Indictment, Lawsuits Revive Trump-Alfa Bank Story

In October 2016, media outlets reported that data collected by some of the world’s most renowned cybersecurity experts had identified frequent and unexplained communications between an email server used by the Trump Organization and Alfa Bank, one of Russia’s largest financial institutions. Those publications set off speculation about a possible secret back-channel of communications, as well as a series of lawsuits and investigations that culminated last week with the indictment of the same former federal cybercrime prosecutor who brought the data to the attention of the FBI five years ago.

The first page of Alfa Bank’s 2020 complaint.

Since 2018, access to an exhaustive report commissioned by the U.S. Senate Armed Services Committee on data that prompted those experts to seek out the FBI has been limited to a handful of Senate committee leaders, Alfa Bank, and special prosecutors appointed to look into the origins of the FBI investigation on alleged ties between Trump and Russia.

That report is now public, ironically thanks to a pair of lawsuits filed by Alfa Bank, which doesn’t directly dispute the information collected by the researchers. Rather, it claims that the data they found was the result of a “highly sophisticated cyberattacks against it in 2016 and 2017” intended “to fabricate apparent communications” between Alfa Bank and the Trump Organization.

The data at issue refers to communications traversing the Domain Name System (DNS), a global database that maps computer-friendly coordinates like Internet addresses (e.g., 8.8.8.8) to more human-friendly domain names (example.com). Whenever an Internet user gets online to visit a website or send an email, the user’s device sends a query through the Domain Name System.

Many different entities capture and record this DNS data as it traverses the public Internet, allowing researchers to go back later and see which Internet addresses resolved to what domain names, when, and for how long. Sometimes the metadata generated by these lookups can be used to identify or infer persistent network connections between different Internet hosts.

The DNS strangeness was first identified in 2016 by a group of security experts who told reporters they were alarmed at the hacking of the Democratic National Committee, and grew concerned that the same attackers might also target Republican leaders and institutions.

Scrutinizing the Trump Organization’s online footprint, the researchers determined that for several months during the spring and summer of 2016, Internet servers at Alfa Bank in Russia, Spectrum Health in Michigan, and Heartland Payment Systems in New Jersey accounted for nearly all of the several thousand DNS lookups for a specific Trump Organization server (mail1.trump-email.com).

This chart from a court filing Sept. 14, 2021 shows the top sources of traffic to the Trump Organization email server over a four month period in the spring and summer of 2016. DNS lookups from Alfa Bank constituted the majority of those requests.

The researchers said they couldn’t be sure what kind of communications between those servers had caused the DNS lookups, but concluded that the data would be extremely difficult to fabricate.

As recounted in this 2018 New Yorker story, New York Times journalist Eric Lichtblau met with FBI officials in late September 2016 to discuss the researchers’ findings. The bureau asked him to hold the story because publishing might disrupt an ongoing investigation. On Sept. 21, 2016, Lichtblau reportedly shared the DNS data with B.G.R., a Washington lobbying firm that worked with Alfa Bank.

Lichtblau’s reporting on the DNS findings ended up buried in an October 31, 2016 story titled “Investigating Donald Trump, F.B.I. Sees No Clear Link to Russia,” which stated that the FBI “ultimately concluded that there could be an innocuous explanation, like marketing email or spam,” that might explain the unusual DNS connections.

But that same day, Slate’s Franklin Foer published a story based on his interactions with the researchers. Foer noted that roughly two days after Lichtblau shared the DNS data with B.G.R., the Trump Organization email server domain vanished from the Internet — its domain effectively decoupled from its Internet address.

Foer wrote that The Times hadn’t yet been in touch with the Trump campaign about the DNS data when the Trump email domain suddenly went offline.  Odder still, four days later the Trump Organization created a new host — trump1.contact-client.com — and the very first DNS lookup to that new domain came from servers at Alfa Bank.

The researchers concluded that the new domain enabled communication to the very same server via a different route.

“When a new host name is created, the first communication with it is never random,” Foer wrote. “To reach the server after the resetting of the host name, the sender of the first inbound mail has to first learn of the name somehow. It’s simply impossible to randomly reach a renamed server.”

“That party had to have some kind of outbound message through SMS, phone, or some noninternet channel they used to communicate [the new configuration],” DNS expert Paul Vixie told Foer. “The first attempt to look up the revised host name came from Alfa Bank. If this was a public server, we would have seen other traces. The only look-ups came from this particular source.”

THE THEORIES

Both the Trump organization and Alfa Bank have denied using or establishing any sort of secret channel of communications, and have offered differing explanations as to how the data gathered by the experts could have been faked or misinterpreted.

In a follow-up story by Foer, the Trump Organization suggested that the DNS lookups might be the result of spam or email advertising various Trump properties, and said a Florida based marketing firm called Cendyn registered and managed the email server in question.

But Cendyn told CNN that its contract to provide email marketing services to the Trump Organization ended in March 2016 — weeks before the DNS lookups chronicled by the researchers started appearing. Cendyn told CNN that a different client had been communicating with Alfa Bank using Cendyn communications applications — a claim that Alfa Bank denied.

Alfa Bank subsequently hired computer forensics firms Mandiant and Stroz Friedberg to examine the DNS data presented by the researchers. Both companies concluded there was no evidence of email communications between Alfa Bank and the Trump Organization. However, both firms also acknowledged that Alfa Bank didn’t share any DNS data for the relevant four-month time period identified by the researchers.

Another theory for the DNS weirdness outlined in Mandiant’s report is that Alfa Bank’s servers performed the repeated DNS lookups for the Trump Organization server because its internal Trend Micro antivirus product routinely scanned domains in emails for signs of malicious activity — and that incoming marketing emails promoting Trump properties could have explained the traffic.

The researchers maintained this did not explain similar and repeated DNS lookups made to the Trump Organization email server by Spectrum Health, which is closely tied to the DeVos family (Betsy DeVos would later be appointed Secretary of Education by President Trump).

FISHING EXPEDITION

In June 2020, Alfa Bank filed two “John Doe” lawsuits, one in Pennsylvania and another in Florida. Their stated purpose was to identify the anonymous hackers behind the “highly sophisticated cyberattacks” that they claim were responsible for the mysterious DNS lookups.

Alfa Bank has so far subpoenaed at least 49 people or entities — including all of the security experts quoted in the 2016 media stories referenced above, and others who’d merely offered their perspectives on the matter via social media. At least 15 of those individuals or entities have since been deposed. Alfa Bank’s most recent subpoena was issued Aug. 26, 2021.

L. Jean Camp, a professor at the Indiana University School of Informatics and Computing, was among the first to publish some of the DNS data collected by the research group. In 2017, Alfa Bank sent Camp a series of threatening letters suggesting she was “a central figure” in the what the company would later claim was “malicious cyber activity targeting its computer network.” The letters and responses from her attorneys are published on her website.

Camp’s attorneys and Indiana University have managed to keep her from being deposed by both Alfa Bank and John H. Durham, the special counsel appointed by the Trump administration to look into the origins of the Russia investigation (although Camp said Alfa Bank was able to obtain certain emails through the school’s public records request policy).

“If MIT had had the commitment to academic freedom that Indiana University has shown throughout this entire process, Aaron Swartz would still be alive,” Camp said.

Camp said she’s bothered that the Alfa Bank and Trump special counsel investigations have cast the researchers in such a sinister light, when many of those subpoenaed have spent a lifetime trying to make the Internet more secure.

“Not including me, they’ve subpoenaed some people who are significant, consistent and important contributors to the security of American networks against the very attacks coming from Russia,” Camp said. “I think they’re using law enforcement to attack network security, and to determine the ways in which their previous attacks have been and are being detected.”

Nicholas Weaver, a lecturer at the computer science department at University of California, Berkeley, told KrebsOnSecurity he complied with the subpoena requests for specific emails he’d sent to colleagues about the DNS data, noting that Alfa Bank could have otherwise obtained them through the schools’ public records policy.

Weaver said Alfa Bank’s lawsuit has nothing to do with uncovering the truth about the DNS data, but rather with intimidating and silencing researchers who’ve spoken out about it.

“It’s clearly abusive, so I’m willing to call it out for what it is, which is a John Doe lawsuit for a fishing expedition,” Weaver said.

TURNABOUT IS FAIR PLAY

Among those subpoenaed and deposed by Alfa Bank was Daniel J. Jones, a former investigator for the FBI and the U.S. Senate who is perhaps best known for his role in leading the investigation into the U.S. Central Intelligence Agency’s use of torture in the wake of the Sept. 11 attacks.

Jones runs The Democracy Integrity Project (TDIP), a nonprofit in Washington, D.C. whose stated mission includes efforts to research, investigate and help mitigate foreign interference in elections in the United States and its allies overseas. In 2018, U.S. Senate investigators asked TDIP to produce and share a detailed analysis of the DNS data, which it did without payment. That lengthy report was never publicly released by the committee nor anyone else.

That is, until Sept. 14, 2021, when Jones and TDIP filed their own lawsuit against Alfa Bank. According to Jones’ complaint, Alfa Bank had entered into a confidentiality agreement regarding certain sensitive and personal information Jones was compelled to provide as part of complying with the subpoena.

Yet on Aug. 20, Alfa Bank attorneys sent written notice that it was challenging portions of the confidentiality agreement. Jones’ complaint asserts that Alfa Bank intends to publicly file portions of these confidential exhibits, an outcome that could jeopardize his safety.

This would not be the first time testimony Jones provided under a confidentiality agreement ended up in the public eye. TDIP’s complaint notes that before Jones met with FBI officials in 2017 to discuss Russian disinformation campaigns, he was assured by two FBI agents that his identity would be protected from exposure and that any information he provided to the FBI would not be associated with him.

Nevertheless, in 2018 the House Permanent Select Committee on Intelligence released a redacted report on Russian active measures. The report blacked out Jones’ name, but a series of footnotes in the report named his employer and included links to his organization’s website. Jones’ complaint spends several pages detailing the thousands of death threats he received after that report was published online.

THE TDIP REPORT

As part of his lawsuit against Alfa Bank, Jones published 40 pages from the 600+ page report he submitted to the U.S. Senate in 2018. From reviewing its table of contents, the remainder of the unpublished report appears to delve deeply into details about Alfa Bank’s history, its owners, and their connections to the Kremlin.

The report notes that unlike other domains the Trump Organization used to send mass marketing emails, the domain at issue — mail1.trump-email.com — was configured in such a way that would have prevented it from effectively sending marketing or bulk emails. Or at least prevented most of the missives sent through the domain from ever making it past spam filters.

Nor was the domain configured like other Trump Organization domains that demonstrably did send commercial email, Jones’ analysis found. Also, the mail1.trump-email.com domain was never once flagged as sending spam by any of the 57 different spam block lists published online at the time.

“If large amounts of marketing emails were emanating from mail1.trump-email.com, it’s likely that some receivers of those emails would have marked them as spam,” Jones’ 2018 report reasons. “Spam is nothing new on the internet, and mass mailings create easily observed phenomena, such as a wide dispersion of backscatter queries from spam filters. No such evidence is found in the logs.”

However, Jones’ report did find that mail1.trump-email.com was configured to accept incoming email. Jones cites testing conducted by one of the researchers who found the mail1.trump-email.com rejected messages with an automated reply saying the server couldn’t accept messages from that particular sender.

“This test reveals that either the server was configured to reject email from everyone, or that the server was configured to accept only emails from specific senders,” TDIP wrote.

The report also puts a finer point on the circumstances surrounding the disappearance of that Trump Organization email domain just two days after The New York Times shared the DNS data with Alfa Bank’s representatives.

“After the record was deleted for mail1.trump-email.com on Sept. 23, 2016, Alfa Bank and Spectrum Health continued to conduct DNS lookups for mail1.trump-email.com,” reads the report. “In the case of Alfa Bank, this behavior persisted until late Friday night on Sept. 23, 2016 (Moscow time). At that point, Alfa Bank ceased its DNS lookups of mail1.trump-email.com.”

Less than ten minutes later, a server assigned to Alfa Bank was the first source in the DNS data-set examined (37 million DNS records from January 1, 2016 to January 15, 2017) to conduct a DNS look-up for the server name ‘trump1.contact-client.com.’ The answer received was 66.216.133.29 — the same IP address used for mail1.trump-email.com that was deleted in the days after The New York Times inquired with Alfa Bank about the unusual server connections.

“No servers associated with Alfa Bank ever conducted a DNS lookup for trump1.contact-client.com again, and the next DNS look-up for trump1.contact-client.com did not occur until October 5, 2016,” the report continues. “Three of these five look-ups from October 2016 originated from Russia.”

A copy of the complaint filed by Jones against Alfa Bank is available here (PDF).

THE SUSSMANN INDICTMENT

The person who first brought the DNS data to the attention of the FBI in Sept. 2016 was Michael Sussmann, a 57-year-old cybersecurity lawyer and former computer crimes prosecutor who represented the Democratic National Committee and Hillary Clinton’s presidential campaign.

Last week, the special counsel Durham indicted Sussmann on charges of making a false statement to the FBI. The New York Times reports the accusation focuses on a meeting Sussmann had Sept. 19, 2016 with James A. Baker, the FBI’s top lawyer at the time. Sussmann had reportedly met with Baker to discuss the DNS data uncovered by the researchers.

“The indictment says Mr. Sussmann falsely told the F.B.I. lawyer that he had no clients, but he was really representing both a technology executive and the Hillary Clinton campaign,” The Times wrote.

Sussmann has pleaded not guilty to the charges.

ANALYSIS

The Sussmann indictment refers to the various researchers who contacted him in 2016 by placeholder names, such as Tech Executive-1 and Researcher-1 and Researcher-2. The tone of indictment reads as if describing a vast web of nefarious or illegal activities, although it doesn’t attempt to address the veracity of any specific concerns raised by the researchers.  Here is one example:

“From in or about July 2016 through at least in or about February 2017, however, Originator-I, Researcher-I, and Researcher-2 also exploited Internet Company­-1′ s data and other data to assist Tech Executive-I in his efforts to conduct research concerning Trump’s potential ties to Russia.”

Quoting from emails between Tech Executive-1 and the researchers, the indictment makes clear that Mr. Durham has subpoenaed many of the same researchers who’ve been subpoenaed and or deposed in the concurrent John Doe lawsuits from Russia’s Alfa Bank.

To date, Alfa Bank has yet to name a single defendant in its lawsuits. In the meantime, the Sussmann indictment is being dissected by many users on social media who have been closely following the Trump administration’s inquiry into the Russia investigation. The majority of these social media posts appear to be crowdsourcing an effort to pinpoint the real-life identities behind the placeholder names in the indictment.

At one level, it doesn’t matter which explanation of the DNS data you believe: There is a very real possibility that the way this entire inquiry has been handled could negatively affect the FBI’s ability to collect crucial and sensitive investigative tips for years to come.

After all, who in their right mind is going to volunteer confidential information to the FBI if they fear there’s even the slightest chance that future shifting political winds could end up seeing them prosecuted, threatened with physical violence or death on social media, and/or exposed to expensive legal fees and depositions from private companies as a result?

Such a perception could give rise to a sort of “chilling effect,” discouraging honest, well-meaning people from speaking up when they suspect or know about a potential threat to national security or sovereignty.

This would be a less-than-ideal outcome in the context of today’s top cyber threat for most organizations: Ransomware. With few exceptions, the U.S. government has watched helplessly as organized cybercrime gangs — many of whose members hail from Russia or from former Soviet nations that are friendly to Moscow — have extorted billions of dollars from victims, and disrupted or ruined countless businesses.

To help shift the playing field against ransomware actors, the Justice Department and other federal law enforcement agencies have been trying to encourage more ransomware victims to come forward and share sensitive details about their attacks. The U.S. government has even offered up to $10 million for information leading to the arrest and conviction of cybercriminals involved in ransomware.

But given the way the government has essentially shot the all of the messengers with its handling of the Sussmann case, who could blame those with useful and valid tips if they opted to stay silent?

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Locks Up Call Center Scammer

US Locks Up Call Center Scammer

A fraudster who tricked and threatened thousands of Spanish-speaking immigrants into paying for educational products has been sentenced to 110 months in prison in the United States.

Peruvian national and call center owner Henrry Adrian Milla Campuzano was part of a conspiracy to defraud victims using false statements and the threat of deportation or legal action in a non-existent “minor crimes court.”

Milla Campuzano, a 37-year-old resident of Lima, owned and operated two call centers in Peru, the Latinos en Accion and Accion Latino. He admitted that from April 2011 until his arrest in July 2019, he and his employees contacted victims via phone and falsely claimed to be lawyers, court officials, federal agents, and minor crimes court representatives.

Victims were erroneously informed that they were required to accept and pay for English-language courses and other educational products that were never delivered.

The conspirators didn’t stop at targeting the victims, but also contacted their family members and friends and fraudulently threatened them with legal consequences if they did not make payments.

Threats used against the victims included court proceedings, negative marks on their credit reports, imprisonment, and immigration consequences.

Milla Campuzano is the sixth individual to plead guilty to involvement in this conspiracy and to receive a lengthy prison term. He and four co-defendants were extradited to the Southern District of Florida in October 2020. 

Jerson Renteria was sentenced to 100 months in prison, and Fernan Huerta, Omar Cuzcano, and Evelyng Milla were each sentenced to serve 90 months in prison.

California resident Angel Armando Adrianzen, who teamed up with the call centers in Peru to run the telemarketing scam, was sentenced in May to serve 121 months in prison followed by fifteen years’ supervised release.

Two additional defendants in the case – Carlos Espinoza Huerta and Josmell Espinoza Huerta – were extradited from Peru to the United States on June 25 and are due to be tried in Florida in February. 

Acting US Attorney Juan Antonio Gonzalez for the Southern District of Florida said: “We will continue to bring American justice to transnational criminals who use fear tactics and intimidation to steal money from immigrants, seniors and others who live in this country.”  

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Enterprises Need 27 New IT Hires to Manage Security Debt

Enterprises Need 27 New IT Hires to Manage Security Debt

Organizations that spent heavily on digital transformation during the pandemic will need two years’ worth of investment to mitigate the resulting security gaps, according to a new report from Veritas.

To compile its latest report, The Vulnerability Lag, the data security vendor polled over 2000 senior IT decision-makers across EMEA, APAC and the US from organizations with at least $100m in revenue.

It found that security (51%) and cloud (56%) are the top two areas in which capability gaps expose these large enterprises to attack.

Respondents claimed they’d need to spend $2.5m on average and hire 27 full-time IT employees to close these gaps within the next 12 months.

The report predicted that it will take firms, on average, two years to eliminate the current vulnerabilities in digital systems, which represent a significant risk to their organization today.

There’s an urgency to them doing so: Veritas claimed the average responding organization had experienced 2.57 ransomware attacks that led to downtime in the past 12 months, while 14% have been hit five times or more.

Organizations with at least one gap in their technology strategy have, on average, experienced five times more ransomware attacks leading to downtime in the past year versus those with no gaps, it added.

Some two-fifths (39%) of respondents claimed that security measures had not kept pace with new digital transformation initiatives prompted by the pandemic. The report claimed that part of the challenge is understanding exactly what technology has been introduced and what needs to be protected.

Douglas Murray, CEO at Valtix, argued that protecting cloud infrastructure and data is particularly challenging, especially in a world where organizations are investing in technology from multiple platform providers.

“The good news is that it inevitably always comes back to the best practices of defense-in-depth and ensuring that the right security controls and policy are deployed against every cloud workload,” he added.

“There are a variety of technologies that can help reduce ransomware risk in the cloud, including network-based intrusion prevention, anti-virus and the segmentation of workloads. By taking a cloud-first approach to these problems, security leaders can set the stage for the future through a cloud-native, multi-cloud security architecture.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

CREST Appoints New President Following Retirement of Ian Glover

CREST Appoints New President Following Retirement of Ian Glover

International information security accreditation and certification body CREST has appointed Rowland Johnson as its new President.

Johnson will take over from Ian Glover, who retired as President of CREST on September 1 after nearly 13 years in the post. This will be for an initial term of one year.

Johnson was previously a member of the CREST GB Executive from 2014–2020 and is credited with playing a major part in the non-profit organization’s development in Singapore and America. Therefore, he is viewed as the ideal candidate to lead the body over the next 12 months. His appointment was unanimously approved by the CREST GB Executive and CREST’s regional Advisory Boards in the USA, Australia and Southeast Asia.

Rowland Johnson is credited with playing a major part in the non-for-profit organization's development in Singapore and America
Rowland Johnson is credited with playing a major part in the non-for-profit organization’s development in Singapore and America

Johnson is also renowned for his role as a founding director at cybersecurity firm Nettitude, where he oversaw its acquisition by Lloyd’s Register in 2018.

A CREST senior management team comprising Elaine Luck, operations manager, Samantha Alexander, principal accreditor and Richard Beddow, CREST’s financial controller, will now support Johnson during the transition period. In addition, former President Glover will continue supporting CREST projects internationally until December 1.

Commenting on his appointment, Johnson said: “I feel hugely privileged by the support from CREST’s elected members and regional chairs for my appointment to this prestigious role. I will be working closely with Ian and the whole of the CREST team to ensure that the transition is as seamless as possible for CREST members and for everyone we work with across the industry, governments, regulators and academia.

“It is important that members are always right at the heart of everything CREST does and we will be focusing on providing greater support and encouraging closer collaboration, helping us to take things forward so that we are able to build on Ian’s legacy. He leaves CREST in a very strong position.”

Glover stated: “Having worked closely with Rowland for six years while he was a member of the CREST GB Executive, I am delighted that he is taking up the President’s role.

“During my time with CREST I hope I have helped organizations to mature and grow and encouraged individuals to enter and thrive in an increasingly professional industry, and I am confident it will also be Rowland’s mission to carry on this work.”

Last week, Infosecurity reported on the conclusion of CREST’s year-long investigation into NCC Group’s exam leak scandal.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#IMOS21: Alyssa Miller’s Advice for Building a Successful Infosecurity Career

#IMOS21: Alyssa Miller’s Advice for Building a Successful Infosecurity Career

Cybersecurity professionals need to shoot for the stars and overcome self-confidence issues to progress in their careers. That was the message of an illuminating keynote address by Alyssa Miller, business information security officer, SMP Global, while giving the keynote address at the Infosecurity Magazine Autumn Online Summit – North America 2021.

Miller began by describing her own career to date, and how she reached the heights of business information security officer at SMP Global, where she leads the cybersecurity strategy for a $4bn a year division.

Her career in information security began at 19 as a programmer at a fintech firm, while she was still studying computer science at university. She stayed at the firm for almost nine years, holding a range of high-profile positions.

At 28, Miller was approached to become a penetration tester; while she was concerned she had no prior knowledge of penetration testing, she was assured she would be able to figure it out. This leap worked, as by the age of 31 Miller was leading a team alongside the entire testing and vulnerability management program for a 35,000 employee company. Despite these achievements, Miller continued to consider her progression as mainly luck. “I never really considered how impressive some of that was,” she explained.

Four years later, at the age of 35, Miller entered the world of consultancy in an application security practice. As the least profitable practice at the consultancy, she was tasked with building a team from the ground up and alongside colleagues, made that team the most profitable in the entire practice, achieving revenue growth of 400%. However, “I never really gave myself a lot of credit for that,” she reflected. 

Following a merger, Miller became head of a program services practice of a new consulting services firm at the age of 37, where she worked with high-ranking security leaders like CIOs and CISOs in major global organizations. Again, Miller largely put this down to “serendipity.”  

Then, a setback occurred at the age of 41 while working for a security consulting organization as part of a larger security practice at a reseller. She was passed over for promotion to director despite being the pick of the previous director. “It really harmed my self-confidence. I felt like I’d shot too high, maybe I wasn’t ready for that high level of a role,” she outlined.

This led her to re-evaluating her goal of progressing in high-level security positions, and she moved into a ‘contributor’ role, focusing on public speaking and advocacy work.

Her perspective changed when she was approached by one of the three big social media companies, who asked if she’d like to be considered for an executive position. While nobody was ultimately hired for that role, just being considered “forced me to go back and look at everything I’d done and ask ‘why did they choose me?’” This made her analyze the extent of her achievements “and it really built up my self-confidence.”

This new found confidence took Miller to her current high-profile position, as BISO for SMP Global. “This is a chance now to do all those things I’ve been working towards all my life — what an exciting position to be in,” she said, adding: “I’d never have gotten here if I’d been afraid to take that leap, if I’d let that damage to my self-confidence hold me back.”

“This is a chance now to do all those things I’ve been working towards all my life — what an exciting position to be in”Alyssa Miller

Miller believes that getting over self-confidence issues is therefore key to progressing security careers, especially for women, who she believes continue to experience numerous disadvantages in the workplace. This includes being expected to give up their careers for their families.

With this in mind, Miller gave the following advice to those keen to develop in their careers:

  • Overcome “imposter syndrome” — the fear of being ‘found out’ in a role is “universally experienced,” particularly in tech. Therefore, it is worth remembering that there is a wide domain of cybersecurity knowledge that is around, meaning each person brings their own unique diverse perspective to the table. “Nobody knows it all,” Miller pointed out.
  • Look at job descriptions differently — Miller said that in cyber, many job descriptions “stink,” setting out experiences, requirements and responsibilities that are simply unrealistic. She gave one example of a job description that required 10 years of experience of Kubernetes, even though it has only existed for six. However, she advised potential candidates to not be put off “as no-one can check off all those boxes,” and instead look at the high level job description and ask themselves “is this something you can do or something you can learn to do?”
  • Know your worth Potential employers should never ask you what your current salary is, and if they do, you should turn the question round and tell them what you expect to be paid or even what they expect to pay someone to do that job, Miller advised. She added that you can look on sites like LinkedIn and Glassdoor to give yourself a better idea of what kind of salary you should be earning for the position you are applying for. This way, you can ensure you will be paid what you are worth to that organization.
  • Get a mentor — Miller also advised people to get a mentor to help guide them on their career journey. Rather than focusing on learning job skills, the mentor “should be sharing their journey, and be that person to help [with] situations you’re experiencing that you need help understanding or navigating.” This relationship is best forged “organically” via people met at work or at conferences.
  • See denials differently — People need to ensure they do not lose confidence if they are not offered a job after attending an interview, said Miller. The decision is never a personal one, and it might just be that “there was something about that role that wasn’t right for you.” She added that it is always worth asking for feedback from the hiring manager about what they could have done differently with their resume or during the interview. “You can use these denials as an opportunity to grow and learn, to understand how a certain position might not be the right fit for you.”
  • Negotiate the job offer — It is also important to understand that any job offer you do receive is negotiable, and don’t be afraid the company will rescind the offer if you do try and negotiate the terms of the deal. This is something that recruiters expect, noted Miller. This negotiation doesn’t just have to revolve around salary either, and can include aspects like bonuses and annual leave. “Always be willing ask, don’t be afraid,” she said.

Miller concluded by saying: “Shoot for those heights – just because you shoot high doesn’t mean that you have a chance of falling.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Execs Tout Retaliation Over Diplomacy

US Execs Tout Retaliation Over Diplomacy

Business executives in the United States favor retaliatory action over diplomacy when it comes to preventing cyber-attacks. 

A day after American president Joe Biden announced his intention to replace “relentless war” with “relentless diplomacy,” new research by Arctic Wolf shows that just 15% of US executives believe that diplomacy effectively stops future cyber-attacks. 

More than twice as many US executives – 31% – believe that retaliatory cyber-attacks against foreign nations would be effective in putting a halt to digital assaults.  

When asked which countries posed the most serious threat to their business, 41% of IT decision makers pointed the finger at China while another 41% named Russia. 

The research is based on a survey of more than 1,400 senior IT decision makers and business executives in Canada, the UK, and the US that took place in August. 

“Survey respondents revealed that despite recent interventions into cybersecurity issues, they lack faith in the government’s ability to protect them from cyber-threats, with 60% of organizations believing that spending on new security tools and services is the most effective way of stopping attacks,” stated Arctic Wolf’s Ian McShane.

This lack of confidence extended to the respondents’ own ability to secure hybrid work environments, with 60% of executives stating that their individual employees wouldn’t be able to identify a cyber-attack targeting their business in any working location. 

Another key finding of the report was that most C-suite executives in Canada, the UK, and the US said that they would pay a ransom to their cyber-attackers.

The survey found that only 22% of C-suite executives, when asked if they would pay a ransom if their organization were hit by a ransomware attack, answered “never.” When the same question was posed to middle managers, more than half (56%) gave “never” as their response. 

Nearly a third of the organizations surveyed (32%) reported suffering a data breach that exceeded six figures in the past year, with most business owners (61%) admitting that they had personally concealed a breach. 

Asked if their organization had deliberately covered up a cyber-attack to prevent the reputation of their organization’s being blemished, one in five respondents admitted that it had.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

SCADAfence Partners with Keysight Technologies

SCADAfence Partners with Keysight Technologies

A new partnership aimed at amplifying the security of operational technology (OT) networks was announced today by cybersecurity company SCADAfence.

Under the new pact, SCADAfence will join forces with American manufacturer of electronics testing and measurement equipment and software, Keysight Technologies, to enhance the cybersecurity of complex OT networks and boost their network visibility.

Through continuous monitoring and proactive mitigation, the new partnership aims to increase the control that organizations have over their industrial environments. The union brings together SCADAfence’s non-intrusive platform for deep packet inspection (DPI) and Keysight’s network test access point (TAP) and network packet broker (NPB) solutions.

“Protecting and securing OT environments from security threats and anomalies has become a top priority for the industrial sector, and we provide deep packet-level visibility with accurate real-time analytics,” said Elad Ben-Meir, chief executive officer of SCADAfence. 

“We’re excited to partner with Keysight Technologies to help industrial organizations leverage both solutions for better visibility and more advanced packet information within OT environments.”

Companies already using SCADAfence’s services include Vestel, Mitsui Fudosan, Taro Pharmaceuticals, and numerous other Fortune 500 companies in the United States.

In a statement released September 22, the companies said that deploying their solution together will increase real-time visibility into OT environments and provide detailed asset visibility and continuous threat detection for manufacturing sites, water and wastewater environments, oil and gas facilities, automotive, and other industrial infrastructures.

The partnership will give Keysight the ability to collect data across all OT environments that can be used to generate actionable insights. 

“Critical infrastructures are being targeted more than ever and are facing more security threats in the OT and IoT networks. The mitigation process can take from weeks to possibly months to patch vulnerabilities within the more complex environments,” said Taran Singh, vice president, enterprise solutions, Keysight. 

“Our joint-partnership with SCADAfence will allow our customers and other industrial organizations to speed up that process from weeks to a few days.”

News of the partnership comes six months after SCADAfence announced that it had secured $12m in funding aimed at accelerating growth. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Treasury Sanctions Russian Crypto Exchange

Treasury Sanctions Russian Crypto Exchange

The US Treasury has added a Russian cryptocurrency exchange to its sanctions list after claiming the firm helped facilitate ransomware payments for countless groups.

SUEX is incorporated in the Czech Republic but reportedly operates out of Russia. The Treasury estimated that 40% of its transaction history is associated with “illicit actors.”

According to separate analysis, the “over the counter” (OTC) broker has received over $160m in Bitcoin alone from illegal and high-risk sources, including Ryuk, Conti and Maze ransomware groups; dark web sites like Hydra Market; and cryptocurrency scammers.

“As a result of today’s designation, all property and interests in property of the designated target that are subject to US jurisdiction are blocked, and US persons are generally prohibited from engaging in transactions with them,” the Treasury explained.

“Additionally, any entities 50% or more owned by one or more designated persons are also blocked. In addition, financial institutions and other persons that engage in certain transactions or activities with the sanctioned entities and individuals may expose themselves to sanctions or be subject to an enforcement action.”

The US government action was widely trailed over the weekend, and includes a separate update from the Treasury’s Office of Foreign Assets Control (OFAC) designed to remind ransomware victims of the risks involved in paying cyber-criminals.

Specifically, payment of certain groups on sanctions lists, like Evil Corp, may result in penalties levied by the government on the victim organization.

“OFAC has updated the advisory to emphasize the importance of improving cybersecurity practices and reporting to, and cooperating with, appropriate US government agencies in the event of a ransomware attack,” the Treasury said.

“Such reporting, as the advisory notes, is essential for US government agencies, including law enforcement, to understand and counter ransomware attacks and malicious cyber actors.”

The FBI recorded victim ransomware losses of just $29m last year. However, the Treasury estimated that organizations paid out $400m in ransom payments alone last year, more than four times the 2019 figure.

Adam Flatley, director of threat intelligence at [redacted], welcomed the sanctions but said that government efforts need to go further.

“It will be critical that actions like these continue to be pursued as part of a larger, coordinated, intelligence-driven campaign that uses all aspects of national and international power,” he added.

“Financial and law enforcement actions are important components to this campaign, but this problem can’t be solved without bringing in capabilities that have not been traditionally used against criminal organizations.”

Sam Curry, chief security officer at Cybereason, had similar concerns: “The announcement from the White House is a good first step but, if this is the only exchange sanctioned, then there will be little effect, and the ransomware economy will continue to grow. There are many more exchanges, so now it’s all about adaptability and evolution. 

“The Department of Justice estimated that 40 percent of the digital transactions facilitated by SUEX were for illicit activity. With yesterday’s news, the ransomware cartels take a one-time loss, re-gear and use new exchanges. So the first move of the chess match has been made. What comes next in this digital frontier skirmishing? Let’s see!”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains