News

500M Avira Antivirus Users Introduced to Cryptomining

Many readers were surprised to learn recently that the popular Norton 360 antivirus suite now ships with a program which lets customers make money mining virtual currency. But Norton 360 isn’t alone in this dubious endeavor: Avira antivirus — which has built a base of 500 million users worldwide largely by making the product free — was recently bought by the same company that owns Norton 360 and is introducing its customers to a service called Avira Crypto.

Avira Crypto

Founded in 2006, Avira Operations GmbH & Co. KG is a German multinational software company best known for their Avira Free Security (a.k.a. Avira Free Antivirus). In January 2021, Avira was acquired by Tempe, Ariz.-based NortonLifeLock Inc., the same company that now owns Norton 360.

In 2017, the identity theft protection company LifeLock was acquired by Symantec Corp., which was renamed to NortonLifeLock in 2019. LifeLock is now included in the Norton 360 service; Avira offers users a similar service called Breach Monitor.

Like Norton 360, Avira comes with a cryptominer already installed, but customers have to opt in to using the service that powers it. Avira’s FAQ on its cryptomining service is somewhat sparse. For example, it doesn’t specify how much NortonLifeLock gets out of the deal (NortonLifeLock keeps 15 percent of any cryptocurrency mined by Norton Crypto).

“Avira Crypto allows you to use your computer’s idle time to mine the cryptocurrency Ethereum (ETH),” the FAQ explains. “Since cryptomining requires a high level of processing power, it is not suitable for users with an average computer. Even with compatible hardware, mining cryptocurrencies on your own can be less rewarding. Your best option is to join a mining pool that shares their computer power to improve their chance of mining cryptocurrency. The rewards are then distributed evenly to all members in the pool.”

NortonLifeLock hasn’t yet responded to requests for comment, so it’s unclear whether Avira uses the same cryptomining code as Norton Crypto. But there are clues that suggest that’s the case. NortonLifeLock announced Avira Crypto in late October 2021, but multiple other antivirus products have flagged Avira’s installer as malicious or unsafe for including a cryptominer as far back as Sept. 9, 2021.

Avira was detected as potentially unsafe for including a cryptominer back in Sept. 2021. Image: Virustotal.com.

The above screenshot was taken on Virustotal.com, a service owned by Google that scans submitted files against dozens of antivirus products. The detection report pictured was found by searching Virustotal for “ANvOptimusEnablementCuda,” a function included in the Norton Crypto mining component “Ncrypt.exe.”

Some longtime Norton customers took to NortonLifeLock’s online forum to express horror at the prospect of their antivirus product installing coin-mining software, regardless of whether the mining service was turned off by default.

“Norton should be DETECTING and killing off crypto mining hijacking, not installing their own,” reads a Dec. 28 thread on Norton’s forum titled “Absolutely furious.”

Others have charged that the crypto offering will end up costing customers more in electricity bills than they can ever hope to gain from letting their antivirus mine ETH. What’s more, there are hefty fees involved in moving any ETH mined by Norton or Avira Crypto to an account that the user can cash out, and many users apparently don’t understand they can’t cash out until they at least earn enough ETH to cover the fees.

In August 2021, NortonLifeLock said it had reached an agreement to acquire Avast, another longtime free antivirus product that also claims to have around 500 million users. It remains to be seen whether Avast Crypto will be the next brilliant offering from NortonLifeLock.

As mentioned in this week’s story on Norton Crypto, I get that participation in these cryptomining schemes is voluntary, but much of that ultimately hinges on how these crypto programs are pitched and whether users really understand what they’re doing when they enable them. But what bugs me most is they will be introducing hundreds of millions of perhaps less savvy Internet users to the world of cryptocurrency, which comes with its own set of unique security and privacy challenges that require users to “level up” their personal security practices in fairly significant ways.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Cyber-Attack on New Mexico County

Cyber-Attack on New Mexico County

A cyber-attack has forced the government of New Mexico’s most populous county to close most of its county buildings to the public.

Bernalillo County had to take some of its IT systems offline on Wednesday after becoming the target of a digital assault that county officials suspect was a ransomware attack. 

In a statement released Wednesday, the county said that all public safety departments, such as emergency 911 communications, the Sheriff’s Office, and Fire and Rescue, were operating as normal “using back-up contingencies.”

However, the incident caused the county’s Metropolitan Detention Center to cancel inmate visits Wednesday.

“Bernalillo County has discovered what is believed to be a ransomware attack on county systems,” stated the county. 

“The county has taken affected systems offline and has severed network connections.”

Vendors for the county’s IT systems have been notified of the attack. The county said that its cybersecurity and IT suppliers are “working to solve the issue and restore the system functions.”

While the disruption of the attack continues, the county said its employees would do their best to fulfill their duties by working remotely.

A county statement read: “Most county buildings are closed to the public; however, county employees are remote working and will assist the public as much as possible, given the circumstances.”

The county did not share any information as to how or by whom the attack was orchestrated. Nor has the county stated if any data has been compromised or if it has received a ransom demand. 

Bernalillo County spokesperson Tia Bland said: “Just know the county is working with a good team of people, long hours, the right people are at the table trying to figure this thing out.”

KOAT Action News reported that the attack on Bernalillo County is causing disruption to the local real estate industry. With key county IT systems offline, realtors are unable to access information such as taxes and deeds that is needed to complete property sales.

“It’s having a ripple effect on the real estate market in general,” said Damon Maddox, the president of the New Mexico Association of Realtors.

“It’s difficult for us to do our job if we can’t access the county website to get that public information.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Cerberus Sentinel Acquires True Digital Security

Cerberus Sentinel Acquires True Digital Security

Cerberus Cyber Sentinel Corporation today announced its acquisition of an American cybersecurity operations and compliance company.

The Arizona-based cybersecurity consulting and managed services firm said the decision to acquire True Digital Security was part of a strategy to bring together global security talent as partners.

True Digital Security was founded in 1985 and currently has offices in West Palm Beach, Florida, Tulsa, Oklahoma, and New York, New York.

Describing itself as “the tech company for tech companies” on its website, True Digital Security assists companies with their IT, security, and compliance operations via its IT/Sec Operational Intelligence SaaS platform, TrueSpeed.

Under the terms of the agreement, True Digital Security will become a wholly-owned subsidiary of Cerberus Cyber Sentinel Corporation. True Digital Security’s current chief executive officer, Rory Sanchez, will serve as an executive to the company and continue to manage his team of professionals. 

Sanchez said the True Digital Security team were “extremely excited” to be joining Cerberus.

“It’s rare to find a company and leadership team that so closely shares our culture, values, goals, and vision,” said Sanchez.

He added: “This move will enable us to jointly accelerate the roll-out of our industry disruptive TrueSpeed platform and continue strengthening our premiere managed compliance and cybersecurity services on a global scale.” 

True Digital Security’s chief information security officer, Dr. Jerald Dawkins, who founded the company and also TRUE-Tulsa, said the deal had fired his passion for future work.

“As the founder of True Digital Security, I couldn’t be more excited about the next chapter we will write with the Cerberus companies and their leadership team,” said Dawkins.

He added: “I’m more passionate now than ever about the potential that lies before us, and I’m thrilled about what the future holds.”

David Jemmett, CEO and founder of Cerberus Sentinel, said his company had been working with the True Digital team for several months to expand its security and network security monitoring capabilities. 

He said: “We are delighted with the way their expertise and services enhance our MCCP+ security solutions.”

The financial terms of the deal were not disclosed.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Monsanto Employee Stole Trade Secret

Monsanto Employee Stole Trade Secret

A man who worked at the Monsanto Company has admitted stealing a trade secret from his former employer and attempting to sell it to the People’s Republic of China.

Xiang Haitao was employed by the American agrochemical and agricultural biotechnology corporation and its subsidiary, The Climate Corporation, as an imaging scientist from 2008 to 2017.

The 44-year-old former resident of Chesterfield, Missouri, exploited his position to steal a proprietary predictive algorithm dubbed the Nutrient Optimizer. 

The algorithm was a key component of a digital online farming software platform developed by Monsanto and The Climate Corporation to increase and improve agricultural productivity for farmers by helping them to collect, store, and visualize agricultural field data.

According to court documents, Xiang transferred the Nutrient Optimizer onto a memory card and copied it onto at least one of his own personal electronic devices. 

The day after Xiang left his employment at Monsanto in June 2017, he tried to fly to China using a one-way airline ticket. Before he boarded the plane, federal officials searched the scientist’s luggage. 

Xiang flew to China and found employment at the Chinese Academy of Science’s Institute of Soil Science. Investigators later found copies of the Nutrient Optimizer on one of Xiang’s electronic devices that was searched at the airport. 

Monsanto was acquired by German chemical company Bayer in 2018 for $66bn. 

Xiang was indicted in November 2019, and arrested when he returned to the United States. On Thursday, he pleaded guilty in Missouri to one count of conspiracy to commit economic espionage.

When Xiang is sentenced on April 7, he faces a maximum penalty of 15 years in prison, a potential fine of $5m, and a term of supervised release lasting up to three years.

“The American worker suffers when adversaries, like the Government of China, steal technology to grow their economies,” said Assistant Director Alan Kohler of the FBI’s Counterintelligence Division. 

“It’s not just military technology developed in secret labs that adversaries want; in this case, it was agricultural technology used by American farmers to improve crop yields.”

Kohler said that the FBI will continue investigating the theft of technology from American companies “because economic security is national security.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Election Fraud Firm to Shut Down After Claims Debunked

Election Fraud Firm to Shut Down After Claims Debunked

A controversial ‘cybersecurity consultancy’ has said it’s closing after its report into alleged election fraud in Arizona was roundly rebuffed by officials.

According to a reporter for The Guardian, boss Doug Logan “and the rest of the employees have been let go and Cyber Ninjas is being shut down.”

Arizona Senate Republicans hired Cyber Ninjas to find evidence supporting Donald Trump’s widely debunked claims that the 2020 election was stolen from him.

Its long-awaited report was this week slammed in a 93-page rebuttal by election officials in Arizona’s Maricopa County. According to reports, 76 of the 77 claims made in the document were branded false or misleading.

The only one confirmed as an error was the double-counting of 50 ballots in the state’s most populous county, not enough to overturn the 10,000+ majority Joe Biden won there.

Cyber Ninjas was accused of deliberately using tactics that would lead to inaccuracies and even consulted conspiracy theorist Shiva Ayyadurai to review mail-in ballots.

“It’s been debunked and it was written by people who are not experts in the field,” said Bill Gates, chairman of the Maricopa County Board of Supervisors. “We’re done. This is the end of the 2020 election. We have addressed the issues; we have debunked them.”

Cyber Ninjas is also in legal trouble after failing to turn over documents related to the audit to a local newspaper after it filed a public records request.

Maricopa County superior court judge John Hannah reportedly said he would impose a $50,000 fine against the firm every day it failed to do so.

“I don’t think I have to find Cyber Ninjas is not acting in good faith,” the judge is reported to have ruled. “All I have to do is find they are not complying, and their noncompliance is not based on good faith and reasonable interpretation of the order. I think the variety of creative positions Cyber Ninjas has taken to avoid compliance with this order speaks for itself.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Thousands of Schools Impacted After IT Provider Hit by Ransomware

Thousands of Schools Impacted After IT Provider Hit by Ransomware

A leading provider of school website infrastructure has been hit by a ransomware attack, potentially disrupting thousands of global customers.

Finalsite claims to serve over 8000 schools worldwide, offering content management, communications, mobile and enrolment software.

A message posted by the firm on Twitter yesterday apologized for the “prolonged outage” customers have been forced to endure as a result of the attack.

“The Finalsite security team monitors our network systems 24 hours a day, seven days a week. On Tuesday, January 4, our team identified the presence of ransomware on certain systems in our environment,” it explained.

“In the time since the incident, our security, infrastructure and engineering teams have been working around the clock to restore backup systems and bring our network back to full performance, in a safe and secure manner.”

Finalsite claimed it had uncovered no evidence that data had been stolen as part of the raid but admitted that forensic work was still ongoing.

Double extortion involving the threat of leaking stolen data is now the norm for such attacks, according to ransomware experts.

According to Coveware, over 80% of attacks in Q3 involved the theft of corporate information alongside file encryption.

There’s no sign of exactly how many schools have been impacted by the attack, although a Reddit user claimed around 2,200 might have been disrupted.

“With numbers like this, there’s a good chance that a school in your town is affected. Many districts are complaining that they are unable to use their emergency notification system to warn their communities about closures due to weather or COVID-19 protocol,” they added.

“The impact of this outage is far greater than the attention it has received.”

There’s no indication of whether Finalsite is engaging with its attackers or when customers can expect a restoration of services

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Researchers Warn of New Log4Shell-Like Java Vulnerability

Researchers Warn of New Log4Shell-Like Java Vulnerability

Security researchers are warning of a critical new Java bug with the same root cause as the notorious Log4Shell vulnerability currently being exploited around the globe.

CVE-2021-42392 has yet to be officially published in the National Vulnerability Database (NVD), but according to JFrog, it impacts the console of the popular H2 Java SQL database.

The security firm urged any organization currently running an H2 console exposed to their LAN or WAN to update the database immediately to version 2.0.206 or risk attackers exploiting it for unauthenticated remote code execution (RCE).

Like Log4Shell, the bug relates to JNDI (Java Naming and Directory Interface) “remote class loading.” JNDI is an API that provides naming and directory functionality for Java apps. It means that if an attacker can get a malicious URL into a JNDI lookup, it could enable RCE.

“In a nutshell, the root cause is similar to Log4Shell – several code paths in the H2 database framework pass unfiltered attacker-controlled URLs to the javax.naming.Context.lookup function, which allows for remote codebase loading (AKA Java code injection AKA remote code execution),” JFrog explained.

“Specifically, the org.h2.util.JdbcUtils.getConnection method takes a driver class name and database URL as parameters. If the driver’s class is assignable to the javax.naming.Context class, the method instantiates an object from it and calls its lookup method.”

It added that supplying a driver class such as “javax.naming.InitialContext” and a URL as simple as ldap://attacker.com/Exploit will lead to remote code execution.

JFrog said the vulnerability is particularly dangerous as the H2 database package is particularly popular. It’s one of the top 50 most popular Maven packages, with almost 7000 artifact dependencies, the firm claimed.

However, there are some reasons why exploitation won’t be as widespread as Log4Shell. For one, it has a “direct scope of impact,” meaning vulnerable servers should be easier to find.

Second, in most H2 distributions, the console only listens to localhost connections, meaning the default setting is not exploitable.

“Many vendors may be running the H2 database, but not running the H2 console,” JFrog added. “Although there are other vectors to exploit this issue other than the console, these other vectors are context-dependent and less likely to be exposed to remote attackers.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains