Financial Services Brace Themselves for Increase in Email-Borne Cyberattacks

Financial Services Brace Themselves for Increase in Email-Borne Cyberattacks

Financial Services (FS) companies expect to see an influx of email-borne attacks during 2021 due to increased volumes in email (81%), according to research.

Accordion to a report from cybersecurity firm Mimecast, 62% of FS organizations believe that it’s likely, extremely likely or inevitable that their company will experience negative business impact from attacks originating from emails. The research also found that 60% of its respondents saw increases in phishing with malicious links or attachments over the past year.

Johan Dreyer, cybersecurity expert at Mimecast, comments, “The use of digital and mobile in the financial services industry is only set to increase further, so we are definitely going to witness an increase in the rate and sophistication of cyberattacks on finance firms and their customers.

“As email remains the most common threat vector and its volume and sophistication of attacks is expected to increase, financial firms need to layer multiple security technologies to protect their email systems,” he continues. “This will ensure any active threat can be dealt with as quickly and efficiently as possible. Such multi-layered defences complement and backstop one another—if a given attack sidesteps one defence, there are others in place that can stop the threat.”

Respondents in the report also noted that they had seen an increase in the misuse of their brands via both email and spoofed cloned web domains (42%). Some also saw an influx in their brand’s misuse in cloned websites (42%) and significant increases in emails that “misappropriated their brands” (11%).

This could mean priorities will change for security specialists or chief information security officers (CISOs). The report found that 57% of respondents expected the volume of attacks to be among their biggest email security challenges of 2021, with 64% saying that sophisticated threats are amongst their biggest security challenges when it comes to email.

Ransomware attacks have also stoked fear in FS organizations, with 53% of the companies surveyed saying that an attack had impacted their business within the last 12 months. Because of these attacks, 44% of companies have had to paid a ransom. Downtime has also impacted businesses, with 30% of the companies having between one and four weeks of downtime from ransomware attacks.

“The threat of ransomware in particular and its potential costs all continue to increase,” warns Dreyer. “While most of these attacks are email-borne and layered defences can help, protecting data with rigorous backup and retention policies — that include off-network repositories — are important solutions for mitigating permanent loss of data for financial firms.”

However, according to Mimecast’s report, necessary protections have not been put in place, with only 44% of FS companies providing security awareness training on a monthly basis or at greater frequency. Further, the largest concentration of companies provide only quarterly training.

Of the finance firms surveyed, 47% said they did not have a cyber resilience strategy already in place.

Mimecast’s Dreyer advises what FS companies can do to mitigate these threats: “The biggest potential difference can be made by shoring up cybersecurity’s weakest links: the people. Financial firms need to extend their leading security awareness training practices with more personalized/individualized training and greater frequency. Preserving customer trust and reputation are critical to a financial firm’s business success.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Data Breach at Georgia Health System

Data Breach at Georgia Health System

A health system in Georgia has begun notifying patients of a six-month-long data breach that culminated in a ransomware attack.  

St. Joseph’s/Candler (SJ/C), one of the largest hospital systems in Savannah, became aware of suspicious network activity on the morning of June 17, 2021. A ransomware attack was confirmed, and steps were taken to limit its impact. 

With its computers out of action, the health system used social media to spread word of the security incident, posting: “On the morning of June 17, St. Joseph’s/Candler became aware of suspicious network activity. As a security measure, SJ/C took immediate steps to isolate systems and to limit the potential impact.

“We also promptly initiated an investigation into the scope of the incident, which is ongoing and in its early stages, although SJ/C has confirmed that the incident involved ransomware.”

SJ/C employees had to revert to downtimes procedures such as using pens and paper to complete documentation. While the incident led to EHR downtime, imaging, primary care, surgery, and special physician appointments were unaffected.

The health system said at the time of the attack that it would notify anyone whose personal data had been compromised. That notification process began on August 10 after an investigation revealed that sensitive information belonging to both SJ/C patients and employees had been accessed by an unauthorized third party. 

In a statement released yesterday, the health system said: “Through SJ/C’s investigation it was determined that the incident resulted in an unauthorized party gaining access to SJ/C’s IT network between the dates of December 18, 2020, and June 17, 2021. 

“While in our IT network, the unauthorized party launched a ransomware attack that made files on our systems inaccessible.”

Data that may have viewed by the malicious hacker(s) included patient names in combination with their address, date of birth, Social Security number, driver’s license number, patient account number, billing account number, financial information, health insurance plan member ID, medical record number, dates of service, provider names, and medical and clinical treatment information regarding care received from the health system.

SJ/C is offering impacted individuals complimentary credit monitoring and identity protection services.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Over $600 Million Stolen in Biggest Ever Cryptocurrency Theft

Over $600 Million Stolen in Biggest Ever Cryptocurrency Theft

The largest hack in recorded history took place yesterday when attackers exploited a vulnerability that could change the “keeper role” of a blockchain contract and make any transaction such as a withdrawal, according to a Medium post by Poly Network.

Poly Network, a platform that looks to connect different blockchains so that they can work together, confirmed that the vulnerability was due to the leakage of a keeper’s private key. 

In a tweet thread, SlowMist confirmed that over $610m was stolen

The security team has also confirmed that it “has got the attacker’s mailbox, IP and device fingerprints through on-chain and off-chain tracking.”

The details of the attack are as follows, according to SlowMist:

“The core of this attack is that the verifyHeaderAndExecuteTx function of the EthCrossChainManager contract can execute specific cross-chain transactions through the _executeCrossChainTx function,” SlowMist explains. “Since the owner of the EthCrossChainData contract is the EthCrossChainManaget contract, [it] can modify the keeper of the contract by calling the putCurEpochConPubKeyBytes function…”

SlowMist goes on to say that the attacker only needs to pass in the carefully constructed data through the verifyHeaderAndExecuteTx function to execute the call to change the keeper role to the address of the specified attackers. “After replacing the address of the keeper role, the attacker can construct a transaction at will and withdraw any amount of funds from the contract.”

The contract attacked was a Bscscan contract and a Etherscan contract, which are now valued at $0. After the attack on the contract was finished, the keeper was modified, which caused other “normal transactions” to be reverted, says SlowMist.

The transactions published by SlowMist and Poly Network show that the exploiter made three withdrawals from the Bscscan contract: $133,023,777.79, $85,519,813.63, $87,594,029.67, $132,907,573.59, $132,907,574.59 and $133,029927.08 (USD). On the Etherscan contract, $93,343,903.87 Ether was withdrawn ($182,628,360.16 USD).

Poly Network took to Twitter to confirm the attack had taken place, addressing the hackers directly: “We want to establish communication with you and urge you to return the hacked assets.”

In this tweet, the alliance confirmed that the hack is the biggest in the decentralized finance platform (DeFi) history and warns the hackers that law enforcement would consider it a “major economic crime.”

Poly Network has also called on miners of the affected blockchains — BinanceChain, Ethereum and Polygon — to blacklist tokens coming from the published addresses.

As a DeFi, Brian Higgins, security specialist at Comparitech, believes that it’s unlikely that users will get their money back. He explains, “It’s an unfortunate hazard of dealing in unregulated financial platforms that regardless of your status, whether you are among the minority of legitimate users or exploiting their pseudo-anonymity to conduct criminal activities, they are vulnerable to attack and there is very little anyone can do once that happens.

“Non-regulated, non-Fiat currencies are highly unstable, and e-money laundering is far easier than the real thing these days. Cryptocurrency is a risky business, and it will probably stay that way.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cybercrime Costs Victims $318 bn Annually

Cybercrime Costs Victims $318 bn Annually

Cybercrime costs victims $318bn per annum globally, according to new research by Comparitech.

The consumer rights and comparison firm made this calculation based on an analysis of cybercrime reports in 67 countries globally for which this information was available in either 2018-19 or 2019-20. It estimated that 71.1 million people fall victim to cybercrime each year, equating to nearly 900 victims per 100,000 people. The average victim lost $4476 per crime, according to the analysis.

Using these figures, Comparitech believes more than $129bn has been lost by victims of cybercrime across these 67 countries, amounting to a total of £318bn across the globe.

The countries that experienced the highest losses due to cybercrime were the US ($28bn), Brazil ($26bn), the UK ($17.4bn) and Russia ($15.2bn).

The country with the largest increase in cybercrime was Sri Lanka, where there was a 359% year-on-year rise from 2019 to 2020 (3566 to 16,376 reports). Most (15,895) of these reports related to social media crimes, likely due to the increased use of these platforms during the COVID-19 pandemic. Significant rises in reported cybercrime were also observed in Belarus (176%), Indonesia (140%), Puerto Rico (125%) and Panama (100%).

According to available figures, the country with the highest proportion of cybercrime victims was the UK, with 1095 per 100,000 people submitting reports. This was followed by Denmark (514 per 100,000 people), Spain (463 per 100,000 people), Brazil (415 per 100,000 people) and Austria (404 per 100,000 people).

Comparitech cautioned that there are vast differences in how each police force or government reports cybercrime; for example, some counties only provided financial losses to cybercrime but no precise victim numbers. It added: “With the lack of transparency and reporting around these types of crimes, it is difficult to gauge the true extent of the problem… until we’re able to see the real cost of these crimes on a country-by-country basis, cybercriminals will continue to have the upper hand. Lack of reporting will lead to a loss in victim confidence (and a reluctance to report the crime), gaps in the awareness of these types of crimes, and inadequate legislation and criminal procedures to hold cyber-criminals to account.”

Commenting on the analysis, PJ Norris, principal systems engineer at Tripwire, said, “We have seen a rise in cybercrime and most notably ransomware. Not only have ransomware attacks been growing globally, but the amounts they have been demanding have been getting higher, and there has been more specific targeting of victims.

“Many high-profile organizations have suffered and lost large sums due to ransomware. This rise in attacks might be a direct result of how profitable these attacks can be. After all, cybercrime in general – and ransomware in particular – is motivated by monetary gain.”

Javvad Malik, security awareness advocate at KnowBe4, stated: “These numbers are not surprising, but still are concerning. Cybercrime continues to be big business for criminals and with more services being digitally connected, it makes it even easier to make off with big gains. 

“It’s easy to create a tech service or to digitise existing services, however, security needs to be built in from the beginning to ensure that there are no vulnerabilities. This also includes educating users of products as to what kind of threats they can expect to face and how to report any suspicious activity. Without educating users to identify and report criminal activity, we won’t be able to stem the flow of cybercrime.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Microsoft Releases High Priority Fixes in August Patch Tuesday

Microsoft Releases High Priority Fixes in August Patch Tuesday

Microsoft fixed a total of 44 vulnerabilities during this month’s patch Tuesday, seven of which were rated as ‘Critical.’

While it was a much lighter Patch Tuesday than the past few months, the tech giant released several high-priority fixes.

These included new patches released to “more completely” address two publicly disclosed Print Spooler vulnerabilities, CVE-2021-34481 and CVE-2021-36936. Chris Goettl, senior director of product management at Ivanti, explained that these fixes should be an especially high priority in light of the public disclosure. 

“In this case, right on the tails of multiple known exploited print spooler vulnerabilities, including PrintNightmare (CVE-2021-34527), the risk of these publicly disclosed vulnerabilities being exploited has increased,” he said. 

“As a threat actor investigates code for vulnerabilities, they will potentially be looking for multiple ways to exploit a weak code area. White Hat researchers were able to uncover and report these additional exploits, so we should expect threat actors to be able to identify these additional vulnerabilities as well.”

Microsoft also published details of an elevation of privilege vulnerability, CVE-2021-36934, on July 20th. Adam Bunn, lead software engineer at Rapid7, said administrators should prioritize taking action on this vulnerability, which he warned requires significant workarounds. He explained, “With a public proof-of-concept having been available for some time, administrators should prioritize taking action on CVE-2021-36934. Remediation for this vulnerability requires volume shadow copies for system files to be deleted. This is due to the nature of the vulnerability, as the files with the vulnerable permissions could be restored from a backup and accessed even after the patch is installed. Microsoft indicates they took caution not to delete users’ backups, but the trade-off is that customers will need to do the chore themselves.”

Bunn believes another high priority for patching teams should be CVE-2021-36942, one of the vulnerabilities exploited in the PetitPotam attack. “After applying this update, there are additional configurations required in order to protect systems from other attack vectors using registry keys,” he added.

A resolution was also released for an elevation of Privilege vulnerability (CVE-2021-36948) in Windows Update Medic Service, which Microsoft rated as ‘Important.’ This affects Windows 10 1809 and Server 2019 and later OS versions and has been publicly disclosed, which Goettl noted puts it “at higher risk of being exploited.”

There was a fix for a zero day in Windows 10 1809 and Server 2019 and later OS versions, CVE-2021-36948. This elevation of privilege vulnerability in the Windows Update Medic Service was assigned as ‘Important’ by Microsoft.

Additionally, there were several updates released by Mozilla for Mozilla Firefox, Firefox ESR and Thunderbird this month. The Firefox updates are rated ‘High’, resolving 11 CVEs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Nortonlifelock and Avast Confirm Merger Deal Worth Over $8 Bn

Nortonlifelock and Avast Confirm Merger Deal Worth Over $8 Bn

Consumer cybersecurity companies NortonLifeLock and Avast have announced an agreement for the Tempe-based cyber safety company to buy the digital security privacy company. NortonLifeLock’s closing share price was $27.20 as of July 13, 2021 — the last trading day before market speculation began — meaning the merger values between $8.1 bn and $8.6 bn.

According to a statement released yesterday (August 10 2021), under the terms of the merger, Avast shareholders will be entitled to receive a combination of cash consideration as well as newly issued shares in NortonLifeLock. The boards of both companies have said they believe the merger has a compelling “strategic and financial rationale” and will represent an attractive opportunity to create a “new industry-leading consumer cyber safety business.”

“This transaction is a huge step forward for consumer cyber safety and will ultimately enable us to achieve our vision to protect and empower people to live their digital lives safely,” says Vincent Pilette, chief executive officer of NortonLifeLock. “With this combination, we can strengthen our cyber safety platform and make it available to more than 500 million users.”

Both companies have a legacy within the cybersecurity space. NortonLifeLock, formally known as Symantec, is known for its consumer cyber safety software, Norton360. Avast is known for its free antivirus software and subscriptions such as Avast Ultimate. 

The merger will see Avast’s chief executive officer, Ondřej Vlček, join NortonLifeLock as president and a member of the company’s board of directors. Pilette and chief financial officer, Natalie Derse, will remain in their positions at NortonLifeLock. Pavel Baudiš, co-founder and current director of Avast, is also expected to join NortonLifeLock’s board as an independent director.

The completion of the merger will see the companies be dual headquartered in Prague, Czech Republic and Tempe, Arizona, U.S. The combined company will also be listed on NASDAQ.

Speaking on the merger, Vlček says, “At a time when global cyber threats are growing, yet cyber safety penetration remains very low, together with NortonLifeLock, we will be able to accelerate our shared vision of providing holistic cyber protection for consumers around the globe.

“Our talented teams will have better opportunities to innovate and develop enhanced solutions and services, with improved capabilities from access to superior data insights. Through our well-established brands, greater geographic diversification and access to a larger global user base, the combined businesses will be poised to access the significant growth opportunity that exists worldwide.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains