News

Pennsylvania Welcomes New Cybersecurity Center

Pennsylvania Welcomes New Cybersecurity Center

A new facility that aims to train the next generation of cybersecurity professionals is coming to Pennsylvania.

The formation of the new Pennsylvania Cybersecurity Center (PCC) was announced by LindenPointe Development Corporation’s technology business incubator, the eCenter@LindenPointe.

Sited in Mercy County in the city of Hermitage, the new center will focus on providing individuals with a pathway to beginning a career in cybersecurity. Training will follow a holistic approach, combining training and certifications with practical lessons on handling real-world cyber-threats.

Users will also be offered opportunities to secure paid internships and apprenticeship positions within the cybersecurity industry. 

Jeffrey Meier, executive director at LindenPointe Development Corporation, said: “With approximately 16,000 open cybersecurity positions in Pennsylvania alone, and more than 600,000 across the country, the Pennsylvania Cybersecurity Center represents an opportunity for our area to become a leader in training the next generation of cybersecurity professionals.”

A kickoff meeting for the new center is due to take place at the end of this month, and the PCC plans to launch its very first pilot program in February. Participating in the program will be 15 high school students and 15 college students from educational establishments in the local area, including Sharon, Hickory, Greenville, Sharpsville, Farrell, Thiel College, Penn State Shenango, and Westminster College.

“In addition to our academic partnerships with local high schools and colleges, our workforce and industry partners will play a large role in the success of the Center,” said Meier.

High school students will study three courses designed by LindenPointe partner CompTIA, while college students will be taking five courses formulated by partner Cisco Network Academy.

On December 20, State Representative Mark Longietti announced $250,000 in new funding to help the Pennsylvania Cybersecurity Center launch a pilot program that aims to prepare students for high-demand careers in cybersecurity.

“As the world grows increasingly digital, the demand for high-paying cybersecurity jobs has quickly increased, and our region needs to keep pace with that demand by providing training for those careers,” said Longietti.

“This funding will allow the eCenter@LindenPointe to lay the groundwork for its pilot program geared toward area high school and college students by funding efforts at recruitment, industry exposure, curriculum, and placement.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

FCC Proposes Stricter Data Breach Reporting Requirements

FCC Proposes Stricter Data Breach Reporting Requirements

The United States’ Federal Communications Commission (FCC) has proposed the introduction of stricter reporting requirements around data breaches.

On Wednesday, FCC chairperson Jessica Rosenworcel circulated a Notice of Proposed Rulemaking (NPRM) that kicked off the process of strengthening the Commission’s rules on notifying customers and federal law enforcement when customer proprietary network information (CPNI) is breached.

The Commission said the proposed updates would more closely align FCC data breach notification rules with federal and state data breach laws governing other sectors. 

Rosenworcel said: “Current law already requires telecommunications carriers to protect the privacy and security of sensitive customer information. But these rules need updating to fully reflect the evolving nature of data breaches and the real-time threat they pose to affected consumers.”

Several updates to existing FCC rules around telecommunications carriers’ breach notification requirements are included in the proposal. Among these is the suggestion to eradicate the current seven business day mandatory waiting period for notifying customers of a breach.

The NPRM also proposes making it a requirement to notify customers of inadvertent breaches, and requiring carriers to notify the FCC, the FBI, and United States Secret Service of all reportable breaches.

“Customers deserve to be protected against the increase in frequency, sophistication, and scale of these data leaks, and the consequences that can last years after an exposure of personal information,” said Rosenworcel.

She added: “I look forward to having my colleagues join me in taking a fresh look at our data breach reporting rules to better protect consumers, increase security, and reduce the impact of future breaches.”

The FCC said that the new rules outlined in the NPRM would help to ensure that “the Commission and other federal law enforcement agencies receive the information they need in a timely manner so they can mitigate and prevent harm due to the breach and take action to reduce the likelihood of future incidents.”

Comments are now being sought by the FCC as to whether the Commission should require customer breach notices to include specific categories of information.

The suggestion to expand data breach reporting requirements follows the FCC’s September proposal to introduce new rules targeting SIM-swapping cybercrime and port-out fraud. 

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

New “Undetected” Backdoor Runs Across Three OS Platforms

New “Undetected” Backdoor Runs Across Three OS Platforms

Security experts are warning of new backdoor malware designed to work across Windows, Mac and Linux, some versions of which are currently undetected in Virus Total.

Dubbed “SysJoker” by researchers at Intezer, the malware was discovered during an attack on a Linux web server running in an education sector organization. It’s believed to date back to the second half of 2021.

“SysJoker masquerades as a system update and generates its C2 [command and control] by decoding a string retrieved from a text file hosted on Google Drive,” the vendor explained in a blog post.

“During our analysis the C2 changed three times, indicating the attacker is active and monitoring for infected machines. Based on victimology and malware’s behavior, we assess that SysJoker is after specific targets.”

The malware is written in C++, with each sample customized for the OS it targets. Worryingly, the Linux and macOS versions were fully undetected in VirusTotal at the time of writing.

Aside from the Windows version containing a first-stage dropper, all three variants work the same. After execution, the malware sleeps for up to 120 seconds, then creates a directory and copies itself under this directory, pretending to be an Intel graphics common user interface service executable.

It then covertly gathers information about the machine and achieves persistence, sleeping between these steps.

Communication with the C2 server is achieved by decoding a hardcoded Google Drive link containing a text file with an encoded C2.

The C2 might download additional malware or run other commands on the victim machine.

Intezer claimed there are several reasons why SysJoker may be the work of a sophisticated actor. It was written from scratch and hadn’t been seen before in other attacks in the wild – apparently a rarity for Linux malware.

The attacker registered at least four separate domains and wrote the malware for three discrete platforms.

“During our analysis, we haven’t witnessed a second stage or command sent from the attacker,” Intezer concluded. “This suggests that the attack is specific which usually fits for an advanced actor.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

US: MuddyWater is Iranian State-Backed Group

US: MuddyWater is Iranian State-Backed Group

The US authorities have, for the first time, explicitly identified the prolific MuddyWater hacking group as an Iranian state-sponsored entity, revealing several open-source tools used by the group to target victims.

US Cyber Command’s Cyber National Mission Force said in a post yesterday that the actors associated with MuddyWater are “a subordinate element within the Iranian Ministry of Intelligence and Security (MOIS).”

According to the Congressional Research Service (CRS), the MOIS “conducts domestic surveillance to identify regime opponents.” It also “surveils anti-regime activists abroad through its network of agents placed in Iran’s embassies,” the CRS said.

Among the tools attributed to the Iranian APT group were variants of the PowGoop DLL side-loader. These are used “to trick legitimate programs into running malware and obfuscate PowerShell scripts to hide command and control functions,” the post noted.

US Cyber Command also pointed to various JavaScript samples used to establish connections to malicious infrastructure and a Mori backdoor used for DNS tunneling to communicate with command and control servers.

“Should a network operator identify multiple of the tools on the same network, it may indicate the presence of Iranian malicious cyber actors,” it warned.

Threat intelligence vendor Mandiant said it had been tracking MuddyWater, or “Seedworm,” since at least May 2017.

“Iran fields multiple teams that conduct cyber espionage, cyberattack, and information operations,” explained Sarah Jones, Mandiant senior principal analyst, threat intelligence. “The security services that sponsor these actors, the MOIS and the IRGC, are using them to get a leg up on Iran’s adversaries and competitors all over the world.”

MuddyWater is best known for attacks on targets in the Middle East, including telecommunications, government and oil sectors. However, it has previously detected attacking victims in Europe and North America.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Report Identifies Weaknesses in Online Banking Security

Report Identifies Weaknesses in Online Banking Security

Some UK banks are letting their customers down with poor authentication and web security issues, according to a consumer rights group.

Which? once again teamed up with independent security consultants 6point6 to appraise the “front-end” security of 15 current account providers. It looked at four criteria: encryption and protection, login, account management and navigation.

The report found that, while all lenders followed strong customer authentication (SCA) rules as laid down in European banking regulations, some exposed their customers to SIM swapping attacks.

That’s because they used two-factor checks using SMS, which hackers can intercept if they have tricked the victim’s network operator into transferring their mobile phone number to a SIM under the attacker’s control.

Lloyds, Metro, Nationwide, TSB, Santander and The Co-operative Bank all dropped points in the tests for this, although the latter two claimed they’re “looking to move away from SMS,” according to Which?.

The report also highlighted issues with insecure passwords.

“We were shocked to find that Triodos lets customers set insecure security words, including ‘password’, ‘1234567’ and ‘admin.’ The risk is mitigated by a two-factor authentication at login (using its physical ‘Digipass’ device) but there is no excuse for a bank to allow such weak credentials,” it argued.

“Six banks (HSBC, NatWest, Santander, Starling, The Co-operative Bank, and Virgin Money) let you choose passwords that include your first name and/or surname. Santander told us this is being phased out, and NatWest and Virgin Money said they might increase password limitations after our investigation.”

Virgin Money was also singled out for allowing the researchers to set up a new payee without additional security steps.

The report also revealed three banks with vulnerable subdomains that could potentially be compromised, and one banking app which doesn’t require users to log in each time.

Overall, HSBC came top in the online banking security tests with a score of 81%, and First Direct was in first place for mobile banking security, with a score of 77%.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains