News

Russia Stops REvil

Russia Stops REvil

Russia says it has ended the criminal activities of the REvil ransomware gang and placed its members under arrest. 

In an action coordinated by the Federal Security Service of the Russian Federation (FSB) in cooperation with the Investigation Department of the Ministry of Internal Affairs of Russia in the cities of Moscow, St. Petersburg, and Lipetsk, searches were executed at residential addresses associated with 14 gang members.

During the operation, Russian authorities seized computer equipment, money and vehicles purchased with the proceeds of crime. 

statement issued today by the Federal Security Service of the Russian Federation (FSB) stated that “funds were seized at 25 addresses at the places of residence of 14 members of the organized criminal community: over 426 million rubles, including in cryptocurrency, 600 thousand US dollars, 500 thousand euros, as well as computer equipment, crypto wallets used to commit crimes, 20 premium cars purchased with money obtained from crime.”

The FSB said members of the ransomware gang had been detained and charged with the illegal circulation of means of payment.

“As a result of the joint actions of the FSB and the Ministry of Internal Affairs of Russia, the organized criminal community ceased to exist, the information infrastructure used for criminal purposes was neutralized,” reads the statement.

Russia said this blow against REvil was dealt in answer to an appeal by the United States and that US authorities had been “informed about the results of the operation.”

The arrests came after unknown hackers targeted Ukrainian government websites early Friday, blocking access and warning internet users to “expect the worst.”

Former US marine and threat intel specialist at Cyware Neal Dennis commented: “When a group gets as large and prolific as this on the global stage, Russia eventually steps in.

“I don’t think this comes exclusively because the US asked Russia to carry out the operation.”

Chris Morgan, senior cyber-threat intelligence analyst at Digital Shadows, said Russia’s actions could be an attempt to diffuse territorial tensions between Russia and the West.  

“It’s likely that the arrests against REvil members were politically motivated, with Russia looking to use the event as leverage,” said Morgan. 

“It could be debated that this may relate to sanctions against Russia recently proposed in the US, or the developing situation on Ukraine’s border.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

DigiCert Acquires Mocana

DigiCert Acquires Mocana

American technology company DigiCert has announced the acquisition of Mocana, a cybersecurity firm based in California.

Mocana was founded in 2002 and is headquartered in Sunnyvale. The focus of the company is on embedded system security for industrial control systems and the internet of things (IoT).

DigiCert said the acquisition will allow it to offer an end-to-end IoT platform and provide customers with a way to manage device identity, secure connections, prevent device tampering, and update firmware and settings remotely and securely.

“IoT security has been a challenge for device manufactures and operators,” said DigiCert chief executive officer John Merrill. 

“With the addition of Mocana, DigiCert is building on its vision for delivering digital trust, a growing necessity in the IoT market as smart devices become ubiquitous in every corner of our personal and professional lives.” 

The deal was executed with the backing of Clearlake Capital Group, Crosspoint Capital, and TA Associates. The financial terms of the transaction were not disclosed.

Mocana’s chief technology officer, Srinivas Kumar, said his colleagues are excited to be joining the DigiCert team.

He added: “Together, our solutions uniquely solve the challenges of IoT security, from embedding security protections on-chip or at device manufacturing to on-device secure communications and firmware updates once in the field.”    

Mocana’s list of clients includes ABB Ltd., Ciena Corp, Citrix Systems Inc., Eaton Corp. PLC, General Atomics, General Electric Company, HP Inc., International Business Machines Corp., Lenovo Group Ltd., Schneider Electric SE, Siemens AG, and VMware Inc.

Mocana hit the headlines in August 2020 when the company won a $1.5m contract to provide cybersecurity support to the United States Air Force (USAF). Under the Phase II Small Business Innovation Research (SBIR) contract, Mocana agreed to work with USAF to deliver advanced cyber-protection for military systems, establishing end-to-end digital supply chain security.

DigiCert specializes in authorizing and issuing TLS/SSL (transport layer security/secure sockets layer) certificates, public key infrastructure (PKI), and IoT security and digital trust solutions.

Four years ago, Symantec’s SSL certificate authority was purchased by DigiCert for $950m. 

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Flaw Found in Biometric ID Devices

Flaw Found in Biometric ID Devices

A critical vulnerability has been discovered in more than ten devices that use biometric identification to control access to protected areas.

The flaw can be exploited to unlock doors and open turnstiles, giving attackers a way to bypass biometric ID checks and physically enter controlled spaces. Acting remotely, threat actors could use the vulnerability to run commands without authentication to unlock a door or turnstile or trigger a terminal reboot so as to cause a denial of service.

Positive Technologies researchers Natalya Tlyapova, Sergey Fedonin, Vladimir Kononovich, and Vyacheslav Moskvin found the flaw, which impacts 11 biometric identification devices made by IDEMIA. 

The team said that the impacted devices are in use in the “world’s largest financial institutions, universities, healthcare organizations, and critical infrastructure facilities.” 

The critical vulnerability (VU-2021-004) has received a score of 9.1 out of 10 on the CVSS v3 scale, with 10 being the most severe.

“The vulnerability has been identified in several lines of biometric readers for the IDEMIA ACS [access control system] equipped with fingerprint scanners and combined devices that analyze fingerprints and vein patterns,” said Vladimir Nazarov, head of ICS Security at Positive Technologies. 

He added: “An attacker can potentially exploit the flaw to enter a protected area or disable access control systems.”

The IDEMIA devices affected by the vulnerability are MorphoWave Compact MD, MorphoWave Compact MDPI, MorphoWave Compact MDPI-M, VisionPass MD, VisionPass MDPI, VisionPass MDPI-M, SIGMA Lite (all versions), SIGMA Lite+ (all versions), SIGMA Wide (all versions), SIGMA Extreme, and MA VP MD.

Enabling and correctly configuring the TLS protocol according to Section 7 of the IDEMIA Secure Installation Guidelines will eliminate the vulnerability. 

IDEMIA has said it will make TLS activation mandatory by default in future firmware versions.

This isn’t the first time Positive Technologies researchers have discovered a flaw in IDEMIA devices. In July 2021, IDEMIA fixed three buffer overflow and path traversal vulnerabilities identified by the cybersecurity company’s team. 

Under certain conditions, these prior vulnerabilities allowed an attacker to execute code, or to gain read and write access to any file from the device. IDEMIA released firmware updates to mitigate the security vulnerabilities.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Ukrainian Government Websites Forced Offline in “Massive” Cyber-Attack

Ukrainian Government Websites Forced Offline in “Massive” Cyber-Attack

Ukraine has been hit by a “massive” cyber-attack, forcing more than a dozen government websites offline, it has been reported today.

The attack, which also targeted the UK, US and Swedish embassies in Ukraine, is suspected to have been perpetrated by Russian threat actors amid significant tensions between the two nations.

The websites taken offline include the Ukrainian ministry of foreign affairs and the education ministry. Before going down, a sinister message appeared stating: “Ukrainians! … All information about you has become public. Be afraid and expect worse. It’s your past, present and future.”

The message also reproduced the Ukrainian flag and map crossed out and referenced “historical land.” This appeared in three languages: Ukrainian, Russian and Polish.

The Guardian quoted the Ukrainian foreign ministry’s spokesperson, Oleg Nikolenko, who said: “As a result of a massive cyber-attack, the website of the ministry of foreign affairs and other government agencies are temporarily down.

“Our specialists have already started restoring the work of IT systems, and the cyber-police has opened an investigation.”

Ukraine’s SBU security service said that no personal data was leaked in the attack.

The incident has come amid heightened tensions in the region, with the Kremlin demanding assurances that Ukraine will not join Nato. Russia has deployed 100,000 troops to the border with Ukraine.

The EU’s top diplomat, Josep Borrell, condemned the attacks, stating: “We are going to mobilize all our resources to help Ukraine to tackle this. Sadly, we knew it could happen.”

He added: “I can’t blame anybody as I have no proof. But we can imagine.”

Commenting on the story, Anthony Gilbert, cyber threat intelligence lead at Bridewell Consulting, said: “At the moment it’s unclear how the attack occurred or who is behind it, but given the current situation, it’s highly likely it was politically charged as there appears to be no financial motivation. The attackers probably wanted to give a warning or ignite civil unrest and spread further undercurrents of no confidence in the government.”

Toby Lewis, global head of threat analysis at Darktrace, said it was too early to jump to conclusions about the nature of the attack and its perpetrators. “We should be cautious around labeling this as a ‘sophisticated’ attack. Some cyber-attacks are more successful than others; some are advanced and others less so. A distributed denial of service (DDoS) attack, for example, which is an attempt to bring down websites or networks by overwhelming the webserver with internet traffic, is not particularly sophisticated and relatively easy to mitigate.

“Some of the website defacements, such as those left on the education website and the ministry of foreign affairs, are designed to mimic ‘nationalist/separatist groups’ with claims that the attack was done in the name of the UPA (Ukrainian Separatist Army), which has not existed for over 50 years. Attribution is impossible to do with digital data alone, and it is not unlikely that this is a false flag to divert attention away from the true perpetrators, to stir up unrest or simply impact the credibility of the website owners.”

Russia has previously been blamed for cyber-attacks on Ukraine in recent years. These include attacks in 2015 and 2016 that took out large parts of the country’s power grids.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains