News

CISA: Prepare Now for Holiday Cyber Onslaught

CISA: Prepare Now for Holiday Cyber Onslaught

Critical infrastructure (CNI) providers must act now to protect their IT systems from attacks during the holiday season, the US government has warned.

The Cybersecurity and Infrastructure Security Agency (CISA) issued a new alert demanding a more proactive stance “in light of persistent and ongoing cyber-threats.”

It urged organizations to ensure they have sufficient staff to monitor IT and OT systems over the holidays continuously and that they stay informed of the latest threats by signing up to CISA mailing lists and feeds.

The agency also urged network defenders to follow industry best practices such as enforcing multi-factor authentication and strong passwords and installing software updates.

CNI firms should also test their incident response processes and cross-sector dependencies and report any incidents and “anomalous activity” immediately to CISA, it said.

“CISA urges critical infrastructure owners and operators to take immediate steps to strengthen their computer network defenses against potential malicious cyber-attacks. Sophisticated threat actors, including nation-states and their proxies, have demonstrated capabilities to compromise networks and develop long-term persistence mechanisms,” the agency warned.

“These actors have also demonstrated capability to leverage this access for targeted operations against critical infrastructure with potential to disrupt National Critical Functions.”

Threat actors often strike during holiday periods or just before, hoping to hit organizations when they are under-staffed and ill-prepared for rapid response.

The Kaseya supply chain attack on MSPs and their downstream customers occurred over the July 4 weekend in the US. There was an attack on meat processing giant JBS USA on Memorial Day weekend, while the notorious Colonial Pipeline outage began on the Mother’s Day weekend in the US.

Although not mentioned, the CISA alert can also be viewed in the context of the recently revealed Log4Shell vulnerability, which security teams are scrambling to patch. Its near-ubiquity complicates their efforts in vendor-produced and homegrown applications and the Java dependencies that may be hiding instances in blind spots across the enterprise.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Meta: Surveillance-for-Hire Firms Hit 50,000 Victims

Meta: Surveillance-for-Hire Firms Hit 50,000 Victims

Meta has removed seven “surveillance-for-hire” companies from its platform to target blameless victims in over 100 countries around the world.

Facebook’s parent company revealed in a report published yesterday that the seven companies are based in China, Israel, India and North Macedonia. Their services are said to have targeted an estimated 50,000 victims, including journalists, dissidents, critics of authoritarian regimes, families of opposition and human rights activists.

Four entities are based in Israel: Cobwebs Technologies, Cognyte, Black Cube and Bluehawk CI. The country has a significant stake in the global surveillance market, notably through the work of controversial firm NSO Group, which WhatsApp launched a legal case against in 2019.

Meta said the organizations operate across the three phases of targeting activity: “reconnaissance” via automated software; “engagement,” in a bid to build trust with the individual; and “exploitation” via phishing emails and messages.

“Although public debate has mainly focused on the exploitation phase, it’s critical to disrupt the entire lifecycle of the attack because the earlier stages enable the later ones,” said Meta. “If we can collectively tackle this threat earlier in the surveillance chain, it would help stop the harm before it gets to its final, most serious stage of compromising people’s devices and accounts.”

The social media giant said the removed entities violated its Community Standards and Terms of Service.

“Given the severity of their violations, we have banned them from our services. To help disrupt these activities, we blocked related internet infrastructure and issued cease and desist letters, putting them on notice that their targeting of people has no place on our platform,” the firm added.

“We also shared our findings with security researchers, other platforms, and policymakers so they can take appropriate action.”

There are signs that the US government is now taking the activities of surveillance companies like these seriously.

In November, the Treasury added NSO Group to its entity list, making it harder for the firm to buy components from US companies

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Attacks on UK Firms Increase Five-Fold During Pandemic

Attacks on UK Firms Increase Five-Fold During Pandemic

Attacks on UK firms surged five-fold during the pandemic and now cost way more than the global average, according to Accenture.

The global consultancy polled 500 UK executives to compile its State of Cybersecurity Resilience 2021 study.

It found that large organizations experienced 885 attempted cyber-attacks in 2020 – up from 156 the previous year and more than triple the global average of 270.

They’re also more expensive than elsewhere. Accenture calculated that incidents and breaches cost over £1.3m a year – £350,000 more than the global average.

Over 80% of respondents said the cost of staying ahead of cyber-criminals is unsustainable, a fifth more than the previous year, and a quarter said they’ve been forced to increase cybersecurity budgets by 10% or more.

Worryingly, supply chain attacks accounted for 64% of breaches in the UK last year, up by a quarter (26%) from the previous year.

This chimes with a recent report from BlueVoyant , which revealed 93% of global organizations suffered a direct breach due to their supply chains over the past year.

Accenture UK security lead, Giovanni Cozzolino, argued that British firms are under siege from digital attackers.

“It’s clear that cyber-criminals are taking full advantage of the overnight shift to home working and digital operations,” he added. “Enterprises need to be on high alert. Whether sophisticated nation-state actors or run of the mill cyber-criminals, adversaries are clearly getting more resourceful and launching attacks from every angle.”

The report claimed that nearly half (49%) of large businesses lost over 100,000 customer records over the course of the past year, an increase of 28% from the previous year.

“Faced with high costs in a difficult economic environment, UK firms must be smart with how they spend on security,” concluded Cozzolino.

“Spending more without being closely aligned to the business doesn’t make your organization safer. To achieve sustained cyber resilience, CISOs need to collaborate with the right executives in their organization to understand where to prioritize.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains