Access Granted: How the DoD Can Stay Cyber-Resilient

Now more than ever, it’s critical to be mission-ready for the next cyber threat. Our digital-first, post-pandemic world is shifting back to a new normal. But the threats are still here.

Mission-Ready

And according to many reports, the threats have – and are continuing to – increase. McAfee Enterprise’s Advanced Threat Research recently published a report highlighting some of the biggest cyber stories dominating the year thus far, including recent ransomware attacks. While the topic itself is not new, there is no question that the threat is now truly mainstream. In fact, the June report provides a deep dive into the DarkSide ransomware, which resulted in an agenda item in talks between U.S. President Biden and Russian President Putin.

Rising Up

So how does the DoD approach modern-day threats like this? McAfee Enterprise’s online cyber training program is a great place to start. I’m proud to say the program is complimentary for our DoD partners and provides anywhere from 1-6 Continuing Professional Education (CPE) hours per course. You can login anywhere in the world to access the various trainings. Plus, the digital course are valid for 30 days from your registration date, so you can start and stop at any time. Not surprisingly, the tech industry is seeing a greater acceptance and return on investment from online training programs. Within the DoD for example, the Airforce recently launched Digital University. Airmen are elevating their digital literacy skills with up to 12,000 courses to better serve our country, while discovering new career paths in the process. Everything from leadership and public speaking to cloud computing and cybersecurity are covered, proving this platform may be the future of IT training.

Access Granted

I know the cyber industry that I joined 20+ years ago isn’t the same as it is today. And without access to trainings and CPE courses, my skill set would not be as strong. But if your day is anything like mine, finding time to squeeze in continuing education courses is a challenge. However, after hearing feedback from a long-time DoD partner, I know we’re on to something good. Success stories like these remind me of the importance of staying cyber-resilient in the field.

CTA Button à Start Now:  https://mcafee-catalog.netexam.com/training/881

Don’t forget to reach out to your McAfee Enterprise Account Executive for your unique DoD voucher code!

 

The post Access Granted: How the DoD Can Stay Cyber-Resilient appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ms. Information Vaccine Campaign Launches

Ms. Information Vaccine Campaign Launches

An entertaining new campaign has been launched to combat the sea of misinformation about coronavirus vaccines on social media that was branded an “infodemic” by the World Health Organization.

The Instagram-based campaign was created by healthcare agency FCB Health New York IPG and non-profit group GMHC and is fronted by drag queen and influencer Miz Jade.

As the glamorous and red-headed Ms. Information, the performer imparts facts about COVID-19 and coronavirus vaccines in a comedic style that bemoans the crippling impact of the pandemic on her social life. 

The campaign’s creators hope that playfully portraying the virus as the destroyer of a “hot girl summer” will encourage members of the LGBTQ+ community to get vaccinated. 

Ms. Information shares the facts in a fun way in a series of short video clips. Visitors to @therealmsinformation will encounter the drag queen wearing a figure-hugging leopard print dress and matching elbow-length gloves, imparting such witticisms as, “Girl, misinformation is spreading faster than a fire in a wig factory.”

Jason Cianciotto, GMHC’s senior managing director of institutional development & strategy, said that the campaign was a light-hearted alternative approach to putting hard pressure on the public to get vaccinated.

“We recognize that shaming people is not effective and can be detrimental to the well-being of the people we serve,” said Cianciotto. “We don’t want to lose the battle of misinformation about HIV/AIDS and Covid-19.”

Recent data analysis from the Human Rights Campaign Foundation and PSB Insights found a high level of vaccine hesitancy in the black LGBTQ community. 

The data is based on a survey of 22,000 adults in the United States which asked how many LGBTQ people may be unlikely to say they want to get vaccinated. 

Overall, 42% of LGBTQ adults said that they were very likely to get the COVID-19 vaccine compared to just 39% of the general American population. However, only 29% of black LGBTQ said they were likely to get vaccinated. 

In exploring the impact of misinformation about the vaccine on the LGBTQ community, HRCF observed: “Despite the vaccines’ being available for free, LGBTQ adults have concerns about the cost of the vaccine, especially LGBTQ adults of color, bisexual adults and transgender adults.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Microsoft Cloud Databases Exposed

Microsoft Cloud Databases Exposed

American multinational technology corporation Microsoft has warned thousands of its cloud computing customers that their data could be accessed, altered or erased, according to a report by Reuters.

Customers were warned that threat actors could even delete their main database by exploiting a vulnerability in Microsoft Azure’s flagship Cosmos DB database that has been named ChaosDB.

The alleged flaw was unearthed on August 9 by a team of security researchers, who found that they could get hold of keys that unlock access to databases belonging to thousands of businesses. The researchers are employed by security company Wiz, which was reportedly paid $40,000 by Microsoft for detecting and reporting the serious vulnerability. 

Microsoft told Reuters: “We fixed this issue immediately to keep our customers safe and protected. We thank the security researchers for working under coordinated vulnerability disclosure.”

However, Reuters reports that Microsoft was not able to immediately fix the issue itself, as the company cannot make changes to customers’ keys. Instead, Microsoft emailed its cloud computing customers yesterday and instructed them to cut new virtual keys. 

In its email to customers, Microsoft said: “We have no indication that external entities outside the researcher (Wiz) had access to the primary read-write key.”

But the severity of the vulnerability was apparent to Wiz chief technology officer Ami Luttwak. The former CTO at Microsoft’s Cloud Security Group said: “This is the worst cloud vulnerability you can imagine. It is a long-lasting secret. This is the central database of Azure, and we were able to get access to any customer database that we wanted.”

In a blog post dedicated to the discovery, Wiz stated that its researchers “were able to gain complete unrestricted access to the accounts and databases of several thousand Microsoft Azure customers, including many Fortune 500 companies.”

Luttwak warned that the flaw, which was found lurking in a visualization tool called Jupyter Notebook, may have impacted additional Microsoft customers who have not been notified, since the company only emailed customers whose keys were visible in August.

Camille Charaudeau, vice president of product strategy at CybelAngel, commented that the flaw met all the conditions for “a proper ransomware attack.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

T-Mobile’s Security Is ‘Awful,’ Says Purported Thief

John Binns, claiming to be behind the massive T-Mobile theft of >50m customer records, dissed the security measures of the US’s No. 2 wireless biggest carrier. T-Mobile is “humbled,” it said, announcing new partnerships with security heavyweights on Friday.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

New Cyber Warfare Wing Coming to Ohio

New Cyber Warfare Wing Coming to Ohio

The US Air Force has chosen a town nicknamed “Danger City” to be the location for the Air National Guard’s first Cyber Warfare Wing.

Mansfield has around 50,000 inhabitants and is situated in the northeastern part of Ohio, midway between Columbus and Cleveland. According to local beer-maker, the Phoenix Brewing Company, the town earned its ominous nickname in the 1970s when businesses fled the downtown area for premises in a suburban shopping mall.

The US Air Force announced on Wednesday that the town’s Mansfield-Lahm Air National Guard Base has beaten Minneapolis-St. Paul International Airport in Minnesota to be chosen as the base for a new Cyber Warfare Wing mission.

News of the selection followed a visit to the base earlier this month by a site survey team. To advance the new cyber mission, the Air Force plans to retire eight C-130H Hercules from its aging inventory at the 179th Airlift Wing in 2022.

The Air Force plans to create 175 new positions at Mansfield ANGB, which will be STEM and IT focused. 

In a press release issued Thursday, 179th Airlift Wing commander, Col. Todd Thomas, said that the transition from air to desk will be a hard one. 

“Since becoming the Wing Commander, I have always told our Airmen we must do everything in our ability to ‘keep the front gate open’ and flex to whatever mission allows us to be viable well into the future and aligns with the National Defense Strategy,” said Thomas. 

“I am extremely confident our Airmen are capable of shifting focus from tactical air-land and air-drop operations to the cyber battlefield. I look forward to what our Airmen will bring to the cyber fight.”

Ohio governor Mike DeWine welcomed the new mission as “a tremendous win” for the state. 

“Ohio is gaining a leading-edge mission that will strengthen the fabric of the military community and further solidify Ohio as a national leader in cybersecurity excellence,” said DeWine. 

“Not only will this new mission bring more jobs into the community, but it will also spur more economic growth and create new opportunities for industry and academic growth.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

FBI Warns Businesses of New Hive Ransomware

FBI Warns Businesses of New Hive Ransomware

The FBI has issued a warning to firms about an increasingly prolific new ransomware variant known as Hive.

The Flash alert posted this week noted that the affiliate-based ransomware uses multiple mechanisms to compromise corporate networks, making it harder for defenders to mitigate.

It noted that these include phishing emails with malicious attachments to gain initial access and the hijacking of Remote Desktop Protocol (RDP) to move laterally.

The malware itself looks for and terminates processes linked to backups, anti-virus and file copying to boost its chances of success. Encrypted files end with a .hive suffix.

“The Hive ransomware then drops a hive.bat script into the directory, which enforces an execution timeout delay of one second in order to perform clean-up after the encryption is finished, by deleting the Hive executable and the hive.bat script,” the alert continued.

“A second file, shadow.bat, is dropped into the directory to delete shadow copies, including disc backup copies or snapshots, without notifying the victim and then deletes the shadow.bat file.”

The ransom note, dropped into every impacted directory, warns that if encrypted files are modified, renamed or deleted, they can’t be recovered. In the spirit of modern ransomware operations, which are highly professionalized, there’s also a live chat link to a ‘sales department,’ accessible through a TOR browser, for further communication.

Some victims told the FBI they had received follow-up phone calls from their attackers urging payment. A second tactic is to exfiltrate and publish stolen files on a public leak site.

It’s believed the group, or affiliates associated with Hive, were responsible for the attack on Memorial Health System earlier this month, which disrupted IT systems at nearly all of its 64 clinics and three hospitals.

According to Palo Alto Networks, Hive had breached 28 organizations listed on its leak site as of this week, including a European airline company. It was first discovered in June.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Critical IoT Camera Flaw Allows for Device Hijacking

Critical IoT Camera Flaw Allows for Device Hijacking

Security researchers have discovered another critical bug in IoT security camera systems that could allow attackers to hijack devices.

Nozomi Networks found remote code execution vulnerability CVE-2021-32941 in the web service of the Annke N48PBB network video recorder (NVR) — used by consumers and businesses.

NVRs are an important part of any connected security camera system in that they’re designed to capture, store and manage incoming video feeds from IP cameras.

If exploited, the vulnerability could cause a stack-based buffer overflow, allowing an unauthenticated, remote attacker to access sensitive information and execute code, according to an ICS advisory from the Cybersecurity and Infrastructure Security Agency (CISA).

Nozomi Networks said this could lead to a loss of confidentiality, integrity and device availability. In practice, this means enabling attackers to snoop on or delete footage, change the configuration of motion detector alarms, or halt recording altogether.

As such, a cyber-attack exploiting CVE-2021-32941 could be used to support physical robberies of premises protected by Annke devices.

The bug itself could be exploited directly by attackers to elevate privileges on the system and indirectly in drive-by-download attacks.

“It is sufficient for an administrator, operator, or user to browse a specifically crafted webpage, while simultaneously logged in to the web interface of the device, to potentially cause the execution of external malicious code on the device itself,” warned Nozomi.

Fortunately, Annke acted quickly to fix the issue, releasing new firmware to patch the problem just 11 days after Nozomi’s responsible disclosure.

This is the second critical flaw affecting IoT cameras that Nozomi Networks has found this summer. Back in June it warned of a bug in a popular software component from ThroughTek, which OEMs use to manufacture IP cameras, and baby and pet monitoring cameras.

This could also have allowed attackers to eavesdrop on users.

Another vulnerability was found in ThroughTek’s Kalay platform just last week, affecting potentially millions of devices.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Chinese Developer Exposes Data on Over One Million Gamers

Chinese Developer Exposes Data on Over One Million Gamers

A Chinese game developer has unwittingly exposed the personal and device details of over a million players after leaving an internet-facing server unsecured, according to researchers.

A team at vpnMentor led by Noam Rotem and Ran Locar, discovered the unprotected Elasticsearch server on July 5. After no reply from its owner, EskyFun Entertainment Network Limited, they contacted the Hong Kong CERT, and the next day, July 28, the database was secured.

The 134GB trove contained an estimated 365 million records linked to players of the firm’s fantasy games: Rainbow Story: Fantasy MMORPG; Metamorph M; and Dynasty Heroes: Legends of Samkok.

This giant collection of user records is even more noteworthy given the firm collected only a rolling log of the previous seven days’ records, with anything older deleted to make way for fresh data.

“The reason for the sheer size of the data exposed appears to be EskyFun’s aggressive and deeply troubling tracking, analytics, and permissions settings,” vpnMentor claimed. “EskyFun gains access and control to almost every aspect of a person’s device and even their private networks. Most of [the data] is totally unnecessary for the games to function.”

Among the data leaked via the unsecured server were IP address, device model, phone number, geolocation and buyer account ID. The researchers also found over 217 million email addresses and plaintext EskyFun passwords.

The vpnMentor team estimated the number of users affected at over one million due to the number of Android downloads the three affected games have: around 1.5 million.

“Combining a user’s email address, gaming history, and support requests, hackers could send thousands of phishing emails posing as EskyFun’s support,” the researchers wrote.

“The database also contained plenty of data to build a profile of users and identify two vulnerable groups: high-paying accounts and children. By focusing on these users, hackers could reap huge financial rewards from a small group of victims.”

Cyber-criminals could also have used the plaintext passwords to hijack user’s EskyFun gaming accounts or to support credential stuffing campaigns designed to unlock other accounts across the web that the same credentials may protect.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains