language that can drive home exactly what we’re trying to achieve from a cyber-perspective or a transformational perspective from IT, I think you will always get through to your c-suite,” he opined.

He added that while tools are essential, organizations should also be focusing on getting security basics right, such as having a CMDB.

Kumar Belu also advised organizations to focus on defending the critical assets of their business and ensuring they remain protected in the event of a breach. “Always focus on the risk that matters to you. One size doesn’t fit all — only the size that matters to you,” he said.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#DTX2021: Louis Theroux Discusses the Coalescence of Tech and Human Behavior

#DTX2021: Louis Theroux Discusses the Coalescence of Tech and Human Behavior

Renowned documentarist Louis Theroux described the growing societal dangers posed by social media use during the keynote interview at the Digital Transformation EXPO Europe 2021.

The session came ahead of the release of Theroux’s new three-part documentary series, exploring how tech is increasingly coalescing with human psychology. In one prominent example of this, he noted that former US president, Donald Trump, was able to “get elected based on his ability to communicate to us through our phones.”

The discussion, which tech journalist Georgie Barrat moderated, then discussed the Capitol Hill riots at the beginning of the year. This is an event Theroux analyzed extensively for the making of his new series, and he explained that the disturbing scenes were only made possible by social media, particularly Twitter. This was partly due to the encouragement given by President Trump for his supporters to protest his election defeat via the platform following constant allegations of vote-rigging. But more profoundly, he described how social media had enabled people with extremist views to “find their tribe” and be able to “live in an echo chamber,” where their beliefs are constantly reinforced rather than largely ignored.

In his new three-part documentary series, Louis Theroux (pictured) explores how tech is increasingly coalescing with human psychology
In his new three-part documentary series, Louis Theroux (pictured) explores how tech is increasingly coalescing with human psychology

This phenomenon has subsequently spilled out into the real world, leading to the chaotic and disturbing scenes at Capitol Hill. Such a scenario could not have occurred without social media, according to Theroux, as most people who believe in conspiracy theories such as election fraud would otherwise live separate lives from one another.

Therefore, “we have poisoned ourselves with information.”

While Theroux believes social media firms should do more to combat misinformation and disinformation on their platforms, he acknowledged that such approaches could lead to quashing legitimate free speech. For example, he pointed out that during the early part of the COVID-19 pandemic, social media companies were banning people for suggesting the virus was caused by a lab leak in Wuhan — a theory now considered plausible by experts.

Theroux also spoke of his fears surrounding large tech firms’ extensive collection of personal data, enabling these companies to “create pictures of your behavior,” thereby targeting individuals with specific content and adverts.

He believes this process can change human behavior, as humans are “socially malleable,” shaped by the environment they reside in. He pointed out that behaviors like pedophilia and slavery would have been considered acceptable many years ago, as they were the norm for their environment. This is an area people should be very mindful of while operating in the online world.

Theroux also emphasized that social media has many positive aspects, including calling powerful people out for inappropriate behavior. However, big tech and governments have much work to do to ensure these benefits are not outweighed by significant societal harms such as disinformation in the future.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

NCSC: Revoke Admin Access for BYOD Users Immediately

NCSC: Revoke Admin Access for BYOD Users Immediately

Government security experts have urged organizations to review and re-plan any BYOD strategies implemented as a quick fix during the pandemic, warning of mounting cyber-risk.

GCHQ-offshoot the National Cyber Security Centre (NCSC) has released updated guidance for organizations designed to help them design, deploy and manage what it claimed could be a “potentially difficult IT set-up.”

Senior platforms researcher, “Luna R,” warned in a new blog post that the time for a “just make it work” mentality is over, and BYOD must now be carefully considered and rigorously implemented to be effective and secure.

“You cannot do all your organization’s functions securely with just BYOD, no matter how well your solution may be configured,” she argued. “If you’ve given BYOD users admin access to company resources, revoke that access immediately, then come back.”

The rapid shift to remote working during the first months of the pandemic made employee use of personal devices virtually essential in many organizations, especially those with smaller IT budgets.

However, stories soon emerged of threat actors targeting vulnerabilities and misconfigurations in these devices and home networks to get to corporate networks and resources.

A Bitglass study from July 2020 revealed that 69% of organizations allow employees to use personal devices for work. However, it also noted that over half (51%) lack visibility into file-sharing apps, 30% have no control over mobile enterprise messaging tools and only 9% have cloud-based anti-malware solutions in place.

Remarkably, by November 2020, over half (51%) of organizations still didn’t have a BYOD policy in place.

An HP study from May 2021 revealed that over half (51%) of global IT decision-makers had seen evidence of compromised personal PCs being used to access company and customer data over the past year.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Atom Silo Uses DLL Side-Loading to Deploy Ransomware

Atom Silo Uses DLL Side-Loading to Deploy Ransomware

Security researchers have warned of a new ransomware variant leveraging a recently disclosed vulnerability for initial access and going to great lengths to evade detection.

Atom Silo is almost identical to the LockFile ransomware spotted spreading earlier this year by exploiting PetitPotam and ProxyShell vulnerabilities in Microsoft products, according to Sophos.

However, in Atom Silo’s case, the variant exploited a vulnerability in Atlassian’s Confluence collaboration software made public just three weeks before the attack.

Interestingly, the researchers discovered that a separate threat actor had exploited the same bug to deploy a coinminer (also called a cryptocurrency miner) on the victim organization’s system.

“For many organizations, keeping up with the pace of patching can be a challenge in the best of times — and the effects of lock-down and other recent stressors affecting staff availability are only making keeping up with patches more difficult,” said Sophos researchers Sean Gallagher and Vikas Singh.

“Ransomware operators and other malware developers are becoming very adept at taking advantage of these gaps, jumping on published proof-of-concept exploits for newly-revealed vulnerabilities and weaponizing them rapidly to profit off them.”

The ransomware actors also used “well-worn techniques in new ways, and made significant efforts to evade detection prior to launching the ransomware,” they argued.

Specifically, the intrusion began with an Object-Graph Navigation Language (OGNL) injection attack, which provided a backdoor via which they dropped and executed additional files for a second covert backdoor.

These files included a legitimate, signed executable from a third-party software provider that was vulnerable to an unsigned DLL side-load attack.

Sophos warned that such techniques are becoming increasingly common and challenging to defend against.

“Abuse of legitimate but vulnerable software components through DLL side-loading and other methods has long been a technique used by attackers with a wide range of capabilities, and it has filtered down to the affiliates of ransomware operators and other cyber-criminals,” the researchers explained.

“While abuse of some of these legitimate, signed components is well-enough known to defend against, the supply of alternative vulnerable executables is likely deep. Spotting legitimate executables that exist outside of the context of the products they are supposed to be part of requires vigilance — and vulnerability disclosure by the vendors they come from.”

Once the backdoor was loaded, the attackers proceeded to lateral movement, exfiltration and encryption, disrupting Sophos endpoint protection in the process via a malicious kernel driver to evade detection.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Patch Apache HTTP Servers Now to Avoid Zero Day Exploit

Patch Apache HTTP Servers Now to Avoid Zero Day Exploit

Apache HTTP Server users have been urged to immediately patch after it emerged that a zero-day vulnerability in the popular open-source software is being exploited in the wild.

CVE-2021-41773 is described as a path traversal flaw in version 2.4.49, which was itself only released a few weeks ago.

“An attacker could use a path traversal attack to map URLs to files outside the expected document root,” a description of the bug noted. “If files outside of the document root are not protected by ‘require all denied’ these requests can succeed. Additionally, this flaw could leak the source of interpreted files like CGI scripts.”

According to Sonatype senior security researcher, Ax Sharma, there are around 112,000 Apache servers across the globe running version 2.4.49, two-fifths of which are located in the US.

He argued that the new zero-day exploit highlights that, even when a vendor releases patches, they may subsequently be bypassed.

On that point, Google research earlier this year claimed that a quarter of zero-day exploits could have been avoided if vendors had taken more time over patching. It noted that 25% of zero-days spotted in 2020 were closely related to previously publicly disclosed vulnerabilities.

The new Apache HTTP Server Version 2.4.50 also includes a fix for a denial of service vulnerability, CVE-2021-41524, discovered a few weeks ago but not thought to have been actively exploited.

Sonatype’s Sharma also warned that unpatched Apache Airflow servers at dozens of tech firms were leaking thousands of credentials and configuration secrets due to poor configuration and security practices.

“Most of these issues could have been avoided by simply upgrading Airflow to version 2, which comes with extensive improvements and security enhancements,” he argued.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains