Podcast: Ransomware Up x10: Disrupting Cybercrime Suppy Chains an Opportunity

Derek Manky, Chief, Security Insights & Global Threat Alliances at Fortinet’s FortiGuard Labs, discusses the top threats and lessons learned from the first half of 2021.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Interesting Privilege Escalation Vulnerability

If you plug a Razer peripheral (mouse or keyboard, I think) into a Windows 10 or 11 machine, you can use a vulnerability in the Razer Synapse software — which automatically downloads — to gain SYSTEM privileges.

It should be noted that this is a local privilege escalation (LPE) vulnerability, which means that you need to have a Razer devices and physical access to a computer. With that said, the bug is so easy to exploit as you just need to spend $20 on Amazon for Razer mouse and plug it into Windows 10 to become an admin.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

How to Spot Fake Login Pages 

Have you ever come across a website that just didn’t look quite right? Perhaps the company logo looked slightly misshapen, or the font seemed off-brand. Odds are, you landed on a phony version of a legitimate corporation’s website—a tried and true tactic relied on by many cybercriminals.  

Fake Login Pages Explained  

A fake login page is essentially a knock-off of a real login page used to trick people into entering their login credentials, which hackers can later use to break into online accounts. These websites mirror legitimate pages by using company logos, fonts, formatting, and overall templates. Depending on the attention to detail put in by the hackers behind the imposter website, it can be nearly impossible to distinguish from the real thing. Consequentially, fake login pages can be highly effective in their end goal: credential theft.  

How do these pages get in front of a consumer in the first place? Typically, scammers will target unsuspecting recipients with phishing emails spoofing a trusted brand. These emails may state that the user needs to reset their password or entice them with a deal that sounds too good to be true. If the consumer clicks on the link in the email, they will be directed to the fake login page and asked to enter their username and password. Once they submit their information, cybercriminals can use the consumer’s data to conduct credential stuffing attacks and hack their online profiles. This could lead to credit card fraud, data extraction, wire transfers, identity theft, and more. 

How Fake Login Pages Are Affecting Canadians 

Scammers have recently targeted Canadians with attacks leveraging fake login pages to harvest personal data. For example, criminals preyed on employees who were expecting COVID-19 relief grants in the form of the CERB (Canada Emergency Response Benefit). These funds were sent via an electronic transfer from Interac, a legitimate Canadian interbank network. However, a phishing campaign spoofing Interac’s e-transfer service circulated emails claiming that the Canada Revenue Agency (CRA) made a CERB deposit of $1,957.50 CAD.  

These emails directed recipients to a fake CRA login page, which then redirected to a phony Interac e-transfer site where users were asked to select their personal bank. From there, the recipient was asked to enter their username, card number, password, security questions and answers for their online banking profile, and other personally identifiable information—providing all the information a criminal would need to hack into the user’s bank account.  

Why Fake Login Pages are Effective  

If you Google “fake login pages,” you will quickly find countless guides on how to create fake websites in seconds. Ethical concerns aside, this demonstrates just how common vector spoofed websites are for cyberattacks. While it has been easier to distinguish between real and fake login pages in the past, criminals are constantly updating their techniques to be more sophisticated, therefore making it more difficult for consumers to recognize their fraudulent schemes.  

One reason why fake login pages are so effective is due to inattentional blindness, or failure to notice something that is completely visible because of a lack of attention. One of the most famous studies on inattentional blindness is the “invisible gorilla test.” In this study, participants watched a video of people dressed in black and white shirts passing basketballs. Participants were asked to count the number of times the team in white passed the ball: 

Because participants were intently focused on counting the number of times the players in white passed the ball, more than 50% failed to notice the person in the gorilla costume walking through the game. If this is the first time you’ve seen this video, it’s likely that you didn’t notice the gorilla, the curtain changing color from red to gold, or the player in black leaving the game. Similarly, if you come across a well-forged login page and aren’t actively looking for signs of fraud, you could inherently miss a cybercriminal’s “invisible gorilla.” That’s why it’s crucial for even those with phishing training to practice caution when they come across a website asking them to take action or enter personal details.  

How to Steer Clear of Fake Login Pages  

The most important defense against steering clear of fake login pages is knowing how to recognize them. Follow these tips to help you decipher between a legitimate and a fake website:  

1. Don’t fall for phishing  

Most fake login pages are circulated vis phishing messages. If you receive a suspicious message that asks for personal details, there are a few ways to determine if it was sent by a phisher aiming to steal your identity. Phishers often send messages with a tone of urgency, and they try to inspire extreme emotions such as excitement or fear. If an unsolicited email urges you to “act fast!” slow down and evaluate the situation. 

2. Look for misspellings or grammatical errors  

Oftentimes, hackers will use a URL for their spoofed website that is just one character off from the legitimate site, such as using “www.rbcr0yalbank.com” versus “www.rbcroyalbank.com.” Before clicking on any website from an email asking you to act, hover over the link with your cursor. This will allow you to preview the URL and identify any suspicious misspellings or grammatical errors before navigating to a potentially dangerous website. 

3. Ensure the website is secured with HTTPS 

HTTPS, or Hypertext Transfer Protocol Secure, is a protocol that encrypts your interaction with a website. Typically, websites that begin with HTTPS and feature a padlock in the top left corner are considered safer. However, cybercriminals have more recently developed malware toolkits that leverage HTTPS to hide malware from detection by various security defenses. If the website is secured with HTTPS, ensure that this isn’t the only way you’re analyzing the page for online safety.  

4. Enable multi-factor authentication 

Multi-factor authentication requires that users confirm a collection of things to verify their identity—usually something they have, and a factor unique to their physical being—such as a retina or fingerprint scan. This can prevent a cybercriminal from using credential-stuffing tactics (where they will use email and password combinations to hack into online profiles) to access your network or account if your login details were ever exposed during a data breach.  

5. Sign up for an identity theft alert service 

An identity theft alert service warns you about suspicious activity surrounding your personal information, allowing you to jump to action before irreparable damage is done. McAfee Total Protection not only keeps your devices safe from viruses but gives you the added peace of mind that your identity is secure, as well.  

The post How to Spot Fake Login Pages  appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Australia Passes Identify and Disrupt Bill

Australia Passes Identify and Disrupt Bill

A coalition bill that grants the police more powers to spy on criminal suspects online has been passed by the Australian government.

The Surveillance Legislation Amendment (Identify and Disrupt) bill has created three new types of warrants that enable the Australian Federal Police (AFP) and Australian Criminal Intelligence Commission (ACIC) to modify and delete data belonging to cybercriminal suspects and take over their accounts. 

Using the new data disruption warrants, the AFP and the ACIC can prevent serious offenses from being committed online by modifying, adding, copying or deleting data. Network activity warrants allow the agencies to gather intelligence on criminal activity being carried out by cyber-criminal networks, while account takeover warrants can be used to take control of a suspect’s online account.

An eligible judge or a nominated member of the administrative appeals tribunal (AAT) can issue the data disruption and network activity warrants. However, the account takeover warrants must come from a magistrate who is satisfied that there are reasonable grounds that such a step is required to collect evidence relating to a relevant offense.

On Tuesday, Labor MP Andrew Giles told the lower house that the bill had gained the support of the opposition because “the cyber-capabilities of criminal networks have expanded, and we know that they are using the dark web and anonymizing technology to facilitate serious crime, which is creating significant challenges for law enforcement.”

The Greens flagged that the new powers go against a central recommendation of the Richardson review of the legal framework for Australia’s intelligence community. Richardson found that “law enforcement agencies should not be given specific cyber-disruption powers.”

Recommendations to improve safeguards and oversight concerning the new powers were made earlier this month by the parliamentary joint committee on intelligence and security (PJCIS), though not all of them were implemented.

The committee can review the bill after four years, and the Independent National Security Legislation Monitor will review the bill in 2024.

Kieran Pender, senior lawyer at the Human Rights Law Centre, told Guardian Australia that the new powers granted to the AFP and ACIC under the bill “are unprecedented and extraordinarily intrusive.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Glitch Exposed Data of Alleged Treaty Violator to FBI

Glitch Exposed Data of Alleged Treaty Violator to FBI

Private data belonging to an alleged treaty violator was accessible to unauthorized FBI agents for months because of a software program flaw.

The glitch in the Palantir program was reportedly exploited by at least four Bureau employees to view data belonging to Singapore resident and US citizen Virgil Griffith

Former Ethereum developer Griffith was arrested at Los Angeles International Airport in November 2019 and charged with violating the International Emergency Economic Powers Act by traveling to the Democratic People’s Republic of Korea to give a presentation and technical advice on using crypto-currency and blockchain technology to evade sanctions. 

In January 2020, in a Southern District of New York courthouse, Griffith pleaded not guilty to the charge.  

The Palantir defect exposed data that had been recovered from Griffith’s Twitter and Facebook accounts in March 2020 during the execution of a federal search warrant. Prosecutors in the case against Griffith, who described the glitch in a letter, said it pertained to the program’s default setting.

“When data is loaded onto the Platform, the default setting is to permit access to the data to other FBI personnel otherwise authorized to access the Platform,” wrote prosecutors. 

The prosecutors wrote that word of the unauthorized access came to Griffith’s assigned FBI case agent via an email sent by another agent. The email explained that material seized in the search and entered in Palantir through the program’s default settings had been accessed by FBI analyst.

A letter filed by the Bureau on Tuesday states: “An FBI analyst, in the course of conducting a separate investigation, had identified communications between the defendant and the subject of that other investigation by means of searches on the Platform that accessed the Search Warrant Returns.”

Prosecutors learned that three FBI analysts and an agent had viewed Griffith’s private data owing to the Palantir glitch. None of the FBI employees who accessed Griffith’s data were working on his case. 

Between May 2020 and August 2021, the seized material was accessed at least four times.

Griffith is scheduled to appear in court on September 21. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Revere Health Data Breach Impacts Cardiology Patients

Revere Health Data Breach Impacts Cardiology Patients

The Personal Identifiable Information (PII) of approximately 12,000 cardiology patients has been exposed in a cyber-attack on a healthcare provider based in Utah.

Patient data in the care of Revere Health was compromised when the organization fell victim to a phishing attack on June 21, 2021.

An attacker impersonating the US Agency for International Development (USAID) sent an email to a Revere Health employee that contained a malicious link. When the employee clicked the link, they inadvertently gave the threat actor access to their login credentials. 

The attacker used the stolen credentials to log in to an employee email account that contained information belonging to patients of Revere Health’s Heart of Dixie Cardiology Department in St. George, Utah. No credit card or payment information was among the data accessed by the attacker.

In a patient notification statement, Revere Health said that the compromised data was limited to patient names, dates of birth, medical record numbers, provider names, procedures, and information about appointments. 

“Since this data is relatively limited, we believe that this poses a low-level risk to your personal information,” said the organization.

It continued: “We have no reason to believe that they [the attacker] accessed, or were interested in, patient information. However, we cannot completely rule this out.”

Revere Health said that active monitoring by its IT security team detected the unauthorized activity quickly. Within 45 minutes of the attack’s commencing, the team was able to sever unauthorized access to the compromised email account. 

An investigation into the incident led Revere Health to conclude that stealing patient data was not the assailant’s main intention. 

“From our detailed investigation of this incident, we believe that the intent of this attack was to harvest login credentials from individuals in our organization and not to gather patient information,” stated the healthcare provider. 

“Our security logs suggest that the attacker had three objectives: (1) to spread phishing emails, (2) to gather active usernames and passwords and (3) to attempt financial fraud against Revere Health.” 

Following the incident, Revere Health has updated its security awareness training, enhanced suspicious activity detection protocols, and accelerated its rollout of two-factor authentication software.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

70% of Cyber Pros Believe Cyber Insurance is Exacerbating Ransomware

70% of Cyber Pros Believe Cyber Insurance is Exacerbating Ransomware

More than two-thirds (70%) of cybersecurity professionals believe that the issue of ransomware is being exacerbated by cyber-insurance payouts to victim organizations, according to a new study by cybersecurity firm Talion.

The survey of 200 UK cybersecurity professionals also unveiled some worrying findings about reporting ransomware attacks to law enforcement. When asked why so many attacks are not reported, nearly half (45%) of respondents said that they believe businesses think law enforcement slows down ransomware recovery and they are focused on getting their systems back online. More than a third (37%) said it was because companies have paid a ransom and don’t want to get into trouble.

Additionally, one in 10 of those surveyed said companies didn’t know how to report ransomware attacks to law enforcement.

The report follows a surge in ransomware attacks globally in 2021. Earlier this month, a study from the International Data Corporation (IDC) found that over one-third of organizations worldwide have experienced a ransomware attack or breach that blocked access to systems or data in the previous 12 months. This has led to numerous eye-watering ransoms being paid to cyber-criminals, ramping up the debate on whether it is ever acceptable to pay a ransomware demand.

Commenting on the study, Mike Brown, CEO of Talion, said: “Our study highlights that many organizations are concerned about reporting ransomware attacks to law enforcement out of fear it could have further negative repercussions. All victims want to get back to business as usual as quickly as possible; however, it can be a complicated landscape to navigate. Should you pay the ransom? If so, is it lawful? Organizations should be mindful that it is unlawful to make a payment to terrorist organizations or prescribed groups in breach of international sanctions. What is required is a clear legal framework that allows organizations to make the best, lawful decisions when they are in this high-stress situation. Law enforcement needs to find a way to work with a commercial organization so that they are viewed as a source of expertise and support, not a further obstacle to overcome.”

“In terms of insurance payouts, it is not surprising so many security professionals see them as fuelling the ransomware industry, as they certainly cushion the blow of attacks. However, payouts are not guaranteed, and insurers are getting stricter every day. The best option is, therefore, to prepare for attacks and rehearse your strategy so when your organization gets hit in real life, losses are kept to a minimum.”

In June, Talion launched the #RansomAware campaign, a coalition of cyber security experts, businesses, academia and government to facilitate collaboration and information sharing around ransomware.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Innovative Recruitment Practices Can Close the Cyber Skills Gap

Innovative Recruitment Practices Can Close the Cyber Skills Gap

Developing more innovative hiring practices is crucial to attracting more talent to the cybersecurity industry, according to panelists speaking during a recent RSA webcast.

The event was held amid growing efforts from the US federal government to attract new candidates to the cybersecurity industry to close the burgeoning skills gap.

Barbara Endicott-Popovsky, executive director of Center for Information Assurance and Cybersecurity and professor at the University of Washington, stated: “It’s been frustrating to watch the lack of awareness of the cyber threats that we face and even more frustrating to spend so much time as we have developing talent and trying to make sure we get the right people to the right places.”

The first step in addressing this issue is to ensure there is much more clarity about the types of people and skills that are needed to work in cyber, according to Lynn Clark, chief of the NSA/DHS Centers of Academic Excellence at the National Security Agency (NSA). “It’s really hard to produce educational programs to prepare people for the workforce if we don’t know what our end objective is,” she outlined.

It is also vital that cybersecurity recruiters recognize the wide variety of motivations candidates have to work in this sector, thereby ensuring they “use the right lure for the right fish,” said Joshua Corman, senior advisor for the Cybersecurity and Infrastructure Security Agency (CISA).

He listed five different drivers (p’s) for those who work in the industry: protectors, purpose, prestige, profit and protest/patriotism, adding that “how you engage and recruit them will be different.”

The discussion then turned to the types of people and skills needed to make up the industry. Endicott-Popovsky observed that traditionally, the cyber industry has primarily been comprised of ‘techies,’ meaning other important skill sets are lacking.

Emily Harding, deputy director and senior fellow with the International Security Program at the Center for Strategic and International Studies (CSIS), said that in her experience, character and mindset are more important than qualifications when looking to recruit candidates for cybersecurity jobs. She believes the ideal person needs to be “smart and can think, and who does not get discouraged by bureaucracy or small hurdles, somebody who doesn’t want a roadmap to accomplish things.”

As well as hackers who can use their technical skills to discover security flaws, Corman feels the cyber industry needs more ‘translators’ in its ranks to translate these flaws into action. During previous experiences, he found that people with backgrounds in areas like law and project management are particularly effective at this role. “The things we were able to do were because we came from incredibly different backgrounds, but we had a common cause, common purpose and could be brought together like a team of Avengers to fight the greatest foes and risks,” he added.

Clark concurred with these perspectives, emphasizing the need for security teams to be comprised of people with strong soft-skills, such as communication and collaboration, alongside “people who understand the technology.” She pointed out, “All the technology in the world is not going to protect us from the hacker who can socially engineer somebody into giving him a password or who can spearphish and get the important information they need to access our systems.”

The panel also agreed that the organizations need to adapt their standard requirements for cybersecurity candidates to enable this type of neurodiversity to become a reality. This includes working with HR and legal departments to reduce the emphasis on formal technical qualifications. Additionally, Harding believes “you have to have that human-to-human connection as much as possible, where you’re going out to career fairs and universities and recruiting.”

The principle of favoring character over qualifications is particularly pertinent when it comes to recruiting for leadership positions. Corman observed that individuals are often pushed into leadership roles based on their technical expertise, which is the wrong criteria to use. “You have to make sure you have the right leaders because they set the tone, the cadence, the value set, the culture, as best they can,” he noted.

More broadly, Corman said that all personnel operating in the rapidly evolving field of cybersecurity must be flexible and willing to learn on the job continuously. “An adaptable person will adapt at the speed of cyber,” he commented.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains