<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/cyber-terrorism" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Cyber-terrorism ]]></title>
                <link>https://www.itpro.com/tag/cyber-terrorism</link>
        <description><![CDATA[ All the latest cyber-terrorism content from the ITPro team ]]></description>
                                    <lastBuildDate>Wed, 27 May 2026 09:36:30 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacks  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/new-ransomware-threat-group-the-gentlemen-has-become-one-of-the-most-active-ransomware-operators-accounting-for-10-percent-of-all-attacks</link>
                                                                            <description>
                            <![CDATA[ NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4gZ8feTHY7ssujqtLTWGv7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LrXBU2G7X45b6NeaQsxQsN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 27 May 2026 09:36:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LrXBU2G7X45b6NeaQsxQsN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware concept image showing a warning symbol in red with binary code in background.]]></media:description>                                                            <media:text><![CDATA[Ransomware concept image showing a warning symbol in red with binary code in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware concept image showing a warning symbol in red with binary code in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LrXBU2G7X45b6NeaQsxQsN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacks and second only to the notorious <a href="https://www.itpro.com/security/cyber-attacks/thousands-of-procedures-canceled-at-london-hospitals-as-qilin-releases-blood-test-data">Qilin</a>.</p><p>Despite only having emerged in July last year, The Gentlemen has quickly evolved into a highly operational RaaS group, <a href="https://insights.nccgroup.com/l/898251/2026-05-22/31nc1rq/898251/1779445538Mpsajkjn/April_2026___Cyber_Threat_Intelligence_Report.pdf">according to the NTT</a>, using advanced tooling and proxy infrastructure to accelerate attacks and improve stealth.</p><p>With a level of technical maturity that would normally be associated with more established <a href="https://www.itpro.com/security/ransomware/the-ransomware-boom-shows-no-signs-of-letting-up-and-these-groups-are-causing-the-most-chaos">ransomware groups</a>, the researchers believe that the group consists of experienced actors with potential ties to other ransomware ecosystems.</p><p>The group's targeting remains focused on industrial organizations, the information technology sector, and some consumer spaces, with notable victims including Synergy France, UK Electronics, and Equity Life. </p><p>In terms of target geography, meanwhile, The Gentlemen largely extorts organizations in Europe, with the UK and Germany among the most heavily targeted countries.</p><p>Its affiliates are increasingly leveraging SystemBC malware, a proxy and backdoor tool often used in human-operated ransomware attacks, to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments.</p><p>The group's rapid growth so far this year, combined with its sophisticated proxy infrastructure and obfuscation techniques, means organizations should expect faster intrusion cycles and reduced dwell times before encryption deployment, NTT said. </p><p>"The rise of groups like The Gentlemen demonstrates how affiliates are now combining shared tooling, stealth infrastructure, and repeatable intrusion methods to accelerate attacks at scale," said Matt Hull, VP of cyber intelligence and response at NCC Group. </p><p>"Techniques such as covert tunnelling and rapid domain-wide deployment are shrinking the window that defenders have to detect and respond before encryption occurs."</p><p>According to NTT, there were 748 ransomware listings worldwide during April, representing a 7% fall from the figure for March. However, ransomware activity in 2026 has been operating at a higher baseline than much of 2025, as the ransomware-as-a-service (RaaS) ecosystem expands and matures.</p><p><a href="https://www.itpro.com/security/ai-is-raising-the-stakes-for-cyber-professionals-claude-mythos-just-took-things-to-another-level">Claude Mythos</a> – the large language model reportedly capable of autonomously identifying vulnerabilities and developing exploit chains – has yet to make its mark, thanks to restricted access, controlled testing environments, and questions around operational effectiveness at scale.</p><p>"Developments around AI models such as Claude Mythos suggest AI-assisted vulnerability discovery and exploitation could further compress attacker timelines in the future," said Hull. "However, the industry should remain cautious about overstating current capabilities, particularly where testing has been limited to controlled environments."</p><p>The report also highlighted several geopolitical developments likely to influence cyber activity in the coming months, including China's expanded supply chain security regulations, which consolidate and extend existing controls on import and export activities.</p><p>Meanwhile, the strategic significance of NASA's Artemis program is motivating China and other nations to carry out espionage, IP theft activities, and potentially even destructive attacks. </p><p>"Numerous other well-resourced countries (and private companies) are pursuing high-stakes interests dependent on the domain of space; including but not exclusive to India, Japan, Israel, South Korea, UAE, Russia, Iran, and North Korea," the researchers warned. "Defenders should avoid being too narrow in their assessments of potential threats."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Foreign states ramp up cyberattacks on EU with AI-driven phishing and DDoS campaigns  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/foreign-states-ramp-up-cyber-attacks-on-eu-with-ai-driven-phishing-and-ddos-campaigns</link>
                                                                            <description>
                            <![CDATA[ ENISA warns of hacktivism, especially through DDoS attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">F8aYpUw4Mqqm7uheNGJhpB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DFxSE87P88iW6pX6P92trE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Oct 2025 09:43:48 +0000</pubDate>                                                                                                                                <updated>Fri, 03 Oct 2025 14:35:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DFxSE87P88iW6pX6P92trE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI render of the EU flag shown as 12 gold stars hovering and creating a ripple effect in a wave of blue data]]></media:description>                                                            <media:text><![CDATA[A CGI render of the EU flag shown as 12 gold stars hovering and creating a ripple effect in a wave of blue data]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI render of the EU flag shown as 12 gold stars hovering and creating a ripple effect in a wave of blue data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DFxSE87P88iW6pX6P92trE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The EU is being battered by cyberattacks, with government and critical infrastructure the top targets, cybersecurity agency ENISA has warned.</p><p>The latest <a href="https://enisa.europa.eu/topics/cyber-threats">ENISA Threat Landscape report</a> found that state-aligned threat groups have been intensifying their operations towards EU organizations. It's seen such groups carrying out cyberespionage against the public administration sector, while feeding EU audiences with misinformation. </p><p>At the top of the target list is public administration, at 38%, mostly <a href="https://www.itpro.com/hacking/30203/what-is-hacktivism">hacktivism</a> and state-nexus intrusion to conduct cyberespionage campaigns against diplomatic and governmental bodies.</p><div class="product"><a data-dimension112="05cea2cd-d21a-4494-97cc-74d209bfe142" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="05cea2cd-d21a-4494-97cc-74d209bfe142" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="05cea2cd-d21a-4494-97cc-74d209bfe142" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Next is the transport sector, at 7.5%, followed by digital infrastructure and services at 5%, finance at 4.5% and manufacturing at 3%.</p><p>Hacktivism accounted for almost 80% of the total number of incidents, mainly through low-impact <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">DDoS</a> campaigns targeting EU member states organizations' websites. Only 2% of hacktivism incidents resulted in service disruption.</p><p><a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing</a> – including vishing, malspam, and malvertising – is the main method for initial intrusion, accounting for about 60% of cases. </p><p>"The recent ENISA report makes it clear that phishing is still the leading entry point for attackers. What's interesting is how the technique is being reshaped by AI," said Mick Leach, field CISO at Abnormal AI. </p><p>"As shown in the report, attackers don't need to innovate while they continue to see success with tried-and-true techniques. Instead, they can make these methods more impactful with generative models that allow the creation of highly convincing and context-aware campaigns."</p><p>Vulnerability exploitation was the next most common vector.</p><p>"Vulnerability exploitation, which accounts for 21.3% of all attacks according to ENISA, is continually seen as a problem for businesses," said Sylvain Cortes, VP strategy, Hackuity. </p><p>"The challenge is that organisations often have difficulty with visibility and prioritization; they need both a centralised view to identify vulnerabilities and then the context around these to know where to prioritise remediation efforts. There's an inherent imbalance in the time it can take for organisations to patch critical vulnerabilities and the speed with which attackers can exploit them."   </p><h2 id="ddos-hacktivism">DDoS hacktivism </h2><p>DDoS attacks were the most common type of incident, accounting for 77%, with most carried out by hacktivists rather than cyber criminals. But, said the researchers, there has been a notable convergence between threat groups. State-aligned actors are showing hacktivist characteristics, while the two groups are using increasingly similar tools.</p><p>The report highlighted the abuse of critical dependency points, for example in the digital supply chain. And AI, meanwhile, is being used both as an optimization tool for malicious activities and also as a new point of exposure. <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models">LLMs</a> are enhancing phishing and automating social engineering activities. </p><p>"The growing role of AI has become an undeniable key trend of the rapidly evolving threat landscape, the researchers said. </p><p>And, they warned, "While the focus of threat activities involving AI was the use of consumer-grade AI tools to enhance their existing operations, the emergent malicious AI systems is raising concerns about their capabilities in the future due to the widespread use of AI models." </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">What is a DDoS attack</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence-ai/370337/organisations-soon-be-using-generative-ai-prevent-phishing">AI phishing</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A new 'top-tier' Chinese espionage group is stealing sensitive data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/a-new-top-tier-chinese-espionage-group-is-stealing-sensitive-data</link>
                                                                            <description>
                            <![CDATA[ Phantom Taurus has been operating for two years and uses custom-built malware to maintain long-term access to critical targets ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">munvQxQC67Rd4pGmebULLS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CYSSvkHTWQZEb3GZNZZFEo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Oct 2025 09:24:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CYSSvkHTWQZEb3GZNZZFEo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chinese hacker concept image showing hands typing on keyboard with People&#039;s Republic of China flag in background.]]></media:description>                                                            <media:text><![CDATA[Chinese hacker concept image showing hands typing on keyboard with People&#039;s Republic of China flag in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Chinese hacker concept image showing hands typing on keyboard with People&#039;s Republic of China flag in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CYSSvkHTWQZEb3GZNZZFEo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A newly-discovered threat group linked to China is targeting governments, the military, and other critical bodies across Africa, the Middle East, and Asia for espionage.</p><p>Palo Alto Networks said the group, which it has dubbed Phantom Taurus, belongs in the top tier of <a href="https://www.itpro.com/security/cyber-attacks/global-cyber-attacks-jumped-44-percent-last-year">global threats</a>. </p><p>"This is largely due to their targeting of both high-level geopolitical intelligence and entities (embassies, foreign ministries, diplomats) and critical telecommunications infrastructure, making them very much a dual threat," the researchers warned. </p><div class="product"><a data-dimension112="adb28087-a85f-4ef6-b35e-86136f610ab1" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="adb28087-a85f-4ef6-b35e-86136f610ab1" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="adb28087-a85f-4ef6-b35e-86136f610ab1" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Phantom Taurus has been operating for two years, using a distinctive set of tactics, techniques, and procedures (TTPs) that allow it to conduct highly covert operations. </p><p>Alongside more common tools, such as China Chopper, the Potato suite, and Impacket, the group uses customized tools, including the <a href="https://www.itpro.com/exploits/30478/what-are-meltdown-and-spectre-and-are-you-affected">Specter malware</a> family and Ntospy. It's also been able to maintain long-term access to critical targets through a custom-built <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> suite called NET-STAR. </p><p>Since 2023, Phantom Taurus has focused on stealing sensitive and specific emails of interest from email servers – but has more recently shifted to the direct targeting of databases using a script named mssq.bat.</p><p>This connects to an <a href="https://www.itpro.com/infrastructure/servers-and-storage/how-to-check-your-sql-server-version">SQL Server</a> database with a given server name, a user ID named sa (system administrator), and a password that the attackers previously obtained. It then reads the SQL query provided in the command-line arguments by the group's operators, allowing dynamic searching for tables and specific keywords.</p><p>Finally, it executes the provided query and returns the results that match the user's search, exports the results to a CSV file, and closes the database connection.</p><p>Perhaps most significantly, the group is using a new and undocumented malware suite, NET-STAR, designed to target Internet Information Services (IIS) web servers.  </p><p>"The NET-STAR malware suite demonstrates Phantom Taurus' advanced evasion techniques and a deep understanding of .NET architecture, representing a significant threat to internet-facing servers," the researchers said. </p><p>The suite consists of three distinct web-based backdoors, each carrying out a specific role in the attack chain, while maintaining persistence within the target's IIS environment.</p><p>IIServerCore is a fileless modular backdoor that supports in-memory execution of command-line arguments, arbitrary commands and payloads; AssemblyExecuter V1 loads and executes additional .NET payloads in memory; and AssemblyExecuter V2 is an enhanced version of AssemblyExecuter V1 that's also equipped with Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) bypass capabilities.</p><p>Palo Alto Networks has published indicators of compromise here, and has upgraded its Advanced WildFire machine-learning models and Cortex XDR to give better protection. It said it has also shared its findings with fellow Cyber Threat Alliance (CTA) members, and is recommending that they do the same. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/harrods-cyber-attack">Harrods hit by cyber attack </a></li><li><a href="https://www.itpro.com/security/asahi-production-halted-by-cyber-attack">Ashai production halted by cyber attack</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘States don’t do hacking for fun’: NCSC expert urges businesses to follow geopolitics as defensive strategy ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/states-dont-do-hacking-for-fun-ncsc-expert-urges-businesses-to-follow-geopolitics-as-defensive-strategy</link>
                                                                            <description>
                            <![CDATA[ Paul Chichester, director of operations at the UK’s National Cyber Security Centre, urged businesses to keep closer tabs on geopolitical events to gauge potential cyber threats. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tWmWKKmQCWqZdQFyWWxsaA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TLqJdzSrYCkAScByVUwGaF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Jun 2025 09:01:08 +0000</pubDate>                                                                                                                                <updated>Thu, 05 Jun 2025 09:01:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;
&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;
&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;
&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;
&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TLqJdzSrYCkAScByVUwGaF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Russian hacker concept image showing a skulls and crossbones colored like the Russian Federation flag, made up of binary code, and imposed over a digital interface.]]></media:description>                                                            <media:text><![CDATA[Russian hacker concept image showing a skulls and crossbones colored like the Russian Federation flag, made up of binary code, and imposed over a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Russian hacker concept image showing a skulls and crossbones colored like the Russian Federation flag, made up of binary code, and imposed over a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TLqJdzSrYCkAScByVUwGaF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Business leaders need to stay up to date with geopolitics to keep their cybersecurity strategies up to date and mitigate the risks posed by state-backed hacker groups. </p><p>This is the message that Paul Chichester, director of operations at the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a>, delivered to attendees at a keynote session of Infosecurity Europe 2025.</p><p>The call to action from Chichester came as states known to support threat actors and engage in cyber attacks of their own step up efforts to disrupt critical infrastructure</p><p>Chichester said Russia’s cyber capabilities in particular have improved in recent years, with its invasion of Ukraine used as an opportunity to hone offensive cyber techniques. Along with Russia, Chichester focused on the threat <a href="https://www.itpro.com/security/cyber-attacks/china-cyber-threats"><u>China-backed groups</u></a> pose to both public and private organizations.</p><p>“I'll come back to this a few times, but states don't do hacking for fun,” Chichester said.</p><p>“They do not do things for the sake of it. There is always a reason. We might not know the reason sometimes and that's quite a challenge for us, but we shouldn't assume that they're just doing it because they can.”</p><p>Chichester urged businesses who are being targeted by a state APT to carefully consider why and to assess how geopolitics feeds into their defensive strategies.</p><p>“At the end of the day, cyber isn't really just, or even, a technical thing. It's a tool that somebody uses, be it a criminal, be it a state. How does that risk manifest itself for you?”</p><p>The past few years have seen a number of high-profile attacks by <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier"><u>state-sponsored groups</u></a> on organizations to achieve ideological and military aims. Chichester said Russia is increasingly targeting supply chains which feed into Ukraine, with defense, energy, and logistics companies firmly in its crosshairs.</p><p>In 2022, for example, Microsoft warned the Russia-backed group Seashell Blizzard was using the Prestige <a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers"><u>ransomware strain</u></a> to target organizations involved in the supply or transport of humanitarian aid and military shipments to Ukraine. </p><p>This is also coming from within the GRU military intelligence service, and Chichester cited the example of Unit 29155. This Russian military sabotage unit is known for its role in the 2018 Skripal poisonings, but it is now using cyber attacks to carry out its aims.</p><p>“Ultimately, if you want to target something in the real world, you need to understand them in the cyber world. You need to understand how they operate, you need to understand their movements, you need to understand what's going where,” Chichester explained.</p><p>“And we're seeing that merger of that real world sabotage being joined with that cyber espionage piece as well – and also cyber sabotage.”</p><p><a href="https://www.itpro.com/security/cyber-attacks/367634/five-eyes-and-us-governments-confirm-russia-behind-attacks"><u>Russia launched a major cyber attack on Viasat</u></a>, a US communications company, on 24 February 2022, the same day it invaded Ukraine. This triggered a widespread outage, impacting Ukrainian military command and control and causing knock-on outages for several thousand internet-connected German wind turbines. </p><p>Chichester said the attack was carefully-timed to hit hardest in the first 24-48 hours of the invasion and “might have been a deciding factor” in the war had events on the ground gone differently.</p><p>Despite the apparently unintentional effects on EU-based companies, Chichester used the attack as an example of how states are increasingly targeting private businesses to achieve military or ideological aims.</p><p>China is also heavily implicated in attacks on critical national infrastructure, with cyber experts Kevin Mandia and Nicole Perlroth having recently warned the nation state has <a href="https://www.itpro.com/security/china-has-almost-doubled-their-aggression-in-cyber-kevin-mandia-and-nicole-perlroth-warn-organizations-arent-waking-up-to-growing-apt-threats"><u>ramped up its cyber aggression</u></a>.</p><p>Chichester said attacks by Volt Typhoon, an <a href="https://www.itpro.com/security/cyber-attacks/what-is-an-apt"><u>advanced persistent threat (APT)</u></a> that <a href="https://www.itpro.com/security/cyber-attacks/volt-typhoon-threat-group-electric-grid"><u>successfully breached the US electric grid</u></a> for almost a year, as well as Salt Typhoon which <a href="https://www.itpro.com/security/fcc-tells-telcos-to-sharpen-up-security-after-salt-typhoon-chaos"><u>carried out major attacks on US telcos in 2024</u></a>, show groups ‘pre-positioning’ themselves inside critical infrastructure.</p><p>As <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a"><u>warned by CISA</u></a>, this could enable undetected groups to carry out devastating attacks in the event of conventional war in the long-term.</p><h2 id="for-profit-attacks-remain-king">For-profit attacks remain king</h2><p>Despite the growing threat posed by state-backed groups pursuing ideological and military aims, evidence suggests that businesses will still largely contend with traditional threat actors.</p><p>In a separate keynote talk at the event, James Lyne, office of the CEO at the SANS Institute and Ciaran Martin, director of CISO network at the SANS Institute and former head of the NCSC, balanced the real threat of state-backed groups with those of profit-motivated groups.</p><p>“Most people are interested in fraud,” said Lyne. “Most of this stuff is about making money, the average obsession of the average criminal gang is far more mundane.”</p><p>“I think that's probably largely going to continue to be the case,” he added.</p><p>Lyne noted that, like the German wind farm operators inadvertently impacted by Russia’s attack on Viasat, some serious cyber attacks are mere “collateral damage” from campaigns aimed at other targets.</p><p>Martin said this was seen in the worst period of his time at the NCSC: the six-week period in 2017 in which <a href="https://www.itpro.com/security/cyber-crime/north-korean-insider-attacks-are-skyrocketing-dozens-of-us-firms-didnt-spot-the-hacker-in-their-midst"><u>North Korea</u></a> launched the <a href="https://www.itpro.com/security/ransomware/367659/wannacry-five-years-on-part-two/2"><u>WannaCry</u></a> ransomware attack, while suspected Russian groups hit Ukrainian banks and other organizations with the <a href="https://www.itpro.com/malware/34381/what-is-notpetya"><u>NotPetya</u></a> malware.</p><p>“Between them, they [did] north of $10 billion of destruction and in my, sadly, favorite example from NotPetya, they’re attacking Ukrainian tax software and they end up stopping production at Cadbury’s chocolate factory in Tasmania, off the south coast of Australia.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat">The Iran cyber threat: Breaking down attack tactics</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/why-government-email-servers-are-top-targets-for-state-backed-hackers">Why government email servers are top targets for state-backed hackers</a></li><li><a href="https://www.itpro.com/security/state-sponsored-cyber-crime-is-officially-out-of-control">State-sponsored cyber crime is officially out of control</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US identifies and places $10 million bounty on LockBit, Hive ransomware kingpin ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/us-identifies-and-places-dollar10-million-bounty-on-lockbit-hive-ransomware-kingpin</link>
                                                                            <description>
                            <![CDATA[ Mikhail Pavlovich Matveev was linked to specific ransomware attacks, including a 2021 raid on the DC police department ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hwF9djR7vWBwEsfwfnburK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GRzTiv8QQH4HCri8B69r3D-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 May 2023 11:53:06 +0000</pubDate>                                                                                                                                <updated>Wed, 17 May 2023 12:31:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/GRzTiv8QQH4HCri8B69r3D-1280-80.png">
                                                            <media:credit><![CDATA[FBI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Headshot of Mikhail Pavlovich Matveev in a field of sunflowers]]></media:description>                                                            <media:text><![CDATA[Headshot of Mikhail Pavlovich Matveev in a field of sunflowers]]></media:text>
                                <media:title type="plain"><![CDATA[Headshot of Mikhail Pavlovich Matveev in a field of sunflowers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GRzTiv8QQH4HCri8B69r3D-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Department of Justice (DoJ) has charged a Russian man over his links to major ransomware groups, offering a $10 million award for information that assists his arrest.</p><p>Mikhail Pavlovich Matveev, a 30-year-old Russian national, was charged over intentionally damaging protected computers, as well as conspiracy to damage protected computers and to transmit ransom demands. </p><p>He is alleged to have helped deploy the LockBit, Hive, and Babuk ransomware variants to extort money from US and international organizations.</p><p>According to the FBI, Matveev is known to have links to both Kaliningrad and St. Petersburg in Russia, where he is understood to reside.</p><p>It has long been established that cyber criminals operating in Russia will escape criminal penalties, providing they don’t attack the Russian government or any organizations operating in the country.</p><p>Many ransomware groups operate out of Russia due to these ‘safe harbor’ protections. They often never leave the country due to fears of being arrested in territories that have extradition agreements with major powers in the West, and rarely meet criminal punishments as a result.</p><p>The DoJ has alleged that on or around 25 June 2020, Matveev and other LockBit operators used the <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware</u></a> strain against a New Jersey-based law enforcement agency.</p><p>It additionally linked him to a 2021 <a href="https://www.itpro.com/security/ransomware/359342/washington-dc-police-ransomware-babuk"><u>Babuk attack on the DC police department</u></a></p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="soqtE8VwWdsw923eWFhcN6" name="HP Wolf Threat Insights Report 2022_listing.jpg" caption="" alt="Whitepaper cover with title bank over an image of skyscrapers from below" src="https://cdn.mos.cms.futurecdn.net/soqtE8VwWdsw923eWFhcN6.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: HP Wolf Security)</span></figcaption></figure><p class="fancy-box__body-text"><strong>HP Wolf Security: Threat insights report</strong></p><p class="fancy-box__body-text"><em>Equipping security teams with the knowledge to combat emerging threats</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361005/hp-wolf-security-threat-insights-report"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“From his home base in Russia, Matveev allegedly used multiple ransomware variants to attack critical infrastructure around the world, including hospitals, government agencies, and victims in other sectors,” said Assistant Attorney General Kenneth A. Polite, Jr. of the Justice Department’s Criminal Division. </p><p>“These international crimes demand a coordinated response. We will not relent in imposing consequences on the most egregious actors in the cyber crime ecosystem.”</p><p>In its official wanted <a href="https://www.fbi.gov/wanted/cyber/mikhail-pavlovich-matveev"><u>notice</u></a> for Matveev, the FBI listed his known aliases as ‘Wazawaka’, ‘Boriscelcin’, ‘m1x’, and ‘Uhodiransomwar’.</p><p>Any individual in possession of information that leads to Matveev’s arrest or conviction has been urged to submit a tip to the FBI. </p><p>The FBI’s Newark Field Office Cyber Crimes Task Force has been put in charge of the case in coordination with a number of European agencies, including the UK’s <a href="https://www.itpro.com/security/cyber-crime/370334/uk-crime-fighters-several-thousand-cyber-criminals-ddos-for-hire-honeypot"><u>National Crime Agency</u></a>.</p><h2 id="what-are-lockbit-hive-and-babuk">What are LockBit, Hive, and Babuk?</h2><p>Both LockBit and Hive are ransomware as a service (RaaS) groups are known for following a <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware"><u>double extortion method</u></a> and are among the most notorious in operation.</p><p>The Babuk group is now believed to have retired, but at its peak was linked to attacks such as one on <a href="https://www.itpro.com/security/ransomware/358476/serco-babuk-ransomware-attack"><u>NHS outsourcing firm Serco</u></a>, and received up to $13 million in paid ransoms.</p><p>The DoJ has estimated that victims have paid the three groups a combined $200 million in ransom over the years.</p><p>LockBit made headlines in recent months for an <a href="https://www.itpro.com/security/ransomware/370067/lockbit-releases-negotiation-history-royal-mail-ransom-65-million"><u>attack against Royal Mail International</u></a>, for which it initially demanded and $81 million  (£65 million) ransom.</p><p>Following talks, <a href="https://www.itpro.com/security/ransomware/370124/lockbit-leaks-44gb-royal-mails-data-sets-fresh-ps33-million-ransom"><u>LockBit leaked 44GB of the firm’s data</u></a> including salary information, contracts, and vaccine records, and lowered its ransom to $41 million (£33 million).</p><p>It has targeted firms such as <a href="https://www.itpro.com/security/ransomware/368875/orion-innovation-hit-by-lockbit-ransomware-hackers-claim"><u>digital transformation company Orion Innovation</u></a> and in December attacked a Canadian children’s hospital, an act for which it <a href="https://www.itpro.com/security/369783/lockbit-issues-rare-apology-for-toronto-sickkids-ransomware-attack"><u>issued a rare apology</u></a> and provided a free decryptor.</p><p>After falling prey to DDoS attacks, the group had <a href="https://www.itpro.com/security/ransomware/368868/lockbit-ransomware-more-aggressive-ddos-attack"><u>pledged to be ‘more aggressive’</u></a> and its strain <a href="https://www.itpro.com/security/ransomware/368418/latest-lockbit-ransomware-strain-strikingly-similar-to-blackmatter"><u>LockBit 3.0</u></a> accounted for 35% of all <a href="https://www.itpro.com/security/ransomware/369352/ransomware-activity-down-11-worldwide-in-q3-but-rise-expected"><u>ransomware activity in Q3 2022</u></a>.</p><p>Hive has been linked to a range of high-profile security incidents in the last year, including an attack on <a href="https://www.itpro.com/security/368903/altice-reportedly-hit-by-hive-ransomware-attack"><u>French telco giant Altice</u></a>, the encryption of systems at <a href="https://www.itpro.com/security/ransomware/369378/hive-ransomware-group-claims-cyber-attack-on-indias-tata-power"><u>Indian energy leader Tata Power</u></a>, and a widespread <a href="https://www.itpro.com/security/ransomware/367910/second-ransomware-group-attacks-costa-rica"><u>assault on Costa Rican healthcare systems</u></a>. </p><p>Microsoft warned in July 2022 that <a href="https://www.itpro.com/security/368462/microsoft-identifies-sophisticated-hive-ransomware-variant-written-in-rust"><u>Hive’s new variant was more sophisticated</u></a>, having adopted the <a href="https://www.itpro.com/security/ransomware/368476/why-are-ransomware-gangs-pivoting-to-rust"><u>programming language Rust</u></a> in its payload executable for improved memory safety and efficiency.</p><p>In January, the <a href="https://www.itpro.com/security/cyber-crime/369952/fbis-landmark-takedown-hive-ransomware-unlikely-significant-impact"><u>FBI confirmed a takedown of Hive ransomware operations</u></a>, though this was deemed unlikely to have lasting effects.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ TSA greenlights trials for Pangiam’s AI-based baggage screening solution in Arlington ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-terrorism/368296/tsa-greenlights-trials-for-pangiams-ai-based-baggage-screening</link>
                                                                            <description>
                            <![CDATA[ The solution is intended to make air travel safer by discerning forbidden items in carry-on baggage in real time ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nqQYA4ffeQEXvpsyGv7qUt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cB4KoTvogKHKe48aPYGuTj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jun 2022 12:12:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cB4KoTvogKHKe48aPYGuTj-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Travel]]></media:description>                                                            <media:text><![CDATA[Travel]]></media:text>
                                <media:title type="plain"><![CDATA[Travel]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cB4KoTvogKHKe48aPYGuTj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Transportation Security Administration (TSA), an agency of the United States Department of Homeland Security (DHS), has announced its collaboration with Pangiam to improve threat detection‌ ‌at‌ ‌airports.</p><p>TSA’s Innovation Task Force (ITF) had previously issued a Broad Agency Announcement (BAA) in December 2021 to identify innovative transport security solutions that are rigorously vetted and demonstrated in a live operational setting.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NJSDBJZzAjpg5aq4yVq3A8" name="NJSDBJZzAjpg5aq4yVq3A8.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/NJSDBJZzAjpg5aq4yVq3A8.png" mos="https://cdn.mos.cms.futurecdn.net/NJSDBJZzAjpg5aq4yVq3A8.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Recommendations for managing AI risks</strong></p><p class="fancy-box__body-text">Integrate your external AI tool findings into your broader security programs</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/367499/recommendations-for-managing-ai-risks" data-original-url="/technology/artificial-intelligence-ai/367499/recommendations-for-managing-ai-risks">FREE DOWNLOAD</a></p></div></div><p>Per the new deal, TSA will trial Pangiam’s artificial intelligence (AI)-powered accessible screening solution, built on open architecture standards. </p><p>The move furthers Project DARTMOUTH, a concord between Pangiam and Google Cloud, that couples artificial intelligence (AI) and pattern analysis technologies ‌to‌ ‌identify possible prohibited items within carry-on luggage in real-time.</p><p>According to reports, ‌the‌ ‌first‌ ‌phase of Project Dartmouth‌ ‌trials is set to commence at TSA’s 128,000-square-foot System Integration Facility in Arlington.</p><p>“As TSA and other security agencies adopt 3D Computed Tomography (CT), this application of AI represents a potentially transformative leap in aviation security, making air travel safer and more consistent, while allowing TSA’s highly trained officers to focus on bags that pose the greatest risk,” said Alexis Long, product director at Pangiam. </p><p>“Our aim is to utilize AI and computer vision technologies to enhance security by providing TSA and security officers with powerful tools to detect prohibitive items that may pose a threat to aviation security is a significant step toward setting a new security standard with worldwide implications,” added Long.</p><p>Pangiam is also partnering with AGS Airports Group to carry out trials at Aberdeen, Glasgow, and Southampton airports in the UK in addition to TSA debuting Project Dartmouth in North America.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISA unveils government cyber security response playbooks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/361593/cisa-unveils-government-cyber-security-response-playbooks</link>
                                                                            <description>
                            <![CDATA[ Playbook follows President Biden's April executive order ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">61AMQGpaM6fTiEsR4wpTSv</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Xtx8rK72HcYorinhyiM3Ma-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Nov 2021 18:07:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Xtx8rK72HcYorinhyiM3Ma-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hand hovering over laptop with padlock graphic superimposed]]></media:description>                                                            <media:text><![CDATA[Hand hovering over laptop with padlock graphic superimposed]]></media:text>
                                <media:title type="plain"><![CDATA[Hand hovering over laptop with padlock graphic superimposed]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Xtx8rK72HcYorinhyiM3Ma-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>CISA has published two playbooks for federal civilian agencies to plan and conduct cyber <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> vulnerability and incident response.</p><p>The <a href="https://www.cisa.gov/sites/default/files/publications/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf">Federal Government Cybersecurity Incident and Vulnerability Response Playbooks</a> follow an <a href="https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity">executive order</a> from President Biden in May urging the US to improve its cyber security measures following a series of data breaches in critical infrastructure and federal agencies, including the <a href="https://www.itpro.com/security/cyber-attacks/358738/intern-blamed-for-weak-password-that-may-have-sparked-solarwinds" data-original-url="https://www.itpro.com/security/cyber-attacks/358738/intern-blamed-for-weak-password-that-may-have-sparked-solarwinds">SolarWinds supply chain attack</a> and the <a href="https://www.itpro.com/security/ransomware/359466/colonial-pipeline-ransomware-attack" data-original-url="https://www.itpro.com/security/ransomware/359466/colonial-pipeline-ransomware-attack">ransomware attacks on the Colonial pipeline</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/361441/cisa-federal-agencies-cyber-security-patch-deadlines" data-original-url="/security/vulnerability/361441/cisa-federal-agencies-cyber-security-patch-deadlines">CISA gives civilian agencies two weeks to patch recent security exploits</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361290/cisa-fbi-nsa-blackmatter-ransomware-warning" data-original-url="/security/ransomware/361290/cisa-fbi-nsa-blackmatter-ransomware-warning">CISA, FBI and NSA publish BlackMatter ransomware warning</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/virtual-private-network-vpn/361060/nsa-and-cisa-offer-new-security-guidance-to" data-original-url="/network-internet/virtual-private-network-vpn/361060/nsa-and-cisa-offer-new-security-guidance-to">NSA and CISA offer new security guidance for VPNs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/360988/cisa-fbi-and-nsa-issue-a-conti-ransomware-advisory" data-original-url="/security/ransomware/360988/cisa-fbi-and-nsa-issue-a-conti-ransomware-advisory">CISA, FBI, and NSA issue a Conti ransomware advisory</a></p></div></div><p>The order from Biden urged better lines of communication between law enforcement and service providers to enhance investigations.</p><p>CISA said the playbooks should provide federal civilian agencies with a standard set of procedures to respond to vulnerabilities and incidents impacting Federal Civilian Executive Branch networks. </p><p>“The playbooks we are releasing today are intended to improve and standardize the approaches used by federal agencies to identify, remediate, and recover from vulnerabilities and incidents affecting their systems,” said Matt Hartman, deputy executive assistant director for Cybersecurity. </p><p>“This important step, set in motion by President Biden’s Cyber Executive Order, will enable more comprehensive analysis and mitigation of vulnerabilities and incidents across the civilian enterprise. We encourage our public and private sector partners to review the playbooks to take stock of their own vulnerability and incident response practices.” </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XaavcxsGTaHzqjVpDpqAfB" name="XaavcxsGTaHzqjVpDpqAfB.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/XaavcxsGTaHzqjVpDpqAfB.png" mos="https://cdn.mos.cms.futurecdn.net/XaavcxsGTaHzqjVpDpqAfB.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Tactics to overcome supply chain shocks and risks</strong></p><p class="fancy-box__body-text">Build better resiliency with modern IT infrastructure</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/supply-chain-management-scm/361602/tactics-to-overcome-supply-chain-shocks-and" data-original-url="/business-operations/supply-chain-management-scm/361602/tactics-to-overcome-supply-chain-shocks-and">FREE DOWNLOAD</a></p></div></div><p>Two playbooks outlined by CIS are for incident and vulnerability response. They should give agencies a standard set of procedures to identify, coordinate, remediate, recover, and track successful mitigations from incidents and vulnerabilities affecting systems, data, and networks. They also contain checklists for incident response, incident response preparation, and vulnerability response that can be adapted to any organization to track necessary activities to completion. </p><p>CISA said the “Incident Response Playbook” applies to incidents involving confirmed malicious cyber activity and for which a major incident has been declared or not yet been reasonably ruled out. The “Vulnerability Response Playbook” applies to any vulnerability observed to be used by adversaries to gain unauthorized entry into computing resources. </p><p>“Agencies should use these playbooks to help shape overall defensive cyber operations to ensure consistent and effective response and coordinated communication of response activities,” CISA <a href="https://www.cisa.gov/sites/default/files/publications/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf">said</a>.</p><p>The playbooks also cover response activities, such as malicious activity detection or vulnerability discovery initiated by federal agencies, CISA, or third parties. CISA warned the playbooks don’t cover threats to classified data or national security systems.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Counting the consequences of cyber attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-warfare/361305/counting-the-consequences-of-cyberattacks</link>
                                                                            <description>
                            <![CDATA[ How can governments respond to the growing risk of online attacks by hostile nations? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cEu4oS2xSkb2SovXe6UW6N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gkmusSyoCSnBYkg6h7WdBd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Nov 2021 08:00:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ James O&#039;Malley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gkmusSyoCSnBYkg6h7WdBd-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Soldiers discuss a cyberattack]]></media:description>                                                            <media:text><![CDATA[Soldiers discuss a cyberattack]]></media:text>
                                <media:title type="plain"><![CDATA[Soldiers discuss a cyberattack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gkmusSyoCSnBYkg6h7WdBd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When Joe Biden met Vladimir Putin in Geneva in June 2021, he took the opportunity to remind his Russian counterpart that the US has “significant <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" target="_blank" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber capability</a>”. With a nudge and a wink, he was warning Russia that enough was enough.</p><p>It’s not surprising that the US felt the need to make a point. From alleged interference in the 2016 American election to the <a href="https://www.itpro.com/security/cyber-warfare/358612/more-than-1000-engineers-executed-solarwinds-attack" target="_blank" data-original-url="https://www.itpro.com/security/cyber-warfare/358612/more-than-1000-engineers-executed-solarwinds-attack">attack last year on networking firm SolarWinds</a>, which compromised software used by the US and UK governments, the United States has long been a target of Russian’s sophisticated hacking capabilities.</p><p>But what can Biden actually do in the event of an online attack?</p><h3 class="article-body__section" id="section-pointing-fingers"><span>Pointing fingers</span></h3><p>“If Country A flies its aeroplane into the airspace of Country B without permission, it’s violated its sovereignty,” said Michael Schmitt, professor of public international law at the University of Reading and a scholar at the US military college West Point.</p><p>“But what if it doesn’t do that? What if it conducts cyber operations? Under what circumstances would we call that a violation of sovereignty? We’re taking rules that were not meant for cyber. And we’re saying, in international law, rules apply to new phenomena and new technologies,” he said.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/361329/the-it-pro-podcast-should-the-us-cyber-army-be-more-aggressive" data-original-url="/security/cyber-warfare/361329/the-it-pro-podcast-should-the-us-cyber-army-be-more-aggressive">The IT Pro Podcast: Should the US cyber army be more aggressive?</a></p></div></div><p>The first question to ask, he points out, is at what point a systems incursion even becomes an attack. “When does a remotely conducted cyber operation violate sovereignty?” asked Schmitt. “You hurt someone? Sure. You physically damaged <a href="https://www.itpro.com/infrastructure" target="_blank" data-original-url="https://www.itpro.com/infrastructure">cyber infrastructure</a>? Sure. What if you caused the system to work in a manner it wasn’t intended to work? What if you’re simply sitting inside their system with malware that you haven’t activated yet?”</p><p>“What if you’re engaging in espionage, and you’re just scooping up <a href="https://www.itpro.com/business-strategy/28163/what-is-big-data-analytics" target="_blank" data-original-url="https://www.itpro.com/business-strategy/28163/what-is-big-data-analytics">mountains of data</a> on people?”</p><p>Unfortunately, there’s no clear definition of what constitutes an attack. But even if the lawyers do agree an attack has occurred, and a response is justified, there’s another important step: figuring out who is responsible.</p><p>“To factually attribute conduct in [cyberspace] is very tricky because of the use of VPNs and stuff like that,” said Dr Talita Dias, a research fellow at the Oxford Institute for Ethics, Law and Armed Conflict. “It’s difficult forensically to identify the source of an attack.”</p><p>Another potential complication is not just the technical attribution, but also the question of whether hackers are working on behalf of a particular country, or just happen to be based there.</p><p>“[Imagine] you have an attack coming from Italy,” said Dr Antonio Coco from the University of Essex’s School of Law. “You may have evidence that the attack comes from a hacker group that operates from Italy, but no evidence that Italy has sponsored or directed this attack at all.” That doesn’t necessarily mean Italy is off the hook, however: “If you can demonstrate that Italy has failed to exercise due diligence in preventing that attack, then the responsibility of Italy may be implicated” – meaning it could still be lawful to respond with countermeasures.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="o4sTtCMXCug5SJJav5HyzL" name="" alt="A cybersecurity expert examines an attack" src="https://cdn.mos.cms.futurecdn.net/o4sTtCMXCug5SJJav5HyzL.jpg" mos="https://cdn.mos.cms.futurecdn.net/o4sTtCMXCug5SJJav5HyzL.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-fighting-back"><span>Fighting back</span></h3><p>“Countermeasures” are presumably what Biden had in mind when he spoke to Putin. “That is clearly what Biden is threatening,” said Schmitt. “I think he’s saying no, no, no, the gloves are off now. If you keep this up, then we’re going to start shooting back.”</p><p>That doesn’t mean the US can literally resort to military measures. Legally, any response must be proportionate and targeted. “International law does not recognise tit for tat, ever,” said Schmitt. “International law is designed to return a situation to one of peacefulness. So, the striking back must always be to make the other side stop.”</p><p>Even so, retaliatory cyber attacks are tempting, simply because they’re cheaper and subtler than real-world action. “When you have two countries confronting each other in the offline world, usually they do it with their armies. This is costly. It’s resource intensive, and it’s also very difficult to conceal,” said Coco. “In cyber dealings, it’s very cost effective to empower hacker groups.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-warfare/33958/are-we-in-the-midst-of-a-cyber-war" data-original-url="/cyber-warfare/33958/are-we-in-the-midst-of-a-cyber-war">Are we in the midst of a cyber war?</a></p></div></div><p>Retaliation can also lead to de-escalation, too. “If you can hack back and shut the system down, great, but you may not get into that system,” said Schmitt. “So what you’re trying to do is impose a bit of pain on the other side, so the other side says, ‘I don’t know if this is worth it any more. Let’s knock this off’.”</p><p>This is one reason why we might be seeing an increase in states grabbing cryptocurrency caches. “If we can’t [hack back], let’s block the resources that these malicious actors are using,” said Dias. “For example, in the context of ransomware, can we seize crypto assets? We could do that as a proportionate response.”</p><h3 class="article-body__section" id="section-sparking-real-confrontations"><span>Sparking real confrontations</span></h3><p>That’s not to say countermeasures have to be “cyber” in nature. Under the current legal understanding, other types of responses are legal.</p><p>Schmitt gives the example of Estonia. In 2007, the country came under a sustained cyber attack from Russia, which launched DDoS blitzes, ping floods and other attacks on a range of Estonian websites and organisations – including the country’s Parliament. This experience, and the questions over how the Tallin government should respond, inspired the naming of the Tallinn Manual – an influential study edited by Schmitt and originally published in 2013 which aims to figure out the laws of cyber conflict.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GmEy94iCPBFPs9V6HWFekm" name="GmEy94iCPBFPs9V6HWFekm.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" mos="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The best defence against ransomware</strong></p><p class="fancy-box__body-text">How ransomware is evolving and how to defend against it</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361095/the-best-defence-against-ransomware" data-original-url="/security/ransomware/361095/the-best-defence-against-ransomware">FREE DOWNLOAD</a></p></div></div><p>The problem is that Estonia is a tiny country of 1.3 million people, with nothing like Russia’s cyber resources. But in Schmitt’s view, under international law it would be legal for the country to respond another way, such as by blocking Russian ships from passing through its territorial waters in the Baltic Sea – a crucial strategic pinch point for Russia.</p><p>“Estonia could impose pressure by doing something that would normally be illegal... but now it’s okay to get the other side to knock it off,” said Schmitt.</p><p>Schmitt suggests that in extreme circumstances it could even be lawful for a country to respond to a cyber attack using military force, if that is the only countermeasure available. Thus, even online conflicts could eventually have very serious consequences.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TMjuN44Louvc9zAFSsU8rY" name="" alt="Military personnel examine a server" src="https://cdn.mos.cms.futurecdn.net/TMjuN44Louvc9zAFSsU8rY.jpg" mos="https://cdn.mos.cms.futurecdn.net/TMjuN44Louvc9zAFSsU8rY.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><h3 class="article-body__section" id="section-do-we-need-a-digital-geneva-convention"><span>Do we need a digital Geneva Convention?</span></h3><p>To help prevent major escalations, some have suggested that major states should agree a “digital Geneva Convention”, which sets out the rules of cyber conflict. One of them is Microsoft’s chief legal officer, Brad Smith.</p><p>The experts we spoke to are sceptical that such a treaty will ever happen, however. “Strictly speaking, we don’t need a treaty,” said Dias. “We already have rules that apply by default to cyber. It’s a matter of fleshing them out and understanding how they apply.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361098/us-30-country-meeting-cyber-crime-threat" data-original-url="/security/cyber-security/361098/us-30-country-meeting-cyber-crime-threat">US plans 30-nation meeting to address growing cyber crime threat</a></p></div></div><p>Dias argues that the cyber rules of the road could be more clearly established by patching together existing law, as it has evolved over time. And this is a process that is already ongoing: in recent years, governments around the world have released position statements, essentially outlining their view of the “rules” of cyber-conflict. While no one is forging formal agreements, these statements help other governments understand each other, and how hostile cyber actions may be received.</p><p>At the same time, the United Nations has convened a group of governmental experts to consult on the legal issues around cyber conflict, while legal academics are hard at work on a new edition of the Tallinn Manual, which will go further in defining how existing international law works in the cyber arena. “If you start with a treaty, you may be forgetting the fact that there already is law,” said Schmitt. “It may actually be a step backwards.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Biden is confident in the nation’s cyber security efforts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/361105/biden-is-confident-in-the-nations-cyber-security-efforts</link>
                                                                            <description>
                            <![CDATA[ President opens Cybersecurity Awareness Month with a commitment to “lead, rather than lag” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u5zLiSRcuLsouCw3Qvc4Ak</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QjHFoUtPdtVLiV4cFoAiH4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Oct 2021 12:56:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QjHFoUtPdtVLiV4cFoAiH4-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[President Joe Biden and Vice President Kamala Harris signing a bill]]></media:description>                                                            <media:text><![CDATA[President Joe Biden and Vice President Kamala Harris signing a bill]]></media:text>
                                <media:title type="plain"><![CDATA[President Joe Biden and Vice President Kamala Harris signing a bill]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QjHFoUtPdtVLiV4cFoAiH4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>President Biden has said his administration is committed to hardening our critical infrastructure against cyber attacks, disrupting ransomware networks, and “working to establish and promote clear rules of the road for all nations in cyberspace”, as Cybersecurity Awareness Month kicks off.</p><p><a href="https://www.whitehouse.gov/briefing-room/statements-releases/2021/10/01/statement-by-president-joe-biden-on-cybersecurity-awareness-month">In a White House statement</a>, President Biden said "cyber threats can affect every American, every business - regardless of size - and every community. That's why my administration is marshaling a whole-of-nation effort to confront cyber threats."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/357752/the-it-pro-podcast-what-does-joe-biden-have-in-store-for-tech" data-original-url="/business/policy-legislation/357752/the-it-pro-podcast-what-does-joe-biden-have-in-store-for-tech">The IT Pro Podcast: What does Joe Biden have in store for tech?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/it-infrastructure/360401/president-biden-urges-critical-companies-to-boost-cyber" data-original-url="/business-strategy/it-infrastructure/360401/president-biden-urges-critical-companies-to-boost-cyber">President Biden urges critical companies to boost cyber defenses</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/360387/biden-says-cyber-attacks-could-lead-to-shooting-war" data-original-url="/security/cyber-attacks/360387/biden-says-cyber-attacks-could-lead-to-shooting-war">Biden warns cyber attacks could lead to “shooting war”</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/360312/biden-names-big-tech-nemesis-as-antitrust-chief" data-original-url="/business/policy-legislation/360312/biden-names-big-tech-nemesis-as-antitrust-chief">Biden names big tech nemesis as antitrust chief</a></p></div></div><p>Last Thursday, the president <a href="https://www.whitehouse.gov/briefing-room/presidential-actions/2021/09/30/a-proclamation-on-cybersecurity-awareness-month-2021">signed a proclamation</a> declaring October Cybersecurity Awareness Month. The proclamation said as the nation got to grips with ransomware attacks disrupting hospitals, schools, police departments, fuel pipelines, food suppliers, and small businesses, the public needed to “take action to better protect yourselves against cyber threats.”</p><p>Biden said that in May he issued an <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2021/05/12/fact-sheet-president-signs-executive-order-charting-new-course-to-improve-the-nations-cybersecurity-and-protect-federal-government-networks">executive order</a> to modernize defenses and position the Federal government to “lead, rather than lag, in its own cybersecurity.” This meant using its substantial buying power to improve security <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> for all Americans.</p><p>He also cited a 100-day action plan to improve the electricity sector’s cyber security. This, he added, has already resulted in more than 150 utilities serving 90 million Americans committing to deploy cyber security technologies. Biden said his administration was working to deploy action plans for additional critical <a href="https://www.itpro.com/infrastructure" data-original-url="https://www.itpro.com/infrastructure">infrastructure</a> sectors.</p><p>He also pointed out that a <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2021/07/28/fact-sheet-biden-administration-announces-further-actions-to-protect-u-s-critical-infrastructure"> National Security Memorandum</a> was issued outlining the cyber <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> practices that owners and operators of critical infrastructure should put in place.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5MSkWhEAq3ThLrFQZzTUsd" name="5MSkWhEAq3ThLrFQZzTUsd.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/5MSkWhEAq3ThLrFQZzTUsd.png" mos="https://cdn.mos.cms.futurecdn.net/5MSkWhEAq3ThLrFQZzTUsd.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Managing security and risk across the IT supply chain: A practical approach</strong></p><p class="fancy-box__body-text">Best practices for IT supply chain security</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361001/managing-security-and-risk-across-the-it-supply-chain-a-practical" data-original-url="/security/cyber-security/361001/managing-security-and-risk-across-the-it-supply-chain-a-practical">FREE DOWNLOAD</a></p></div></div><p>Biden also lauded efforts to bring 30 countries around the world to speed up cooperation in combating cyber crime, improving law enforcement collaboration, stemming the illicit use of cryptocurrency, and engaging on these issues diplomatically. </p><p>“We are building a coalition of nations to advocate for and invest in trusted 5G technology and to better secure our supply chains. And, we are bringing the full strength of our capabilities to disrupt malicious cyber activity, including managing both the risks and opportunities of emerging technologies like quantum computing and artificial intelligence,” said Biden.</p><p>"This October, even as we recognize how much work remains to be done and that maintaining strong cybersecurity practices is ongoing work, I am confident that the advancements we have put in place during the first months of my administration will enable us to build back better,” he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bahrain targets activists with NSO's Pegasus spyware  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/spyware/360682/bahrain-targets-activists-with-nsos-pegasus-spyware</link>
                                                                            <description>
                            <![CDATA[ The spyware reportedly employed two exploits targeting Apple's iMessage system ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nHTUiQrh9QkuVumWrdX4ZM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/odk8ZSinsL42PxYiMaFHy7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Aug 2021 18:55:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/odk8ZSinsL42PxYiMaFHy7-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Computer code on a screen with a skull representing a computer virus / malware attack.]]></media:description>                                                            <media:text><![CDATA[Computer code on a screen with a skull representing a computer virus / malware attack.]]></media:text>
                                <media:title type="plain"><![CDATA[Computer code on a screen with a skull representing a computer virus / malware attack.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/odk8ZSinsL42PxYiMaFHy7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The government of Bahrain has once again used <a href="https://www.itpro.com/spyware/30001/what-is-spyware" data-original-url="https://www.itpro.com/spyware/30001/what-is-spyware">spyware</a> from Israeli surveillance company NSO to target activists' <a href="https://www.itpro.com/mobile/20522/best-android-smartphones" data-original-url="https://www.itpro.com/mobile/20522/best-android-smartphones">smartphones</a>, according to <a href="https://citizenlab.ca/2021/08/bahrain-hacks-activists-with-nso-group-zero-click-iphone-exploits">a Citizen Lab report</a>,</p><p>The spyware employed two exploits targeting Apple's iMessage system, including a new one first spotted in June. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/355231/facebook-tried-to-buy-spyware-firm-its-now-suing-to-monitor-ios-users" data-original-url="/security/privacy/355231/facebook-tried-to-buy-spyware-firm-its-now-suing-to-monitor-ios-users">Facebook tried to buy NSO Group's Pegasus spyware to monitor iOS users</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/360265/microsoft-attacks-traced-to-secretive-israeli-spyware-candiru" data-original-url="/security/hacking/360265/microsoft-attacks-traced-to-secretive-israeli-spyware-candiru">Recent Microsoft attacks traced to secretive Israeli spyware firm</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/359049/dangerous-android-spyware-disguising-itself-as-system-update-app" data-original-url="/security/malware/359049/dangerous-android-spyware-disguising-itself-as-system-update-app">Android spyware disguised as 'system update' app discovered</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/356887/new-android-spyware-strain-masquerades-as-covid-19-tracking-app" data-original-url="/security/malware/356887/new-android-spyware-strain-masquerades-as-covid-19-tracking-app">New Android spyware strain masquerades as COVID-19 tracking app</a></p></div></div><p>The report tracked the targeting of nine Bahraini activists using the NSO <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a>. The investigation ties the infection servers to NSO's <a href="https://www.itpro.com/security/spyware/360276/journalists-human-rights-activists-targeted-with-pegasus-spyware" data-original-url="https://www.itpro.com/security/spyware/360276/journalists-human-rights-activists-targeted-with-pegasus-spyware">Pegasus</a> spyware, and tracked the spyware's use of multiple vulnerabilities in iMessage. </p><p>Citizen Lab researchers noted that a Bahrain government operator codenamed LULU compromised iPhones using Pegasus via a zero-click iMessage exploit known as KISMET between July and September 2020. This simply required the phone to receive a message, enabling the spyware to compromise the operating system and monitor its internet traffic. </p><p>KISMET compromised iOS versions until at least version 13.7, according to the Citizen Lab. At that point, Apple updated iOS with the BlastDoor security feature that defended against zero-click iMessage attacks. NSO's Pegasus spyware then resorted to a single-click attack, requiring victims to follow a link in an iMessage. </p><p>Pegasus returned to zero-click attacks from February 2021 with a more recent exploit Citizen Lab called FORCEDENTRY. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jhaHY3RvAk8nfb9KJaMSFL" name="jhaHY3RvAk8nfb9KJaMSFL.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/jhaHY3RvAk8nfb9KJaMSFL.png" mos="https://cdn.mos.cms.futurecdn.net/jhaHY3RvAk8nfb9KJaMSFL.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Challenging the rules of security</strong></p><p class="fancy-box__body-text">Protecting data and simplifying IT management with Chrome OS</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/360664/challenging-the-rules-of-security" data-original-url="/security/360664/challenging-the-rules-of-security">FREE DOWNLOAD</a></p></div></div><p>FORCEDENTRY appears to be the same as Megalodon, an attack Amnesty International <a href="https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus">identified in June</a>. It is a zero-click attack that could compromise phones without any user interaction. Amnesty confirmed it had compromised iPhones running iOS 14.6 in June, and Apple told the organization it was investigating the issue. At the time of writing, the latest version of iOS is 14.7. </p><p>Freedom House, a non-profit that promotes democracy worldwide, <a href="https://freedomhouse.org/country/bahrain/freedom-net/2020">classified</a> Bahrain as “Not Free,” and gives it a freedom score of 29% due to heavy restrictions on internet use and strong censorship practices. The country arrests internet users for discussing forbidden topics online and engages in online surveillance practices, including spyware. </p><p>Citizen Lab first documented Bahrain Pegasus use in 2018 via a government operator that it called PEARL. It posited that LULU may be the same state surveillance team. </p><p>NSO continues to face challenges as it sells spyware to countries with oppressive histories, including Bahrain. <a href="https://www.itpro.com/cloud/amazon-web-services-aws/360298/aws-shuts-down-nso-group-infrastructure" data-original-url="https://www.itpro.com/cloud/amazon-web-services-aws/360298/aws-shuts-down-nso-group-infrastructure">Amazon Web Services shut down NSO infrastructure</a> running on its servers last month, and United Nations human rights experts renewed calls for an international moratorium on the sale of spyware. </p><p>The Citizen Lab cited tools from other companies the Bahrain government used for online surveillance, including Cellebrite, FinFisher, Netsweeper, Trovicor, and Verint. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ State Department reportedly suffers a cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/360661/state-department-reportedly-suffers-a-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ Details of the hack are still developing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fvVbaqAqgjk2CxhcykbZHc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dQnNShVMy4kwGs6aeJWHb4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Aug 2021 13:33:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dQnNShVMy4kwGs6aeJWHb4-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[US State Department sign in front of a building]]></media:description>                                                            <media:text><![CDATA[US State Department sign in front of a building]]></media:text>
                                <media:title type="plain"><![CDATA[US State Department sign in front of a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dQnNShVMy4kwGs6aeJWHb4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers recently hit the Department of State with a cyber attack, according <a href="https://www.reuters.com/world/us/us-state-department-recently-hit-by-cyber-attack-fox-news-2021-08-21">to <em>Fox News</em> and <em>Reuters</em></a> reports, The Department of Defense Cyber Command also reportedly released notifications of a potentially serious data breach.</p><p>According to a <a href="https://twitter.com/JacquiHeinrich/status/1429173370730553345">tweet by a <em>Fox News</em></a> reporter on Saturday, the breach is believed to have happened a couple of weeks ago. In a later tweet, the reporter said the extent of the breach, the investigation into the suspected entity behind it, efforts taken to mitigate it, and any ongoing risk to operations remain unclear.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/360253/state-department-offers-10-million-for-tips-on-foreign-hackers" data-original-url="/security/ransomware/360253/state-department-offers-10-million-for-tips-on-foreign-hackers">State Department offers $10 million for tips on foreign hackers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/23521/hackers-hit-us-state-department-email-system" data-original-url="/security/23521/hackers-hit-us-state-department-email-system">Hackers hit US State Department email system</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/360607/most-it-executives-fear-nation-state-hacking-tools-will-be-used-on-them" data-original-url="/security/hacking/360607/most-it-executives-fear-nation-state-hacking-tools-will-be-used-on-them">Most IT executives fear nation-state hacking tools will be used on them</a></p></div></div><p>However, a source told <em>Reuters</em> that the State Department has not experienced significant disruptions and has not had its operations impeded in any way.</p><p>"The Department takes seriously its responsibility to safeguard its information and continuously takes steps to ensure information is protected. For security reasons, we are not in a position to discuss the nature or scope of any alleged cybersecurity incidents at this time," a State Department spokesperson said in a statement to Reuters.</p><p>Steven Hope, CEO and co-founder of Authlogics, told <em>IT Pro</em> the State Department is a juicier target for hackers than the shop around the corner. </p><p>“While we don’t know what was breached, and we may never know in this case, the fact it is listed as ‘serious’ indicates that there could be a lot behind this, either in terms of the volume of data accessed or importance of it. It would be very interesting to know how the bad guys got in to affect the breach,” Hope said.</p><p>“By far the most common way into a network is via weak authentication, e.g. breached passwords or poor MFA. After all, we do have over 12 thousand breached U.S. State Department credentials in our database alone, but again, in this case, we may never know."</p><p>Sam Curry, chief security officer at Cybereason, told <em>IT Pro</em> that while the State Department isn’t likely to disclose any further details of this attack, given the chaos in Afghanistan, and lingering tensions with Russia over the Colonial and JBS attacks and China for the <a href="https://www.itpro.com/security/358894/exchange-server-attacks-increase-10-times-since-last-week" data-original-url="https://www.itpro.com/security/358894/exchange-server-attacks-increase-10-times-since-last-week">Microsoft Exchange Server attacks</a>, public and private sector security teams should be on high alert. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HuVkXKYxS9nVFkEwoBk7MR" name="HuVkXKYxS9nVFkEwoBk7MR.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/HuVkXKYxS9nVFkEwoBk7MR.png" mos="https://cdn.mos.cms.futurecdn.net/HuVkXKYxS9nVFkEwoBk7MR.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Don’t just educate: Create cyber-safe behaviour</strong></p><p class="fancy-box__body-text">Designing effective security awareness and training programmes</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/training/356984/dont-just-educate-create-cybersafe-behaviour" data-original-url="/business-strategy/training/356984/dont-just-educate-create-cybersafe-behaviour">FREE DOWNLOAD</a></p></div></div><p>“Also, allies of the U.S. across Europe, Asia-Pacific, and Africa should also be on high alert. Let's hope the perception by some that the U.S. is distracted doesn't lead to more attacks and chaos,” he said.</p><p>“The State Department attack is one of the reasons for the EDR mandate for the US Federal government agencies in the recent White House Executive Order. Having a means of finding the attacks like the one on the State Department as threat actors move in the slow, subtle, stealthy way through networks is the only option in returning defenders to higher ground above threat actors.</p><p>"Advanced prevention, building resilience, ensuring that the blast radius of payloads is minimized and generally using peacetime to foster antifragility is achievable. Today, it’s not about who we hire or what we buy. It’s about how we adapt and improve every day."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US has new cyber security rules for pipelines ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/360301/us-has-new-cyber-security-rules-for-pipelines</link>
                                                                            <description>
                            <![CDATA[ DHS now requires “urgently needed protections against cyber intrusions” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">d1oZFSKkdoHGWAQeuy68Mg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tZGm9zxujGADCwjMQPKyK9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Jul 2021 16:45:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mike Brassfield ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tZGm9zxujGADCwjMQPKyK9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Long pipeline heading toward a mountain range]]></media:description>                                                            <media:text><![CDATA[Long pipeline heading toward a mountain range]]></media:text>
                                <media:title type="plain"><![CDATA[Long pipeline heading toward a mountain range]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tZGm9zxujGADCwjMQPKyK9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The federal government has launched new regulations requiring owners of critical pipelines that transport hazardous liquids and natural gas to implement “urgently needed protections against cyber intrusions.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/359800/doj-recovers-majority-of-ransom-paid-by-colonial-pipeline" data-original-url="/security/ransomware/359800/doj-recovers-majority-of-ransom-paid-by-colonial-pipeline">DoJ recovers 'majority' of ransom paid by Colonial Pipeline</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/359698/us-pipelines-ordered-to-strengthen-cyber-defenses" data-original-url="/security/359698/us-pipelines-ordered-to-strengthen-cyber-defenses">US pipelines ordered to strengthen cyber defenses</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/359615/colonial-pipeline-ceo-confirms-the-company-paid-darkside-hackers-44" data-original-url="/security/ransomware/359615/colonial-pipeline-ceo-confirms-the-company-paid-darkside-hackers-44">Colonial Pipeline CEO confirms $4.4 million payment to DarkSide hackers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/359558/ransomware-operators-in-turmoil-after-colonial-pipeline-backlash" data-original-url="/security/ransomware/359558/ransomware-operators-in-turmoil-after-colonial-pipeline-backlash">Ransomware operators in turmoil after Colonial Pipeline backlash</a></p></div></div><p>This was the second time since May that the Department of Homeland Security (DHS) issued a <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> directive aimed at US pipeline operators. It comes in the wake of the <a href="https://www.itpro.com/security/ransomware/354821/ransomware-attack-shuts-us-pipeline-for-two-days" data-original-url="https://www.itpro.com/security/ransomware/354821/ransomware-attack-shuts-us-pipeline-for-two-days">Colonial Pipeline hack</a> that disrupted fuel supplies across the southeastern US for days.</p><p>DHS said Tuesday’s move was in response to “the ongoing cybersecurity threat to pipeline systems,” <a href="https://www.reuters.com/world/us/us-announces-new-cybersecurity-requirements-critical-pipeline-owners-2021-07-20"><em>Reuters</em> reported</a>.</p><p>“The lives and livelihoods of the American people depend on our collective ability to protect our nation’s critical infrastructure from evolving threats,” DHS Secretary Alejandro Mayorkas said.</p><p>The <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> directive requires critical pipelines to take defensive measures to protect themselves from ransomware attacks and other known threats to IT systems. Pipeline owners must also have a cyber security contingency and recovery plan in place.</p><p>In an earlier security directive in late May, immediately following the Colonial Pipeline cyber attack, the DHS began requiring US pipeline operators to conduct a cyber security assessment. Until then, American pipeline companies operated under purely voluntary cyber security guidelines.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MhoDQHbDgtzbg6RyMTEvAn" name="MhoDQHbDgtzbg6RyMTEvAn.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/MhoDQHbDgtzbg6RyMTEvAn.jpg" mos="https://cdn.mos.cms.futurecdn.net/MhoDQHbDgtzbg6RyMTEvAn.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Aberdeen Report: How a platform approach to security monitoring initiatives adds value</strong></p><p class="fancy-box__body-text">Integration, orchestration, analytics, automation, and the need for speed</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/360172/aberdeen-report-how-a-platform-approach-to-security-monitoring-initiatives-adds" data-original-url="/security/360172/aberdeen-report-how-a-platform-approach-to-security-monitoring-initiatives-adds">FREE DOWNLOAD</a></p></div></div><p>That late-May directive required pipeline owners and operators to report any cyber incidents to the federal government. They also needed a designated cyber security coordinator available 24/7 to work with authorities in an attack.</p><p>When <a href="https://www.itpro.com/security/ransomware/359466/colonial-pipeline-ransomware-attack" data-original-url="https://www.itpro.com/security/ransomware/359466/colonial-pipeline-ransomware-attack">DarkSide hackers attacked Colonial Pipeline</a>, they forced it to shut down 5,500 miles of pipeline between Texas and New York for several days, disrupting the fuel supply to large swaths of the East Coast. The hackers also took 100GB of data from the network before locking computers and extorting the company for a ransom payment. </p><p>Colonial’s CEO has confirmed the pipeline company <a href="https://www.itpro.com/security/ransomware/359615/colonial-pipeline-ceo-confirms-the-company-paid-darkside-hackers-44" data-original-url="https://www.itpro.com/security/ransomware/359615/colonial-pipeline-ceo-confirms-the-company-paid-darkside-hackers-44">paid $4.4 million</a> to cyber criminals who hit it with the ransomware attack.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MI5 chief warns public of growing cyber espionage threat ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-terrorism/360221/mi5-chief-to-warn-public-of-cyber-espionage-threat</link>
                                                                            <description>
                            <![CDATA[ More than 10,000 people have been targeted by foreign spies in the last five years, according to the agency ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mVpjpMZPXAiYMw6vtwKmAu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ir4L6pejtx8MnDny2EanNL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Jul 2021 11:22:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ir4L6pejtx8MnDny2EanNL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The homepage of the official website for the MI5 Security Service]]></media:description>                                                            <media:text><![CDATA[The homepage of the official website for the MI5 Security Service]]></media:text>
                                <media:title type="plain"><![CDATA[The homepage of the official website for the MI5 Security Service]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ir4L6pejtx8MnDny2EanNL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The head of the UK’s domestic counter-intelligence and security agency, MI5, will today deliver a warning to the general public about the threats posed by <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber espionage</a>.</p><p>Ken McCallum, who last year succeeded Sir Andrew Parker as Director General, will emphasise the importance of vigilance among regular people in the UK, who are being increasingly approached by <a href="https://www.itpro.com/security/cyber-attacks/359574/russia-spy-chief-denies-involvement-in-solarwinds-hack" data-original-url="https://www.itpro.com/security/cyber-attacks/359574/russia-spy-chief-denies-involvement-in-solarwinds-hack">foreign intelligence agencies</a>. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/360093/us-and-uk-security-agencies-warn-against-russian-global-brute-force" data-original-url="/security/cyber-warfare/360093/us-and-uk-security-agencies-warn-against-russian-global-brute-force">US, UK security agencies warn against Russian ‘global brute force campaign’</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/358057/russian-sponsored-hackers-reportedly-breach-fireeye-security" data-original-url="/security/358057/russian-sponsored-hackers-reportedly-breach-fireeye-security">Cyber security firm FireEye hit by 'state-sponsored' attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/359478/russian-hackers-are-exploiting-these-11-flaws-to-attack-businesses" data-original-url="/security/hacking/359478/russian-hackers-are-exploiting-these-11-flaws-to-attack-businesses">Russian hackers are exploiting these 11 flaws to attack businesses</a></p></div></div><p>The MI5 has recorded more than 10,000 cyber espionage incidents in the last five years, with many taking place on networking social media platform <a href="https://www.itpro.com/business-strategy/data-controller/360053/linkedin-data-breach-denial" data-original-url="https://www.itpro.com/business-strategy/data-controller/360053/linkedin-data-breach-denial">LinkedIn</a>.</p><p>McCallum is expected to say that “UK victims of state espionage range way wider than just government”, in a speech scheduled for today at MI5’s Thames House headquarters.</p><p>“We see the UK’s brilliant universities and researchers having their discoveries stolen or copied; we see businesses hollowed out by the loss of advantage they’ve worked painstakingly to build. Given half a chance, hostile actors will short-circuit years of patient British research or investment. This is happening at scale. And it affects us all. UK jobs, <a href="https://www.itpro.com/security/innovation-at-work/29794/what-have-we-learnt-from-the-nhs-ransomware-attack" data-original-url="https://www.itpro.com/security/innovation-at-work/29794/what-have-we-learnt-from-the-nhs-ransomware-attack">UK public services</a>, UK futures,” he will say.</p><p>McCallum will also urge businesses engaged in export, scientific research, and the high-tech sector to be aware of the potential risks of falling victim to cyber espionage. These could include "frustration and inconvenience”, but also “loss of livelihood, potentially up to loss of life".</p><p>However, McCallum is to add that these companies “don’t have to be scared; but be switched on”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ffna7TmpqYrgTZpXMRi9u6" name="ffna7TmpqYrgTZpXMRi9u6.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ffna7TmpqYrgTZpXMRi9u6.jpg" mos="https://cdn.mos.cms.futurecdn.net/ffna7TmpqYrgTZpXMRi9u6.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Forrester Wave: Top security analytics platforms</strong></p><p class="fancy-box__body-text">The 11 providers that matter most and how they stack up</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360171/the-forrester-wave-top-security-analytics-platforms" data-original-url="/security/cyber-security/360171/the-forrester-wave-top-security-analytics-platforms">FREE DOWNLOAD</a></p></div></div><p>McCallum will also appeal for action across the government as well as the general public: "We must, over time, build the same public awareness and resilience to state threats that we have done over the years on terrorism," he will say.</p><p>The warning comes three months after the Centre for the Protection of National Infrastructure (CPNI) <a href="https://www.itpro.com/security/phishing/359276/mi5-warns-of-foreign-agents-using-linkedin-to-steal-information" data-original-url="https://www.itpro.com/security/phishing/359276/mi5-warns-of-foreign-agents-using-linkedin-to-steal-information">launched the <em>Think Before You Link</em> campaign</a>, which aims to increase awareness of foreign agents targeting officials with access to sensitive information.</p><p>The project shares concerns that once a request has been accepted, the victim's colleagues will be more likely to accept a follow-up request as it <a href="https://www.itpro.com/security/phishing/356581/what-are-you-giving-away-on-social-media" data-original-url="https://www.itpro.com/security/phishing/356581/what-are-you-giving-away-on-social-media">looks like they share a mutual acquaintance</a>. Nearly all government departments and some key industries are thought to have been targeted by fake LinkedIn accounts.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SolarWinds hackers breach Microsoft support agent to target customers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/360017/solarwinds-hackers-target-microsoft-customers</link>
                                                                            <description>
                            <![CDATA[ Nobelium engaged in password spray and brute-force attacks after implanting malware on a device belonging to a Microsoft employee ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">czyXpTXVwxoFAmnWjPMy5K</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xvXroFtTUCHD5xPk6iQzdD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 28 Jun 2021 09:54:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xvXroFtTUCHD5xPk6iQzdD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[View of a Microsoft building]]></media:description>                                                            <media:text><![CDATA[View of a Microsoft building]]></media:text>
                                <media:title type="plain"><![CDATA[View of a Microsoft building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xvXroFtTUCHD5xPk6iQzdD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has confirmed that some of its customers have been targeted by the Russian state-backed hacking group responsible for last year’s <a href="https://www.itpro.com/security/358111/solarwinds-confirms-cyber-attack" data-original-url="https://www.itpro.com/security/358111/solarwinds-confirms-cyber-attack">SolarWinds cyber attack</a> after successfully compromising an employees' computer. </p><p>Known as Nobelium, the group was found to have engaged in “<a href="https://www.itpro.com/biometrics/33570/microsoft-wants-you-to-ditch-passwords-for-biometrics" data-original-url="https://www.itpro.com/biometrics/33570/microsoft-wants-you-to-ditch-passwords-for-biometrics">password spray</a> and brute-force attacks” on the tech giant’s customers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/359957/us-investigates-solarwinds-clients-over-cyber-breach-disclosures" data-original-url="/security/359957/us-investigates-solarwinds-clients-over-cyber-breach-disclosures">US SEC investigates SolarWinds clients over cyber breach disclosures</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/359574/russia-spy-chief-denies-involvement-in-solarwinds-hack" data-original-url="/security/cyber-attacks/359574/russia-spy-chief-denies-involvement-in-solarwinds-hack">Russian spy chief rebuffs “pathetic” SolarWinds hack accusations</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/video-conferencing/360004/microsoft-teams-integrated-into-windows-11" data-original-url="/software/video-conferencing/360004/microsoft-teams-integrated-into-windows-11">Microsoft Teams will be natively integrated into Windows 11 at launch</a></p></div></div><p>The hackers implanted “information-stealing malware” on a device belonging to a Microsoft customer support agent, through which they obtained “basic account information for a small number of [Microsoft’s] customers”, according to the firm.</p><p>They then “used this information in some cases to launch highly-targeted attacks as part of their broader campaign”. </p><p>“We responded quickly, removed the access and secured the device,” said Microsoft, adding that while the attacks were “mostly unsuccessful”, hackers managed to compromise three of its customers.</p><p>"This recent activity was mostly unsuccessful, and the majority of targets were not successfully compromised – we are aware of three compromised entities to date," the Microsoft Security Response Center team announced in a <a href="https://msrc-blog.microsoft.com/2021/06/25/new-nobelium-activity">blog post</a>. "All customers that were compromised or targeted are being contacted through our nation-state notification process.</p><p>Around 10% of the targeted customers were UK-based, with the hackers mostly focusing on “US interests”. The majority of the targets were “IT companies (57%), followed by government (20%), and smaller percentages for non-governmental organisations and think tanks, as well as financial services”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bRgjxZYos5Bjth4n8XKXvf" name="bRgjxZYos5Bjth4n8XKXvf.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/bRgjxZYos5Bjth4n8XKXvf.jpg" mos="https://cdn.mos.cms.futurecdn.net/bRgjxZYos5Bjth4n8XKXvf.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The definitive guide to IT security</strong></p><p class="fancy-box__body-text">Protecting your MSP and your customers</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/359166/the-definitive-guide-to-it-security" data-original-url="/business-operations/managed-service-provider-msp/359166/the-definitive-guide-to-it-security">FREE DOWNLOAD</a></p></div></div><p>Overall, the hackers targeted organisations from 36 countries, the tech giant stated, adding that it recommends that customers enable <a href="https://www.itpro.com/security/innovation-at-work/30184/why-is-multi-factor-authentication-so-important" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/30184/why-is-multi-factor-authentication-so-important">multi-factor authentication</a> in order “to protect their environments from this and similar attacks”. </p><p>The news comes weeks after Nobelium <a href="https://www.itpro.com/security/cyber-attacks/359708/solarwinds-hackers-target-150-organisations-microsoft" data-original-url="https://www.itpro.com/security/cyber-attacks/359708/solarwinds-hackers-target-150-organisations-microsoft">launched a wave of attacks</a> on more than 150 government agencies, think tanks, consultants, and NGOs from 24 countries, targeting an estimated 3,000 email accounts.</p><p>Microsoft's corporate VP of Customer Security & Trust, Tom Burt, said at the time said that Nobelium's main objective is to "gain access to trusted <a href="https://www.itpro.com/technology" data-original-url="https://www.itpro.com/technology">technology</a> providers and infect their customers". The hacking group’s activities also tend to coincide with the "issues of concern to the country from which they are operating", according to the cyber security expert.</p><p>"This is yet another example of how cyber attacks have become the tool of choice for a growing number of nation-states to accomplish a wide variety of political objectives, with the focus of these attacks by Nobelium on human rights and humanitarian organisations," Burt added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers breach San Francisco water treatment plant  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/359934/hackers-breach-a-san-francisco-water-treatment-plant</link>
                                                                            <description>
                            <![CDATA[ A successful attack could have poisoned the well ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c2j9EBUQ7wxPkk5Ps4Ahyb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gzLKxjrqjsuzgs9RRr3XyT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Jun 2021 14:47:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gzLKxjrqjsuzgs9RRr3XyT-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Water treatment tanks]]></media:description>                                                            <media:text><![CDATA[Water treatment tanks]]></media:text>
                                <media:title type="plain"><![CDATA[Water treatment tanks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gzLKxjrqjsuzgs9RRr3XyT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A hacker accessed systems belonging to a water treatment plant in the San Francisco Bay area and deleted applications the plant used to treat drinking water.</p><p>The incident happened in January but only came to light this week. According to <a href="https://www.nbcnews.com/tech/security/hacker-tried-poison-calif-water-supply-was-easy-entering-password-rcna1206">reports</a> by <em>NBC News,</em> the hackers used the username and password from a former employee's TeamViewer account to gain access to the plant and delete programs.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358566/hackers-stopped-from-poisoning-the-water-supply-in-florida" data-original-url="/security/hacking/358566/hackers-stopped-from-poisoning-the-water-supply-in-florida">Hackers attempt to poison Florida water supply</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/359927/north-korea-attackers-hack-nuclear-research-centre" data-original-url="/security/hacking/359927/north-korea-attackers-hack-nuclear-research-centre">North Korean hackers target nuclear research centre</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/359919/ransomware-criminals-look-to-other-hackers-to-provide-them-with-network" data-original-url="/security/ransomware/359919/ransomware-criminals-look-to-other-hackers-to-provide-them-with-network">Ransomware criminals look to other hackers to provide them with network access</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/359847/ea-hackers-steal-source-code-for-fifa-battlefield-game-series" data-original-url="/security/hacking/359847/ea-hackers-steal-source-code-for-fifa-battlefield-game-series">EA hackers steal source code for FIFA, Battlefield game series</a></p></div></div><p>There is no indication who the hacker was or what their motivations were, according to a private report compiled by the Northern California Regional Intelligence Center in February. </p><p>The breach went undetected until the next day. Once plant staff noticed the breach, it reinstalled all the deleted programs and reset all employee passwords.</p><p>"No failures were reported as a result of this incident, and no individuals in the city reported illness from water-related failures," the report said.</p><p>According to some reports, the hacker "tried to poison" the area's water, but Michael Sena, executive director of the Northern California Regional Intelligence Center, <a href="https://www.sfchronicle.com/local/article/Cyberattack-on-Bay-Area-water-supply-No-16256688.php">told the <em>San Francisco Chronicle</em></a> there was no attempt to poison the water supply. </p><p>“No one tried to poison any of our water,” he told the newspaper. “That is not accurate”.</p><p>“It takes a lot to influence a water supply chain,” he said. “For a large impact, there has to be a large change in the chemicals in the system. The amount of chemicals it would take to cause harm to people...the numbers are astronomical.”</p><p>Joseph Carson, chief <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> scientist at <a href="https://thycotic.com">ThycoticCentrify</a>, told <em>IT Pro</em> that this highlights and reminds us how bad password hygiene is getting and how important it is for organizations to priorities password security and management. </p><p>“Organizations must help employees move passwords into the background, so they do not have to choose, remember or store passwords, using privileged access security solutions helps organizations reduces the risk of weak passwords which is a common cause of many security incidents and data breaches moving passwords into the background at the same time reducing cyber fatigue,” Carson said.</p><p>Carson added that organizations must have a solid provisioning and deprovisioning process for privileged access, especially for employees with remote access to sensitive systems.</p><p>“Companies should demand <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication</a> by default and integrate it into privileged access management security solutions, as this breach shows the importance of not letting a password be your only security control,” he said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware operators in turmoil after Colonial Pipeline backlash ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/359558/ransomware-operators-in-turmoil-after-colonial-pipeline-backlash</link>
                                                                            <description>
                            <![CDATA[ US authorities seize DarkSide’s assets while a widely-used cyber crime forum cuts ties with ransomware groups ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">h4ow1T9pemmhmGQXwXihAm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5wkeomh2nVzHq8qxPSsPaS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 May 2021 09:21:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5wkeomh2nVzHq8qxPSsPaS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A chained lock situated on a laptop displaying a red screen]]></media:description>                                                            <media:text><![CDATA[A chained lock situated on a laptop displaying a red screen]]></media:text>
                                <media:title type="plain"><![CDATA[A chained lock situated on a laptop displaying a red screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5wkeomh2nVzHq8qxPSsPaS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The operators behind the ransomware attack that took down the Colonial Pipeline last week claim their infrastructure has been taken offline, and that they will cease their <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service" target="_blank" data-original-url="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service">ransomware as a service (RaaS)</a> programme. </p><p>Last week, <a href="https://www.itpro.com/security/ransomware/359466/colonial-pipeline-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/ransomware/359466/colonial-pipeline-ransomware-attack">DarkSide hackers attacked Colonial Pipeline</a>, forcing the operator to suspend 5,500 miles of pipeline between Texas and New York and disrupting the fuel supply to large swathes of the US east coast. They also took 100GB of data from the network before locking computers and demanding payment in a double extortion attempt. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/359539/toshiba-unit-hacked-in-france-blames-darkside" data-original-url="/security/ransomware/359539/toshiba-unit-hacked-in-france-blames-darkside">Toshiba hit by ransomware in suspected DarkSide attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/ransomware/34808/ransomware-as-a-service-threat-targeting-enterprise-servers" data-original-url="/ransomware/34808/ransomware-as-a-service-threat-targeting-enterprise-servers">‘Ransomware as a service’ threat targeting enterprise servers</a> The truth about ransomware</p></div></div><p>Amid reports that Colonial Pipeline <a href="https://www.itpro.com/security/359534/colonial-pipeline-reportedly-paid-5-million-ransom" target="_blank" data-original-url="https://www.itpro.com/security/359534/colonial-pipeline-reportedly-paid-5-million-ransom">paid the hackers $5 million (roughly £3.5 million)</a> to restore data and services, DarkSide released a statement rowing back on the attack, expressing regret, and insisting the only motive was financial, not geopolitical.</p><p>The operators have now claimed they would immediately cease operations of their RaaS scheme, issuing decryptors to all targets they attacked, alongside the promise of compensation, <a href="https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime" target="_blank">according to <em>Intel 471</em></a><em>.</em></p><p>The group also shared a message with their affiliates claiming that a public portion of their infrastructure had been disrupted by an unnamed law enforcement agency. DarkSide’s name-and-shame blog, ransom collection site and breach data delivery network were all seized, while funds from their <a href="https://www.itpro.com/technology/cryptocurrencies" target="_blank" data-original-url="https://www.itpro.com/technology/cryptocurrencies">cryptocurrency</a> wallet were siphoned away.</p><p>The backlash against the Colonial Pipeline attack has spread, with another prominent group, Babuk, also stepping down from ransomware. The group handed its ransomware source code to “another team” with the aim of continuing this work under a new brand, while Babuk would continue to run a name-and-shame blog. </p><p>Meanwhile, the administrators for XSS, a widely-used Russian cyber crime forum, have announced an immediate ban of all ransomware advertising and activity, with the promotion of services or related discussions also prohibited. </p><p>An admin explained the decision by claiming there’s “too much PR”, and that the forum had “accumulated a critical mass of nonsense”, according to <em><a href="https://www.databreaches.net/russian-language-hacking-forum-bans-ransomware-related-ads">DataBreaches.net</a>.</em></p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JwSoyQgoyuGSpPdZKLFeqQ" name="JwSoyQgoyuGSpPdZKLFeqQ.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/JwSoyQgoyuGSpPdZKLFeqQ.png" mos="https://cdn.mos.cms.futurecdn.net/JwSoyQgoyuGSpPdZKLFeqQ.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2021 state of email security report: Ransomware on the rise</strong></p><p class="fancy-box__body-text">Securing the enterprise in the COVID world</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/359471/2021-state-of-email-security-report-ransomware-on-the-rise" data-original-url="/security/ransomware/359471/2021-state-of-email-security-report-ransomware-on-the-rise">FREE DOWNLOAD</a></p></div></div><p>Almost immediately after, another popular cyber crime site, Exploit.in, followed suit and announced that ransomware-related chatter and activity would be banned. </p><p>Several other highly prominent groups have reacted to the fallout by announcing rule changes to their organisation, effectively clamping down on the free reign that affiliates have had in the organisation they target. </p><p><a href="https://www.itpro.com/security/ransomware/359161/evidence-suggests-revil-behind-harris-federation-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/ransomware/359161/evidence-suggests-revil-behind-harris-federation-ransomware-attack">REvil, for example, has banned affiliates from targeting government</a>, healthcare, educational and charitable organisations. All targets must also be pre-approved by the ransomware operators prior to deployment. </p><p>“Intel 471 believes that all of these actions can be tied directly to the reaction related to the high-profile ransomware attacks covered by the media this week,” the firm said in a blog post. “However, a strong caveat should be applied to these developments: it’s likely that these ransomware operators are trying to retreat from the spotlight more than suddenly discovering the error of their ways.</p><p>“A number of the operators will most likely operate in their own close-knit groups, resurfacing under new names and updated ransomware variants. Additionally, the operators will have to find a new way to “wash” the cryptocurrency they earn from ransoms.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI shuts down web shells in hacked Exchange servers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/359212/fbi-shuts-down-web-shells-in-hacked-exchange-servers</link>
                                                                            <description>
                            <![CDATA[ Court approves FBI operation to remove web shells from vulnerable Exchange servers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tyopYEmmdx5D2EY4Mc8tX8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x7evKP8CxCaQ7fW5TwmmyC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Apr 2021 14:38:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x7evKP8CxCaQ7fW5TwmmyC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[FBI, DOJ badge on a crest]]></media:description>                                                            <media:text><![CDATA[FBI, DOJ badge on a crest]]></media:text>
                                <media:title type="plain"><![CDATA[FBI, DOJ badge on a crest]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x7evKP8CxCaQ7fW5TwmmyC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The FBI has used a search warrant to access Exchange servers vulnerable to the <a href="https://www.itpro.com/security/ransomware/358876/microsoft-warns-of-ransomware-attacks-as-exchange-hack-escalates" data-original-url="https://www.itpro.com/security/ransomware/358876/microsoft-warns-of-ransomware-attacks-as-exchange-hack-escalates">ProxyLogon</a> exploit, copy the offending web shells for evidence, and then remove them.</p><p>According to the Department of Justice, though many infected system owners successfully removed the web shells from thousands of computers, the Feds moved to close down the shells because “others appeared unable to do so, and hundreds of such web shells persisted unmitigated.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/servers/359207/microsoft-releases-three-new-exchange-server-patches" data-original-url="/server-storage/servers/359207/microsoft-releases-three-new-exchange-server-patches">NSA uncovers new "critical" flaws in Microsoft Exchange Server</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/358894/exchange-server-attacks-increase-10-times-since-last-week" data-original-url="/security/358894/exchange-server-attacks-increase-10-times-since-last-week">Exchange Server attacks increase 10 times in a week</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/358856/microsoft-exchange-servers-targeted-by-at-least-10-hacker-groups" data-original-url="/security/cyber-attacks/358856/microsoft-exchange-servers-targeted-by-at-least-10-hacker-groups">Microsoft Exchange servers targeted by 'at least ten hacker groups'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/358817/microsoft-was-aware-of-exchange-vulnerabilities-since-early-january" data-original-url="/security/cyber-attacks/358817/microsoft-was-aware-of-exchange-vulnerabilities-since-early-january">Microsoft was warned about Exchange Server flaws two months ago</a></p></div></div><p>The FBI said the operation removed one early hacking group’s remaining web shells, which hackers could have used to maintain and escalate continued, unauthorized access to US networks.</p><p>The FBI conducted the removal by issuing a command to the server through the web shell that caused the server to delete only the web shell. Because the web shells the FBI removed each had a unique file path and name, they may have been more challenging for individual server owners to detect and eliminate than other web shells, according to the FBI.</p><p>Assistant Attorney General John Demers of the Justice Department’s National Security Division said the the malicious web shells’ court-authorized removal “demonstrates the Department’s commitment to disrupt hacking activity using all of our legal tools, not just prosecution”.</p><p>“There’s no doubt that more work remains to be done but let there also be no doubt that the Department is committed to playing its integral and necessary role in such efforts,” Demers added.</p><p>Ilia Kolochenko CEO, founder, and chief architect at ImmuniWeb, told <em>ITPro</em> this was a wise move given exposed web shells indicate server owners are unaware of the server or grossly negligent by having unpatched and compromised system exposed to the internet.</p><p>“Hacked servers are actively used in sophisticated attacks against other systems, amplify phishing campaigns and hinder investigation of other intrusions by using the breached servers as chained proxies,” Kolochenko said.</p><p>“Thus, arguably, such preventive removal may be considered a legitimate self-defense in cyberspace. In any case, neither hackers nor server owners will probably complain or file a lawsuit for unwarranted intrusion. What is interesting, is whether the FBI later transfers the list of sanitized servers to FTC or state attorney generals for investigation of bad data protection practices in violation of state and federal laws.”</p><p>In related news, the Cybersecurity and Infrastructure Security Agency (CISA) has ordered agencies to apply new security patches for vulnerable exchange servers. The updates mitigate significant vulnerabilities that affect on-premises Exchange Servers 2013, 2016, and 2019.</p><p>According to CISA, hackers could use these vulnerabilities to access and maintain persistence on the target host. It added the flaws are different from the ones disclosed and fixed in March 2021.</p><p>“CISA has determined that these vulnerabilities pose an unacceptable risk to the Federal enterprise and require an immediate and emergency action. This determination is based on the likelihood of the vulnerabilities being weaponized, combined with the widespread use of the affected software across the Executive Branch and high potential for a compromise of integrity and confidentiality of agency information,” a statement read.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI is too risky for hackers, says former GCHQ boss ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence-ai/359067/no-evidence-of-ai-in-cyber-attacks-says-ex-gchq-boss</link>
                                                                            <description>
                            <![CDATA[ Robert Hannigan suggests that the technology isn't worth the trouble for state-sponsored attackers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hqY3g5dFMLiC5yfCW4j4FP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SP2G9TJD8mbzMiyYEjFoWW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Mar 2021 11:18:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SP2G9TJD8mbzMiyYEjFoWW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The former head of GCHQ, Robert Hannigan]]></media:description>                                                            <media:text><![CDATA[The former head of GCHQ, Robert Hannigan]]></media:text>
                                <media:title type="plain"><![CDATA[The former head of GCHQ, Robert Hannigan]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SP2G9TJD8mbzMiyYEjFoWW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/23427/gchq-boss-says-tech-giants-in-denial-over-online-terrorism-threat" target="_blank" data-original-url="https://www.itpro.com/security/23427/gchq-boss-says-tech-giants-in-denial-over-online-terrorism-threat">Robert Hannigan</a>, the former head of GCHQ, has said that there is very little evidence of artificial intelligence (AI) being used in cyber crime or terrorism.</p><p>Hannigan was speaking at an event hosted by the London Office For Rapid Cybersecurity Advancement (LORCA), where he delivered a keynote on the so-called 'myths' and 'buzzwords' around AI in cyber security. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-warfare/34444/universities-a-huge-target-for-nation-state-attackers-warns-ncsc" data-original-url="/cyber-warfare/34444/universities-a-huge-target-for-nation-state-attackers-warns-ncsc">Universities a 'huge target' for nation-state attackers, warns NCSC</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358979/researchers-discover-threat-actors-with-links-to-solarwinds-hack" data-original-url="/security/hacking/358979/researchers-discover-threat-actors-with-links-to-solarwinds-hack">Researchers discover threat actors with links to SolarWinds hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/28181/what-is-ai" data-original-url="/strategy/28181/what-is-ai">What is AI?</a></p></div></div><p>In his opinion, while AI has transformed many aspects of modern life, it is yet to prove all that useful to state-sponsored hackers. He suggested there were not enough benefits to outweigh the "trouble" of investing in the technology for malicious purposes. </p><p>"The cyber industry is great at scare stories, and I've read lots and lots of scare stories about criminal groups and even terrorists using AI, and to be honest, I've seen virtually no evidence for this at all, with a couple of exceptions," Hannigan said. "I would say that I think it's again a confusion with automation."</p><p>He added that AI would likely form a part of a hackers arsenal in the near future, but right now it simply presented too much "risk". As an example, he cited the <a href="https://www.itpro.com/security/358288/solarwinds-hackers-breached-systems-september-2019" target="_blank" data-original-url="https://www.itpro.com/security/358288/solarwinds-hackers-breached-systems-september-2019">SolarWinds</a> hack, which he said was sophisticated but also appeared to be "hand-curated". </p><p>"You can understand why the attackers might have wanted to do that, in order to hide themselves," Hannigan said. "And doing it at the scale, and going to the trouble of doing it through AI would probably be at high risk for them."</p><p>From there the subject of AI in cyber security flipped, with Hannigan expressing concerns about the security of AI. He said the issue was "high on everyone's list" because technologies such as driverless cars and automated medical diagnostics were rapidly becoming the norm. </p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/nUrPdc_FxIM" allowfullscreen></iframe></div></div><p>"The data is a huge vulnerability, and there have been lots of studies on so-called data poisoning, adversarial models, which basically say, we can trick the machine into misdiagnosing, for example, an MIT study on chest X rays," he said. </p><p>"And if you have a malicious actor, or even an accidental actor, it is perfectly possible to see how data poisoning or incorrectly categorised data can lead the machine to do something completely wrong with potentially very serious consequences."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK's National Cyber Force will be based in the North ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/358892/gov-to-launch-nation-cyber-force-in-the-north</link>
                                                                            <description>
                            <![CDATA[ The centre aims to create a 'cyber corridor' that will sustain thousands of jobs in defence and intelligence services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9V1qFLffZvVuhiDk3dDKVS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mBCRCyBxf69EPvsiPfAGwZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 15 Mar 2021 12:10:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mBCRCyBxf69EPvsiPfAGwZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The prime minister, Boris Johnson, holding a folder]]></media:description>                                                            <media:text><![CDATA[The prime minister, Boris Johnson, holding a folder]]></media:text>
                                <media:title type="plain"><![CDATA[The prime minister, Boris Johnson, holding a folder]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mBCRCyBxf69EPvsiPfAGwZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Prime minister Boris Johnson is set to <a href="https://www.gov.uk/government/news/international-policy-review-puts-cyber-at-the-centre-of-the-uks-security" target="_blank">announce</a> a cyber security hub headquartered in the North of England. </p><p>The National Cyber Force (NCF) will be formally announced later in the week, along with the strategy behind it, as part of an 'Integrated Review' . </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/357708/its-too-late-to-let-slip-the-robodogs-of-war-now-we-have-ransomware" data-original-url="/security/cyber-warfare/357708/its-too-late-to-let-slip-the-robodogs-of-war-now-we-have-ransomware">It's too late to let slip the robodogs of war now we have ransomware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/358550/uk-general-reveals-military-use-of-malware-against-isis" data-original-url="/security/malware/358550/uk-general-reveals-military-use-of-malware-against-isis">UK military used malware to disrupt extremist networks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="/security/28170/what-is-cyber-warfare">What is cyber warfare?</a></p></div></div><p>The review will lay out the government's approach to cyber security and will include a 'cyber corridor' across the North of England that aims to create and "sustain" thousands of jobs in defence and intelligence services.</p><p>The location of the NCF is a key element of the plans with the government hoping to drive further growth in the digital tech and defence sectors outside of London and foster wider government partnerships within the industry and universities around the region.</p><p>The NCF was first touted by the government last year and is part of its "full-spectrum approach" to cyber security. Specifically, the hub will carry out operations for interfering with <a href="https://www.itpro.com/security/malware/358550/uk-general-reveals-military-use-of-malware-against-isis" target="_blank" data-original-url="https://www.itpro.com/security/malware/358550/uk-general-reveals-military-use-of-malware-against-isis">terrorist mobile phone networks</a>, monitoring cyber space for serious crimes, and keeping military aircraft safe from targeted weapon systems. It will also pull together experts from both defence and intelligence agencies under one unified command line. </p><p>"Cyber power is revolutionising the way we live our lives and fight our wars, just as airpower did 100 years ago," the PM said. "We need to build up our cyber capability so we can grasp the opportunities it presents while ensuring those who seek to use its powers to attack us and our way of life are thwarted at every turn."</p><p>The North of England already has a strong record within the defence sector, and it currently sustains more than 35,000 jobs in the north-west alone, according to the government.</p><p><a href="https://www.itpro.com/strategy/29261/manchester-chases-london-to-be-the-next-tech-hub" target="_blank" data-original-url="https://www.itpro.com/strategy/29261/manchester-chases-london-to-be-the-next-tech-hub">Manchester,</a> for example, has a rapidly growing tech community that's said to be one of the fastest-growing in Europe, and the city is also home to <a href="https://www.itpro.com/security/32470/gchq-opens-up-about-concealing-cyber-threats-from-global-community" target="_blank" data-original-url="https://www.itpro.com/security/32470/gchq-opens-up-about-concealing-cyber-threats-from-global-community">GCHQ</a>. The government estimates that 15% of Manchester's population is employed by the digital tech sector. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK military used malware to disrupt extremist networks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/358550/uk-general-reveals-military-use-of-malware-against-isis</link>
                                                                            <description>
                            <![CDATA[ Experts cite WannaCry with warnings that hacking tools have the potential for severe collateral damage ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i2nc69BaCgbyoLTWcaj2AZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/A9motGiGRMQfYAc3ovEwpn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Feb 2021 12:09:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/A9motGiGRMQfYAc3ovEwpn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Military operative on a remote computer]]></media:description>                                                            <media:text><![CDATA[Military operative on a remote computer]]></media:text>
                                <media:title type="plain"><![CDATA[Military operative on a remote computer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/A9motGiGRMQfYAc3ovEwpn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Using malware as a deterrent, disrupting extremist networks and remotely disabling devices are just some of the ways the UK is fighting on the cyber front lines, the head of the country's strategic command has revealed. </p><p>General Sir Patrick Sanders discussed the UK's cyber offensive capabilities on the <em>Sky News</em> podcast <a href="https://news.sky.com/story/into-the-grey-zone-the-offensive-cyber-used-to-confuse-islamic-state-militants-and-prevent-drone-attacks-12211740" target="_blank"><em>Into The Grey Zone</em></a>, which also featured insight from Jeremy Fleming, the director of GCHQ.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/357708/its-too-late-to-let-slip-the-robodogs-of-war-now-we-have-ransomware" data-original-url="/security/cyber-warfare/357708/its-too-late-to-let-slip-the-robodogs-of-war-now-we-have-ransomware">It's too late to let slip the robodogs of war now we have ransomware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="/malware/28076/what-is-malware">What is malware?</a></p></div></div><p>The key theme of the discussion was the Islamic State (Isis) with Sanders speaking in detail about the cyber offensive strategies used against the organisation. Along with the US and other allies, <a href="https://www.itpro.com/security/cyber-warfare/357708/its-too-late-to-let-slip-the-robodogs-of-war-now-we-have-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/cyber-warfare/357708/its-too-late-to-let-slip-the-robodogs-of-war-now-we-have-ransomware">visible military tech</a> has been deployed against Isis, such as warplanes and drones, but there has also been a more covert use of online attacks.</p><p>The UK's military has previously suggested the use of 'cyber offensives', but this is the first time it has publicly discussed it. </p><p>"I think it sends a really strong signal that we and our allies were not going to leave cyberspace as an uncontested place," Fleming said to <em>Sky News</em>.</p><p>"We have to defend it. We have to make sure it's as secure as possible. We have to make sure that it is still underpinning our commerce, our economy, our society and our communities. But equally, when adversaries like Daesh (Islamic State) overstep the line, then they need to expect us to contest it, too."</p><p>As part of its cyber campaign, the UK military targeted mobile phones and laptops, devices that Isis extremists used to communicate with their contacts on the ground. The attacks were thought to be successful by stopping senior Isis officers from sending instructions, altering the content of the messages and confusing ground troops. In some cases, the attacks lead foot soldiers into the path of UK and allied troops. </p><p>The UK also launched <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> against computer servers in various countries around the world to shut down Isis accounts, delete and distort information on their files, and also to remove online posts and videos. It is thought that US cyber operators were also involved in these efforts.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PV2YaZYSxfAfzwfGVaZaeM" name="PV2YaZYSxfAfzwfGVaZaeM.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/PV2YaZYSxfAfzwfGVaZaeM.png" mos="https://cdn.mos.cms.futurecdn.net/PV2YaZYSxfAfzwfGVaZaeM.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Ransomware report</strong></p><p class="fancy-box__body-text">The global state of the channel</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/358523/ransomware-report" data-original-url="/security/ransomware/358523/ransomware-report">FREE DOWNLOAD</a></p></div></div><p>The 'Friendly' use of malware by the UK military should come as no surprise to anyone, according to Chris Sedgwick, director of security operations at Sy4 Security. </p><p>"The files <a href="https://www.itpro.com/security/34436/us-sues-edward-snowden-over-his-memoir" target="_blank" data-original-url="https://www.itpro.com/security/34436/us-sues-edward-snowden-over-his-memoir">Edward Snowden</a> released in 2013 highlight the immense capability that GCHQ and other countries within Five Eyes have in relation to hacking personal devices and access to our sensitive data," Sedgwick told <em>IT Pro</em>. "Since then the UK Military has established "77th Brigade" which aims to tackle online disinformation. However, the launching of actual malware should follow very clear legal frameworks and justifications much the same as a physical military attack."</p><p>Similarly, malware attacks have the potential for severe collateral damage, according to Mike Beck, global <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do" target="_blank" data-original-url="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO</a> for Darktrace.</p><p>"We saw how malware can bleed from initial targets to cause widespread destruction with <a href="https://www.itpro.com/wannacry/34352/what-is-wannacry" target="_blank" data-original-url="https://www.itpro.com/wannacry/34352/what-is-wannacry">WannaCry</a>, <a href="https://www.itpro.com/malware/34381/what-is-notpetya" target="_blank" data-original-url="https://www.itpro.com/malware/34381/what-is-notpetya">NotPetya</a>, and Stuxnet" Beck explained. "Cyber conflict is asymmetrical and it is much easier to attack than to defend. The rules of conventional warfare do not apply to cyber and states must strive for good defence, not just good offence."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Biden nominees highlight tough cyber security challenges ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/358383/biden-nominees-highlight-tough-cyber-security-challenges</link>
                                                                            <description>
                            <![CDATA[ Senators warn government cyber security operations are in disarray ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6JFALbUnvPwidBTDxSgT9T</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PWLLb6q6p2DJwHK7BiiSRE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 Jan 2021 17:25:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PWLLb6q6p2DJwHK7BiiSRE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Military IT professionals in a server room]]></media:description>                                                            <media:text><![CDATA[Military IT professionals in a server room]]></media:text>
                                <media:title type="plain"><![CDATA[Military IT professionals in a server room]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PWLLb6q6p2DJwHK7BiiSRE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>President Joe Biden's nominations for top defense, intelligence, and homeland security positions committed to reviewing and refining <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> operations under the new government in hearings yesterday. They testified as senators slammed the government's performance in dealing with the recent <a href="https://www.itpro.com/security/358111/solarwinds-confirms-cyber-attack" data-original-url="https://www.itpro.com/security/358111/solarwinds-confirms-cyber-attack">SolarWinds attack</a> that affected numerous agencies.</p><p>Senators held confirmation hearings for Alejandro Mayorkas, nominee for Secretary of Homeland Security; Avril Haines, who Biden has chosen as his Director of National Intelligence; and Lloyd Austin, who testified for his appointment as Secretary of Defense. Between them, they addressed various issues, including the SolarWinds hack, the need to bolster internal cyber security operations, and the structure of US military cyber space operations.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/358216/hackers-accessed-microsoft-source-code-in-solarwinds-attack" data-original-url="/security/358216/hackers-accessed-microsoft-source-code-in-solarwinds-attack">SolarWinds hackers accessed Microsoft source code</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/358240/solarwinds-hack-likely-russian-in-origin-says-fbi" data-original-url="/security/358240/solarwinds-hack-likely-russian-in-origin-says-fbi">US government blames Russia for SolarWinds hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/358288/solarwinds-hackers-breached-systems-september-2019" data-original-url="/security/358288/solarwinds-hackers-breached-systems-september-2019">SolarWinds hackers first breached systems in September 2019</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358373/solarwinds-hackers-hit-malwarebytes-through-microsoft-exploit" data-original-url="/security/hacking/358373/solarwinds-hackers-hit-malwarebytes-through-microsoft-exploit">SolarWinds hackers hit Malwarebytes through Microsoft exploit</a></p></div></div><p>Mayorkas, who was Deputy Secretary of Homeland Security in the Obama administration before returning to private legal practice during the Trump years, said the US had to do "a much better job" on cyber security. </p><p>The Department of Homeland Defense's Cybersecurity and Infrastructure Security Agency (CISA) would need to shoulder a lot of that work, Mayorkas added. He would explore two programs to see if they could stop future cyber attacks: the Einstein network security program, and the Continuous Diagnostic and Mitigation program.</p><p>Haines, former Deputy Director of the CIA under Obama, also called for strong action to shore up cybersecurity defenses in the US.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="L8vUrzgp7mhwUJ5GEHSyyi" name="L8vUrzgp7mhwUJ5GEHSyyi.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/L8vUrzgp7mhwUJ5GEHSyyi.png" mos="https://cdn.mos.cms.futurecdn.net/L8vUrzgp7mhwUJ5GEHSyyi.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Managing security risk and compliance in a challenging landscape</strong></p><p class="fancy-box__body-text">How key technology partners grow with your organisation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/354266/managing-security-risk-and-compliance-in-a" data-original-url="/business-strategy/digital-transformation/354266/managing-security-risk-and-compliance-in-a">FREE DOWNLOAD</a></p></div></div><p>"Here at home, we must strengthen our cybersecurity, safeguard our critical infrastructure, and turn the ongoing technological revolution from a threat to an advantage by integrating new technologies to improve the capacity and superiority of our intelligence into the future," Haines said during prepared remarks.</p><p>Haines said she was committed to recruiting more people into the intelligence community, following work completed on a Trusted Workforce 2.0 initiative to reform <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> clearances.</p><p>Austin, who has served as head of US Central Command, said he would continue to support an offensive cyber security policy that the US government has already implemented. The Department of Defense formalized this policy, known as “defend forward,” in October 2018 as a way to disrupt enemy engagement in cyber space before they happen.</p><p>"Having an offensive capability that we're able to use is really important," he said, highlighting the need for fast action in cyberspace. "Speed matters, so anything we can do to facilitate the work of the operators is goodness." He also said that Russia needed to be held accountable for its <a href="https://www.itpro.com/security/358240/solarwinds-hack-likely-russian-in-origin-says-fbi" data-original-url="https://www.itpro.com/security/358240/solarwinds-hack-likely-russian-in-origin-says-fbi">role in the SolarWinds hack</a>.</p><p>Austin and Haynes separately said they would review the relationship between the National Security Agency (NSA) and US Cyber Command, which have shared leadership since the latter’s creation. The idea of placing the two under different leadership has been a recurring theme among defense and intelligence officials for several years. The Trump administration proposed doing so during its final days.</p><p>Senators expressed dissatisfaction with the government's current cyber security capabilities during the hearings. Republican Senator Roy Blunt complained Congress hadn't received a report on the SolarWinds attack. Senate Intelligence Committee Vice Chairman Mark Warner said the government had to rely on a private-sector company to find out about it. "One part of the government doesn't seem to know what the other is doing," Warner said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ World’s largest dark web marketplace taken offline ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/358297/worlds-largest-dark-web-marketplace-taken-offline</link>
                                                                            <description>
                            <![CDATA[ A multinational operation also involving Europol, UK and US authorities has put a halt to illegal trade valued at approximately £125 million ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dtVKJYku9jM7rrP5NM8jio</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VhYZAkkx5vCjyJNDbzgnzj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Jan 2021 09:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VhYZAkkx5vCjyJNDbzgnzj-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Closeup of a criminal&amp;#039;s wrists in handcuffs ]]></media:description>                                                            <media:text><![CDATA[Closeup of a criminal&amp;#039;s wrists in handcuffs ]]></media:text>
                                <media:title type="plain"><![CDATA[Closeup of a criminal&amp;#039;s wrists in handcuffs ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VhYZAkkx5vCjyJNDbzgnzj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The EU’s law enforcement agency has spearheaded an operation taking down DarkMarket, the world’s largest illegal marketplace, and put a stop to trade worth more than €140 million (roughly £125 million).</p><p>Cooperating with the UK’s <a href="https://www.itpro.com/malware/27424/uks-national-crime-agency-joins-fight-against-ransomware" target="_blank" data-original-url="https://www.itpro.com/malware/27424/uks-national-crime-agency-joins-fight-against-ransomware">National Crime Agency</a> (NCA) and several US law enforcement agencies, the operation led officers to switch off servers and seize the criminal infrastructure, comprising more than 20 servers in Moldova and Ukraine.</p><p>This has put an end to one of the busiest platforms for illegal trade over the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web" target="_blank" data-original-url="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358048/dark-web-markets-consolidate-as-competition-takes-its-toll" data-original-url="/security/hacking/358048/dark-web-markets-consolidate-as-competition-takes-its-toll">Dark web markets consolidate as competition takes its toll</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/26820/four-cheap-dark-web-threats-and-how-to-protect-your-firm" data-original-url="/hacking/26820/four-cheap-dark-web-threats-and-how-to-protect-your-firm">Four cheap dark web threats, and how to protect your firm</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/356999/netwalker-ransomware-has-raked-in-29m-since-march" data-original-url="/security/ransomware/356999/netwalker-ransomware-has-raked-in-29m-since-march">'NetWalker' ransomware explodes thanks to 'as a service' expansion</a></p></div></div><p>DarkMarket boasted almost 500,000 users, more than 2,400 sellers, 320,000 transactions, and more than 4,650 Bitcoin and 12,800 Monero transferred. DarkMarket mostly traded drugs, counterfeit money, credit card details, anonymous SIM cards and malware.</p><p>Europol facilitated international information exchange, provided specialist operational support, and offered advanced analytics that assisted primarily German authorities in tracking down the alleged administrator.</p><p>The takedown is made even more significant because of research published in December 2020 by cryptocurrency forensics firm Chainalysis that showed <a href="https://www.itpro.com/security/hacking/358048/dark-web-markets-consolidate-as-competition-takes-its-toll" data-original-url="https://www.itpro.com/security/hacking/358048/dark-web-markets-consolidate-as-competition-takes-its-toll">fewer dark web markets were competing for illicit online revenues</a>. </p><p>Revenues across the wider dark web hit more than $1.5 billion (approximately £1.1 billion) as of November 2020, across nine million transactions. There were also just 37 active markets as of November, down from an all-time peak of almost 60 in February.</p><p>The dismantling of DarkMarket represents a major step for European law enforcement in its aim to foster a coordinated approach to tackling crime on the dark web. To achieve this, Europol’s cybercrime division established a dedicated Dark Web Team to work together with EU member states and law enforcement agencies across the globe to break down the underground illegal economy. </p><p>Europol has previously played a key role in taking down criminal networks, having only recently dismantled the EncroChat site, which supplied encrypted mobile phones to drug dealers and criminal syndicates. Working with the NCA, hacking the website was deemed the law enforcement equivalent of breaking the <a href="https://www.itpro.com/business-strategy/careers-training/356180/why-alan-turing-is-a-queer-icon" data-original-url="https://www.itpro.com/business-strategy/careers-training/356180/why-alan-turing-is-a-queer-icon">Enigma code</a>, according to officers involved.</p><p>“Darkweb Market Places remain the primary route to buy illicit commodities such as drugs and guns online, and have continued to operate with criminals exploiting anonymising technologies and virtual currencies to avoid law enforcement," an NCA spokesperson told <em>IT Pro</em>. </p><p>“The NCA’s Darkweb Intelligence, Collection and Exploitation (DICE) unit supported the EUROPOL led international Darkmarket operation with specialist investigative capabilities, and will continue to work with its regional policing partners to co-ordinate the ongoing UK response.</p><p>“The Darkweb provides organised criminals a place to conduct their business using military grade encryption on a global basis. This operation demonstrates the capabilities of the NCA, UK policing and international partners to tackle this growing threat”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Biden promises tough response to cyber attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/358207/biden-promises-tough-response-to-cyber-attacks</link>
                                                                            <description>
                            <![CDATA[ President-elect promises that he "won't stand idly by" when nation-states hack US ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pxRXUYQcNTA5Md5bmm5Rww</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zJarv45eL25jp27gCxJbPD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Dec 2020 17:27:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zJarv45eL25jp27gCxJbPD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Joe Biden behind the campaign podium with his arms spread open]]></media:description>                                                            <media:text><![CDATA[Joe Biden behind the campaign podium with his arms spread open]]></media:text>
                                <media:title type="plain"><![CDATA[Joe Biden behind the campaign podium with his arms spread open]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zJarv45eL25jp27gCxJbPD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>President-elect <a href="https://www.itpro.com/business/policy-legislation/357752/the-it-pro-podcast-what-does-joe-biden-have-in-store-for-tech" data-original-url="https://www.itpro.com/business/policy-legislation/357752/the-it-pro-podcast-what-does-joe-biden-have-in-store-for-tech">Joe Biden</a> has taken a stance on the recently discovered hack of US government and private sector systems, promising to hold adversaries accountable. In a <a href="https://buildbackbetter.gov/press-releases/statement-by-president-elect-joe-biden-on-cybersecurity">statement</a> issued by his transition team, Biden said he had already been briefed by government officials on the attack and would make dealing with it a priority when it took office.</p><p>Biden promised to strengthen partnerships with the private sector and expand investments in cyber security infrastructure, but he also hinted at a more hawkish cyber security approach.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/social-media/356068/biden-campaign-publishes-an-open-letter-to-facebook" data-original-url="/marketing-comms/social-media/356068/biden-campaign-publishes-an-open-letter-to-facebook">Biden campaign publishes an open letter to Facebook</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/357660/tla-biden-win-good-for-global-tech" data-original-url="/business/policy-legislation/357660/tla-biden-win-good-for-global-tech">Biden win 'would be good for global tech'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/357752/the-it-pro-podcast-what-does-joe-biden-have-in-store-for-tech" data-original-url="/business/policy-legislation/357752/the-it-pro-podcast-what-does-joe-biden-have-in-store-for-tech">The IT Pro Podcast: What does Joe Biden have in store for tech?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/358014/biden-team-signals-change-on-section-230" data-original-url="/business/policy-legislation/358014/biden-team-signals-change-on-section-230">Biden team signals president-elect may target Section 230 and data privacy</a></p></div></div><p>"A good defense isn’t enough; we need to disrupt and deter our adversaries from undertaking significant cyber attacks in the first place," Biden said. "We will do that by, among other things, imposing substantial costs on those responsible for such malicious attacks, including in coordination with our allies and partners. Our adversaries should know that, as President, I will not stand idly by in the face of cyber assaults on our nation."</p><p>In the last few days, government officials and private sector companies have discovered the scope of a <a href="https://www.itpro.com/security/358111/solarwinds-confirms-cyber-attack" data-original-url="https://www.itpro.com/security/358111/solarwinds-confirms-cyber-attack">massive cyber attack on US government</a> and private sector systems. The attack, delivered via malicious code injected into SolarWinds' IT monitoring software, is ongoing, officials warned. In an <a href="https://blogs.microsoft.com/on-the-issues/2020/12/17/cyberattacks-cybersecurity-solarwinds-fireeye">update</a>, Microsoft president Brad Smith called the incident, believed now to have been engineered by Russia, "an attack on the United States and its government and other critical institutions."</p><p>Biden has a tough job ahead of him. "This is big," <a href="https://www.cnbc.com/2020/12/17/biden-hints-at-a-tougher-stance-against-state-sponsors-of-cyberattacks.html">said</a> Sue Gordon, who served as principal deputy director of national intelligence in the Office of the Director of National Intelligence (DNI) until resigning from the position in August 2019, likening it to the <a href="https://www.itpro.com/security/24760/opm-refusing-to-co-operate-with-government-data-breach-enquiry" data-original-url="https://www.itpro.com/security/24760/opm-refusing-to-co-operate-with-government-data-breach-enquiry">Office of Personnel Management hack</a> revealed in 2015. "Even bigger than that because this is public and private, and global," Gordon said, pointing out that the problem is ongoing. "This is not only problematic in terms of the information, but problematic in terms of getting rid of it."</p><p>President Trump remained silent on the hack this week. During his term as president, more than a third of his National Infrastructure Advisory Council members quit, <a href="https://nakedsecurity.sophos.com/2017/08/30/trumps-cybersecurity-advisers-quit-warning-of-insufficient-attention">citing</a> "insufficient attention to the growing threats to the cybersecurity of the critical systems upon which all Americans depend." </p><p>Trump appointed Bush-era security advisor Tom Bossert to head up the administration's cyber security efforts, but the White House's John Bolton <a href="https://www.nbcnews.com/politics/politics-news/tom-bossert-trump-s-homeland-security-adviser-resign-n864321">removed</a> him in April 2018, leaving the position vacant.</p><p>In 2018, senators <a href="https://nakedsecurity.sophos.com/2018/08/31/proposed-us-law-would-require-president-to-act-on-overseas-hackers">announced</a> the bipartisan Cyber Deterrence and Response Act that would have forced the president to act against overseas hackers found targeting the US or explain why he hadn't. However, lawmakers <a href="https://www.congress.gov/bill/115th-congress/senate-bill/3378?q=%257B%2522search%2522%253A%255B%2522S.+3378%2522%255D%257D&r=1">failed to pass</a> the bill.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trump website defaced in second successive cyber breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/357570/trump-site-hacked-in-second-successive-cyber-breach</link>
                                                                            <description>
                            <![CDATA[ Attackers briefly seize control of the presidential campaign website a week after Trump claimed “nobody gets hacked” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qCQj3jzMtwXoxAoxyj1A8P</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/m7F8cgzFDkSZpc4tYYBsBR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 28 Oct 2020 11:40:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/m7F8cgzFDkSZpc4tYYBsBR-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The US President Donald Trump standing in front of the American flag]]></media:description>                                                            <media:text><![CDATA[The US President Donald Trump standing in front of the American flag]]></media:text>
                                <media:title type="plain"><![CDATA[The US President Donald Trump standing in front of the American flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/m7F8cgzFDkSZpc4tYYBsBR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Donald Trump’s presidential campaign website was briefly hijacked last night with attackers using the platform to claim “the world has had enough of the fake news”.</p><p>The culprits pinned a messaged to the website posing as the US Department of Justice, claiming “this site was seized” and that it was time to allow the world to know the truth, according to <a href="https://www.nbcnews.com/politics/2020-election/trump-campaign-website-hacked-n1245038" target="_blank"><em>NBC News</em></a>.</p><p>This is the second time this month that a platform belonging to the US President was compromised. Trump’s Twitter account was also breached by a Dutch researcher who <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" target="_blank" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">correctly guessed the president’s password</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password" data-original-url="/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password">The IT Pro Podcast: How hackers steal your password</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/social-media/355846/president-trump-signs-executive-order-targeting-social-media" data-original-url="/marketing-comms/social-media/355846/president-trump-signs-executive-order-targeting-social-media">President Trump signs executive order targeting social media companies</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/356417/trump-confirms-cyber-attacks-on-russia-election-trolls" data-original-url="/security/cyber-attacks/356417/trump-confirms-cyber-attacks-on-russia-election-trolls">Trump confirms US cyber attack on Russia election trolls</a></p></div></div><p>Security expert Victor Gevers claims he gained access to Trump’s direct messages, could post tweets in his name and change aspects of his profile after guessing his password as “maga2020!”, <a href="https://myprivacy.dpgmedia.nl/consent?siteKey=PUBX2BuuZfEPJ6vF&callbackUrl=https%3a%2f%2fwww.volkskrant.nl%2fprivacy-wall%2faccept%3fredirectUri%3d%252fnieuws-achtergrond%252fdutch-ethical-hacker-logs-into-trump-s-twitter-account%257ebadaa815%252f%253freferrer%253dhttps%25253A%25252F%25252Ft.co%25252FDE5GNYHY4d%25253Famp%25253D1" target="_blank"><em>de Volkskrant</em></a> reported.</p><p>In the latest security breach, hackers claimed to have information that discredited the president, as well as his family, and demanded cryptocurrency payment under the threat of releasing the material publicly. They also claimed <a href="https://www.itpro.com/security/endpoint-security/354130/close-the-gap-in-device-security" target="_blank" data-original-url="https://www.itpro.com/security/endpoint-security/354130/close-the-gap-in-device-security">multiple devices were compromised</a> giving full access to Trump and his relatives, as well as internal conversations and classified intel. There's no confirming the veracity of these claims, however.</p><p>The site soon went offline before being fully restored as normal without the spoofed message. A Trump campaign spokesperson told <em>NBC News</em> the “website was defaced and we are working with law enforcement authorities to investigate the source of the attack”. </p><p>President Trump previously claimed “nobody gets hacked”, and that you “need somebody with 197 IQ” in order to get hacked.</p><p>Details as to how the attackers infiltrated Trump’s campaign website are scarce at the moment, although the ease with which they’ve defaced the President’s platform should raise national security alarm bells.</p><p>It’s not unusual for prominent politicians or even entire government agencies to suffer the consequences of a cyber intrusion, with attackers claiming to have <a href="https://www.google.com/search?q=site:itpro.co.uk+US+government+hack&rlz=1C1CHBF_en-GBGB791GB791&sxsrf=ALeKk00L1x8TaD4hszkjYoP8DYJWZEnF2A:1603884421427&source=lnms&tbm=nws&sa=X&ved=2ahUKEwi2tcyJl9fsAhURfMAKHeQ3B2AQ_AUoAXoECAsQAw&biw=958&bih=927">compromised a NASA IT contractor</a> earlier this year, for example.</p><p>Closer to home, the personal email account of the UK’s former international trade secretary <a href="https://www.itpro.com/security/phishing/356642/russia-hack-liam-fox-email-steal-trade-secrets" target="_blank" data-original-url="https://www.itpro.com/security/phishing/356642/russia-hack-liam-fox-email-steal-trade-secrets">Dr Liam Fox</a> was compromised last year in a <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">spear-phishing</a> exercise, wth hackers making away with sensitive trade documents.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian military targeting Linux systems with Drovorub malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-warfare/356779/russian-military-targeting-linux-systems-with-drovorub-malware</link>
                                                                            <description>
                            <![CDATA[ The NSA and FBI warn the malware is being deployed in real-world espionage attacks by the group known as Fancy Bear ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mhNCspVWVSht6SY3pV42ub</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/M4RyGzwEbWsD2Gak7ssgQh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2020 10:48:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/M4RyGzwEbWsD2Gak7ssgQh-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker in front of a Russian flag]]></media:description>                                                            <media:text><![CDATA[Hacker in front of a Russian flag]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker in front of a Russian flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/M4RyGzwEbWsD2Gak7ssgQh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Critical US national security systems running Linux are being targeted with malware as part of cyber espionage campaign spearheaded by a division of the Russian military, <a href="http://Search%20Results%20Web%20results%20%20Fancy%20Bear%20cracks%20into%20government%20compu" target="_blank">also known as Fancy Bear or ATP28</a>.</p><p>The Drovorub malware is targeting Linux systems operated by US national security agencies, the Department of Defense, and the US government’s industrial assets directly relevant to producing equipment for armed forces.</p><p>The malware is being deployed by the division of the GRU, also publicly known as Strontium, as part of the organisation’s cyber espionage operations, according to an advisory published by the FBI and the NSA.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/32009/fancy-bear-cracks-into-government-computers-with-lojax-uefi-rootkit" data-original-url="/security/32009/fancy-bear-cracks-into-government-computers-with-lojax-uefi-rootkit">Fancy Bear cracks into government computers with LoJax UEFI rootkit</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/355259/apt-groups-targeting-linux-servers-for-china" data-original-url="/security/hacking/355259/apt-groups-targeting-linux-servers-for-china">Chinese APT groups are targeting Linux servers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34153/microsoft-observes-russian-hackers-actively-attacking-businesses-through-iot-devices" data-original-url="/security/34153/microsoft-observes-russian-hackers-actively-attacking-businesses-through-iot-devices">Microsoft observes Russian hackers actively attacking businesses through IoT devices</a></p></div></div><p><a href="https://media.defense.gov/2020/Aug/13/2002476465/-1/-1/0/CSA_DROVORUB_RUSSIAN_GRU_MALWARE_AUG_2020.PDF" target="_blank">The jointly-published advisory</a> offers detailed technical information on Drovorub, guidance on how to detect the <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> on infected systems, and mitigation recommendations. The malware itself compromises an implant coupled with a kernel module rootkit, a file transfer and port forwarding tool, and a command and control (C2) server. </p><p>When deployed on a Linux machine, the Drovorub client paves the way for direct communication with the C2 infrastructure, allowing for file download and upload capabilities, execution of arbitrary commands as "root", and port forwarding of network traffic to other hosts on the network. The malware also implements hiding techniques to evade detection. </p><p>"This Cybersecurity Advisory represents an important dimension of our cybersecurity mission, the release of extensive, technical analysis on specific threats," said NSA cybersecurity director Anne Neuberger. </p><p>"By deconstructing this capability and providing attribution, analysis, and mitigations, we hope to empower our customers, partners, and allies to take action," she said. "Our deep partnership with FBI is reflected in our releasing this comprehensive guidance together."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="B2g4zsZF8gXw8vL5oHePg5" name="B2g4zsZF8gXw8vL5oHePg5.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/B2g4zsZF8gXw8vL5oHePg5.jpg" mos="https://cdn.mos.cms.futurecdn.net/B2g4zsZF8gXw8vL5oHePg5.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Rethink your cybersecurity strategy for the new world</strong></p><p class="fancy-box__body-text">5 steps to secure the enterprise and be fit for a flexible future</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/356670/rethink-your-cybersecurity-strategy-for-the-new-world" data-original-url="/security/cyber-security/356670/rethink-your-cybersecurity-strategy-for-the-new-world">FREE DOWNLOAD</a></p></div></div><p>The advisory suggests that organisations running Linux systems to apply any system updates immediately, by continually checking for the latest version of vendor-supplied software. Specifically, system administrators should update to Linux Kernel 3.7 or later in order to take advantage of kernel signing enforcement.</p><p>System owners are also being advised to configure their systems to load only modules with a valid digital signature, making it more difficult for a hacker to introduce a malicious kernel module into the system. </p><p>System administrators should also activate UEFI-Secure Boot to ensure only signed kernel modules can be loaded. This would, of course, require a UEFI-compliant platform configured in UEFI native mode in Thorough or Full enforcement mode.</p><p>"For the FBI, one of our priorities in cyberspace is not only to impose risk and consequences on cyber adversaries but also to empower our private sector, governmental, and international partners through the timely, proactive sharing of information," said FBI assistant director, Matt Gorham. </p><p>"This joint advisory with our partners at NSA is an outstanding example of just that type of sharing," he added. "We remain committed to sharing information that helps businesses and the public protect themselves from malicious cyber actors."</p><p>Research from Blackberry outlined earlier this year previously identified Chinese-sponsored hackers as <a href="https://www.itpro.com/security/hacking/355259/apt-groups-targeting-linux-servers-for-china" target="_blank" data-original-url="https://www.itpro.com/security/hacking/355259/apt-groups-targeting-linux-servers-for-china">targeting Linux servers in order to steal intellectual property</a>. Compromising Linux web servers in this way that these hackers had done allowed them to steal massive amounts of data disguised as conventional web traffic.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU freezes assets in major crackdown against notorious cyber gangs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/356623/eu-freezes-assets-in-major-crackdown-against-notorious-cyber-gangs</link>
                                                                            <description>
                            <![CDATA[ Six individuals and three organisations behind WannaCry, NotPetya and Cloud Hopper are being targeted by sanctions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aD7rSG43RfkNMdjnhxLgki</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HbVfAihAygQSj3WNVVVzS5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 31 Jul 2020 11:30:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HbVfAihAygQSj3WNVVVzS5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A shadowy figure in front of a digital EU flag]]></media:description>                                                            <media:text><![CDATA[A shadowy figure in front of a digital EU flag]]></media:text>
                                <media:title type="plain"><![CDATA[A shadowy figure in front of a digital EU flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HbVfAihAygQSj3WNVVVzS5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The EU has issued sanctions against individuals and organisations associated with the world’s most notorious hacks for the first time, with the aim of restricting resources and deterring them from future attacks.</p><p>Individuals <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32020D1127&from=EN" target="_blank">highlighted by a European Council legal document</a> face asset freezes and travel bans as part of a package of measures that comprise a fightback against <a href="https://www.itpro.com/security/29224/the-cyber-security-threat-in-charts" target="_blank" data-original-url="https://www.itpro.com/security/29224/the-cyber-security-threat-in-charts">some of the most dangerous cyber threats</a> facing European countries.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34511/tech-giants-form-cyber-security-supergroup" data-original-url="/security/34511/tech-giants-form-cyber-security-supergroup">Tech giants form cyber security 'supergroup'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27924/are-companies-paying-enough-attention-to-cybersecurity-1" data-original-url="/security/27924/are-companies-paying-enough-attention-to-cybersecurity-1">Are companies paying enough attention to cybersecurity?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/356577/cyber-resilience-centres-launching-throughout-uk" data-original-url="/security/cyber-crime/356577/cyber-resilience-centres-launching-throughout-uk">Cyber resilience centres will help protect SMBs from cyber crime</a></p></div></div><p>This is in addition to a ban on any other individuals or companies from conducting business with or providing funds to those mentioned in the report. So far six individuals and three organisations are listed.</p><p>Those included are said to be behind the devastating <a href="https://www.itpro.com/wannacry/34352/what-is-wannacry" target="_blank" data-original-url="https://www.itpro.com/wannacry/34352/what-is-wannacry">WannaCry</a>, <a href="https://www.itpro.com/malware/34381/what-is-notpetya" target="_blank" data-original-url="https://www.itpro.com/malware/34381/what-is-notpetya">NotPetya</a> and <a href="https://www.itpro.com/cyber-attacks/32556/china-hacking-surges-against-us-claims-trumps-former-cyber-security-adviser" target="_blank" data-original-url="https://www.itpro.com/cyber-attacks/32556/china-hacking-surges-against-us-claims-trumps-former-cyber-security-adviser">Operation Cloud Hopper</a> campaigns.</p><p>“Sanctions are one of the options available in the EU’s cyber diplomacy toolbox to prevent, deter and respond to malicious cyber activities directed against the EU or its member states, and today is the first time the EU has used this tool,” the European Council said.</p><p>“In recent years, the EU has scaled up its resilience and its ability to prevent, discourage, deter and respond to cyber threats and malicious cyber activities in order to safeguard European security and interests.”</p><p>The sanctions aim to deter cyber criminals from carrying out malicious campaigns, and follows the establishment of a framework in June 2017, giving EU member states the power to use such measures against organisations and individuals.</p><p>Gao Qiang and Zhang Shilong, as well as the Huaying Haitai Science and Technology Development Co Ltd, have been identified as being behind <a href="https://www.itpro.com/security/32630/ncsc-accuses-china-of-targeting-global-msps-in-malicious-cyber-campaign" target="_blank" data-original-url="https://www.itpro.com/security/32630/ncsc-accuses-china-of-targeting-global-msps-in-malicious-cyber-campaign">Operation Cloud Hopper</a> which targeted businesses in December 2018.</p><p>IBM and HPE were reportedly among those targeted by the cyber campaign which mainly arose through a malware known as Quasar RAT, with the aim being to steal corporate secrets for competitive advantage. Huaying Haitai is charged with providing financial, technical or material support for Operation Cloud Hopper.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UzYjWqqUFrZfUCsqkHDVs6" name="UzYjWqqUFrZfUCsqkHDVs6.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UzYjWqqUFrZfUCsqkHDVs6.png" mos="https://cdn.mos.cms.futurecdn.net/UzYjWqqUFrZfUCsqkHDVs6.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Remote worker cybersecurity best practices</strong></p><p class="fancy-box__body-text">Strategies and tips to follow, helping to secure your workforce</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/356579/remote-worker-cybersecurity-best-practices" data-original-url="/security/cyber-security/356579/remote-worker-cybersecurity-best-practices">FREE DOWNLOAD</a></p></div></div><p>The special technologies branch of the GRU, the Russian armed forces, is also included in the report and has been implicated in several cyber attacks, <a href="https://www.itpro.com/security/28940/notpetya-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28940/notpetya-ransomware">including the NotPetya campaign</a>. Individuals listed in the legal document, who are also members of the GRU, include Alexey Minin, Aleksei Morenets, Evgenii Serebriakov and Oleg Sotnikov.</p><p>These attacks rendered data inaccessible for a number of companies by targeting machines with ransomware in June 2017. The infamous <a href="https://www.itpro.com/malware/25804/ukrainian-power-grid-downed-by-cyber-attack" target="_blank" data-original-url="https://www.itpro.com/malware/25804/ukrainian-power-grid-downed-by-cyber-attack">attacks against the Ukrainian power grid in 2015 and 2016</a> were also as a result of NotPetya.</p><p>The WannaCry attack, which <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">inadvertently devastated the NHS</a>, was facilitated in-part by Chosun Expo, which provided financial, technical or material support to the hackers, according to the European Council.</p><p>The cyber crime outfit known as <a href="https://www.itpro.com/security/32756/lazarus-hackers-compromise-chiles-atm-network-through-linkedin-job-advert" target="_blank" data-original-url="https://www.itpro.com/security/32756/lazarus-hackers-compromise-chiles-atm-network-through-linkedin-job-advert">the Lazarus Group</a>, or APT38, has been associated with the North Korean-linked Chosun Group by European officials.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Former eBay employees charged with cyber stalking ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-operations/356086/ex-ebay-employees-charged-with-cyber-stalking</link>
                                                                            <description>
                            <![CDATA[ Ex-security personnel allegedly sent live spiders and a funeral wreath to the publishers of a critical newsletter ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nABUwhN7hWGUUacYQq25vV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/isXJTAEVsTEjXu5Lti7BqW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Jun 2020 11:03:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/isXJTAEVsTEjXu5Lti7BqW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[eBay sign]]></media:description>                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/isXJTAEVsTEjXu5Lti7BqW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Six former senior <a href="https://www.itpro.com/business-strategy/30439/ebay-dumps-paypal-after-15-years-together" target="_blank" data-original-url="https://www.itpro.com/business-strategy/30439/ebay-dumps-paypal-after-15-years-together?amp">eBay</a> employees have been charged with launching a campaign to intimidate and terrorise the owners of a website that was critical of the e-commerce website. </p><p>The ex-employees sent sinister items, such as a funeral wreath and a bloody mask of a pigs head, to the door of a Massachusetts couple that edited and published the online newsletter, according to a <a href="https://www.theguardian.com/technology/2020/jun/15/ebay-employees-stalking-charges-spiders-cockroaches-pig-mask" target="_blank">federal court</a>. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/634858/qa-how-can-businesses-deal-with-cyber-stalking" data-original-url="/634858/qa-how-can-businesses-deal-with-cyber-stalking">Q&A: How can businesses deal with cyber stalking?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/91941/disgruntled-ebay-users-revolt" data-original-url="/91941/disgruntled-ebay-users-revolt">Disgruntled eBay users revolt</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/90988/over-half-of-all-phishing-emails-aimed-at-paypal-users-with-ebay-accounts-not-far-behind" data-original-url="/90988/over-half-of-all-phishing-emails-aimed-at-paypal-users-with-ebay-accounts-not-far-behind">Over half of all phishing emails aimed at PayPal users, with eBay accounts not far behind</a></p></div></div><p>The group targeted the couple after eBay executives became upset by the newsletters' coverage of the platform. They sent a number of strange items, including live spiders and cockroaches, and attempted to smear the couple by putting their names on pornographic material which they then sent to their neighbours.</p><p>According to officials, they also attempted to break into the couple's garage to install a <a href="https://www.itpro.com/technology/blockchain" target="_blank" data-original-url="https://www.itpro.com/613570/gps-tech-monitors-driving-performance-on-buses">GPS</a> device on their car. </p><p>"This was a determined, systematic effort by senior employees of a major company to destroy the lives of a couple in Natick all because they published content that company executives didn't like. For a while they succeeded, psychologically devastating these victims for weeks as they desperately tried to figure out what was going on and stop it," Massachusetts US attorney, Andrew Lelling, told reporters.</p><p>James Baugh, former senior director of safety & security at eBay, and David Harville, the company's director of global resiliency, have been charged with conspiracy to commit <a href="https://www.itpro.com/634858/qa-how-can-businesses-deal-with-cyber-stalking" target="_blank" data-original-url="https://www.itpro.com/634858/qa-how-can-businesses-deal-with-cyber-stalking">cyber stalking</a> and conspiracy to tamper with witnesses.</p><p>The other former employees charged are Stephanie Popp, Brian Gilbert, Stephanie Stockwell and Veronica Zea.</p><p>According to court documents, two members of the group orchestrated the plot to go after the couple because the newsletter published an article about litigation that involved eBay. It cites an unnamed executive that directed Baugh to "take her down", allegedly referring to the newsletter's editor. </p><p>The employees also set up fake social media accounts to send threatening messages to the couple and posted their names and address online to encourage people to knock on their door.</p><p>According to a company statement, <a href="https://www.itpro.com/security/25975/ebay-refuses-to-fix-app-security-flaw" target="_blank" data-original-url="https://www.itpro.com/security/25975/ebay-refuses-to-fix-app-security-flaw">eBay</a> launched an internal investigation in August after it was notified by the police of suspicions actions by its security personnel. The employees were fired a month later.</p><p>CEO Devin Wenig also stepped down in September, citing differences with the board of directors at the time. The company didn't clarify whether its investigation played a role in his departure.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ North Korean hackers allegedly targeted Indian space agency ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34779/north-korean-hackers-allegedly-targeted-indian-space-agency</link>
                                                                            <description>
                            <![CDATA[ The Dtrack malware infection successfully disrupted an active lunar mission ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">briLuudaeSkiQCbsEYh6Wf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/txpFD8TqmvS4U5LPHbyqpJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Nov 2019 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/txpFD8TqmvS4U5LPHbyqpJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A rocket taking off out of clouds to a planet]]></media:description>                                                            <media:text><![CDATA[A rocket taking off out of clouds to a planet]]></media:text>
                                <media:title type="plain"><![CDATA[A rocket taking off out of clouds to a planet]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/txpFD8TqmvS4U5LPHbyqpJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>At least five critical Indian government agencies have been reportedly targeted by North Korean hackers in recent months, including its atomic regulatory board and space agency.</p><p>The Indian Space Research Organisation (ISRO) was alerted by a US cyber security company to a potential malware breach in early September, according to <a href="https://indianexpress.com/article/india/not-only-kudankulam-isro-too-was-alerted-of-cyber-security-breach-6105184" target="_blank"><em>the Indian Express</em></a>. The alert suggested that cyber criminals had infiltrated master 'domain controllers' at the Kudankulam nuclear power plant and the ISRO using the same malware strain.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33609/fbi-thwarts-lazarus-linked-north-korean-surveillance-malware" data-original-url="/security/33609/fbi-thwarts-lazarus-linked-north-korean-surveillance-malware">FBI thwarts Lazarus-linked North Korean surveillance malware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30510/kaspersky-north-korea-framed-for-winter-olympics-malware" data-original-url="/hacking/30510/kaspersky-north-korea-framed-for-winter-olympics-malware">Kaspersky: North Korea framed for Winter Olympics malware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-infrastructure/34019/europe-s-galileo-satellite-system-crippled-by-days-long-outage" data-original-url="/it-infrastructure/34019/europe-s-galileo-satellite-system-crippled-by-days-long-outage">Europe’s Galileo satellite system crippled by days-long outage</a></p></div></div><p>The incident also may have had an effect on a failed lunar landing mission, Chandrayaan 2, which was due to touch down approximately 100 hours after the attack struck, sources who spoke with the newspaper said.</p><p>This mission was due to make a soft-landing on the Moon's South Pole on 7 September but lost contact with the earth station.</p><p>India's National Cyber Coordination Centre, similar in nature to the UK's National Cyber Security Centre (NCSC), was tipped off on 3 September about the attacks, with the power plant breach becoming public knowledge just last week.</p><p>The attackers were among at least five launched against India's critical national infrastructure, according to the founder of cyber security firm Security Brigade Yash Kadakia, speaking with <a href="https://www.ft.com/content/ac6a8782-ffad-11e9-b7bc-f3fa4e77dd47" target="_blank"><em>the FT</em></a>.</p><p>The malware strain itself was identified as Dtrak, which could allow cyber criminals to gain control over any and all infected devices. The 'domain controllers' targeted were server computers that responded to security authentication requests.</p><p>The Kudankulam plant initially said no cyber attack on its systems were possible, but the Nuclear Power Corporation of India which runs the plant conceded later that an infection had spread into the administrative network.</p><p>People within the respective agencies are reported to have opened phishing emails that were sent by the hackers, which led to the malware infiltrating agency systems.</p><p>Dtrack has been associated with activity by the Lazarus group, <a href="https://securelist.com/my-name-is-dtrack/93338" target="_blank">Kaspersky's SecureList platform suggests</a>. The Lazarus Group has, in turn, been previously associated with the North Korean state.</p><p>A variation of the strain was last used on a widespread scale in 2018 in the form of a banking malware that targeted Indian banks. Analysis by Kaspersky showed the malware was designed to be planted on ATMs, where it could read and store information from cards inserted into the individual machines.</p><p>This attack may have been part of its 'FASTCash' scheme, identified by Symantec, <a href="https://www.itpro.com/cyber-crime/32331/lazarus-hackers-engage-in-fastcash-scheme-to-steal-tens-of-millions-of-dollars" target="_blank" data-original-url="https://www.itpro.com/cyber-crime/32331/lazarus-hackers-engage-in-fastcash-scheme-to-steal-tens-of-millions-of-dollars">through which Lazarus aimed to steal millions of dollars</a> from ATMs across the world.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US allies targeted by WhatsApp video hack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34715/us-allies-targeted-by-whatsapp-video-hack</link>
                                                                            <description>
                            <![CDATA[ Victims include high profile government and military officials spread across 20 countries, report ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3pgJf5k2Rw3nxAvZcuVWoK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N8B2T7rWeumat7ruF429Vc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Nov 2019 10:16:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N8B2T7rWeumat7ruF429Vc-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WhatsApp, Web app, Messaging]]></media:description>                                                            <media:text><![CDATA[WhatsApp, Web app, Messaging]]></media:text>
                                <media:title type="plain"><![CDATA[WhatsApp, Web app, Messaging]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N8B2T7rWeumat7ruF429Vc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Senior government and military officials in US-allied countries were the target of a WhatsApp video hack earlier this year, it has emerged.</p><p>The hack allegedly enabled attackers to take over a users smartphone through the Facebook-owned messenger app simply by ringing the target's device, according to <a href="https://www.reuters.com/article/us-facebook-cyber-whatsapp-nsogroup/exclusive-whatsapp-hacked-to-spy-on-top-government-officials-at-u-s-allies-sources-idUSKBN1XA27H" target="_blank"><em>Reuters</em></a>.</p><p>On Tuesday, Facebook launched legal action against an Israeli-based <a href="https://www.itpro.com/spyware/30001/what-is-spyware" target="_blank" data-original-url="https://www.itpro.com/spyware/30001/what-is-spyware">spyware</a> firm NSO Group also known as Q Cyber Technologies which is part-owned by Novalpina Capital, a European private equity firm.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/31575/why-encryption-is-the-key-to-your-security-strategy" data-original-url="/security/31575/why-encryption-is-the-key-to-your-security-strategy">Why encryption is the key to your security strategy</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34572/uk-and-us-plead-with-mark-zuckerberg-to-bin-encryption-plans" data-original-url="/security/34572/uk-and-us-plead-with-mark-zuckerberg-to-bin-encryption-plans">UK and US plead with Mark Zuckerberg to bin encryption plans</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/encryption/32302/critical-vulnerabilities-ssd-encryption" data-original-url="/encryption/32302/critical-vulnerabilities-ssd-encryption">Researchers expose 'critical vulnerabilities' in SSD encryption</a></p></div></div><p>The social network accused it of providing tools to government agencies to target individuals through <a href="https://www.itpro.com/bugs/32095/whatsapp-fixes-video-call-security-bug-that-enabled-hackers-to-take-over-app" target="_blank" data-original-url="https://www.itpro.com/bugs/32095/whatsapp-fixes-video-call-security-bug-that-enabled-hackers-to-take-over-app">WhatsApp video calling</a>.</p><p>It's alleged that the group developed Pegasus, a tool that exploited a vulnerability in the messaging app to track users. WhatsApp fixed this issue in May and began an investigation with the University of Toronto's Citizen's Lab.</p><p>"As part of our investigation into the incident, Citizen Lab has identified over 100 cases of abusive targeting of human rights defenders and journalists in at least 20 countries across the globe, ranging from Africa, Asia, Europe, the Middle East, and North America that took place after Novalpina Capital acquired NSO Group and began an ongoing public relations campaign to promote the narrative that the new ownership would curb abuses," the Lab said in a <a href="https://citizenlab.ca/2019/10/nso-q-cyber-technologies-100-new-abuse-cases" target="_blank">blog post</a>.</p><p>NSO Group has said it sells spyware exclusively to government customers, however, in a statement to <em>Reuters</em> it said it was "not able to disclose who is or is not a client or discuss specific uses of its technology". Initially, the firm had denied any wrongdoing, saying that its products are for governments to catch terrorists.</p><p>However, it has been used to target high profile government and military officials, spread across 20 countries on five continents, according to <em><a href="https://www.reuters.com/article/us-facebook-cyber-whatsapp-nsogroup/exclusive-whatsapp-hacked-to-spy-on-top-government-officials-at-u-s-allies-sources-idUSKBN1XA27H" target="_blank">Reuters</a>,</em> which cites sources familiar with WhatsApp's internal investigation. What's more, these sources said many of these nations are US allies.</p><p>WhatsApp claimed that approximately 1,400 individuals were effected by attacks launched between April and May, but these were initially thought to be just journalists and human rights activists.</p><p><strong>30/10/2019: WhatsApp sues NSO Group for Pegasus spyware attack</strong></p><p>Facebook has launched legal action against an Israeli spyware firm after accusing the company of providing the tools for government agencies to target individuals through WhatsApp video calling.</p><p>Pegasus, allegedly developed by NSO Group, was <a href="https://www.itpro.com/spyware/33632/whatsapp-call-hack-installs-spyware-on-users-phones" target="_blank" data-original-url="https://www.itpro.com/spyware/33632/whatsapp-call-hack-installs-spyware-on-users-phones">used between April May to attack a litany of users</a> by exploiting a WhatsApp vulnerability in order to track their communications and even their location. WhatsApp, which is owned by Facebook, claims approximately 1,400 individuals were impacted by the attack, including a raft of journalists and human rights activists, <a href="https://scontent.whatsapp.net/v/t61/71401326_433512174021632_8968884873265386273_n.pdf/WhatsAppNDCAL102019.pdf?_nc_oc=AQnJ5vPzIj3Jt1WQXsry_1g8ckDfZOUwPXg-kP-C-qGIheWmpTabXgTres415ORMXfg&_nc_ht=scontent.whatsapp.net&oh=8894591c759637d52bb33bedf7fa2e7a&oe=5DBBF747" target="_blank">according to court filings</a>.</p><p>NSO Group is known for developing spyware technology for national governments and public sector agencies. WhatsApp, with the help of CitizenLab, claims NSO Group and similar companies do not have strict enough controls in place to ensure their products aren't complicit in cyber attacks.</p><p>"Some of your most personal moments are shared on WhatsApp, which is why we provide end-to-end encryption for all messages and calls by default," <a href="https://faq.whatsapp.com/help/video-calling-cyber-attack" target="_blank">WhatsApp said in a blog post</a>.</p><p>"This attack was developed to access messages after they were decrypted on an infected device, abusing in-app vulnerabilities and the operating systems that power our mobile phones."</p><p>CitizenLab claims the sophisticated Pegasus attack involved malware being installed on users phones through a number of tactics, ranging from zero-day exploits to deception. Once installed, it contacted the operator's command and control (C&C) servers to retrieve commands, and exfiltrate users' personal data.</p><p>WhatsApp claims that clients of NSO, which vary from government agencies and secret services to private companies, could at this stage retrieve any personal data harvested from targeted users.</p><p>The lawsuit claims NSO Group violated several federal acts that prohibit computer misuse, as well as violating WhatsApp's property. Facebook is seeking "reasonable damages" as a result of the claim.</p><p>"In the strongest possible terms, we dispute today's allegations and will vigorously fight them," a spokesperson from NSO said.</p><p>"The sole purpose of NSO is to provide technology to licensed government intelligence and law enforcement agencies to help them fight terrorism and serious crime. Our technology is not designed or licensed for use against human rights activists and journalists."</p><p>"The truth is that strongly encrypted platforms are often used by paedophile rings, drug kingpins and terrorists to shield their criminal activity.</p><p>"Without sophisticated technologies, the law enforcement agencies meant to keep us all safe face insurmountable hurdles. NSO's technologies provide proportionate, lawful solutions to this issue."</p><p>The company's firm stance against <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption</a> chimes with that persistently expressed by several national governments, including the UK government.</p><p>Security agencies have <a href="https://www.itpro.com/security/34572/uk-and-us-plead-with-mark-zuckerberg-to-bin-encryption-plans" target="_blank" data-original-url="https://www.itpro.com/security/34572/uk-and-us-plead-with-mark-zuckerberg-to-bin-encryption-plans">long-railed against end-to-end encryption</a>, used in WhatsApp and other platforms, as it prevents agents from accessing the private communications data of those suspected of crimes.</p><p>The <a href="https://www.itpro.com/encryption/32593/australia-passes-controversial-anti-encryption-law" target="_blank" data-original-url="https://www.itpro.com/encryption/32593/australia-passes-controversial-anti-encryption-law">Australian government even passed a controversial law against encryption</a> in 2018, which would allow law enforcement to compel tech and telecoms firms to break their own encryption.</p><p>The long-standing request for social media firms to insert backdoors into their products, however, has been <a href="https://www.itpro.com/it-legislation/24741/should-tech-firms-leave-the-uk-over-encryption-laws" target="_blank" data-original-url="https://www.itpro.com/it-legislation/24741/should-tech-firms-leave-the-uk-over-encryption-laws">roundly rejected by developers</a> due to risks that it would also allow cyber criminals to exploit them.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Could Virgin Galactic’s IPO indicate an interstellar step change for cyber security? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34711/could-virgin-galactic-s-ipo-indicate-an-interstellar-step-change-for-cyber-security</link>
                                                                            <description>
                            <![CDATA[ When we think about the cyber attacks of the future, we may have to think bigger ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hEtnWGnkRGvckzYWFUckmi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gKAYnZUw7zVNZnds5axamB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Oct 2019 11:09:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gKAYnZUw7zVNZnds5axamB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Virgin Galactic]]></media:description>                                                            <media:text><![CDATA[Virgin Galactic]]></media:text>
                                <media:title type="plain"><![CDATA[Virgin Galactic]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gKAYnZUw7zVNZnds5axamB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The largely unknown but somewhat predictable future of cyber threats is both fascinating and terrifying perhaps in equal measure. With Industry 4.0 on the horizon and all the new technology that's going to come with it, a brand new state of affairs is likely to greet cyber security practitioners.</p><p>There's technology emerging right now that will eventually lend its hand to the dark side of cyber; deepfake technology may well join ransomware campaigns and 5G is still scaring the pants off networking professionals. Ten years down the line, however, we can indeed expect previously fantastical ideas of <a href="https://www.itpro.com/security/34698/what-are-the-biggest-career-trends-in-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/34698/what-are-the-biggest-career-trends-in-cyber-security">cyber security</a> threats to become reality. With Virgin Galactic planning its first trips to the surface of space next year, you can bet good money that hackers are also going to want to head to the stratosphere and beyond. So, what do the next ten years of cyber security really look like?</p><h3 class="article-body__section" id="section-the-space-tourism-opportunity"><span>The space tourism opportunity</span></h3><p>Cyber attacks will soon expand their targets to include systems located in space and the increasingly automated maritime sector, according to a according to Tony Cole, (ISC)2 board member and cyber security expert.</p><p>Virgin Galactic's recent landmark IPO may have roused the interest of every stockbroker across the pond, but it could indicate a step change in the cyber security landscape, particularly where hackers direct their nefarious attentions in years to come.</p><p>"Ten years from now, we may have somebody on Mars," said Cole to <em>IT Pro</em>, and thanks to the low Earth orbit technology being pioneered by Virgin Galactic, internet services are going to be beamed to those who take part in space tourism. Where there's internet, there's the possibility to hack something.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34698/what-are-the-biggest-career-trends-in-cyber-security" data-original-url="/security/34698/what-are-the-biggest-career-trends-in-cyber-security">What are the biggest career trends in cyber security?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34703/iot-botnets-are-on-the-rise-and-5g-isn-t-helping-anything" data-original-url="/security/34703/iot-botnets-are-on-the-rise-and-5g-isn-t-helping-anything">IoT botnets are on the rise and 5G isn’t helping anything</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34693/what-to-expect-from-isc2-security-congress" data-original-url="/security/34693/what-to-expect-from-isc2-security-congress">What to expect from (ISC)2 Security Congress</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-attacks/30393/maersk-rebuilt-hefty-it-infrastructure-a-mere-10-days-after-notpetya-attack" data-original-url="/cyber-attacks/30393/maersk-rebuilt-hefty-it-infrastructure-a-mere-10-days-after-notpetya-attack">Maersk rebuilt hefty IT infrastructure a mere 10 days after NotPetya attack</a></p></div></div><p>Thinking further in the future, "somebody may be FaceTiming their kids and live streaming to YouTube from Mars," said Cole. NASA TV already broadcasts numerous livestreams and interviews from the International Space Station back to Earth via the internet, so Cole thinks "we're going to see a lot of expansion in that area". He added that he thought the main opportunity for space-based cyber attacks involves disruption of services.</p><p>However, as we start to send more humans space-bound with new technology, other innovations arise to accompany it. Laser-based quantum communication, which is inherently secure, has been proven possible for years now and it's one area of research which could aim to prevent nefarious hackers from intercepting, altering or deleting data transmitted from Earth to space.</p><p>For now, speculating about the possibility of space-based cyber attacks is just that speculation. There's too much left to learn about what that world will look like to make any accurate predictions, but it's undeniably a logical next-step for hackers looking to make their CV stand out from the crowd.</p><h3 class="article-body__section" id="section-less-39-up-in-the-air-39"><span>Less 'up in the air'</span></h3><p>We can better predict other methods of cyber attacks that will proliferate over the coming years and one area of concern is the maritime sector, which is digitising at a rapid rate, such as the addition of sensors to shipping containers. As the digitisation process matures, it will naturally invite unwanted attention from hackers.</p><p>"You're going to see the impact in maritime where we have crews that are much, much smaller because almost everything's going to be automated, all the containers are going to be centralised that's going to be very, very interesting," said Cole.</p><p>"Going to back to the space piece, you're going to have blanket satellites around the globe that are also able to track other ships ... then you're going to see jamming for some of these satellites, potentially." Hacking ships, the containers they carry and the databases that control where they go can result in sabotaged shipments, resulting in the downfall in the shipping company through reputational damage.</p><h3 class="article-body__section" id="section-no-consensus"><span>No consensus</span></h3><p>Of course, when you ask different experts about the same questions, you're almost definitely going to get different answers, especially when it's guesswork. That's no different here and after speaking to such experts recently, <em>IT Pro</em> has predictably received different responses.</p><p>One of the more compelling answers relates to AI-driven malware and AI-driven defences, technology that's still far away from widespread deployment, but one of the more likely answers to the question.</p><p>For example, <a href="https://www.itpro.com/security/34660/hackers-are-no-longer-winning-says-kpmg-cyber-chief" target="_blank" data-original-url="https://www.itpro.com/security/34660/hackers-are-no-longer-winning-says-kpmg-cyber-chief">British universities are currently testing the idea of creating an AI that can think differently to human hackers</a> and find new exploits in systems using methods that wouldn't come naturally to the way we think about things.</p><p>At the moment, AI-driven attacks and defences are embryonic and experimental at best "just have a conversation with Alexa, Siri or Google and [you'll see] it's not that advanced yet [and] there are billions poured in just those three," said Cole.</p><p>He also said that it's possible these kinds of attacks are currently only being used by nation-states and are in the early stages of development. But, it's "only a matter of time" before the code starts to leak underground and businesses start to feel to the wrath of malware designed to outfox AI-driven defences.</p><p>We also heard earlier this week at (ISC)2 Security Congress that <a href="https://www.itpro.com/security/34703/iot-botnets-are-on-the-rise-and-5g-isn-t-helping-anything" target="_blank" data-original-url="https://www.itpro.com/security/34703/iot-botnets-are-on-the-rise-and-5g-isn-t-helping-anything">IoT botnets are on the rise</a> and are showing no signs of slowing down. This is partly due to manufacturers competing in races to get new features to market before competitors, usually at the cost of security provisions.</p><p>Others even go far as to say that politicians may start commissioning hackers to develop <a href="https://www.itpro.com/ransomware/34432/deepfake-ransomware-among-experts-list-of-cyber-fears" target="_blank" data-original-url="https://www.itpro.com/ransomware/34432/deepfake-ransomware-among-experts-list-of-cyber-fears">deepfake ransomware</a> to tarnish the reputation of the opposition campaigners. Whatever the future of cyber security looks like, it's probably going to be a lot wilder than it is currently.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian hacking group masquerades as Iranian spy network ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34667/russian-hacking-group-masquerades-as-iranian-spy-network</link>
                                                                            <description>
                            <![CDATA[ Hacking technique highlights how difficult it is to attribute blame after a cyber attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rfRpUpm2Vt44DV4ngcbEfo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/M4RyGzwEbWsD2Gak7ssgQh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Oct 2019 11:11:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/M4RyGzwEbWsD2Gak7ssgQh-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker in front of a Russian flag]]></media:description>                                                            <media:text><![CDATA[Hacker in front of a Russian flag]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker in front of a Russian flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/M4RyGzwEbWsD2Gak7ssgQh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Russian hackers hijacked Iranian <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" target="_blank" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber espionage</a> infrastructure to attack government and industry organisations in dozens of countries while pretending to be Iranian cyber attackers.</p><p>The Turla group, also known as VENOMOUS BEAR, infiltrated the systems of Iranian cyber criminals to launch attacks on Western targets, according to a joint report by the National Cyber Security Centre (NCSC) and National Security Agency (NSA).</p><p>Analysis by the two agencies revealed the Russian-linked group acquired a pair of tools associated with Iranian hackers, namely Neuron and Nautilus, as well as the data linked with it.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" data-original-url="/security/31527/how-russia-hacked-the-2016-election">How Russia hacked the 2016 election</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="/security/34616/the-top-password-cracking-techniques-used-by-hackers">The top 12 password-cracking techniques used by hackers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-warfare/33958/are-we-in-the-midst-of-a-cyber-war" data-original-url="/cyber-warfare/33958/are-we-in-the-midst-of-a-cyber-war">Are we in the midst of a cyber war?</a></p></div></div><p>Turla then tested these tools against victims it had already compromised, before turning its attention towards new victims. Hackers scanned target organisations for backdoors planted by Iranian cyber criminals in order to exploit them and gain a foothold.</p><p>"The behaviour of Turla in scanning for backdoor shells indicates that whilst they had a significant amount of insight into the Iranian tools, they did not have full knowledge of where they were deployed," the <a href="https://www.ncsc.gov.uk/news/turla-group-exploits-iran-apt-to-expand-coverage-of-victims" target="_blank">NCSC said in an advisory</a>.</p><p>"While attribution of attacks and proving authorship of tools can be very difficult particularly in the space of incident response on a victim network the weight of evidence demonstrates that Turla had access to Iranian tools and the ability to identify and exploit them to further Turla's own aims."</p><p>The <a href="https://www.itpro.com/security/34038/microsoft-warns-business-customers-at-risk-of-state-sponsored-attacks" target="_blank" data-original-url="https://www.itpro.com/security/34038/microsoft-warns-business-customers-at-risk-of-state-sponsored-attacks">volume of cyber attacks emanating from both Russia and Iran</a> have risen substantially in recent months and years, as geopolitical tensions with the US have escalated.</p><p>Microsoft, for example, disclosed data in July suggesting that approximately 10,000 of its customers were targeted by state-sponsored attacks during the 12 months. Further analysis showed these attackers were predominately launched by five groups divided between three nations; Iran, Russia, and North Korea.</p><p>Analysis by the NCSC and NSA shows that the Neuron and Nautilus tools, deployed by Turla, were first seen deployed with the Snake rootkit on a range of victims. Followup investigations have shown inconsistencies, however, with these tools also deployed on a large cluster of victims in the Middle East, but not all in conjunction with the Snake implant.</p><p>Breaking this down further, it became clear to investigators that these victims were targeted by cyber criminals using <a href="https://www.itpro.com/security/27098/best-vpn-services" target="_blank" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">virtual private</a> server (IP) addresses linked with Iranian hackers. Furthermore, Iranian cyber criminals were actually the first to deploy these tools, with Turla piggybacking off them subsequently.</p><p>Turla, moreover, accessed and used the command and control (C2) infrastructure of Iranian hacking groups to launch its own attacks. The group also deployed its own implants against the infrastructure used by Iranian groups, using this to further their own access into the global operational infrastructure and to exfiltrate data.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is cyber warfare? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/28170/what-is-cyber-warfare</link>
                                                                            <description>
                            <![CDATA[ We explain what cyber warfare is and why you need to pay attention to the threats posed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a6RV3jwS84ZFsqzAc6jncY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PsnQ9icqFsoufJ4SikjD8g-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Sep 2019 10:02:00 +0000</pubDate>                                                                                                                                <updated>Fri, 20 May 2022 12:13:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PsnQ9icqFsoufJ4SikjD8g-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A red world map with white pixels]]></media:description>                                                            <media:text><![CDATA[A red world map with white pixels]]></media:text>
                                <media:title type="plain"><![CDATA[A red world map with white pixels]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PsnQ9icqFsoufJ4SikjD8g-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The world has changed markedly since the widespread uptake of technology - there isn’t a single industry that has been left unaffected by the world’s transition to a more tech-assisted life.</p><p>While not an industry itself, the statement also rings true for international conflict where the days of traditional, or 'kinetic', warfare that purely takes place on land, air, and sea, are now far behind us.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/27729/are-we-ready-for-cyber-war" data-original-url="/security/27729/are-we-ready-for-cyber-war">Are we ready for cyber war?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/malware/33734/laptop-laden-with-malwares-greatest-hits-sells-for-13m" data-original-url="/malware/33734/laptop-laden-with-malwares-greatest-hits-sells-for-13m">Laptop laden with malware's greatest hits sells for $1.3m</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-warfare/33958/are-we-in-the-midst-of-a-cyber-war" data-original-url="/cyber-warfare/33958/are-we-in-the-midst-of-a-cyber-war">Are we in the midst of a cyber war?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-warfare/34444/universities-a-huge-target-for-nation-state-attackers-warns-ncsc" data-original-url="/cyber-warfare/34444/universities-a-huge-target-for-nation-state-attackers-warns-ncsc">Universities a 'huge target' for nation-state attackers, warns NCSC</a></p></div></div><p>The value of technology is lost on no-one and certainly not on the finest hackers on the planet who are often courted by nation-states in their ambition to build a battalion of front-line cyber security experts. This is because cyber warfare is on the rise - taking out a country’s Internet systems remotely, perhaps via a <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">DDoS attack</a>, is more time and resource-efficient than sending a squadron to blow up the physical infrastructure, for example.</p><p>Since technology has value everywhere, it doesn’t take a military mind to understand that the same level of disruption can be caused more easily and with less risk to life from behind a keyboard, nowadays, than it sometimes can on the battlefield.</p><h2 id="is-anyone-currently-engaged-in-cyber-warfare">Is anyone currently engaged in cyber warfare?</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aBycXhZoRVuqxFZVzicEUR" name="" alt="A warning of a Student infection in front of a binary background" src="https://cdn.mos.cms.futurecdn.net/aBycXhZoRVuqxFZVzicEUR.jpg" mos="https://cdn.mos.cms.futurecdn.net/aBycXhZoRVuqxFZVzicEUR.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The blunt answer to this question is ‘yes’. The ongoing conflict in Ukraine, instigated by Russia’s invasion earlier this year has led to one of the most visceral examples of concurrent kinetic and open cyber warfare seen to date.</p><p>We’ve seen a string of remarkable incidents happen on the cyber side that would each in themselves merit consideration for a ‘story of the year’ award in any other, more normal and historically insignificant year.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=46862322&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><p>For example, the Ukrainian government <a href="https://www.itpro.com/security/botnets/367744/ukraines-vigilante-it-army-deploys-ddos-bot-automate-russia-attacks" data-original-url="https://www.itpro.com/security/botnets/367744/ukraines-vigilante-it-army-deploys-ddos-bot-automate-russia-attacks">has assembled a cross-border ‘IT army’</a> to help fight against Russian cyber attacks - of which there have been many. We’ve also seen underground criminal outfits <a href="https://www.itpro.com/security/hacking/367685/russian-hackers-declare-war-on-10-countries-after-failed-eurovision-ddos" data-original-url="https://www.itpro.com/security/hacking/367685/russian-hackers-declare-war-on-10-countries-after-failed-eurovision-ddos">pledge allegiance to Russia</a>, dedicating their nefarious services to assist the aggressors in cyber space, while foot soldiers continue to fight the war on the ground.</p><p>The situation in Ukraine aside, just about every developed country has robust capabilities in cyber space and there are a number of countries actively developing digital weapons to use in future conflicts. Russia and China are the main focal points there, but other countries that are just as active include the US, France, and Israel.</p><p>This isn't to say that these countries are using these capabilities, although we know they possess the cyber weapons themselves and have used them in the past. For example, Stuxnet was a joint venture between the US and Israel to destroy Iran's nuclear programme capability.</p><h2 id="what-weapons-are-used-in-cyber-war">What weapons are used in cyber war?</h2><p>The tools of destruction used in cyber attacks do bear some resemblance to weapons commonly used in other criminal attacks, in that they incur the same effect.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kPuErMBvZCZGuFde9ciRgW" name="" alt="A bot net" src="https://cdn.mos.cms.futurecdn.net/kPuErMBvZCZGuFde9ciRgW.jpg" mos="https://cdn.mos.cms.futurecdn.net/kPuErMBvZCZGuFde9ciRgW.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>For example, <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet" data-original-url="https://www.itpro.com/botnets/1644/what-is-a-botnet">botnets</a> that exist to launch distributed denial of service (DDoS) attacks can target critical services and cripple entities digitally or may even serve as a diversion from other malicious cyber activities, such as attempts to infiltrate the network. <a href="https://www.itpro.com/616135/businesses-cant-ignore-spear-phishing-attacks" target="_blank" data-original-url="https://www.itpro.com/616135/businesses-cant-ignore-spear-phishing-attacks">Spear phishing</a> and social engineering, too, are techniques also deployed to get cyber criminals closer to the targeted systems. Threats from the inside pose a significant risk for organisations hoping to safeguard their systems against intruders, though are highly potent as far as hackers are concerned, allowing hackers to directly expose a network to a threat, or allow a group to steal sensitive data.</p><p>One useful example of how multiple layers of attack can be used to great effect is <a href="https://www.itpro.com/627223/stuxnet-hits-iran-nuclear-plant" data-original-url="https://www.itpro.com/627223/stuxnet-hits-iran-nuclear-plant">Stuxnet, which was first encountered ten years ago</a>. An employee situated inside an Iranian nuclear power site inserted a USB stick embedded with the Stuxnet worm, either knowingly or unknowingly, into an air-gapped system. Exploiting multiple zero-day exploits, this malware searched for specific software running centrifuges, and commanded them to spin dangerously fast and then slow for a period of months without being detected. These centrifuges eventually broke and more than 1,000 machines were rendered useless.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NeFDhiupASoeoyipbhF9uf" name="NeFDhiupASoeoyipbhF9uf.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/NeFDhiupASoeoyipbhF9uf.jpg" mos="https://cdn.mos.cms.futurecdn.net/NeFDhiupASoeoyipbhF9uf.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The state of brand protection 2021</strong></p><p class="fancy-box__body-text">A new front opens up in the war for brand safety</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360246/the-state-of-brand-protection-2021" data-original-url="/security/cyber-security/360246/the-state-of-brand-protection-2021">FREE DOWNLOAD</a></p></div></div><p>The attack was never successfully blamed on any known party, although it's thought that this cyber weapon was created jointly between the US and Israeli military entities. While neither nation has denied the charge, it's also alleged <a href="https://www.telegraph.co.uk/news/worldnews/middleeast/israel/8326387/Israel-video-shows-Stuxnet-as-one-of-its-successes.html">Stuxnet was played as part of a showreel</a> at the retirement party of the head of the Israeli Defence Force (IDF).</p><p>However, cyber warfare can also take a more subtle form. In April 2021, MI5 issued a warning of <a href="https://www.itpro.com/security/phishing/359276/mi5-warns-of-foreign-agents-using-linkedin-to-steal-information" data-original-url="https://www.itpro.com/security/phishing/359276/mi5-warns-of-foreign-agents-using-linkedin-to-steal-information">foreign agents using LinkedIn to steal information</a>, with more than 10,000 British nationals, including government employees, having been approached by <a href="https://www.itpro.com/security/hacking/359144/data-belonging-to-500-million-linkedin-users-found-for-sale-on-hacker" data-original-url="https://www.itpro.com/security/hacking/359144/data-belonging-to-500-million-linkedin-users-found-for-sale-on-hacker">fake LinkedIn</a> profiles associated with hostile states. However, public sector workers aren’t the only targets: in July, the <a href="https://www.itpro.com/security/cyber-terrorism/360221/mi5-chief-to-warn-public-of-cyber-espionage-threat" data-original-url="https://www.itpro.com/security/cyber-terrorism/360221/mi5-chief-to-warn-public-of-cyber-espionage-threat">MI5’s director general warned</a> that businesses engaged in export, scientific research, and the high-tech sector should also be aware of the potential risks of falling victim to cyber espionage. These attacks have prompted the Centre for the Protection of National Infrastructure (CPNI) to launch the <a href="https://www.cpni.gov.uk/security-campaigns/think-you-link">Think Before You Link</a> campaign, which warns people against accepting messages or connection requests from unknown accounts.</p><h2 id="other-examples-of-cyber-warfare">Other examples of cyber warfare</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wDVUpxBULdy4FgbjK7iUEP" name="" alt="The main UN building with flags of several countries on display" src="https://cdn.mos.cms.futurecdn.net/wDVUpxBULdy4FgbjK7iUEP.jpg" mos="https://cdn.mos.cms.futurecdn.net/wDVUpxBULdy4FgbjK7iUEP.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>While Stuxnet is one of the best examples of cyber warfare in action, there are other significant events that can be attributed to state-level attacks.</p><p>The most recent example, and perhaps the most prominent in recent history, is Russian aggression towards Ukraine, which has included a <a href="https://www.itpro.com/security/cyber-warfare/367342/russian-cyber-attacks-should-your-business-worry" data-original-url="https://www.itpro.com/security/cyber-warfare/367342/russian-cyber-attacks-should-your-business-worry">sophisticated hacking element</a>. This includes the NotPetya malware attack that masqueraded as typical ransomware but was in fact designed to destroy the systems it infected, or the <a href="https://www.itpro.com/malware/25804/ukrainian-power-grid-downed-by-cyber-attack" target="_blank" data-original-url="https://www.itpro.com/malware/25804/ukrainian-power-grid-downed-by-cyber-attack">BlackEnergy</a> attack in 2015, which cut the power to 700,000 homes across Ukraine.</p><p>The UK, US, and EU have all <a href="https://www.itpro.com/security/cyber-attacks/367634/five-eyes-and-us-governments-confirm-russia-behind-attacks" data-original-url="https://www.itpro.com/security/cyber-attacks/367634/five-eyes-and-us-governments-confirm-russia-behind-attacks">blamed Russia</a> for cyber attacks on Ukrainian infrastructure in the early stages of the Ukraine war, after a lengthy attribution process. This included attacks on Ukrainian government websites on 13 January 2022, which involved the deployment of the Whispergate destructive malware, as well as a 24 February attack on global communications company Viasat, which was attributed to the Russian military intelligence service (GRU).</p><p>Another nation that has been fairly active in the cyber warfare space is North Korea. Researchers have linked the country in the past to a hacking organisation Lazarus Group, which was behind the Sony hack of 2014 as well as a <a href="https://www.itpro.com/security/27561/bangladesh-bank-recovers-15m-from-cyber-hack" data-original-url="https://www.itpro.com/security/27561/bangladesh-bank-recovers-15m-from-cyber-hack">Bangladeshi bank</a> in 2016.</p><p>In September 2022, the US government even managed to <a href="https://www.itpro.com/security/cyber-attacks/369035/us-reclaims-30-million-in-crypto-from-lazarus-group" data-original-url="https://www.itpro.com/security/cyber-attacks/369035/us-reclaims-30-million-in-crypto-from-lazarus-group">confiscate $30 million</a> worth of <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining" data-original-url="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency</a> from the threat group. Lazarus had originally managed to steal the money from the token-based play-to-earn game Axie Infinity earlier in the year. This was reportedly the first time that cryptocurrency stolen by a North Korean hacking group had been seized.</p><p>During the pandemic, threat actors were also mobilising by focusing their efforts on public health providers and research facilities. This sector became a tempting target for state-sponsored cyber criminals considering how important healthcare and medical research became during the pandemic.</p><p>For example, the US Cybersecurity and Infrastructure Security Agency (CISA) and UK’s National Cyber Security Centre (NCSC) told organisations to be wary of password spraying attacks from state-backed hacking groups. The groups were reportedly focusing their efforts on pharmaceutical companies or healthcare bodies.</p><p>Even though the advisory the cyber security agencies published didn’t specifically name any threat actors, Microsoft discovered months later that healthcare companies carrying out vaccine research were being targeted by Russian and North Korean state-sponsored hackers. The groups launching the attacks were called Cerium, Zinc, and Strontium, and they targeted seven organisations, including a clinical research organisation.</p><p>Although ransomware attacks on healthcare providers can be <a href="https://www.itpro.com/security/innovation-at-work/29794/what-have-we-learnt-from-the-nhs-ransomware-attack" data-original-url="https://www.itpro.com/security/innovation-at-work/29794/what-have-we-learnt-from-the-nhs-ransomware-attack">traced back to long before the pandemic</a>, the last year has magnified these attacks, proving that no target is off-limits for cyber criminals. Attacks on <a href="https://www.itpro.com/security/ransomware/359466/colonial-pipeline-ransomware-attack" data-original-url="https://www.itpro.com/security/ransomware/359466/colonial-pipeline-ransomware-attack">key infrastructure may severely impact the functioning of a state</a>, but attacking hospitals can lead to much more than just financial loss. An example of such was the March 2020 attack on one of the largest coronavirus testing facilities in Czechia, which was forced to temporarily <a href="https://www.itpro.com/security/cyber-security/355108/hackers-target-hospital-computer-systems" data-original-url="https://www.itpro.com/security/cyber-security/355108/hackers-target-hospital-computer-systems">cancel surgeries and transfer new patients to other facilities</a> as it became a target of cyber criminals. In two days after the cyber attack took place, the number of confirmed coronavirus cases in the country more than doubled to 298.</p><h2 id="cyber-attacks-and-hybrid-warfare">Cyber attacks and hybrid warfare</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="a64JjgTWrdv9SfXZfbWZPF" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/a64JjgTWrdv9SfXZfbWZPF.jpg" mos="https://cdn.mos.cms.futurecdn.net/a64JjgTWrdv9SfXZfbWZPF.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Increasingly, cyber attacks are being seen as an aspect of what's known as hybrid warfare. As explained by <a href="http://theconversation.com/explainer-what-is-hybrid-warfare-and-what-is-meant-by-the-grey-zone-118841" target="_blank"><em>The Conversation</em></a>, the term hybrid warfare is ill-defined and has changed in meaning over the past ten years or so since it came into use. Increasingly, however, it's used to describe the typical cyber warfare practices laid out here with efforts to disrupt democratic processes.</p><p>For example, in the run-up to an election, "Group A" may engage in efforts to alter sentiment through channels like social media while simultaneously targeting the websites of its main competitors, "Group B" and "Group C", with DDoS attacks or cyber vandalism.</p><p>Often, it won't be Group A itself that engages in these activities, but instead, it will outsource to companies that specialise in the spreading of disinformation and hackers for hire. This makes it more difficult to trace back.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="d25pnmHteqMFEXehyV5g2n" name="d25pnmHteqMFEXehyV5g2n.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/d25pnmHteqMFEXehyV5g2n.png" mos="https://cdn.mos.cms.futurecdn.net/d25pnmHteqMFEXehyV5g2n.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Securing endpoints amid new threats</strong></p><p class="fancy-box__body-text">Ensuring employees have the flexibility and security to work remotely</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/367650/securing-endpoints-amid-new-threats" data-original-url="/technology/367650/securing-endpoints-amid-new-threats">FREE DOWNLOAD</a></p></div></div><p>This is a tactic also seen in state-sponsored cyber attacks, where countries claim an attack originates from "patriotic hackers" acting on their own terms without any persuasion or reward from the state.</p><p>Indeed, when it comes to <a href="https://www.itpro.com/cyber-warfare/34444/universities-a-huge-target-for-nation-state-attackers-warns-ncsc" target="_blank" data-original-url="https://www.itpro.com/cyber-warfare/34444/universities-a-huge-target-for-nation-state-attackers-warns-ncsc">nation-states</a>, we can see another aspect of hybrid cyber warfare when cyber attacks are carried out alongside "kinetic attacks", which is to say traditional warfare tactics like bombs. This is similar to when, in the past, saboteurs would target critical infrastructure ahead of an invasion, only now the attacks can happen remotely.</p><p>However, the presence of cyber warfare doesn’t rule out armed conflict in the “real” world. President Joe Biden recently warned that the US could end up in a “shooting war” with a major power as a result of a cyber attack. During a visit to the Office of the Director of National Intelligence in late July 2021, Biden said that he believes that if the US gets involved in “a real shooting war with a major power, it’s going to be as a consequence of a cyber breach of great consequence”. He also went on to describe Russian president Vladimir Putin as “dangerous”, with <a href="https://www.itpro.com/security/cyber-attacks/359238/us-and-uk-in-agreement-over-russian-involvement-in-solarwinds-hack" data-original-url="https://www.itpro.com/security/cyber-attacks/359238/us-and-uk-in-agreement-over-russian-involvement-in-solarwinds-hack">Russia being previously accused</a> of being behind last year’s <a href="https://www.itpro.com/security/358111/solarwinds-confirms-cyber-attack" data-original-url="https://www.itpro.com/security/358111/solarwinds-confirms-cyber-attack">SolarWinds cyber attack</a> which saw hackers infiltrate the networks of hundreds of companies as well as nine US governmental agencies. </p><p>This was <a href="https://www.itpro.com/security/cyber-attacks/359574/russia-spy-chief-denies-involvement-in-solarwinds-hack" data-original-url="https://www.itpro.com/security/cyber-attacks/359574/russia-spy-chief-denies-involvement-in-solarwinds-hack">denied</a> by the head of the Russian Foreign Intelligence Service (SVR), who told <a href="https://www.bbc.co.uk/news/av/world-europe-57144297"><em>the BBC</em></a> that he is "flattered" by the accusations from US and UK authorities, yet added that he could not "claim the creative achievements of others as his own". Nevertheless, the US responded by <a href="https://www.itpro.com/business/policy-legislation/360278/us-puts-trade-restrictions-on-six-russian-organisations" data-original-url="https://www.itpro.com/business/policy-legislation/360278/us-puts-trade-restrictions-on-six-russian-organisations">imposing trade restrictions</a> on four Russian IT firms as well as two other entities over “aggressive and harmful” activities. </p><h2 id="false-flags">False flags</h2><p>The only cyber weapon that is perhaps even more dangerous and disruptive than the zero-day is the false flag. We know that, for example, the attack by the so-called 'Cyber Caliphate' claiming to be affiliated to ISIS on a US military database was a false flag operation by the Russian state-sponsored hacking group APT 28. Why does this matter? Because the US retaliated with kinetic attacks on cyber communication channels and drone strikes against human targets in Syria. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GitHub faces lawsuit for role in Capital One leak ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34143/github-faces-lawsuit-for-role-in-capital-one-leak</link>
                                                                            <description>
                            <![CDATA[ Class action complaint accuses the platform of failing to detect and remove hacked data for three months ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8js5jaqTsVnXgoeLDPFAqb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/77vJGaSB5YgJ2D9sLQcnRR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 05 Aug 2019 10:27:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/77vJGaSB5YgJ2D9sLQcnRR-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GitHub office with GitHub logo over top]]></media:description>                                                            <media:text><![CDATA[GitHub office with GitHub logo over top]]></media:text>
                                <media:title type="plain"><![CDATA[GitHub office with GitHub logo over top]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/77vJGaSB5YgJ2D9sLQcnRR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Development platform <a href="https://www.itpro.com/open-source/31833/what-is-github" target="_blank" data-original-url="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a> is being sued for allegedly failing to prevent 100 million people's personal information from being disseminated online following the Capital One data breach.</p><p>The <a href="https://www.courtlistener.com/recap/gov.uscourts.cand.345666/gov.uscourts.cand.345666.3.0.pdf" target="_blank">class action complaint</a>, filed in California, has accused theMicrosoftsubsidiary of negligence after a dump of hacked personal data, including bank account numbers and social security numbers, was hosted on its platform for three months. It's alleged that GitHub didn't remove this "obviously hacked" data in a timely way, nor alert victims their information was posted online.</p><p>The Capital One hack, in which the <a href="https://www.itpro.com/data-breaches/34107/capital_one_data_breach" target="_blank" data-original-url="https://www.itpro.com/data-breaches/34107/capital_one_data_breach">details for approximately 106 million customers were stolen</a>, was disclosed in late July, although the incident itself took place in April. The stolen information, approximately 50GB worth of data, was posted onto GitHub on 21 April, according to the filings, and remained on the platform until mid-July.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/open-source/32436/what-does-a-microsoft-buyout-mean-for-github-developers" data-original-url="/open-source/32436/what-does-a-microsoft-buyout-mean-for-github-developers">What does a Microsoft buyout mean for GitHub developers?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34070/lancaster-university-hit-by-double-data-breach" data-original-url="/security/34070/lancaster-university-hit-by-double-data-breach">Lancaster University hit by double data breach</a></p></div></div><p>GitHub's alleged failings also extend to the enforcement of its own terms-of-service, as it did not revoke the hacker's access to the site, let alone suspend their user account, the claim states.</p><p>"GitHub knew or should have known that obviously hacked data had been posted toGitHub.com," the lawsuit claims. "Indeed, GitHub actively encourages (at least) friendly hacking as evidenced by, inter alia, GitHub.com's "Awesome Hacking" page.</p><p>"GitHub had an obligation, under California law, to keep off (or to remove from) its site Social Security numbers and other Personal Information."</p><p>The claimants' arguments also centre on comparisons with the way similar tech platforms, like Facebook and YouTube, approach content moderation. These sites often dedicate resources and staff to monitoring and removing offensive and illegal content, or content which breaches their term-of-service.</p><p>Because social security numbers are readily identifiable, generally following a nine-digit sequence, GitHub should have, but chose not to, dedicate time and resource into scanning its platform for such information, it has been argued.</p><p>Following the beach disclosure, further research by Israeli firm CyberInt revealed a <a href="https://www.itpro.com/data-breaches/34107/capital_one_data_breach" target="_blank" data-original-url="https://www.itpro.com/data-breaches/34107/capital_one_data_breach">host of other large organisations could have been struck by the same hacker</a>. These businesses include Vodafone and Ford.</p><p>"GitHub promptly investigates content, once it's reported to us, and removes anything that violates our Terms of Service," a spokesperson told<em>IT Pro</em>.</p><p>"The file posted on GitHub in this incident did not contain any Social Security numbers, bank account information, or any other reportedly stolen personal information.</p><p>"We received a request from Capital One to remove content containing information about the methods used to steal the data, which we took down promptly after receiving their request."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA to create new division to bolster US cyber defences  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34077/nsa-to-create-new-division-to-bolster-us-cyber-defences</link>
                                                                            <description>
                            <![CDATA[ Focus on defensive operations comes amid mounting geopolitical tensions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">py8VxPj1VJKkPiHi1N25Kp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KFyeatNKiZR6Kr9bp75VJ7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Jul 2019 12:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KFyeatNKiZR6Kr9bp75VJ7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KFyeatNKiZR6Kr9bp75VJ7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The USA's National Security Agency (NSA) is setting up a cyber security division with a specific focus on guarding the country against attacks from foreign adversaries like North Korea and Iran.</p><p>The organisation, which is tasked with overseeing America's cyber security operations, will establish a group dubbed the Cybersecurity Directorate with the aim of unifying foreign intelligence and cyber defence missions, according to <a href="https://edition.cnn.com/2019/07/23/politics/nsa-cybersecurity-directorate/index.html" target="_blank"><em>CNN</em></a>.</p><p>This new directorate, which has an exclusive focus on defence, is being formed amid rising geopolitical tensions with countries like Iran, against which the <a href="https://www.itpro.com/cyber-warfare/33958/are-we-in-the-midst-of-a-cyber-war" target="_blank" data-original-url="https://www.itpro.com/cyber-warfare/33958/are-we-in-the-midst-of-a-cyber-war">US was widely reported to have launched a cyber attack in June</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" data-original-url="/security/31527/how-russia-hacked-the-2016-election">How Russia hacked the 2016 election</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="/security/28170/what-is-cyber-warfare">What is cyber warfare?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy" data-original-url="/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy">Who should take ownership of your cyber security strategy?</a></p></div></div><p>The group will be led by the NSA's lead investigator on election fraud, Ann Neuberger, and will become operational from 1 October.</p><p>"This new approach to cyber security will better position NSA to collaborate with key partners across the US government like US Cyber Command, Department of Homeland Security, and Federal Bureau of Investigation," the NSA said.</p><p>"It will also enable us to better share information with our customers so they are equipped to defend against malicious cyber activity."</p><p>The NSA is renowned for its focus on offensive cyber capabilities and also gained notoriety for its role in devising a series of programmes to orchestrate mass data gathering, <a href="https://www.itpro.com/security/25092/nsa-and-gchq-have-been-spying-on-you-for-50-years" target="_blank" data-original-url="https://www.itpro.com/security/25092/nsa-and-gchq-have-been-spying-on-you-for-50-years">as revealed by the Edward Snowden leaks</a>.</p><p>Most recently the organisation was indirectly linked <a href="https://www.itpro.com/security/33716/us-security-agency-linked-to-baltimore-hack" target="_blank" data-original-url="https://www.itpro.com/security/33716/us-security-agency-linked-to-baltimore-hack">with a devastating hack on the government of Baltimore</a>. Researchers learned the tool used to shut down the government and lock people out of essential services, dubbed EternalBlue, was developed by the NSA and used by cyber criminals.</p><p>This additional focus on defence reflects a time of heightened tensions across borders, not just between the US and Iran, <a href="https://www.itpro.com/policy-legislation/33722/huawei-and-china-launch-fresh-offensives-amid-us-trade-war" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/33722/huawei-and-china-launch-fresh-offensives-amid-us-trade-war">but with China too</a>.</p><p>Both nations, as well as North Korea, have been linked with a <a href="https://www.itpro.com/security/34038/microsoft-warns-business-customers-at-risk-of-state-sponsored-attacks" target="_blank" data-original-url="https://www.itpro.com/security/34038/microsoft-warns-business-customers-at-risk-of-state-sponsored-attacks">handful of known cyber gangs</a>. The NSA's decision to create a defence-centric unit comes <a href="https://www.itpro.com/security/34074/ransomware-attacks-on-uk-businesses-soar-195" target="_blank" data-original-url="https://www.itpro.com/security/34074/ransomware-attacks-on-uk-businesses-soar-195">as the scale and severity of cyber attacks continue to rise</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft warns business customers at risk of state-sponsored attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34038/microsoft-warns-business-customers-at-risk-of-state-sponsored-attacks</link>
                                                                            <description>
                            <![CDATA[ Geopolitical tensions on the rise ahead of the 2020 US presidential race ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aj4zePEHX6Sg2e9WrXqSEi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TB4k65RSHCpj6gEkZnJqpD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Jul 2019 09:37:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TB4k65RSHCpj6gEkZnJqpD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic depicting cyber warfare as a soldier works in a room full of computers]]></media:description>                                                            <media:text><![CDATA[Graphic depicting cyber warfare as a soldier works in a room full of computers]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic depicting cyber warfare as a soldier works in a room full of computers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TB4k65RSHCpj6gEkZnJqpD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has revealed that approximately 10,000 of its customers were the target of a state-sponsored attack, or even compromised by a foreign power, over the last 12 months.</p><p>As organisations and politicians gear up for the US presidential race in 2020, the firm published data showing that enterprise customers make up 84% of those targeted. The vast majority of these groups are based in America, while the remaining 16% are consumer personal email accounts.</p><p>Those targeted are mostly connected with the essential functions of democracy, like think tanks or non-governmental organisations (NGOs), and tend not to have the resources to defend against cyber threats of this scale, the firm added.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" data-original-url="/security/31527/how-russia-hacked-the-2016-election">How Russia hacked the 2016 election</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27729/are-we-ready-for-cyber-war" data-original-url="/security/27729/are-we-ready-for-cyber-war">Are we ready for cyber war?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/social-media/30339/russian-bots-shared-trumps-election-tweets-500k-times" data-original-url="/social-media/30339/russian-bots-shared-trumps-election-tweets-500k-times">Russian bots shared Trump's election tweets 500k times</a></p></div></div><p><a href="https://blogs.microsoft.com/on-the-issues/2019/07/17/new-cyberthreats-require-new-ways-to-protect-democracy" target="_blank">Data has also revealed that attacks</a> are being launched by five main groups spread across Iran, Russia, and North Korea, according to Microsoft's Threat Intelligence Centre. Holmium and Mercury operate from Iran, while Yttrium and Strontium run campaigns from Russia. The most prominent North Korean group on the company's radar is dubbed Thallium.</p><p>"While many of these attacks are unrelated to the democratic process, this data demonstrates the significant extent to which nation-states continue to rely on cyberattacks as a tool to gain intelligence, influence geopolitics or achieve other objectives," said Microsoft's corporate vice president for customer security and trust Tom Burt.</p><p>"Many of the democracy-focused attacks we've seen recently target NGOs and think tanks, and reflect a pattern that we also observed in the early stages of some previous elections.</p><p>"In this pattern, a spike in attacks on NGOs and think tanks that work closely with candidates and political parties, or work on issues central to their campaigns, serve as a precursor to direct attacks on campaigns and election systems themselves."</p><p>Cyber attacks have become a preferred method for spreading economic disruption in recent years compared to traditional tools like economic sanctions or deploying military units, particularly as an attack can be launched with relative ease and without necessarily exposing the attacking country to immediate international attention. This has been <a href="https://www.itpro.com/cyber-warfare/33958/are-we-in-the-midst-of-a-cyber-war" target="_blank" data-original-url="https://www.itpro.com/cyber-warfare/33958/are-we-in-the-midst-of-a-cyber-war">highlighted most recently by rising tensions between the US and Iran</a>.</p><p>Russia, meanwhile, was found to have <a href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" target="_blank" data-original-url="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election">interfered with the 2016 US election</a>, and subsequent public votes, like the <a href="https://www.itpro.com/policy-legislation/32310/facebook-blocks-115-bot-accounts-over-us-midterm-meddling-fears" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/32310/facebook-blocks-115-bot-accounts-over-us-midterm-meddling-fears">2018 US mid-terms</a> or even the <a href="https://www.itpro.com/government-it-strategy/28301/france-withdraws-electronic-vote-over-hacking-fears" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/28301/france-withdraws-electronic-vote-over-hacking-fears">French parliamentary elections in 2017</a> were shrouded in fears of meddling with electronic ballots.</p><p>Microsoft showcased its new ElectionGuard technology at the Aspen Security Forum this week, a secure voting machine that the company hopes will prevent manipulation of voting records in future elections.</p><p>The system works by giving voters a tracking code when they cast their ballot, which they then enter into an election website to verify their identity, and confirm whether or not their vote has been tampered with.</p><p>Encryption will be deployed, moreover, to allow the counting of votes without revealing to any user what those votes are. The machines will also print physical copies of voters' ballots to drop into traditional voting boxes.</p><p>The company is planning to release the software behind the technology as open-source on <a href="https://www.itpro.com/open-source/31833/what-is-github" target="_blank" data-original-url="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a> later in 2019, rather than commercially release its own voting machines.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Law enforcement tool paves way for full data extraction on iPhones ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/privacy/33846/law-enforcement-tool-paves-way-for-full-data-extraction-on-iphones</link>
                                                                            <description>
                            <![CDATA[ Israeli developer claims its UFED Premium tool can also crack flagship Android devices like the Samsung Galaxy S9 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4Rfup6RsAZ4rpGdNwMX6Fp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h3QcMDi9SR7FLz934VCvY3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Jun 2019 10:19:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h3QcMDi9SR7FLz934VCvY3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h3QcMDi9SR7FLz934VCvY3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Law enforcement agencies will soon have access to a tool that can breach a raft of the latest flagship smartphones including the <a href="https://www.itpro.com/hardware/mobile-phones" target="_blank" data-original-url="https://www.itpro.com/mobile/32099/apple-iphone-xs-review-a-genuine-pocket-rocket">most recently-launched iPhone models</a>.</p><p>Using a newly launched tool, developed by data extraction firm Cellebrite, organisations like the FBI and MI5 will be able to breach any iOS device and a host of high-end Android handsets.</p><p>At a time where tech manufacturers are placing a greater emphasis on user privacy, the UFED Premium tool can be used to perform full file system extractions on their flagship devices.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/31115/nca-complains-that-encryption-hampers-crime-fighting" data-original-url="/security/31115/nca-complains-that-encryption-hampers-crime-fighting">NCA complains that encryption hampers crime fighting</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31864/apple-launches-global-law-enforcement-web-portal-for-data-access" data-original-url="/policy-legislation/31864/apple-launches-global-law-enforcement-web-portal-for-data-access">Apple launches global law enforcement web portal for data access</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/31300/apples-usb-restricted-mode-closes-security-loophole-on-locked-iphones-thwarting-police" data-original-url="/mobile/31300/apples-usb-restricted-mode-closes-security-loophole-on-locked-iphones-thwarting-police">Apple's 'USB Restricted Mode' closes security loophole on locked iPhones, thwarting police data extraction</a></p></div></div><p>Law enforcement agencies can then gain access to third-party app data, chat conversations, downloaded emails and email attachments, as well as deleted content. Moreover, the tool's developers promise to "increase your chances of finding the incriminating evidence and bringing your case to a resolution".</p><p>Smartphones vulnerable to UFED Premium include the Samsung Galaxy S6 through to <a href="https://www.itpro.com/google-android/30626/samsung-galaxy-s9-review" target="_blank" data-original-url="https://www.itpro.com/google-android/30626/samsung-galaxy-s9-review">S9 models</a>, as well as "popular device models" from Motorola, <a href="https://www.itpro.com/mobile-phones/33125/huawei-mate-20-pro-review-a-fire-breathing-dragon" target="_blank" data-original-url="https://www.itpro.com/mobile-phones/33125/huawei-mate-20-pro-review-a-fire-breathing-dragon">Huawei</a>, LG and Xiaomi. The tool also supports all Apple devices running iOS 7 to iOS 12.3.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1139569499206643715"></a></p></blockquote><div class="see-more__filter"></div></div><p>With UFED Premium, law enforcement agencies can determine passcodes and perform unlocks for all Apple devices, as well as make use of sophisticated algorithms to minimise unlock attempts. Android devices, similarly, can be bypassed with ease, with users then accessing unallocated data to maximise the chances of recovering deleted items.</p><p>As an 'on-premise' tool, law enforcement officers can use the UFED Premium to extract data and infer results without the need to use any additional Cellebrite services, meaning it can be deployed at their discretion. </p><p>But the company has given clients the option of using in-house services, provided by certified forensic experts, to gain access to evidence from locked, encrypted or damaged devices using in-lab only techniques.</p><p>Apple and other smartphone manufacturers have begun <a href="https://www.itpro.com/mobile/31300/apples-usb-restricted-mode-closes-security-loophole-on-locked-iphones-thwarting-police" target="_blank" data-original-url="https://www.itpro.com/mobile/31300/apples-usb-restricted-mode-closes-security-loophole-on-locked-iphones-thwarting-police">placing a much greater emphasis on user privacy and information security</a> in their marketing to consumers. This has come at a time where the EU's <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know/page/0/1">General Data Protection Regulation (GDPR)</a> hit mainstream consciousness, and large-scale data breaches regularly populate newspaper headlines.</p><p>The likes of Facebook and Google, for example, have also come under heavy public scrutiny for allegations of disregarding user privacy, the former in particular given <a href="https://www.itpro.com/policy-legislation/31483/facebook-fined-500000-by-the-ico-following-cambridge-analytica-data-scandal" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/31483/facebook-fined-500000-by-the-ico-following-cambridge-analytica-data-scandal">the scale of the Cambridge Analytica scandal</a>.</p><p>Manufacturers, therefore, are unlikely to approve of a tool that can be harnessed to break a fundamental component of their sell to the market. The conflict this could spark between tech giants and governments bears similarity to that which exists over <a href="https://www.itpro.com/security/31575/why-encryption-is-the-key-to-your-security-strategy" target="_blank" data-original-url="https://www.itpro.com/security/31575/why-encryption-is-the-key-to-your-security-strategy">end-to-end encryption</a>.</p><p>The UK government, in particular, has been <a href="https://www.itpro.com/encryption/31822/five-eyes-nations-hand-tech-giants-encryption-ultimatum" target="_blank" data-original-url="https://www.itpro.com/encryption/31822/five-eyes-nations-hand-tech-giants-encryption-ultimatum">especially vocal about the need for tech giants to compromise the absolute privacy that end-to-end encryption offers</a>. This is because, as politicians and law enforcement agencies argue, this allows criminals to organise freely through social networks, such as WhatsApp, that use encryption.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How Mr. Robot ‘fudged’ its hacks to protect the public ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/33779/how-mr-robot-fudged-its-hacks-to-protect-the-public</link>
                                                                            <description>
                            <![CDATA[ Showrunners debated over how accurate to make the show’s exploits ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dWVeyS7dAhXDh9GqKyji6h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9syBA25jenx2PCaRZQrR9n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Jun 2019 09:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9syBA25jenx2PCaRZQrR9n-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mr. Robot poster]]></media:description>                                                            <media:text><![CDATA[Mr. Robot poster]]></media:text>
                                <media:title type="plain"><![CDATA[Mr. Robot poster]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9syBA25jenx2PCaRZQrR9n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AMC's Mr. Robot is a modern <em>Robin Hood</em> tale about a gang of hacktivists taking on a morally reprehensible multinational corporation. The show has garnered particular attention for the authenticity with which it portrays hacking and cybersecurity, and showrunner Sam Esmail went to great pains to make sure all of the hacks shown in the series were plausible and realistic up to a point.</p><p>James Plouffe, a strategic technologist at MobileIron, was one of many cybersecurity industry practitioners that Esmail brought in to advise the writers on the technical elements of fsociety's hacks and exploits. According to Plouffe, there was some debate among the show's writers and technical experts as to exactly how true to life the fictional anarcho-hacker collective's exploits should be.</p><p>"You wanted to get it right, but not right enough that someone could copy," he explained in an interview with <em>IT Pro</em>. "And I don't want to spoil it for folks who haven't seen some of the things that take place in season three, but I remember kicking around some of the ideas to make certain things happen. And there was this debate between those of us who are working as tech consultants about whether or not it was technically feasible, and a little bit of research suggested that it was."</p><p>"There were some folks on the side of 'we want to make this hyper accurate'. And my position was, for the safety of total strangers, let's maybe fudge the math a little bit, so that it doesn't become a public safety issue."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30203/what-is-hacktivism" data-original-url="/hacking/30203/what-is-hacktivism">What is hacktivism?</a></p></div></div><p>It's hard to argue Mr. Robot hasn't had a huge impact in the cybersecurity industry in the years since it first hit screens; various hackers (including black, white and grey hat varieties) have already begun adopting the show's iconography as part of their public personas.</p><p>For Plouffe, it's gratifying he gets to be a part of something that resonates so deeply with the cyber security community: "I appreciate it, in the sense that it was great to be part of something that I would have wanted to watch." </p><p>He also hopes that seeing the reality of cyber attacks as portrayed in Mr. Robot has helped contextualise cyber security issues for members of the general public, and raise awareness of threats.</p><p>"All the things that happened in Mr. Robot are practical, are based on real things. When you see them log into a firewall console, that's actually a piece of Cisco hardware that's been mocked up. So if anything, I hope that people see that the issues are real," said Plouffe. </p><p>"A lot of the activities in Mr. Robot hinge on pretty basic stuff, like getting people to do something dumb; pick up a USB drive in a parking lot, take a free CD from a musician, you know, social engineering stuff. Stuff that we're all susceptible to, potentially. I think people can understand those. And hopefully, it also underscored the ease with which some of that can happen and makes people think twice."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Former US defence chief calls for public and private sector cyber taskforce ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/33694/former-us-defence-chief-calls-for-public-and-private-sector-cyber-taskforce</link>
                                                                            <description>
                            <![CDATA[ Non-state actors must be let in on cyber security discussions or our biggest public institutions will fall behind ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ib77zQQc8Fk9HVzhBPLrhG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/f2F4H2KWLYyVEAUCkwfp3C-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 May 2019 08:27:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/f2F4H2KWLYyVEAUCkwfp3C-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Former US secretary of state Madeleine Albright]]></media:description>                                                            <media:text><![CDATA[Former US secretary of state Madeleine Albright]]></media:text>
                                <media:title type="plain"><![CDATA[Former US secretary of state Madeleine Albright]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/f2F4H2KWLYyVEAUCkwfp3C-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Despite myriad benefits businesses have accrued from technological leaps, bad actors are finding it easier and cheaper than ever before to abuse the internet by stealing trade secrets and spread disinformation.</p><p>Collaboration between the institutions we rely on and private sector organisations is critical, according to former US secretary of state Dr Madeleine Albright, because non-state actors now own swathes of the physical infrastructure the internet is built on.</p><p>If private sector tech firms and non-governmental organisations (NGOs) aren't let in on conversations around how to combat emerging cyber threats at a state-to-state level, they will begin to crumble as cyber threats continue to evolve, she argued.</p><p>"Of course the technological revolution has been an incredible gift in several ways," Albright told delegates during a special address at this year's Citrix Synergy, "but we still don't know whether information technology is simply the latest in a line of advances that have helped to modernise the world without doing much to civilise it.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software-as-a-service-saas/33689/citrix-synergy-2019-citrix-revamps-workspace-to-tackle" data-original-url="/software-as-a-service-saas/33689/citrix-synergy-2019-citrix-revamps-workspace-to-tackle">Citrix Synergy 2019: Citrix revamps Workspace to tackle “disengagement epidemic”</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/31086/condoleezza-rice-warns-against-threat-of-cyber-warfare-at-citrix-synergy-2018" data-original-url="/cyber-security/31086/condoleezza-rice-warns-against-threat-of-cyber-warfare-at-citrix-synergy-2018">Condoleezza Rice warns against threat of cyber warfare at Citrix Synergy 2018</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="/security/28170/what-is-cyber-warfare">What is cyber warfare?</a></p></div></div><p>"I hardly need to describe for this audience how bad actors, whether governments or criminal groups, have taken advantage of the internet to pilfer trade secrets, surveille critical infrastructure and cause economic or even physical damage."</p><p>As a means of showing how quickly the world has changed in a short space of time, Albright revealed that she didn't even have a computer on her desk, let alone an email address, when in office.</p><p>Emerging cyber threats, like state-sponsored disinformation campaigns, were quite simply not something Albright had to concern herself in her role as secretary of state.</p><p>"The cyber threat that has continued to evolve is something we need to keep looking at," she continued.</p><p>"For all the warnings that were issued for a cyber Pearl Harbour, it appears now that the most immediate threat are attacks that are harder to deter because they stop short of what we would consider an act of war."</p><p>In recent years, enemies have become skilled at abusing social media platforms to pollute users' feeds with rumours and disinformation, as well as anti-democratic propaganda. She also cited Russian television adverts that warn viewers that <a href="https://www.itpro.com/mobile/28081/what-is-5g" target="_blank" data-original-url="https://www.itpro.com/mobile/28081/what-is-5g">5G wireless technology</a> could kill you.</p><p>This form of cyber warfare is running rampant among forces not just within Russia, but the likes of China, North Korea, Venezuela and Turkey, as well as extremist groups littered across the world.</p><p>To fight this global issue, which is akin to "assembling an airplane while already in the air", businesses must follow the lead of firms like Microsoft, which has spearheaded joint-efforts with NGOs and other companies to create 'rules of the road' to protect digital society.</p><p>"Of course I'm not saying that we should put non-state actors at every decision table," she added. "But the international system needs to adjust to the impact of these agents of change and they need to be there at the beginning of decision-making and not just to pick up the pieces."</p><p>Any such efforts to engage in discussions and share best practice, led by businesses in the international interest, would be crucial to preventing a cyber arms race between nations.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LoJax rootkit used by Russian-linked Fancy Bear has been silently active since 2016 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/malware/32769/lojax-rootkit-used-by-russian-linked-fancy-bear-has-been-silently-active-since-2016</link>
                                                                            <description>
                            <![CDATA[ Researchers question what the malware was used to accomplish before being first exposed last year ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">45PES15BNrPSDozN5Cu9Gq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KbHnePV74fQHSJrJPtnrX6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Jan 2019 10:59:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KbHnePV74fQHSJrJPtnrX6-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KbHnePV74fQHSJrJPtnrX6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have discovered that LoJax, the malware that formed the foundation for devastating Fancy Bear attacks in 2018, has been silently active for years.</p><p>Use of this infrastructure by the Russian-linked hacking group was exposed in September 2018, just a few months after the LoJax servers were first discovered by security researchers in May.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/32009/fancy-bear-cracks-into-government-computers-with-lojax-uefi-rootkit" data-original-url="/security/32009/fancy-bear-cracks-into-government-computers-with-lojax-uefi-rootkit">Fancy Bear cracks into government computers with LoJax UEFI rootkit</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32054/the-uk-us-and-netherlands-accuse-russia-of-cyber-attacks" data-original-url="/security/32054/the-uk-us-and-netherlands-accuse-russia-of-cyber-attacks">The UK, US and Netherlands accuse Russia of cyber attacks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/32733/is-your-weakest-link-really-where-you-think-it-is" data-original-url="/endpoint-security/32733/is-your-weakest-link-really-where-you-think-it-is">Is your weakest link really where you think it is?</a></p></div></div><p>LoJax was last year found to be incorporated as part of a Fancy Bear Unified Extensible Firmware Interface (UEFI)-based rootkit, which meant LoJax was resistant to hard drive replacements and operating system re-installs.</p><p>But a NETSCOUT team of ASERT security researchers have found that LoJax may have been alive in the wild since 2016, by tracing its fingerprint, also learning there still remains two active command and control (C2) servers.</p><p>"Continued diligence in tracking activity related to LoJax proved that the actors still maintain live C2 servers," the <a href="https://asert.arbornetworks.com/lojax-fancy-since-2016" target="_blank">researchers summarised in a blog post</a>.</p><p>"They may also have additional ongoing operations outside the 'in the wild' use reported by ESET activity. Even with all of the publicity around Lojax, Fancy Bear operations did not take the publicly disclosed servers offline.</p><p>"Because these C2 servers have a long shelf life, organizations should ensure they incorporate the IOCs [indicators of compromise] into their defensive posture. This longevity underscores the importance that LoJax C2s remain in active defense postures for longer periods of time."</p><p>The team used intelligence gathered from a known LoJax C2 server to build a network-scanning fingerprint. They used this to search for additional LoJax servers, and discovered seven in late-2018. Of these seven, two were subsequently deemed to still be active.</p><p>The researchers used DNS records to cross-reference the servers with known LoJax samples, and found the LoJax C2 server had ties to two domains, regvirt.com and elaxo.org.</p><p>NETSCOUT determined when LoJax first became active by examining domain registration information for when confirmed and suspected domains first came online. Beyond a minor flurry in 2004 and 2006, the cyber security firm detected a massive spike in late 2016.</p><p>The findings raise questions as to what the LoJax infrastructure was used to accomplish, and how successful it was before it was first publicly-exposed in 2018. Moreover, NETSCOUT says the rootkit doesn't look like an isolated incident or one-off attack aimed at a specific group of targets.</p><p>An ASERT security researcher told <em>IT Pro </em>the LoJax domain names were likely picked to blend in as best they can with a target organisation's network traffic, and were not necessarily mapped to an organisation's sector.</p><p>"Why an organization might be targeted varies as the priorities may shift during the course of an operation, but in general Lojax makes for a good beacon for device tracking along with executing code sent by the command and control server," they said.</p><p>"Fancy Bear remains highly active in the cyber landscape. Regardless, if the business is the primary target of the actor or not, the business may still be targeted due to their connections. Businesses should remain vigilant against cyber-attacks and in particular phishing attempts which account for the majority of network compromises."</p><p>The infamous Russian hacking group previously used the LoJax rootkit to <a href="https://www.itpro.com/security/32009/fancy-bear-cracks-into-government-computers-with-lojax-uefi-rootkit" target="_blank" data-original-url="https://www.itpro.com/security/32009/fancy-bear-cracks-into-government-computers-with-lojax-uefi-rootkit">breach and seize control of government systems in September last year</a>. The same rootkit is also claimed to be part of a campaign run by the Sednit group against high-profile targets in Central and Eastern Europe.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The scariest security horror stories of 2018 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/32572/the-scariest-security-horror-stories-of-2018</link>
                                                                            <description>
                            <![CDATA[ From data breaches to hardware vulnerabilities, these are the most embarrassing security blunders of the year ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bUYG7nxn3PNSBszHNpucSx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jQqJ7cTgccfCCohQaaLvBe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Dec 2018 06:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jQqJ7cTgccfCCohQaaLvBe-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A fishing hook rests on top of a stack of credit cards, while a padlock sits in the background out of focus]]></media:description>                                                            <media:text><![CDATA[A fishing hook rests on top of a stack of credit cards, while a padlock sits in the background out of focus]]></media:text>
                                <media:title type="plain"><![CDATA[A fishing hook rests on top of a stack of credit cards, while a padlock sits in the background out of focus]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jQqJ7cTgccfCCohQaaLvBe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There's no such thing as a quiet year when it comes to security, but 2018 has been particularly eventful. From systemic CPU vulnerabilities to hacks affecting hundreds of millions of people, the last twelve months have been a seemingly non-stop parade of cyber gaffes and security blunders. Here's our pick of the year's biggest and most embarrassing security snafus.</p><h3 class="article-body__section" id="section-meltdown-amp-spectre"><span>Meltdown & Spectre</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6xNuTL5xyFjrGEBV5Pgy5Z" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/6xNuTL5xyFjrGEBV5Pgy5Z.jpg" mos="https://cdn.mos.cms.futurecdn.net/6xNuTL5xyFjrGEBV5Pgy5Z.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/32397/four-ways-to-secure-sensitive-data" data-original-url="/security/32397/four-ways-to-secure-sensitive-data">Four ways to secure sensitive data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/internet-security/31517/seven-ways-to-test-your-online-security" data-original-url="/internet-security/31517/seven-ways-to-test-your-online-security">Seven ways to test your online security</a></p></div></div><p>The hardware world was rocked at the start of the year by the discovery of <a href="https://www.itpro.com/security/30223/meltdown-and-spectre" target="_blank" data-original-url="https://www.itpro.com/security/30223/meltdown-and-spectre">a series of major vulnerabilities</a> affecting virtually every Intel processor produced in the last twenty years, as well as AMD and ARM chips. The flaws allow for data exfiltration and snooping, making them a particular concern for businesses.</p><p>It's currently unknown whether or not <a href="https://www.itpro.com/exploits/30478/what-are-meltdown-and-spectre-and-are-you-affected" target="_blank" data-original-url="https://www.itpro.com/exploits/30478/what-are-meltdown-and-spectre-and-are-you-affected">Meltdown and Spectre are being exploited in the wild</a> to target victims, but the widespread impact of the issues make it likely that it will play an ongoing role in future breaches as unpatched systems inevitably fall victim to Meltdown and Spectre-based exploits.</p><h3 class="article-body__section" id="section-google-plus-unceremoniously-axed"><span>Google Plus unceremoniously axed</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="B3Fb4DMiaWjFz3FUCxCiwZ" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/B3Fb4DMiaWjFz3FUCxCiwZ.jpg" mos="https://cdn.mos.cms.futurecdn.net/B3Fb4DMiaWjFz3FUCxCiwZ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Google Plus, the company's oft-derided rival to the likes of Twitter and Facebook, met an early (although arguably not untimely) demise towards the end of the year, after Google <a href="https://www.itpro.com/security/32076/google-plus-to-shut-down-after-massive-data-leak" target="_blank" data-original-url="https://www.itpro.com/security/32076/google-plus-to-shut-down-after-massive-data-leak">discovered a massive data leak</a> in the service's APIs that affected the personal data of up to 500,000 users.</p><p>To add insult to injury, <a href="https://www.itpro.com/security/32546/second-google-api-bug-exposes-private-data-of-525-million" target="_blank" data-original-url="https://www.itpro.com/security/32546/second-google-api-bug-exposes-private-data-of-525-million">a second security flaw</a> was discovered earlier this month this time affecting more than 52 million users and forcing Google to shutter the platform four months earlier than it had originally intended to. An ignominious end for one of Google's least successful projects.</p><h3 class="article-body__section" id="section-marriott-39-s-unexpected-chinese-visitors"><span>Marriott's unexpected Chinese visitors</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RoNDqgHrtvxwzZS3tJemUo" name="" alt="Marriott hotel sign" src="https://cdn.mos.cms.futurecdn.net/RoNDqgHrtvxwzZS3tJemUo.jpg" mos="https://cdn.mos.cms.futurecdn.net/RoNDqgHrtvxwzZS3tJemUo.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The Marriott hotel chain found itself with <a href="https://www.itpro.com/data-breaches/32474/marriotts-starwood-hotel-system-breached-exposing-data-of-up-to-500-million" target="_blank" data-original-url="https://www.itpro.com/data-breaches/32474/marriotts-starwood-hotel-system-breached-exposing-data-of-up-to-500-million">some unexpected guests this</a> year, after it discovered that hackers had been squatting on its network for at least four years. To be specific, it was the hotels in Marriott's Starwood Group which were affected, including prestigious chains like the Sheraton, Westin and W Hotels.</p><p>Hackers may have accessed the information of up to 500 million guests, including passport numbers, phone numbers and email addresses. According to investigators, the hack may haveeven been part of <a href="https://www.itpro.com/hacking/32528/china-was-behind-the-marriott-hotel-hack-claim-investigators" target="_blank" data-original-url="https://www.itpro.com/hacking/32528/china-was-behind-the-marriott-hotel-hack-claim-investigators">a Chinese espionage operation</a>.</p><h3 class="article-body__section" id="section-british-airways-flies-into-trouble"><span>British Airways flies into trouble</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="J2fnnEur3kNHDbtbVzH7qN" name="" alt="British flag on airplane" src="https://cdn.mos.cms.futurecdn.net/J2fnnEur3kNHDbtbVzH7qN.jpg" mos="https://cdn.mos.cms.futurecdn.net/J2fnnEur3kNHDbtbVzH7qN.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Towards the end of this year, British Airways announced <a href="https://www.itpro.com/data-breaches/31854/british-airways-reveals-massive-data-breach-could-face-500m-fine-under-gdpr" target="_blank" data-original-url="https://www.itpro.com/data-breaches/31854/british-airways-reveals-massive-data-breach-could-face-500m-fine-under-gdpr">two separate hacks on their systems</a>, resulting in a total of 565,000 customers having their data stolen, including payment data and personal information. Given the sensitive nature of the data handled by airlines, this breach was a particularly egregious one.</p><p>It was made all the more egregious by the possibility that <a href="https://www.itpro.com/security/32434/did-british-airways-accidentally-break-its-own-security" target="_blank" data-original-url="https://www.itpro.com/security/32434/did-british-airways-accidentally-break-its-own-security">BA itself may have inadvertently introduced the vulnerability</a> that led to the hack. As Barry Collins revealed, BA's rush to address the complaints about its data gathering raised by security researcher Mustafa Al-Bassam may have accidentally led them to introduce a flawed script. Oops...</p><h3 class="article-body__section" id="section-equifax-pays-the-piper"><span>Equifax pays the piper</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gdx4fwqzxmGNpEGDXhYHmm" name="" alt="Equifax on phone" src="https://cdn.mos.cms.futurecdn.net/gdx4fwqzxmGNpEGDXhYHmm.jpg" mos="https://cdn.mos.cms.futurecdn.net/gdx4fwqzxmGNpEGDXhYHmm.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>It's remarkable how quickly we all seem to have forgotten about Equifax, the company that let the personal data of 146 million users across the globe get <a href="https://www.itpro.com/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far" target="_blank" data-original-url="https://www.itpro.com/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far">stolen out from under its nose</a>. Although US citizens were the worst affected, brits also fell victim to the breach, with some 15 million UK users affected.</p><p>Although the breach was disclosed last year, the company has only started to feel the full ramifications of its failing relatively recently. It was <a href="https://www.itpro.com/data-protection/31950/equifax-hit-with-maximum-500000-fine-after-massive-security-breach" target="_blank" data-original-url="https://www.itpro.com/data-protection/31950/equifax-hit-with-maximum-500000-fine-after-massive-security-breach">slapped with a top-level 500,000 fine</a> by the ICO, and the US government pointed the finger of blame squarely at <a href="https://www.itpro.com/security/32550/former-equifax-ceo-blamed-for-entirely-preventable-data-breach" target="_blank" data-original-url="https://www.itpro.com/security/32550/former-equifax-ceo-blamed-for-entirely-preventable-data-breach">ex-CEO Richard Smith</a>, claiming it was his aggressive expansion strategy that led to the breach in the first place.</p><h3 class="article-body__section" id="section-apple-39-s-blunder-down-under"><span>Apple's blunder down under</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hzpZe3jezcPwxDZqEhVZH3" name="" alt="Apple building" src="https://cdn.mos.cms.futurecdn.net/hzpZe3jezcPwxDZqEhVZH3.jpg" mos="https://cdn.mos.cms.futurecdn.net/hzpZe3jezcPwxDZqEhVZH3.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>It's one thing to get hacked, but <a href="https://www.itpro.com/security/31720/australian-teen-hacked-apple-mainframe-sparking-fbi-investigation" target="_blank" data-original-url="https://www.itpro.com/security/31720/australian-teen-hacked-apple-mainframe-sparking-fbi-investigation">getting hacked by a bored Aussie teenager</a> is something else entirely. That's the fate that befell Apple, after a Melbourne private schoolboy exfiltrated 90GB of secret data from the company's servers. A rather embarrassing gaffe for a company that prides itself on the security of its products.</p><p>This breach feels comfortably nostalgic, harking back to the teenage hackers of the 90s, rather than the Russian gangsters and state-funded cybercriminals that we're more familiar with today. The young hacker told courts that he hacked the company because he's such a big fan, and he stored all his custom-built intrusion tools in a folder labelled 'hacky hack hack'. That's faintly charming somehow.</p><h3 class="article-body__section" id="section-reddit-hackedit"><span>Reddit? Hackedit.</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="AdFAmG6tkS5FS3mF8X7TNA" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/AdFAmG6tkS5FS3mF8X7TNA.jpg" mos="https://cdn.mos.cms.futurecdn.net/AdFAmG6tkS5FS3mF8X7TNA.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Social media platform Reddit is <a href="https://www.itpro.com/strategy/24994/whats-happening-to-reddit" target="_blank" data-original-url="https://www.itpro.com/strategy/24994/whats-happening-to-reddit">no stranger to controversy</a>, and it made headlines yet again this year after announcing that an attack on its SMS-based two-factor authentication system (which the company admitted was "not nearly as secure as we would hope") led to <a href="https://www.itpro.com/data-breaches/31612/reddit-suffers-massive-breach-as-all-user-data-before-2007-is-compromised" target="_blank" data-original-url="https://www.itpro.com/data-breaches/31612/reddit-suffers-massive-breach-as-all-user-data-before-2007-is-compromised">hackers making off with a huge cache of data</a> from between 2005 and 2007.</p><p>The attackers gained access to among other things current email addresses, old salted and hashed passwords and internal Reddit data such as config files, logs, source code and more. A relatively minor breach as far as the impact on users goes, it was another setback for an embattled company that has weathered more than its share of storms.</p><h3 class="article-body__section" id="section-dixons-carphone-phones-in-its-security"><span>Dixons Carphone phones in its security</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6DKNGPr7fe7wyWAFehtVjJ" name="" alt="Currys PC World Carphone Warehouse signage at building entrance" src="https://cdn.mos.cms.futurecdn.net/6DKNGPr7fe7wyWAFehtVjJ.jpg" mos="https://cdn.mos.cms.futurecdn.net/6DKNGPr7fe7wyWAFehtVjJ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Dixons Carphone has had a rough year. The <a href="https://www.itpro.com/strategy/22262/carphone-warehouse-and-dixons-in-38-billion-merger" target="_blank" data-original-url="https://www.itpro.com/strategy/22262/carphone-warehouse-and-dixons-in-38-billion-merger">parent company behind Carphone Warehouse and Currys PC World</a> has recently <a href="https://www.channelpro.co.uk/news/11141/dixons-carphone-reports-440m-loss-after-mobile-division-slump" target="_blank">announced a 440 million loss</a>, and back in June the company announced that it had been the victim of <a href="https://www.itpro.com/data-breaches/31600/dixons-carphones-data-breach-hit-10-million-customers" target="_blank" data-original-url="https://www.itpro.com/data-breaches/31600/dixons-carphones-data-breach-hit-10-million-customers">a breach which saw 10 million customers' records stolen</a>.</p><p>Dixons Carphone should be bracing itself for another fine from the ICO at some point in the future; it was <a href="https://www.itpro.com/data-protection/30266/carphone-warehouse-hit-with-400k-fine-for-2015-data-breach" target="_blank" data-original-url="https://www.itpro.com/data-protection/30266/carphone-warehouse-hit-with-400k-fine-for-2015-data-breach">hit with a 400,000 fine in January</a> this year for a breach that occured in 2015. That breach only affected three million people, though, and occured before the advent of GDPR. The fine for this year's incident could well be significantly higher.</p><h3 class="article-body__section" id="section-government-39-s-counter-terror-trello-leak"><span>Government's counter-terror Trello leak</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7TqxTGZYm4SY4zczK9rNxJ" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/7TqxTGZYm4SY4zczK9rNxJ.jpg" mos="https://cdn.mos.cms.futurecdn.net/7TqxTGZYm4SY4zczK9rNxJ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>It's commonly said that the only things that are certain in life are death and taxes, but there's a strong argument for adding 'government IT blunders' to that list. In one of the most embarrassing screw-ups of the year, the government accidentally leaked sensitive information <a href="https://www.itpro.com/desktop-software/29302/best-free-project-management-tools" target="_blank" data-original-url="https://www.itpro.com/desktop-software/29302/best-free-project-management-tools">via project management tool Trello</a>.</p><p>In yet another case of a lack of authentication coming back to bite a forgetful admin, a Trello board including anti-terror tools, contact details for top civil servants and guides for accessing government buildings was <a href="https://www.itpro.com/data-protection/31560/government-accidentally-leaks-counter-terrorism-tools-via-trello" target="_blank" data-original-url="https://www.itpro.com/data-protection/31560/government-accidentally-leaks-counter-terrorism-tools-via-trello">left publicly accessible via Google search</a>. An even more concerning detail is that this information may have been accessible for up to four years.</p><h3 class="article-body__section" id="section-zuckerberg-gets-egg-on-his-facebook"><span>Zuckerberg gets egg on his Facebook</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9HReG6dJxDzguAV79bDSDk" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/9HReG6dJxDzguAV79bDSDk.jpg" mos="https://cdn.mos.cms.futurecdn.net/9HReG6dJxDzguAV79bDSDk.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Between <a href="https://www.itpro.com/data-protection/30792/cambridge-analytica-facebook-scandal" target="_blank" data-original-url="https://www.itpro.com/data-protection/30792/cambridge-analytica-facebook-scandal">the Cambridge Analytica scandal</a>, <a href="https://www.itpro.com/strategy/28570/126-million-us-citizens-may-have-seen-russian-facebook-posts" target="_blank" data-original-url="https://www.itpro.com/strategy/28570/126-million-us-citizens-may-have-seen-russian-facebook-posts">Russian information warfare</a> and <a href="https://www.itpro.com/data-protection/30907/mark-zuckerberg-at-congress-why-when-and-where-to-watch" target="_blank" data-original-url="https://www.itpro.com/data-protection/30907/mark-zuckerberg-at-congress-why-when-and-where-to-watch">a series of painfully awkward congressional hearings</a>, Facebook has finally started attracting the attention of lawmakers, and not in a good way. It seems the company has a slight problem with preventing exploitation of its platform, which was highlighted by <a href="https://www.itpro.com/data-breaches/32023/facebook-hack-three-million-eu-users-affected-by-breach" target="_blank" data-original-url="https://www.itpro.com/data-breaches/32023/facebook-hack-three-million-eu-users-affected-by-breach">the theft of 30 million users' access tokens</a> a few months ago.</p><p>These tokens allowed attackers to access a range of personal information from victims' Facebook profiles, including contact details and, in some cases, location information and search history. Three million EU users were affected in the breach, so it's a virtual certainty that the company will have a rather hefty GDPR fine to deal with at some point.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Supermicro finds no evidence of China spy chip infiltration ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/32554/supermicro-finds-no-evidence-of-china-spy-chip-infiltration</link>
                                                                            <description>
                            <![CDATA[ An investigation of the firm’s products finds no evidence of tampering as its CEO hits back at the initial reports ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8Wsxcq6SCQayD97oNr2qGU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KXhz88MrNJwJh4wjmD4kfd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Dec 2018 10:09:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KXhz88MrNJwJh4wjmD4kfd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of a motherboard being examined closely]]></media:description>                                                            <media:text><![CDATA[Image of a motherboard being examined closely]]></media:text>
                                <media:title type="plain"><![CDATA[Image of a motherboard being examined closely]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KXhz88MrNJwJh4wjmD4kfd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hardware manufacturer Supermicro has released the findings of an audit showing no evidence that malicious chips have been inserted into its widely-used motherboards.</p><p>Concerns were <a href="https://www.itpro.com/security/32064/us-dhs-and-uks-ncsc-defend-apple-and-amazons-denial-of-china-spy-chip-infiltration" target="_blank" data-original-url="https://www.itpro.com/security/32064/us-dhs-and-uks-ncsc-defend-apple-and-amazons-denial-of-china-spy-chip-infiltration">sparked after a <em>Bloomberg</em> report in October</a> alleged Chinese operatives had been conducting covert surveillance on major firms such as Apple and Amazon by inserting spy chips' onto Supermicro's motherboards.</p><p>But the firm has now shared the results of a "thorough investigation" of its hardware conducted via a third-party investigations firm and has concluded its chips have not been infiltrated by any threat actors.</p><p>"After thorough examination and a range of functional tests, the investigations firm found absolutely no evidence of malicious hardware on our motherboards," Supermicro's president and CEO Charles Liang <a href="https://www.supermicro.com/en/news/CEO-3rdPartySecurity-Update" target="_blank">said in a letter to customers</a>.</p><p>"These findings were no surprise to us. As we have stated repeatedly, our process is designed to protect the integrity and reliability of our products."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/32064/us-dhs-and-uks-ncsc-defend-apple-and-amazons-denial-of-china-spy-chip-infiltration" data-original-url="/security/32064/us-dhs-and-uks-ncsc-defend-apple-and-amazons-denial-of-china-spy-chip-infiltration">US DHS and UK's NCSC defend Apple and Amazon's denial of China spy chip infiltration</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/32353/china-erases-citizens-social-media-accounts-in-widespread-censorship" data-original-url="/policy-legislation/32353/china-erases-citizens-social-media-accounts-in-widespread-censorship">China erases citizens’ social media accounts in widespread censorship campaign</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/32528/china-was-behind-the-marriott-hotel-hack-claim-investigators" data-original-url="/hacking/32528/china-was-behind-the-marriott-hotel-hack-claim-investigators">China was behind the Marriott Hotel hack, claim investigators</a></p></div></div><p>After the allegations first emerged, both the US Department for Homeland Security (DHS) and the UK's National Cyber Security Centre (NCSC) backed up Supermicro's statements, each suggesting there were no reasons to doubt the denials.</p><p>But the statements came after no official investigation had taken place, with the findings of the newly published security audit, conducted by a third-party company, the only examination of Supermicro's hardware since the reports emerged.</p><p>"As we have stated repeatedly since these allegations were reported, no government agency has ever informed us that it has found malicious hardware on our products," Laing continued.</p><p>"No customer has ever informed us that it found malicious hardware on our products, and we have never seen any evidence of malicious hardware on our products.</p><p>"Today's announcement should lay to rest the unwarranted accusations made about Supermicro's motherboards. We know that many of you are also addressing these issues with your own customers."</p><p>The investigations firm tested a representative sample of Supermicro's motherboards, including the specific motherboard Bloomerberg referenced in its initial report, motherboards bought by companies referenced in the article, and more recently manufactured hardware.</p><p>Supermicro has also said there is a range of safeguards in place to ensure it's difficult as possible to release motherboards that have been tampered with or infiltrated by threat actors, Chinese or otherwise.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Stuxnet is back, Iran admits ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/32264/stuxnet-is-back-iran-admits</link>
                                                                            <description>
                            <![CDATA[ The infamous malware is back, and it's "more violent, more advanced and more sophisticated" than ever ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">trqMttNtQSPwkw5H4msX7t</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TQNcgETvcgaWtWUNsa5r5P-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Nov 2018 12:44:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TQNcgETvcgaWtWUNsa5r5P-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Skull mixed within computer code]]></media:description>                                                            <media:text><![CDATA[Skull mixed within computer code]]></media:text>
                                <media:title type="plain"><![CDATA[Skull mixed within computer code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TQNcgETvcgaWtWUNsa5r5P-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new version of the infamous Stuxnet worm has been used to attack Iranian government networks, according to reports.</p><p>The famous malware has apparently re-emerged, with <a href="https://www.timesofisrael.com/tv-report-israel-silent-as-iran-hit-by-computer-virus-more-violent-than-stuxnet" target="_blank">Israeli news programme Hadashot</a> stating that Iran "has admitted in the past few days that it is again facing a similar attack, from a more violent, more advanced and more sophisticated virus than before, that has hit infrastructure and strategic networks".</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/627223/stuxnet-hits-iran-nuclear-plant" data-original-url="/627223/stuxnet-hits-iran-nuclear-plant">Stuxnet hits Iran nuclear plant</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/29577/the-10-best-or-should-that-be-worst-malware-attacks" data-original-url="/security/innovation-at-work/29577/the-10-best-or-should-that-be-worst-malware-attacks">The 10 best (or should that be worst?) malware attacks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/627013/stuxnet-the-most-serious-threat-yet" data-original-url="/627013/stuxnet-the-most-serious-threat-yet">Stuxnet: The most serious threat yet?</a></p></div></div><p>Iranian General Gholam Reza Jalali also confessed that "recently we discovered a new generation of Stuxnet which consisted of several parts... and was trying to enter our systems," according to <a href="https://www.aljazeera.com/news/2018/10/iranian-official-president-rouhani-cellphone-tapped-181029174453144.html" target="_blank">the Islamic Society of North America</a>.</p><p>Iran has not specified which networks were attacked, or how successful the attack was. It has also not named any suspects as to who orchestrated the attack.</p><p>Stuxnet first made headlines in 2010, when the malware was used to target Iran's nascent nuclear sector. It marked one of the earliest uses of malware in nation-state attacks, and was widely-hailed as the first example of malware specifically designed to attack industrial control systems.</p><p>The first Stuxnet attack is widely believed to have been carried out as a joint operation by US and Israeli intelligence agencies, with the goal of derailing the development of Iran's nuclear weapons programme. The Israeli government has, according to Hadashot, remained silent on its potential involvement in the latest attack.</p><p>Stuxnet used <a href="https://www.itpro.com/642502/the-stuxnet-legacy" target="_blank" data-original-url="https://www.itpro.com/642502/the-stuxnet-legacy">no less than four zero-day exploits</a> in its original form, and was used as a basis for creating further strains of malware than have been used by cybercriminals for the past eight years, including Duqu, Flame and Gauss.</p><p>"Now, over 22 million pieces of malware use that blueprint to attack organisations and states alike across the world," said Broderick Perelli-Harris, senior director of professional services at security firm Venafi.</p><p>"It's easy for organisations and governments to ignore when it's used against an adversarial state, but the blueprint remains 'in the wild' for cybercriminals to exploit. The new Stuxnet reminds us that governments need to think very carefully when they are creating cyber-arms, so that they do not escalate the problem. Cyber weapons are much more prone to proliferation and almost impossible to control, it's nave to think we can."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The UK will face a category one attack in the future ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/32126/the-uk-will-face-a-category-one-attack-in-the-future</link>
                                                                            <description>
                            <![CDATA[ The NCSC's boss says the UK has yet to see a major state-sponsored cyber attack, but it is coming ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bocb1QcJJxZkAVThn7x6k8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hNULXFScd23tuNBhSYydMD-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Oct 2018 08:46:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/hNULXFScd23tuNBhSYydMD-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[USB face mechanical bug]]></media:description>                                                            <media:text><![CDATA[USB face mechanical bug]]></media:text>
                                <media:title type="plain"><![CDATA[USB face mechanical bug]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hNULXFScd23tuNBhSYydMD-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Cyber Security Centre (NCSC) has been thwarting more than 10 cyber threats per day, on average, according to its annual review, but it's still warning that something bigger is looming.</p><p>Despite preventing over 1,000 cyber attacks in its two-year history, the NCSC's CEO Ciaran Martin said that the UK will face a real test of its security infrastructure soon enough. </p><p>"Although the UK is making significant progress in improving our cybersecurity, that does not mean that we are getting everything right, or that the threat is abating," Martin said.</p><p>"Proof of that, if it were needed, is that in the two years of our existence the NCSC has dealt with well over 1,000 cyber security incidents.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" data-original-url="/security/31527/how-russia-hacked-the-2016-election">How Russia hacked the 2016 election</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32054/the-uk-us-and-netherlands-accuse-russia-of-cyber-attacks" data-original-url="/security/32054/the-uk-us-and-netherlands-accuse-russia-of-cyber-attacks">The UK, US and Netherlands accuse Russia of cyber attacks</a></p></div></div><p>"The majority of these incidents were, we believe, perpetrated from within nation states in some way hostile to the UK. They were undertaken by groups of computer hackers directed, sponsored or tolerated by the governments of those countries."</p><p>These groups constitute the most acute and direct cyber threat to the UK's national security, according to Martin. </p><p>"I remain in little doubt we will be tested to the full, as a centre, and as a nation, by a major incident at some point in the years ahead, what we would call a Category 1 attack."</p><p>A category one attack is the most serious of six-levels of cyber attack classification, which is defined as an attack that causes sustained disruption of essential services or affects national security to the extent that it results in severe economic or social consequences or even loss of life. A category one attack is the only classification ministers and cabinet members must be strategically involved in.</p><p>According to the NCSC, there have been several very significant incidents, but the UK has avoided a Category one. However, some of its foremost international partners have not. A known example of a category one incident is the alleged assault on the <a href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" target="_blank" data-original-url="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election">US national elections in 2016</a> by Russian state-sponsored agents.</p><p>Earlier this year the NCSC published evidence of Russian pre-positioning on some of the UK's critical sectors, along with detailed technical guidance for business, but according to Martin, it's not just Russia the UK needs to worry about.</p><p>"These attacks have come from a range of states, as well as many non-state sources. There is much, much more to the cybersecurity threat to the UK than just Russia," he said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The UK, US and Netherlands accuse Russia of cyber attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/32054/the-uk-us-and-netherlands-accuse-russia-of-cyber-attacks</link>
                                                                            <description>
                            <![CDATA[ Russian spies have been accused of involvement in a series of cyber-plots across the globe ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jhmnqBiDqi4igZ3rzyk9xu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NNiQSxqq39Pw6Hkzq6TtNM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Oct 2018 08:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NNiQSxqq39Pw6Hkzq6TtNM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Putin looking villianish]]></media:description>                                                            <media:text><![CDATA[Putin looking villianish]]></media:text>
                                <media:title type="plain"><![CDATA[Putin looking villianish]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NNiQSxqq39Pw6Hkzq6TtNM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK, US and the Netherlands have accused Russia of being responsible for a spate of global cyber attacks, with seven people being charged by the US.</p><p>The charges against the seven include conspiracy to commit computer fraud, conspiracy to commit wire fraud, aggravated identity theft and conspiracy to commit money laundering.</p><p>Four the seven were the men expelled from the Netherlands having after being caught attempting a cyber-attack on the headquarters of the international chemical weapons watchdog, which was disrupted by Dutch military intelligence.</p><p>The hack was thwarted with the aid of British intelligence officials and on Thursday the UK government accused the Kremlin of violating international laws with "indiscriminate and reckless cyber attacks".</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/29017/fancy-bears-names-footballers-permitted-to-use-prohibited-substances" data-original-url="/hacking/29017/fancy-bears-names-footballers-permitted-to-use-prohibited-substances">Fancy Bears names footballers permitted to use prohibited substances</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29808/bad-rabbit-ransomware-found-to-be-similar-to-notpetya" data-original-url="/security/29808/bad-rabbit-ransomware-found-to-be-similar-to-notpetya">'Bad Rabbit' ransomware found to be similar to NotPetya</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" data-original-url="/security/31527/how-russia-hacked-the-2016-election">How Russia hacked the 2016 election</a></p></div></div><p>The NCSC said it has assessed with high confidence that the GRU has almost certainly been conducting attacks under various aliases, such as Fancy Bear, Sednit and APT 28.</p><p>The NCSC has blamed the GRU for attacks such as the <a href="https://www.itpro.com/hacking/29017/fancy-bears-names-footballers-permitted-to-use-prohibited-substances" target="_blank" data-original-url="https://www.itpro.com/hacking/29017/fancy-bears-names-footballers-permitted-to-use-prohibited-substances">2017 WADA email leak</a>, which saw the identities of 28 football players who had received a Therapeutic Use Exemptions (TUEs) released online.</p><p>The Kremlin has also been accused of the 2017 <a href="https://www.itpro.com/security/29808/bad-rabbit-ransomware-found-to-be-similar-to-notpetya" target="_blank" data-original-url="https://www.itpro.com/security/29808/bad-rabbit-ransomware-found-to-be-similar-to-notpetya">'Bad Rabbit</a>' ransomware that encrypted hard drives and rendered IT inoperable, resulting in mass disruption to services including the Kyiv metro, Odessa airport, Russia's central bank and two Russian media outlets.</p><p>The NCSC also said, with high confidence, that the Kremlin was also responsible for hacking the <a href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" target="_blank" data-original-url="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election">Democratic National Committee (DNC)</a> in 2016, which also affected the US presidential election of the same year.</p><p>Now, Seven Russian government operatives have been charged by the FBI with hacking into the computer networks. According to the indictment, starting in 2014, the defendants, who worked in for the GRU, engaged in "persistent and sophisticated criminal cyber intrusions".</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LSk22kCxu7RqooUyJDRDdH" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/LSk22kCxu7RqooUyJDRDdH.png" mos="https://cdn.mos.cms.futurecdn.net/LSk22kCxu7RqooUyJDRDdH.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><strong><em>The seven men appear on a wanted poster released by the FBI</em></strong></p><p>In the past week, the Fancy Bear group has been implicated as being responsible for a series of attacks on government entities using the <a href="https://www.itpro.com/security/32009/fancy-bear-cracks-into-government-computers-with-lojax-uefi-rootkit" target="_blank" data-original-url="https://www.itpro.com/security/32009/fancy-bear-cracks-into-government-computers-with-lojax-uefi-rootkit">'LoJax' malware</a>, a new strain that exploits the Unified Extensible Firmware Interface (UEFI) on modern computers and is almost impossible to remove.</p><p>SonicWall CEO Bill Conner, has previously advised both the UK and US governments on cybersecurity, has called for global cooperation to fight the growing threat of international cyber attacks.</p><p>"Whether it's elections, tariffs or natural disasters, countries currently tend to operate independently. However, the cyber landscape, with its non-existent borders and limitless boundaries, is forcing us to work together in new ways.</p><p>"The announcement by the UK government highlights a growing need for public and private sectors around the world to work together to detect, defend and dissipate the rising volume and ferocity of cyber attacks."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ and MoD to form £250m ‘joint cyber-force’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cyber-warfare/31958/gchq-and-mod-to-form-250m-joint-cyber-force</link>
                                                                            <description>
                            <![CDATA[ The 2,000-strong unit will launch cyber attacks against ISIS, Russia and criminal gangs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oUHc8f5yEbNXmxP88J2Crb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TB4k65RSHCpj6gEkZnJqpD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Sep 2018 10:21:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TB4k65RSHCpj6gEkZnJqpD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic depicting cyber warfare as a soldier works in a room full of computers]]></media:description>                                                            <media:text><![CDATA[Graphic depicting cyber warfare as a soldier works in a room full of computers]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic depicting cyber warfare as a soldier works in a room full of computers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TB4k65RSHCpj6gEkZnJqpD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GCHQ will create an offensive cyber unit to fight the growing wave of national security threats Britain faces from around the world.</p><p>A partnership between the Ministry of Defence (Mod) and the UK's intelligence organisation will see the government committing more than 250 million with 2,000 individuals deployed to orchestrate offensive actions.</p><p>According to <a href="https://www.thetimes.co.uk/edition/news/britain-launches-250m-cyber-force-to-wage-war-on-terrorists-wnq9q506c" target="_blank"><em>The Times</em></a>, the rising cyber threat from nations such as Russia and Iran, as well as terrorist groups like ISIS, will see experts brought in from the military, security services, and the cyber security industry.</p><p>"The MoD and GCHQ have a long and proud history of working together," a government spokesperson told <em>IT Pro</em>. "We are both committed to continuing to invest in this area, given the real threats the UK faces."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/31675/gchq-5g-could-open-doors-to-cyber-rogues" data-original-url="/network-internet/31675/gchq-5g-could-open-doors-to-cyber-rogues">GCHQ: 5G could open doors to 'cyber rogues'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31932/has-demand-for-cyber-security-skills-hit-crisis-point" data-original-url="/security/31932/has-demand-for-cyber-security-skills-hit-crisis-point">Has demand for cyber security skills hit crisis point?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" data-original-url="/security/31527/how-russia-hacked-the-2016-election">How Russia hacked the 2016 election</a></p></div></div><p>The new force, expected to be announced soon, will represent a step change in cyber strategy from a more defensive outlook to an offensive one. Targets on the list include rogue nations, extremist groups, and people-traffickers as well as paedophile rings.</p><p>The formation of this unit follows a <a href="https://www.gov.uk/government/news/british-prosperity-relies-on-defence-according-to-independent-review" target="_blank">review ordered by</a> defence <a href="https://www.gov.uk/government/news/british-prosperity-relies-on-defence-according-to-independent-review" target="_blank">secretary Gavin Williamson</a>, and has been given the working name "joint cyber-force". It'll see a quadrupling in manpower allocated towards offensive actions - and comes just five months after GCHQ revealed it had conducted its first successful cyber attack on ISIS.</p><p>In his first speech as GCHQ director in April, Jeremy Fleming confirmed the massive offensive action which was orchestrated last year <a href="https://www.itpro.com/cyber-warfare/30932/gchq-reveals-isis-was-the-target-of-its-first-major-cyber-attack" target="_blank" data-original-url="https://www.itpro.com/cyber-warfare/30932/gchq-reveals-isis-was-the-target-of-its-first-major-cyber-attack">systematically degraded the extremist group's online infrastructure</a>.</p><p>"Daesh's ability to inspire, direct and enable attacks, and the simple tactics they use make stopping attacks much, much harder," Fleming said. "But the UK's CT team - led by MI5 and the Police, supported by GCHQ, MI6 and the Military - is evolving fast to match this threat."</p><p>He continued: "These operations have made a significant contribution to coalition efforts to suppress Daesh propaganda, hindered their ability to coordinate attacks, and protected coalition forces on the battlefield.</p><p>"But cyber is only one part of the wider international response. This is the first time the UK has systematically and persistently degraded an adversary's online efforts as part of a wider military campaign. Did it work? I think it did."</p><p>The threat faced by nations such as Russia not only manifest as incidents such as the Salisbury poisoning but a number of aggressive cyber events like the <a href="https://www.itpro.com/cyber-warfare/30932/gchq-reveals-isis-was-the-target-of-its-first-major-cyber-attack" target="_blank" data-original-url="https://www.itpro.com/cyber-warfare/30932/gchq-reveals-isis-was-the-target-of-its-first-major-cyber-attack">alleged hacking of the 2016 US presidential election</a>.</p><p>The nation has also been accused of polluting public discourse in the West after research last month revealed the rise in anti-vaxx conspiracy theories circulating online can be <a href="https://www.itpro.com/botnets/31777/growing-anti-vaxx-online-debate-pinned-on-russian-botnets" target="_blank" data-original-url="https://www.itpro.com/botnets/31777/growing-anti-vaxx-online-debate-pinned-on-russian-botnets">pinned on Russian-originating botnets</a>.</p><p>Unlike conventional botnets, used to spread malware, these networks served as 'content polluters' to disseminate fake news and erode public trust in the scientific establishment.</p><p>"This announcement highlights the growing need for more cyber-savvy workers in the UK, to secure our future at a national, organisational and personal level," said CEO of Cyber Security Challenge UK Colin Lobley.</p><p>"While many people are still unsure of what a career in cyber security would look like, the reality is that many of these jobs require similar skills and knowledge to more known careers.</p><p>"For example, we need architects to build secure networks, lawyers to process cybercrime cases, psychologists to assess how human behaviour influences security, as well as military roles to act against national threats."</p><p><em>IT Pro </em>approached GCHQ for comment but did not get a response at the time of writing.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US charges North Korean hacker with WannaCry and Sony hack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/wannacry/31857/us-charges-north-korean-hacker-with-wannacry-and-sony-hack</link>
                                                                            <description>
                            <![CDATA[ A North Korean programmer is accused of conducting cyber attacks on behalf of the government ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tH9ccpLCiEKBfpJwYpvwvt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zW5FHpNwsFKAPJ5XeTXpzD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Sep 2018 09:36:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zW5FHpNwsFKAPJ5XeTXpzD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korea]]></media:description>                                                            <media:text><![CDATA[North Korea]]></media:text>
                                <media:title type="plain"><![CDATA[North Korea]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zW5FHpNwsFKAPJ5XeTXpzD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Department of Justice has formally charged a North Korean government hacker with a series of major cyber attacks, including <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" target="_blank" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">the Sony Pictures hack</a>, the theft of $81 million from the Bangladesh Bank and the WannaCry ransomware.</p><p>The <a href="https://assets.documentcloud.org/documents/4834314/Read-the-DOJ-s-criminal-complaint-against-an.pdf" target="_blank">charges</a> have been filed against North Korean programmer Park Jin Hyok, who the US claims was working as part of a North Korean government-backed hacking operation known commonly as Lazarus Group.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30510/kaspersky-north-korea-framed-for-winter-olympics-malware" data-original-url="/hacking/30510/kaspersky-north-korea-framed-for-winter-olympics-malware">Kaspersky: North Korea framed for Winter Olympics malware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" data-original-url="/security/31527/how-russia-hacked-the-2016-election">How Russia hacked the 2016 election</a></p></div></div><p>Park, who was educated at a North Korean university, spent a number of years employed by Chosun Expo Joint Venture, a company that is used as a front by the North Korean government and is allegedly used to fund a government cyber espionage division known as 'Lab 110'.</p><p>Through an elaborate network of dummy email addresses and social media accounts, network infrastructure paths and IP addresses, investigators say they have managed to link Park and a number of unnamed co-conspirators to key hacks - most notably, the WannaCry ransomware that temporarily crippled the NHS and caused global chaos.</p><p>Park and his colleagues were also linked to the 2014 attack on Sony Pictures, which saw caches of internal emails - as well as whole unreleased films - leaked online in retaliation for the release of Seth Rogen and James Franco's film The Interview, which mocks North Korean 'Supreme Leader' Kim Jong Un.</p><p>"The scope and damage of the computer intrusions perpetrated [by Park and his allies] is virtually unparalleled," said FBI Special Agent Nathan Shields as part of a sworn affidavit. "The attacks and intrusions described...would have each required the efforts of a well-resourced team of persons working in concert, each performing different tasks.</p><p>"The technical evidence... shows that those attacks and intrusions were carried out by a group of persons with access to the same email and social media accounts, computer infrastructure, and source code. Tracing connections back through the operational infrastructure reveals numerous connections between Park, his true-name email and social media accounts and the operational accounts used to conduct the cyber attacks."</p><p>While both the UK and the US have publicly <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">blamed North Korea for unleashing WannaCry</a>, this marks the first time that the US government has formally charged an operative of the Democratic People's Republic of Korea for hacking. It follows similar charges which have been levelled at Russian, Iranian and Chinese hackers over the last few years.</p><p>While it has no bearing on his own legal battle, the news has been greeted warmly by <a href="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges" target="_blank" data-original-url="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges">British malware researcher Marcus Hutchins</a>. Hutchins was the one who discovered the 'kill-switch' that was built into WannaCry, effectively halting the malware's devastating spread.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1037866475426467840"></a></p></blockquote><div class="see-more__filter"></div></div><p>Although the US government has not charged him with any involvement in the creation of WannaCry, the allegations that he was involved with the Kronos banking Trojan has led some to accuse him of being part of WannaCry as well.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1037754488302399488"></a></p></blockquote><div class="see-more__filter"></div></div><p>"Law enforcement agencies and government officials around the world are challenged by the internet's invisible borders and its nameless perpetrators when it comes to pursuing or charging cybercriminals," said SonicWall CEO Bill Conner.</p><p>"While almost four years have passed since the communications giant sent notifications of its attacks, the U.S. Justice Department's actions are commendable and should serve as a reminder for consumers and organizations alike to remain vigilant."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Five Eyes’ nations hand tech giants encryption ultimatum  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/encryption/31822/five-eyes-nations-hand-tech-giants-encryption-ultimatum</link>
                                                                            <description>
                            <![CDATA[ Industry given final warning as governments declare they are ready to legislate for backdoor access ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">35B1iBncwPZe5T33Sh9Czk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EfPtkbb6TsPgz8vybDsG2R-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Sep 2018 09:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EfPtkbb6TsPgz8vybDsG2R-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Padlock over lines of binary code]]></media:description>                                                            <media:text><![CDATA[Padlock over lines of binary code]]></media:text>
                                <media:title type="plain"><![CDATA[Padlock over lines of binary code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EfPtkbb6TsPgz8vybDsG2R-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The 'Five Eyes' governments of the UK, US, Canada, Australia, and New Zealand have challenged tech companies to voluntarily create backdoor access to their systems, or be compelled to by law.</p><p>Encryption, deployed by companies such as WhatsApp and Google to guarantee user privacy, poses a significant challenge to combating serious crimes and terrorism, the five nations' interior ministers agreed at a two-day summit on Australia's Gold Coast last week.</p><p>"Encryption is vital to the digital economy and a secure cyberspace, and to the protection of personal, commercial and government information," the five ministers, including the UK's home secretary Sajid Javid, <a href="https://www.homeaffairs.gov.au/about/national-security/five-country-ministerial-2018" target="_blank">said in a joint statement</a>.</p><p>"However, the increasing use and sophistication of certain encryption designs present challenges for nations in combating serious crimes and threats to national and global security.</p><p>"Many of the same means of encryption that are being used to protect personal, commercial and government information are also being used by criminals, including child sex offenders, terrorists and organized crime groups to frustrate investigations and avoid detection and prosecution."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/encryption/31022/amber-rudds-war-on-tech-is-over" data-original-url="/encryption/31022/amber-rudds-war-on-tech-is-over">Amber Rudd's war on tech is over</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/31030/whatsapp-s-jan-koum-cuts-ties-with-facebook-amid-claims-of" data-original-url="/business-strategy/careers-training/31030/whatsapp-s-jan-koum-cuts-ties-with-facebook-amid-claims-of">WhatsApp’s Jan Koum cuts ties with Facebook amid claims of clashes over data privacy and encryption</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-terrorism/31247/quantum-computing-could-help-fight-terrorism-says-uk-gov" data-original-url="/cyber-terrorism/31247/quantum-computing-could-help-fight-terrorism-says-uk-gov">Quantum computing could help fight terrorism, says UK gov</a></p></div></div><p>If the industry does not "voluntarily establish lawful access solutions to their products" the statement continued, "we may pursue technological, enforcement, legislative or other measures" to guarantee entry.</p><p>The Five Country Ministerial (FCM), which concluded this weekend, also saw the five nations discuss intelligence sharing, and how to most-effectively remove illegal and harmful content from the internet.</p><p>Despite being <a href="https://www.itpro.com/policy-legislation/31163/uk-government-draws-up-new-laws-after-social-media-firms-spurn-abuse-talks" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/31163/uk-government-draws-up-new-laws-after-social-media-firms-spurn-abuse-talks">spurned by tech companies for consultations</a> over how best to manage online spaces, the ministers agreed to another joint statement reiterating their commitment to ridding the internet of "child predators, terrorists, violent extremists and other illicit actors".</p><p>They called for the industry to implement functions that prevent illicit content from being uploaded in the first place, and build user safety into the design of all online platforms, among a host of other demands.</p><p>This tougher stance, on both encryption and illicit online content, follows the European Union's (EU's) soundings in August that it would draw up new laws to fine companies like YouTube and Facebook for failing to remove extremist material within an hour.</p><p>"We cannot afford to relax or become complacent in the face of such a shadowy and destructive phenomenon," said <a href="https://www.itpro.com/policy-legislation/31733/eu-will-fine-social-media-firms-for-failing-to-remove-extremist-material" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/31733/eu-will-fine-social-media-firms-for-failing-to-remove-extremist-material">European commissioner for the security union Julian King</a>.</p><p>The principles agreed at the FCM, particularly around encryption, have reignited a debate centring on privacy versus security - with law enforcement agencies increasingly frustrated at being unable to access communications seized as part of their investigations.</p><p>The UK's National Crime Agency (NCA) <a href="https://www.itpro.com/security/31115/nca-complains-that-encryption-hampers-crime-fighting" target="_blank" data-original-url="https://www.itpro.com/security/31115/nca-complains-that-encryption-hampers-crime-fighting">said in its annual assessment of serious crime</a> earlier this year that encryption impacts how effective law enforcement organisations can be in gathering intelligence and collecting evidence.</p><p>But former home secretary Amber Rudd, as with her successor Sajid Javid, had gone <a href="https://www.itpro.com/encryption/31022/amber-rudds-war-on-tech-is-over" target="_blank" data-original-url="https://www.itpro.com/encryption/31022/amber-rudds-war-on-tech-is-over">one step further to suggest tech companies should insert backdoor access into their products</a> - undermining the principles of encryption entirely.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Growing 'anti-vaxx' online debate pinned on Russian botnets ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/botnets/31777/growing-anti-vaxx-online-debate-pinned-on-russian-botnets</link>
                                                                            <description>
                            <![CDATA[ Sophisticated bots and trolls are ‘playing both sides’ of the debate to spread public health myths ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rpWU9soLa6BAWoYiemswva</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VaYq4WC25EYpzyS4Lwhmwg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Aug 2018 10:38:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VaYq4WC25EYpzyS4Lwhmwg-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Map of Russian-originating bots connected together through a botnet]]></media:description>                                                            <media:text><![CDATA[Map of Russian-originating bots connected together through a botnet]]></media:text>
                                <media:title type="plain"><![CDATA[Map of Russian-originating bots connected together through a botnet]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VaYq4WC25EYpzyS4Lwhmwg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Russian bots are engaged in a campaign to spread health-related myths on Twitter - by promoting the views of vaccine sceptics and posing as users concerned with public health.</p><p>Unlike conventional <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet" target="_blank" data-original-url="https://www.itpro.com/botnets/1644/what-is-a-botnet">botnets</a>, which are used to spread malware, "content polluters" - likely originating in Russia - use similar methods to promote conspiracy theories and myths around vaccination, according to a study in the American Journal of Public Health (AJPH).</p><p>Researchers examined the frequency of anti-vaxx messages posted by humans and suspected bots between 2014 and 2017, and analysed the content posted on Twitter hashtags associated with Russian troll activity.</p><p>The study, titled '<a href="https://ajph.aphapublications.org/doi/pdf/10.2105/AJPH.2018.304567" target="_blank">Weaponised Health Communication</a>', found that by confronting vaccine sceptics directly, bots were able to legitimise their position in the public discourse - and artificially inflate the anti-vaccine debate.</p><p>"Unlike troll accounts, content polluters (ie, disseminators of malware, unsolicited commercial content, and other disruptive material that typically violates Twitter's terms of service) post anti-vaccine messages 75% more often than does the average non-bot Twitter user," the researchers concluded.</p><p>"Thus, it is unclear to what extent their promotion of vaccine-related content is driven by true anti-vaccine sentiment or is used as a tactic designed to drive up click-through rates by propagating motivational content ("clickbait")."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/botnets/1644/what-is-a-botnet" data-original-url="/botnets/1644/what-is-a-botnet">What is a botnet?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/botnets/31641/duo-unravels-massive-three-tiered-crypto-giveaway-botnet" data-original-url="/botnets/31641/duo-unravels-massive-three-tiered-crypto-giveaway-botnet">Duo unravels massive three-tiered ‘crypto-giveaway’ botnet</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/30776/chinese-hackers-building-a-botnet-out-of-five-million-compromised-android-devices" data-original-url="/mobile/30776/chinese-hackers-building-a-botnet-out-of-five-million-compromised-android-devices">Chinese hackers building a botnet out of five million compromised Android devices</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" data-original-url="/security/31527/how-russia-hacked-the-2016-election">How Russia hacked the 2016 election</a></p></div></div><p>Vaccines have long been considered safe and risk-free according to the overwhelming medical and scientific consensus. But myths and scare campaigns around vaccine usage at different points in time have led to the needless spread of disease and public health issues.</p><p>A recent resurgence of Measles across Europe, for instance, with <a href="https://www.theguardian.com/society/2018/aug/20/low-mmr-uptake-blamed-for-surge-in-measles-cases-across-europe" target="_blank">41,000 cases recorded in the six first months of 2018</a> - more than double the whole of last year - has been tied with false claims around vaccinations which have hindered parents from immunising their children.</p><p>The study found that Russian trolls and Twitter bots post content about vaccinations, both positive and negative, at significantly higher rates than the average user, indicating the aim was not to promote either side of the debate - but t raise the prominence of the debate itself.</p><p>Examples of myths propagated include the idea that vaccines can cause fatal side effects, that a secret government database of vaccine-damaged children exists, and that most diseases vaccines target are relatively harmless - making vaccines a needless risk.</p><p>"The highest proportion of anti-vaccine content is generated by accounts with unknown or intermediate bot scores," the researchers continued.</p><p>"Although we speculate that this set of accounts contains more sophisticated bots, trolls, and cyborgs, their provenance is ultimately unknown.</p><p>"Therefore, beyond attempting to prevent bots from spreading messages over social media, public health practitioners should focus on combating the messages themselves while not feeding the trolls."</p><p>Botnets are conventionally deployed to spread malware, and are becoming increasingly sophisticated as cyber security specialists attempt to combat them. Duo Security, for instance, earlier this month revealed <a href="https://www.itpro.com/botnets/31641/duo-unravels-massive-three-tiered-crypto-giveaway-botnet" target="_blank" data-original-url="https://www.itpro.com/botnets/31641/duo-unravels-massive-three-tiered-crypto-giveaway-botnet">the existence of a 15,000-strong botnet structured in a three-tiered hierarchy</a> which promoted a fake cryptocurrency giveaway; evolving over time to remain undetected.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is hacktivism? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hacking/30203/what-is-hacktivism</link>
                                                                            <description>
                            <![CDATA[ From Anonymous to the IT Army of Ukraine, we answer 'what is hacktivism' and guide you through the history of the most compelling corner of the tech industry ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dc4MU3PCvVo64fDmCFx45C</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2Duur9at2EY8WrGhCr8Tx6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Aug 2018 07:45:00 +0000</pubDate>                                                                                                                                <updated>Mon, 20 Feb 2023 16:07:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ connor.jones@futurenet.com (Connor Jones) ]]></author>                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Connor Jones is the News and Analysis Editor at ITPro, CloudPro, and ChannelPro. As the brands’ leader for news, he welcomes pitches on all topics, and he personally still reports breaking news on the topics of cyber security, software, and Big Tech firms.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;He has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs.&lt;/p&gt;
&lt;p&gt;Connor is currently in his third year at ITPro, but has been a journalist for much longer, having written for the likes of Red Bull Esports and UNILAD. He has a master’s degree in Magazine Journalism from one of the UK’s leading journalism departments at the University of Sheffield, as well as an undergraduate degree in English Language from Sheffield Hallam University.&lt;/p&gt;
&lt;p&gt;When he’s not hitting the phones trying to squeeze stories out of sources and press offices, in his free time Connor studies software development, is a keen cook, and enjoys leading an active life through cycling, hiking, racket sports, and weightlifting.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2Duur9at2EY8WrGhCr8Tx6-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Two masked members of Anonymous demonstrating during the Occupy protest on October 15, 2011 in The Hague]]></media:description>                                                            <media:text><![CDATA[Two masked members of Anonymous demonstrating during the Occupy protest on October 15, 2011 in The Hague]]></media:text>
                                <media:title type="plain"><![CDATA[Two masked members of Anonymous demonstrating during the Occupy protest on October 15, 2011 in The Hague]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2Duur9at2EY8WrGhCr8Tx6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The often offensive form of cyber activism, hacktivism, is just as curious a concept as its analogue counterpart. Doing things that skirt the line between good and bad, all for a higher cause - worthy or not - is always guaranteed to divide onlookers. But, whatever your views are on hackers, it’s worth holding your judgement until you understand what hacktivism is and how it plays into the wider cyber security industry.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/27953/will-president-trump-inspire-a-hacktivism-revival" data-original-url="/security/27953/will-president-trump-inspire-a-hacktivism-revival">Will President Trump inspire a hacktivism revival?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/635278/five-reasons-hacktivists-cant-be-stopped" data-original-url="/635278/five-reasons-hacktivists-cant-be-stopped">Five reasons hacktivists can’t be stopped</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/29937/anti-isis-hacktivists-compromise-terrorists-website" data-original-url="/hacking/29937/anti-isis-hacktivists-compromise-terrorists-website">Anti-Isis hacktivists compromise terrorists' website</a></p></div></div><p>Hackers who carry out cyber attacks are the ones most associated with the concept of hacking. Cyber criminals have enjoyed a rewarding threat landscape over the past few years, especially since the advent of <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a>, which continues to be a scourge on the wider tech industry. Indeed, the business model for black hats is nuanced and successful. It’s no wonder there are so many of them. </p><p>But for every bad egg, there are a dozen good ones that stay on the right side of the moral line. <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">Ethical hackers</a> and <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testers</a> are two of the most well-known types of hacking experts that use their skills for good, to keep the bad guys at bay.</p><p>Hacktivists commonly fall somewhere in between these two groups, arguably leaning more into the nefarious side of the equation. The methods hacktivists use to complete their goals are often illegal ones, but whether you think their cause is for good or bad, they believe what they’re doing is right. Hacktivists can certainly operate on both sides of the good-bad gamut - we’ve seen it in play during Russia’s invasion of Ukraine. The latter’s ‘IT Army of Ukraine conducts daily attacks against Russian targets, and Russia-aligned hacking groups do the same right back. Then, of course, who could forget Anonymous - perhaps the most famous hacktivist collective of them all?</p><h2 id="the-history-of-hacktivism">The history of hacktivism</h2><p>Hacktivism has its roots in the early days of the internet when hackers primarily congregated on Usenet and message boards. Many of these early hackers were motivated by idealism, with a general tendency towards left-wing, anti-capitalist, and anti-corporate viewpoints. This, combined with a sense of anarchic mischief and a love of messing with people and systems, spurred numerous hacks protesting various social and political issues.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=45148356&theme=light&playlist=false&playlist-continuous=false&autoplay=false&live-autoplay=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><p>Hackers deployed various forms of <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> against targets to disrupt their operations, hindering progress by rendering computer systems and networks unusable. An early example was the hilariously named Worms Against Nuclear Killers<em> </em>malware, which was released into NASA's networks in 1989 to protest the launch of the nuclear-powered rocket carrying the Galileo probe into orbit. The attack reportedly cost the project half a million dollars in lost time and resources, according to officials.</p><h2 id="who-are-the-anonymous-hacking-group">Who are the Anonymous hacking group?</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6JWu5tPs6NR2CXDxtPqvCE" name="" alt="A person wearing a Guy Fawkes mask as a symbol of the Anonymous hacking collective" src="https://cdn.mos.cms.futurecdn.net/6JWu5tPs6NR2CXDxtPqvCE.jpg" mos="https://cdn.mos.cms.futurecdn.net/6JWu5tPs6NR2CXDxtPqvCE.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Modern hacktivism, however, has been defined mainly by the group known as Anonymous. First emerging in the early 2000s, Anonymous was originally the collective name given to groups of users from the 4chan message boards, who would frequently band together to attack targets based on little more than an idle whim. These attacks ranged from relatively harmless pranks, such as ordering numerous pizzas to someone's house, to more vicious attacks such as carrying out DDoS strikes against websites or doxxing people.</p><p>What makes Anonymous unique is that it has no formal membership, controlling body or internal structure. Anyone can participate in its operations at will, and the targets and attack vectors it picks are determined by popular consensus amongst its members and fans. In its early days, Anonymous wasn't overly focused on political or ideological issues, preferring instead to target internet personalities that its members felt needed to be taken down a peg or two.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9qDUhmSsLu8o6C4Q9NqjAX" name="9qDUhmSsLu8o6C4Q9NqjAX.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/9qDUhmSsLu8o6C4Q9NqjAX.png" mos="https://cdn.mos.cms.futurecdn.net/9qDUhmSsLu8o6C4Q9NqjAX.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>PowerEdge - Cyber resilient infrastructure for a Zero Trust world</strong></p><p class="fancy-box__body-text">Combat threats with an in-depth security stance</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370028/poweredge-cyber-resilient-infrastructure-for-a-zero-trust-world" data-original-url="/security/cyber-security/370028/poweredge-cyber-resilient-infrastructure-for-a-zero-trust-world">FREE DOWNLOAD</a></p></div></div><p>The group's first real foray into hacktivism came in 2008 when the group began a campaign of attacks against the church of Scientology. Operation Chanology, as it was known, included a week-long <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">DDoS</a> against the church's website, along with physical protests outside various Scientologist properties. The adoption by protestors of the Guy Fawkes mask from cult graphic novel V for Vendetta, incidentally, is what led to its now-iconic status as a symbol of hacktivism.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/https://www.itpro.com/security/cyber-security/359759/the-it-pro-podcast-why-is-it-so-hard-to-convict-hackers" allowfullscreen></iframe></div></div><p>Following Project Chanology, Anonymous has also been heavily involved in various campaigns to foil attacks on internet freedoms. The group mounted significant efforts to fight the Stop Online Piracy Act (SOPA) and the Protect Intellectual Property Act (PIPA), both of which were accused of being efforts to censor the web. In more recent years, the group has been carrying out persistent attacks against the online arms of the terrorist group ISIS, targeting websites and social media accounts used to spread propaganda.</p><p>Most recently the group formed a stand against Putin’s invasion of Ukraine and has shouted loud and proud about its efforts in cyber space so far. Most notably, the group claimed it was able to replace the disinformation broadcast to the Russian public through state-affiliated media with <a href="https://www.itpro.com/security/hacking/365021/anonymous-hack-russian-state-broadcasts" data-original-url="https://www.itpro.com/security/hacking/365021/anonymous-hack-russian-state-broadcasts">genuine images and messages from inside Ukraine</a>.</p><p>Hacktivism is often controversial. While many decry the use of objectively illegal cyber attacks, no matter how noble the cause, many applaud vigilante hackers like Anonymous and others for taking the law into their own hands.</p><h2 id="recent-cases-of-hacktivism">Recent cases of hacktivism</h2><p>The number of large-scale, international hacking operations most commonly associated with hacktivism has declined dramatically over the last 10 years, with IBM reporting a 95% drop in the number of hacktivist attacks between 2015 and 2019. According to <em>Recorded Future</em>, this could be due to the fact that, while corporate defences have improved over the years, the attack vectors, tools, and techniques used by hacktivist groups have remained largely unchanged since 2010.</p><p>However, this doesn’t mean that hacktivists have given up their efforts. In fact, multiple events from earlier this year have been considered to be symptoms of a resurgence of hacktivism, one of them being the <a href="https://www.itpro.com/business/business-strategy/358296/big-tech-companies-put-political-donations-on-hold-following" data-original-url="https://www.itpro.com/business/business-strategy/358296/big-tech-companies-put-political-donations-on-hold-following">storming of the US Capitol</a> on 6 January 2021, videos of which were taken and uploaded onto right-wing social media site <a href="https://www.itpro.com/business/policy-legislation/358326/the-fate-of-parler-exposes-reality-of-deregulated-social-media" data-original-url="https://www.itpro.com/business/policy-legislation/358326/the-fate-of-parler-exposes-reality-of-deregulated-social-media">Parler</a> by the rioters themselves. One hacker, known online as donk_enby, launched a collective action to gather the evidence of the Capitol lootings so that the perpetrators could be identified and prosecuted. Weeks later, donk_enby was asked by protesters in Myanmar to use her skills and platform to help identify numerous military contractors involved in the coup. According to <a href="https://www.reuters.com/article/us-cyber-hacktivism-focus-idUSKBN2BH3HJ"><em>Reuters</em></a>, this ultimately led to the military leaders having their <a href="https://www.itpro.com/email-providers/30214/how-to-delete-a-gmail-account" data-original-url="https://www.itpro.com/email-providers/30214/how-to-delete-a-gmail-account">Google accounts</a> suspended and sanctions imposed on them.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bvfrDixcPq8CeZ74cb4kWn" name="" alt="George Floyd mural in Manchester" src="https://cdn.mos.cms.futurecdn.net/bvfrDixcPq8CeZ74cb4kWn.jpg" mos="https://cdn.mos.cms.futurecdn.net/bvfrDixcPq8CeZ74cb4kWn.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>The new wave of hacktivism can be traced to May 2020, specifically after the murder of <a href="https://www.itpro.com/technology/355874/tech-industry-calls-for-action-over-the-death-of-george-floyd" data-original-url="https://www.itpro.com/technology/355874/tech-industry-calls-for-action-over-the-death-of-george-floyd">George Floyd</a> at the hands of police officer Derek Chauvin. The event reportedly prompted Anonymous to <a href="http://www.forbes.com/sites/zakdoffman/2020/05/31/anonymous-hackers-threaten-to-expose-the-many-crimes-of-minneapolis-police">shut down the website</a> belonging to the Minneapolis Police Department, which is where Chauvin was stationed prior to his arrest and trial. When the site was finally restored, users were asked to complete a captcha in order to ensure they were not <a href="https://www.itpro.com/network-internet/bots/360765/bad-bots-make-up-huge-slice-of-internet-traffic-and-target-e-commerce" data-original-url="https://www.itpro.com/network-internet/bots/360765/bad-bots-make-up-huge-slice-of-internet-traffic-and-target-e-commerce">automated bots</a> orchestrating a DDoS attack.</p><p>Two months later, hackers managed to breach the server of a major contractor working on behalf of the Russian intelligence service. They obtained <a href="https://www.itpro.com/security/34056/massive-75tb-breach-reveals-secret-russian-it-projects" data-original-url="https://www.itpro.com/security/34056/massive-75tb-breach-reveals-secret-russian-it-projects">7.5TB of sensitive data</a> and shared it freely with other hackers and journalists. Much of this included detailed information about sensitive government IT projects commissioned by the Federal Security Service of the Russian Federation (FSB).</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gsrHFWG5yYnV7wtojcUNZY" name="gsrHFWG5yYnV7wtojcUNZY.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/gsrHFWG5yYnV7wtojcUNZY.jpg" mos="https://cdn.mos.cms.futurecdn.net/gsrHFWG5yYnV7wtojcUNZY.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>In unpredictable times, a data strategy is key</strong></p><p class="fancy-box__body-text">Data processes are crucial to guide decisions and drive business growth</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/data-insights/367519/in-unpredictable-times-a-data-strategy-is-key" data-original-url="/business-strategy/data-insights/367519/in-unpredictable-times-a-data-strategy-is-key">FREE DOWNLOAD</a></p></div></div><p>Of course, the most recent high-profile example of activism at play is the <a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far" data-original-url="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far">conflict between Russia and Ukraine</a>. The hacktivist efforts began even before the invasion as unknown <a href="https://www.itpro.com/security/hacking/362059/belarusian-hacktivists-railway-ransomware-halt-russian-military" data-original-url="https://www.itpro.com/security/hacking/362059/belarusian-hacktivists-railway-ransomware-halt-russian-military">hackers targeted the Belarusian railway network</a> in a bid to stop Russian troops from mobilising near Ukraine's borders.</p><p>What followed was genuine <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber warfare</a>, with forces from both sides attacking <a href="https://www.itpro.com/security/cyber-attacks/367634/five-eyes-and-us-governments-confirm-russia-behind-attacks" data-original-url="https://www.itpro.com/security/cyber-attacks/367634/five-eyes-and-us-governments-confirm-russia-behind-attacks">telecoms infrastructure</a>, broadcast networks, government websites, and more. The war is thought to be the first ever to be fought across both kinetic and cyber space and even saw a Ukrainian government official assemble an online 'cyber army' from the early days of the war, known most commonly as the <a href="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war" data-original-url="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war">IT Army of Ukraine</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How Russia hacked the 2016 election ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election</link>
                                                                            <description>
                            <![CDATA[ A timeline of how 12 hackers allegedly corrupted the world's most powerful democracy ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aNZcFqGdcf1yetBbbNtqu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zqGThXHsoLCcMmV9pbCpMW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Jul 2018 08:53:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zqGThXHsoLCcMmV9pbCpMW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zqGThXHsoLCcMmV9pbCpMW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>//</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>