Zoom Pays $85m to Settle Privacy Suit

Zoom Pays $85m to Settle Privacy Suit

Video-conferencing company Zoom has agreed to improve its security practices and pay a fine of $85m to settle a legal challenge over privacy.

lawsuit alleged that Zoom Video Communications Inc., violated the rights of its users by failing to prevent zoombombing and by sharing their personal data with social networking sites Facebook, Google and LinkedIn. 

In March, Zoom asked the court to dismiss the motion. Then, on Saturday, the San Jose-based company filed a proposed settlement that now awaits the approval of California District Judge Lucy Koh. 

The settlement does not include any admission of wrongdoing. Under the preliminary deal, plaintiffs in the proposed class-action suit who were Zoom subscribers would be eligible to claim $25 or a 15% refund on their subscription. Other users would only be eligible to receive up to $15.

The plaintiffs’ lawyers claim that Zoom Meetings’ paid subscribers generated $1.3bn in revenue for the company. Another hearing in the case is set for October.

Zoom said in a statement: “The privacy and security of our users are top priorities for Zoom, and we take seriously the trust our users place in us. We are proud of the advancements we have made to our platform and look forward to continuing to innovate with privacy and security at the forefront.”

As part of the proposed settlement, Zoom agreed to bolster its security by providing its employees with training in data handling and privacy. The company also said it would alert users when Zoom meeting hosts or participants use third-party apps during a meeting. 

The class-action lawsuit, filed in March 2020 in the US District Court in the Northern District of California, is just one of multiple legal complaints that have been lodged against Zoom.

In another class-action lawsuit, Cullen v. Zoom Video Communications, Inc., California consumers accused the video-conferencing company of sharing their personal data with Facebook and other third parties without giving proper or adequate notice. 

The plaintiffs claimed that after they installed Zoom, the company gathered their personal information and later disclosed it without their consent to third parties.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#BHUSA: How Supply-Chain Attacks Change the Economics of Mass Exploitation

#BHUSA: How Supply-Chain Attacks Change the Economics of Mass Exploitation

Supply-chain security is one of the most impactful topics today, and it was the subject of the opening keynote at the Black Hat US 2021 hybrid event, held both online and in-person in Las Vegas.

Jeff Moss, the founder of the Black Hat conference, opened the event with a brief conversation on what’s needed to help immunize the global IT community from attacks. When it comes to supply-chain security, he had a very somber observation.

“We all depend on the supply chain’s being fully immunized, and it’s not there,” Moss said.

Some ideas on how to address the challenge of supply-chain security were put forth in a keynote address by Matt Tait, chief operating officer at Corellium. Tait noted that supply-chain intrusions are completely appending the entire traditional mechanics from the attackers’ perspective.

“Supply-chain intrusions are relatively straightforward; instead of targeting the system that you actually want to target, you target a system that’s upstream from that system,” Tait said.

The Scope of Supply-Chain Intrusions

Supply-chain attacks have had an enormous impact in 2021, though it could have been much worse.

In the case of the SolarWinds attack, Tait noted that SolarWinds has over 300,000 customers; of those, 33,000 were using the Orion platform that was attacked, and ultimately it was approximately 18,000 customers that got infected with the first stage of that attack.

In the case of the Kaseya ransomware attack, Tait observed that Kaseya has up to one million small businesses using their software, while only approximately 1,500 were infected by the attack.  As such, only  0.1% of Kaseya’s actual customers ended up getting infected. However, while the infection numbers were only a small percentage, the real-world impact was significant.

“Supply-chain intrusions are not like other intrusions; we might like to think of them as just unusually big intrusions, but they’re not—they’re different,” Tait emphasized.

With other types of attack, threat actors need to specifically identify a target. Tait noted that with supply-chain attacks, the target selection is easy, as it could potentially be all of the supplier’s customers. Finding the attack surface for a supply-chain attack is also easy, in his opinion. With a supply-chain attack, the threat actors go after the supplier’s update system, which will just automatically route the malware directly, often bypassing any cybersecurity defenses that the organization might have. Additionally, lateral movement across an organization is not a problem, because the supply-chain software often has agents that are running on all the client systems.

How to Fix Supply-Chain Risk

In Tait’s view, the only way to tackle supply-chain intrusions at the scale that’s needed is to fix the underlying technology, and this requires platform vendors to step in.

“Ultimately, the question that we’re asking in supply-chain security is: Can we automate trust?” Tait said.

Tait noted that in the mobile space there is the concept of entitlements. He explained that with mobile entitlements, an app does not have any components running as root, and there is no system-wide permission.

“In the event that a supply-chain attack does compromise your app, it is only going to compromise the app; it’s not going to compromise the entire phone,” Tait said.

In the desktop world on Windows, entitlements are rarely, if ever, used. In Tait’s view, there is a need to de-privilege Windows applications. He said that an entitlement gives the system a machine-readable understanding of what the app should be allowed to do. As such, Tait said, in the event of that app’s becoming compromised, the ability of malware inside that app to do things outside of the scope of the application becomes dramatically reduced.

While mobile devices provide entitlements, Tait noted, there is limited device observability, as the mobile operating system vendors do not generally allow full device forensics to operate. Tait wants both mobile and desktop vendors to step up and help provide the necessary visibility and controls to limit the risk of supply-chain attacks.

“Supply-chain infections can only be fixed by platform vendors; the government is not coming to save you,” Tait said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Son Charged in Murder of Cybersecurity ‘Genius’

Son Charged in Murder of Cybersecurity ‘Genius’

Maryland police have arrested the son of a successful cybersecurity executive on suspicion of her murder.

Juanita Naomi Koilpillai was killed at her home in Tracy’s Landing on July 25. The cybersecurity expert, who co-founded the advanced automated attack warning system CyberWolf and went on to found Waverley Labs, was 58 years old at the time of her death.

The alarm was raised after blood was discovered in Koilpillai’s waterfront residence by her boyfriend. When he was unable to locate his partner, he called 911 and reported her as missing.

Soon after this report was made, Koilpillai’s body was discovered outside her home. An investigation by a medical examiner determined that the computer expert, described as “a certifiable genius” by her friend Dr. Ron Martin, had died as a result of sharp force injuries.

Koilpillai’s car, which was missing from her driveway when her body was discovered, was later found in Leesburg, Virginia.  

search of the car by the Anne Arundel County Police Department revealed a knife, believed to be the murder weapon. Forensic testing of the knife uncovered the presence of DNA belonging to the victim’s 23-year-old son, Andrew Weylin Beavers. 

Beavers was arrested in Virginia on Saturday and charged with first- and second-degree murder. He was later extradited to Maryland. 

Koilpillai, who grew up in India and Sri Lanka, earned a master’s in computer science and mathematics at the University of Kansas, then spent three decades working in network management and computer security. 

“To grow a startup into a great company and then sell it to a bigger technology company was an incredible accomplishment,” said Koilpillai’s friend, Connie Moore.

“But to do it as a woman, to do it as a person of color, just speaks volumes about her tenacity, about her brilliance, about her business acumen, about her technology expertise, it was extraordinary. And then she did it again.” 

The CyberWolf system, which is used by the US government, was acquired by cybersecurity company Symantec in 2002 with the purchase of software vendor Mountain Wave. 

Shortly before she was killed, Waverley Labs CEO Koilpillai helped to launch information security offering Resiliant.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

MoD Boosts Cyber-Resilience with Ethical Hacker Project

MoD Boosts Cyber-Resilience with Ethical Hacker Project

The UK’s Ministry of Defence (MoD) has just completed a 30-day bug bounty challenge which opened its systems to probing by ethical hackers.

Bug bounty programs are designed to challenge “white hat” hackers to find vulnerabilities which may otherwise be exploited by those with nefarious intent. These researchers are rewarded, whilst the organization running the exercises gains valuable visibility into possible security holes.

While such programs are popular in the private sector, governments have traditionally been more reluctant to open their IT systems to probing, given the national security implications.

This is the first initiative of its kind the MoD has run and it claimed the exercise had been “extremely valuable” in helping to find and remediate vulnerabilities across the department’s networks and 750,000 devices.

The MoD said it will continue to run bug bounty programs alongside other initiatives to boost cyber-resilience and share any relevant lessons learned with the government.

MoD CISO, Christine Maxwell, argued that the initiative is part of the department’s commitment to transparency and security-by-design principles.

“It is important for us to continue to push the boundaries with our digital and cyber development to attract personnel with skills, energy and commitment. Working with the ethical hacking community allows us to build out our bench of tech talent and bring more diverse perspectives to protect and defend our assets,” she added.

“Understanding where our vulnerabilities are and working with the wider ethical hacking community to identify and fix them is an essential step in reducing cyber risk and improving resilience.”

The project was run by US firm HackerOne, which has also contributed to the Hack the Pentagon initiative over the past few years. That vulnerability disclosure program was recently expanded to include all publicly accessible Department of Defense information systems, not just its websites and apps.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Over 60 Million Americans Exposed Through Misconfigured Database

Over 60 Million Americans Exposed Through Misconfigured Database

Security researchers have discovered an online database completely unsecured and exposed to the public internet, containing the personal details of at least 63 million Americans.

A team at vpnMentor led by Ran Locar and Noam Rotem found the Elasticsearch database wide open during a “routine research project.”

It soon traced the trove back to OneMoreLead, a B2B sales and marketing company which claims on its unfinished website to have a database of “40+ million 100% verified B2B prospects to search from.”

The database itself contained around 126 million records. Depending on the number of duplicates in there, the number of affected individuals could be anywhere between 63 million and 126 million, vpnMentor claimed.

Personally identifiable information (PII) featured in the trove included full names, job titles, personal email and home addresses, work email and office addresses, personal and work phone numbers, home IP addresses and employer names.

“The database contained detailed personal information about tens of millions of people — everything from their job title to their home IP address,” vpnMentor claimed.

“Cybercriminals could easily use this information to pursue financial fraud against everyone exposed. Simultaneously, they could use the information to build effective phishing campaigns, posing as a person’s employer, the government, and other trusted organizations.”

Many of the emails viewed by the research team had .gov suffixes, or indicated the individual as working for the New York Police Department.

“Private data from members of the government and police are a goldmine for criminal hackers — especially if a foreign government supports them,” vpnMentor claimed.

There are also question marks over where the information came from.

“The company is new, with no known clients and an unfinished website. So, it’s unlikely they collected data from 126 million people since opening in 2020 — unless the people behind OneMoreLead were working on a similar business previously,” vpnMentor claimed.

“Furthermore, the exposed data bears an uncanny resemblance to a leak originally connected German B2B marketing company Leadhunter in 2020. Leadhunter denied responsibility for the leak at the time, and researchers couldn’t confirm a link.”

The good news is that, when informed about the leak, OneMoreLead apparently secured the database the next day.

“Any leak like this could be easily avoided with some basic security measures taken including, securing servers, implementing proper access rule, and never leaving a system that doesn’t require authentication open to the internet,” vpnMentor said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Personal Data Breach Reports Fall Despite Rising Attacks

Personal Data Breach Reports Fall Despite Rising Attacks

Personal data breach reports to the UK’s Information Commissioner’s Office (ICO) fell by 20% in financial year 20/21 compared to 19/20. This is according to figures published in the ICO’s recent annual report, which were analyzed by the Parliament Street think tank.

The report revealed there were 9532 personal data breach reports in the most recent financial year (20/21), representing a significant drop from 11,854 reports made in 19/20.

This is despite a huge rise in cyber-attacks during the COVID-19 pandemic and organizations becoming more vulnerable to breaches following the shift to home working in that period. The ICO cited the pandemic and the introduction of mandatory breach reporting from sectors that handle large volumes of personal data as the primary factors in the fall in personal data breach reports.

The sector with the highest proportion (16.8%) of personal data breaches reported to the ICO in FY 20/21 was healthcare. This was followed by education and childcare (13.6%), retail and manufacturing (10.9%), finance insurance and credit (10.5%) and local government (8.8%).

Close to three-quarters (71.4%) of personal data breaches reported to the ICO led to no further action, while 21.6% were investigated further, although no further details on the outcomes of these cases were given.

In addition, 3.9% of breaches led to ‘informal’ action being taken, and just 0.1% led to formal action, which includes administrative punishment or a lower-tier fine.

Commenting on the figures, Chris Ross, SVP sales international for Barracuda Networks, said, “While the ICO has reported a surprising decline in personal data breach incidents this year, business owners and workers must not get complacent. Despite what the figures suggest, cyber-attacks targeting remote workers and businesses have increased in intensity over the last 18 months. This is particularly because more employees were working from home for the first time, and thus more sensitive data has been handled across email, cloud storage and personal devices than ever before, presenting a gold mine of opportunity for hackers.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Seeks Espionage Retrial for Chinese Researcher

US Seeks Espionage Retrial for Chinese Researcher

Federal prosecutors in the United States are seeking to retry an engineering researcher accused of concealing his links to a university in China while working on a NASA contract. 

Dr. Anming Hu, who was born in the People’s Republic of China (PRC), formerly worked at the University of Tennessee, Knoxville (UTK), as an associate professor in the Department of Mechanical, Aerospace and Biomedical Engineering. 

Hu was arrested in February 2020 on a federal indictment as part of the US Department of Justice China Initiative and charged with three counts of wire fraud and three counts of making false statements.

The indictment accused Hu of defrauding the National Aeronautics and Space Administration by concealing his affiliation with Beijing University of Technology while receiving research grants from the federal government. Under federal law, NASA is barred from using appropriated funds on projects in collaboration with China or Chinese universities.  

Prosecutors alleged that Hu made false representations and omissions to UTK about his links to the Beijing University of Technology, which caused the Tennessee academic institution to falsely certify to NASA that it was following federal law. 

In June 2021, after Hu’s original trial ended in a hung jury, it was declared a mistrial by a federal judge. On July 30, the United States Department of Justice filed a notice of intent to seek a retrial of the former researcher. 

US representative Judy Chu, chair of the Congressional Asian Pacific American Caucus, said Hu was being targeted by prosecutors on account of his race.

“The case of Dr. Anming Hu is the most glaring example of how investigations rooted in racial profiling lead to flimsy cases that cannot stand up in court,” said Chu.

“Worse, in order to justify this investigation, we know that FBI agents have falsified evidence.”

John Yang, president and executive director of Asian Americans Advancing Justice, said Hu’s trial had “exposed the deeply problematic investigations, surveillance and prosecutions of Asian Americans and Asian immigrants.”

The Asian-American advocacy group APA Justice said: “What happened to Hu and his family is not an isolated event; it is part of systemic racial bias, discrimination, and profiling by our federal government.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Senate: Seven out of Eight Agencies Are Failing on Cyber

US Senate: Seven out of Eight Agencies Are Failing on Cyber

Seven out of eight key federal agencies have failed to meet the basic cybersecurity standards expected of them over the past decade, despite being warned by a Senate committee two years ago, according to a new bipartisan report.

The Committee on Homeland Security’s new reportFederal Cybersecurity, America’s Data Still at Risk, claimed seven agencies had made “minimal improvements” over the period, and only the Department of Homeland Security (DHS) “managed to employ an effective cybersecurity regime for 2020.”

These seven are the Departments of State, Transportation, Housing and Urban Development, Agriculture, Health and Human Services, Education and the Social Security Administration.

The report analyzed the audits of each departments’ inspectors general for fiscal 2020 and found “essentially the same failures as the prior ten years.”

These included: inadequate protection for personally identifiable information (PII); failure to maintain accurate IT asset inventories; failure to install timely patches; and use of legacy systems and applications.

The report claimed that even though the DHS came top with a “B” grade, it failed to apply patches for the past 12 years properly.

Other concerning findings included that the Department of Transportation had no record of over 14,000 of its IT assets, and the Department of Agriculture had no knowledge of a “significant number” of high severity bugs on its public-facing websites. The State Department could not provide documentation for 60% of employees with access to its classified network.

The findings come at a time when the US government is being regularly probed by state-backed attackers, especially from Russia and China. Notable recent campaigns include the Kremlin’s SolarWinds attacks, which compromised nine federal agencies, and the exploitation of vulnerabilities in Pulse Connect Secure, which enabled Beijing-backed operatives to infiltrate multiple agencies.

Burton Group founder and former Gartner executive, Jamie Lewis, said a mindset change had to take place among agency leadership.

“Government agencies can substantially enhance their security posture by improving their execution around basic security practices. These include streamlining the consistent and timely implementation of patches for known system vulnerabilities, increasing the security awareness of front-line employees, and creating better incident response programs,” he added.

“Government agencies must also limit the collection and use of personal information, which will reduce the risks they must manage.”

It’s hoped that President Biden’s recent executive order on cybersecurity will also force agencies to improve baseline security.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk