News

Researchers Hack Olympic Games App

Researchers Hack Olympic Games App

Cybersecurity researchers in Canada have found a “devastating flaw” in the MY2022 app, designed for use by attendees of this year’s Winter Olympic Games in Beijing.

The vulnerability was discovered by the Citizen Lab – an academic research laboratory based at the Munk School of Global Affairs at the University of Toronto.

In findings published Tuesday, researchers said that the flaw allows encryption that protects users’ voice audio and file transfers to be “trivially sidestepped.”

Researchers warned: “Health customs forms which transmit passport details, demographic information and medical and travel history are also vulnerable. Server responses can also be spoofed, allowing an attacker to display fake instructions to users.”

The Citizen Lab reported its findings to the app’s vendor but did not respond.

“While the vendor did not respond to our security disclosure, we find that the app’s security deficits may not only violate Google’s Unwanted Software Policy and Apple’s App Store guidelines but also China’s own laws and national standards pertaining to privacy protection, providing potential avenues for future redress,” stated researchers. 

The German Olympic Sports Confederation (DOSB) said that downloading the app has been mandated for travelers seeking entry to the People’s Republic of China to attend the 2022 Winter Olympic Games.

“Without My 2022 there is no immigration into China according to the Beijing playbooks,” said the DSOB.

The confederation shared some cybersecurity advice it had received from the German Federal Institute of Information Security (BSI) regarding the MY2022 app.

“Our athletes are being equipped with a smartphone from IOC partner Samsung in Beijing. BSI recommends using MY2022 on these devices in China and deinstalling it at home,” it said. 

The International Olympic Committee (IOC) stated that MY2022 users could configure the app to disable access to features including files, media, calendar, camera, contacts, microphone and location data. 

Many countries have planned a diplomatic boycott of the Beijing Olympics over China’s record of human rights violations, including the systemic abuse of the Uyghur and other minority ethnic communities.

Boycotts have been planned by the UK, United States, Lithuania, New Zealand, Scotland, Australia, Canada, Latvia, Estonia, Belgium, Austria, Japan, Netherlands, Denmark and Sweden.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Ransomware Attack on Moncler

Ransomware Attack on Moncler

Cyber-criminals have stolen data from Italian luxury fashion brand Moncler and published it on the dark web.

The maker of down jackets confirmed Tuesday that it had suffered a data breach after being attacked by the AlphV/BlackCat ransomware operation in December. 

Attackers hit Moncler in the final week of 2021, causing a temporary outage of its IT services which delayed shipments of goods ordered online.

Some data stolen in the incident was published online on Tuesday after Moncler refused to pay a ransom to its attackers. 

Data compromised in the security incident relates to Moncler employees, former employees, suppliers, consultants, business partners and some customers registered on the company’s website.

Moncler said in a statement: “​While the investigation related to the attack is still ongoing, Moncler confirms that the stolen information refers to its employees and former employees, some suppliers, consultants and business partners, as well as customers registered in its database. 

“With regard to information linked to customers, the company informs that no data relating to credit cards or other means of payment have been exfiltrated, as the company does not store such data on its systems.”

The fashion brand said that the brief interruption to the logistical side of its operation had not put a major dent in its profits. 

“Data breaches are part of the web attack lifecycle and continue to fuel Account Takeover (ATO) and credential stuffing attacks. Therefore, we need to protect the apps that power our daily lives by disrupting the web attack lifecycle,” commented Kim DeCarlis, CMO at cybersecurity company PerimeterX.

They added: “This includes stopping the theft, validation and fraudulent use of account and identity information everywhere along the digital journey.” 

Trevor Morgan, product manager with data security specialists comforte AG, said that data-dependent businesses need to assume that they are a target for cyber-criminals.

“Squirreling sensitive data away behind protected perimeters won’t cut it anymore as a defensive measure,” said Morgan. 

He added: “Only robust data-centric security, such as tokenization or format-preserving encryption applied directly to sensitive data elements, can help mitigate the situation if the wrong hands get ahold of your data.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

US Organizations Urged to Improve Cybersecurity

US Organizations Urged to Improve Cybersecurity

The United States’ Cybersecurity and Infrastructure Security Agency (CISA) is urging every organization in the US to implement cybersecurity measures.

Insights issued Tuesday by the cyber defense agency warned that cyber-threats could disrupt essential services and potentially impact public safety.

“Over the past year, cyber-incidents have impacted many companies, non-profits and other organizations, large and small, across multiple sectors of the economy,” said CISA.

“Most recently, public and private entities in Ukraine have suffered a series of malicious cyber-incidents, including website defacement and private-sector reports of potentially destructive malware on their systems that could result in severe harm to critical functions.”

The agency emphasized that past deployments of similar malware, such as NotPetya and WannaCry ransomware, had caused significant, widespread damage to critical infrastructure.

Organizations of all sizes were urged by CISA to “take urgent, near-term steps to reduce the likelihood and impact of a potentially damaging compromise.”

Actions advised by the agency include ensuring that all remote access to the organization’s network and privileged or administrative access requires multi-factor authentication and ensuring that software is up to date. 

Organizations should also confirm that all ports and protocols not essential for business purposes have been disabled and test backup procedures to ensure that critical data can be rapidly restored if the organization is impacted by ransomware or a destructive cyber-attack.

For US organizations working with other organizations in Ukraine, particular caution was urged.

CISA said: “If working with Ukrainian organizations, take extra care to monitor, inspect and isolate traffic from those organizations; closely review access controls for that traffic.”

Tom Kellermann, head of cybersecurity strategy at VMware, said that the importance of patching software with known exploited vulnerabilities could not be understated to reduce the risk of ransomware. 

“We must remember that modern ransomware leaves a RAT behind and secondary infections will metastasize,” warned Kellerman.

Kellerman believes that cyber-criminals will increasingly deploy ransomware for reasons other than financial gain. 

“Ransomware attacks that aim to cripple systems, rather than receive payment, will increase due to geopolitical tension,” he predicted.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

UK Proposes New Laws to Strengthen National Cyber-Resiliency

UK Proposes New Laws to Strengthen National Cyber-Resiliency

The UK is planning new laws to strengthen the county’s cyber-resilience in response to surging critical infrastructure and supply chain attacks.

The proposals were published by Department for Digital, Culture, Media and Sport (DCMS) today, who stated that new measures are required to drive up security standards in IT services used by almost all UK businesses.

This involves amending and widening the Network and Information Systems (NIS) Regulations 2018, which places cybersecurity obligations on companies that provide essential services such as water, energy, transport, healthcare and digital infrastructure. This includes requirements to undertake risk assessments, put in place reasonable security measures to protect their network and report significant events. Failure to comply can result in fines of up to £17m.

The government now wants to include managed service providers (MSPs) within the scope of this legislation. This is because MSPs have privileged access to their client’s networks and systems, potentially enabling attackers to attack a wide range of organizations through a single breach.

The government also wants to amend the NIS regulations to force large companies to provide better cyber-incident reporting to regulators like Ofcom, Ofgem and the ICO. This includes a requirement to inform these bodies of all cyber-attacks they are hit with, not just those impacting their services. In addition, the government plans to give itself the power to update the NIS regulations in the future without introducing new legislation.

Minister of State for Media, Data, and Digital Infrastructure, Julia Lopez, commented: “Cyber-attacks are often made possible because criminals and hostile states cynically exploit vulnerabilities in businesses’ digital supply chains and outsourced IT services that could be fixed or patched.

“The plans we are announcing today will help protect essential services and our wider economy from cyber-threats. Every UK organization must take its cyber-resilience seriously as we strive to grow, innovate and protect people online. It is not an optional extra.”

Another aspect of the DCMS’ plans is to give more powers to the UK Cyber Security Council, which began work as an independent body last year. Under the proposals, the council, which works to boost professional standards and career prospects for cybersecurity professionals, will be able to define and recognize cyber job titles and link them to existing qualifications and certifications.

This means people would have to meet competency standards set by the council before using a specific job title in cybersecurity. This will help employers identify the specific cyber skills they need in their organizations and develop clearer career pathways for those operating in the sector. As part of this initiative, a Register of Practitioners will be created to show the cyber professionals recognized as ethical, suitably qualified or senior. This is similar to registers that exist in the medical and legal professions.

Simon Hepburn, the CEO of the UK Cyber Security Council, said: “The UK Cyber Security Council is delighted that these proposals recognize our cyber workforce lead role that will help to define and recognize cyber job roles and map them to existing certifications and qualifications.

“We look forward to being involved in and contributing to this important government consultation and would encourage all key stakeholders to participate too.”

The DCMS is now inviting stakeholders to respond to these proposals, with a deadline of April 10 2022 regarding the planned legislation to improve the UK’s cyber-resilience, and March 20 2022 for the plans to embed standards and pathways across the cyber profession.

The strategy forms part of the UK government’s National Cyber Strategy, which was published at the end of last year.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

McAfee Enterprise and FireEye Relaunches as Trellix

McAfee Enterprise and FireEye Relaunches as Trellix

McAfee Enterprise and FireEye have relaunched as a new company called Trellix, its parent firm Symphony Technology Group (STG) has announced.

McAfee Enterprise and FireEye merged in October 2021 following STG’s acquisition of McAfee Enterprise earlier in the year.

The name Trellix has been chosen for the relaunch as it evokes the structure of a trellis, a strong and safe framework used to support the structured growth of climbing plants and trees.

The company aims to offer customers ‘living security,’ the concept of technologies that can learn and adapt to counter evolving cyber-threats. Trellix’s XDR platform provides over six hundred native and open security technologies, designed to provide security analysts with the insights to respond quickly to threats.

William Chisholm, managing partner at STG, commented: “We are incredibly excited to have Trellix in the STG portfolio. Customers can expect Trellix’s living security platform to deliver bold innovation across the XDR market.”

Bryan Palma, chief executive officer of Trellix, said: “As today’s organizations push to achieve digital transformation, a strong security foundation is required to ensure continued innovation, growth and resiliency.

“Trellix’s XDR platform protects our customers as we bring security to life with automation, machine learning, extensible architecture and threat intelligence.”

STG added that it expects to launch the McAfee Enterprise Secure Service Edge (SSE) portfolio as a separate business later this quarter, inclusive of cloud access security broker (CASB), secure web gateway (SWG) and zero trust network access (ZTNA).  

In November 2021, a deal was agreed for the purchase of the rest of the McAfee business by a group of private investors.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Man Charged with Smuggling Tech Exports to Iran

Man Charged with Smuggling Tech Exports to Iran

A US citizen has been charged with violating sanctions by exporting IT goods and services to Iran.

Kambiz Attar Kashani, 44, who also holds Iranian citizenship, was arrested last Friday and charged with conspiring to illegally export to the Central Bank of Iran (CBI).

He allegedly acted as principal for two United Arab Emirates (UAE) companies, set up to procure the technology from US companies from around February 2019 to June 2021. Kashani and his co-conspirators are said to have lied about the final destination of these exports, claiming they would be used by the UAE firms.

The technology in question included several fixed attenuators, common electrical components found in radio frequency (RF) products. Also “exported” were subscriptions to open-source operating systems, several network storage systems and six power supplies.

A license was also purchased from a US company that produces software allowing large organizations to “develop and deploy proprietary, internal-use applications to their employees,” according to court documents.

Kashani is being charged with violating the International Emergency Economic Powers Act (IEEPA). The US Treasury’s powerful Office of Foreign Assets Control (OFAC) previously classified CBI as a Specially Designated National (SDN), indicating that the bank is acting for or on behalf of terrorist organizations.

That’s because of its support for Lebanese Hizballah and the Qods Force of Iran’s Islamic Revolutionary Guards Corps (IRGC).

Kashani is charged with one count of conspiracy to unlawfully export goods to Iran, which carries a maximum jail term of 20 years and a $1m fine.

“Technology illegally transferred to Iran from the United States could be used by terrorists, which is why the FBI and its partners devote significant resources to these investigations,” said assistant director Alan Kohler Jr. of the FBI’s Counterintelligence Division.

“Those doing the bidding for Iran in the United States should expect the full force of our law enforcement and intelligence community partners.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Thousands of US Public Sector Ransomware Victims in 2021

Thousands of US Public Sector Ransomware Victims in 2021

An estimated 2323 local governments, schools and healthcare providers in the US were compromised by ransomware in 2021 after another bumper year for financially motivated attackers, according to Emsisoft.

The security vendor claimed in its latest research that healthcare providers (1203) were the most affected by such attacks during the year, followed by schools (1043) and finally state and municipal governments and agencies (77).

However, despite most attacks today resulting in double extortion, where victims have data stolen and are extorted with the threat of it being published online, just 118 of the 2323 attacks listed resulted in data breaches.

Despite the relatively high headline figures for ransomware compromises, the numbers are somewhat positive, claimed Emsisoft.

For example, 113 government bodies were hit in both 2019 and 2020, while the number of schools impacted in 2020 was a much higher 1681. In 2020, more healthcare providers were targeted (80 versus 68 in 2021), but fewer sites were impacted (560).

Emsisoft explained that the numbers quoted are “minimums” as not all incidents from last year were disclosed, while others were not labeled explicitly as “ransomware.” The report also omitted supply chain attacks such as the breach at payroll firm Kronos, which impacted multiple public sector organizations.

Nevertheless, it claimed things are moving in the right direction, with threat actors no longer acting with impunity.

“The May attacks on Colonial Pipeline and JBS – which is responsible for around 20% of the global meat supply – seemed to finally focus governments’ attention on the ransomware problem and there has since been multiple initiatives and actions aimed at both bolstering security domestically and at putting more risk in the risk-reward ratio,” it concluded.

“Ransom payments have been recovered, gangs have been disrupted and arrests have been made. Perhaps most significantly, Russia arrested multiple members of REvil, one of the most active operations, in January 2022 at the request of the US, possibly indicating that the country may now be less of a safe haven for cyber-criminals.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Government to Regulate Crypto Advertising in New Crack Down

Government to Regulate Crypto Advertising in New Crack Down

The UK government has announced plans to crack down on the advertising of cryptocurrency products to prevent consumers from being misled into purchases.

The Treasury claimed that around 2.3 million people in the country now own some form of “cryptoasset,” but that understanding of these financial products is declining. That could lead to them being mis-sold to investors, it warned.

As a result, the government will be legislating to ensure the promotion of cryptoassets are subject to the same Financial Conduct Authority (FCA) rules as other financial promotions such as stocks, shares and insurance products.

Specifically, it will do this by amending the existing Financial Promotion Order.

“Under the Financial Services and Markets Act 2000, a business cannot promote a financial product unless they are authorized by the FCA or the Prudential Regulatory Authority, or the content of the promotion is approved by a firm which is,” the Treasury explained.

“Firms that wish to promote such investments and activities must comply with binding rules that financial promotions must be fair, clear, and not misleading.”

According to 2021 research by financial regulator the FCA, over 4% of the population now owns cryptocurrency assets, at a median value of £300.

However, while consumers are less likely to cite such investments as a “gamble,” those who are persuaded by adverts “are much more likely to regret their purchase.”

Mis-selling is not the same as outright fraud, as the products being sold are genuine, unlike those offered by many cryptocurrency investment scammers.

However, the practice is another example of the difficulties facing would-be investors in what is still something of a Wild West for consumers.

Investment fraud is one of the highest-grossing cybercrimes, according to the FBI. It revealed that over $336m was lost to scammers in 2020, more than any other crime category except for romance scams and the compromise of business email.

“Cryptoassets can provide exciting new opportunities, offering people new ways to transact and invest – but it’s important that consumers are not being sold products with misleading claims,” said chancellor Rishi Sunak.

“We are ensuring consumers are protected, while also supporting innovation of the cryptoasset market.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains