<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/kaspersky" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Kaspersky ]]></title>
                <link>https://www.itpro.com/tag/kaspersky</link>
        <description><![CDATA[ All the latest kaspersky content from the ITPro team ]]></description>
                                    <lastBuildDate>Tue, 23 Sep 2025 10:24:39 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Hackers are disguising malware as ChatGPT, Microsoft Office, and Google Drive to dupe workers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/hackers-are-disguising-malware-as-chatgpt-microsoft-office-and-google-drive-to-dupe-workers</link>
                                                                            <description>
                            <![CDATA[ Beware of downloading applications like ChatGPT, Microsoft Office applications, and Google Drive through search engines ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SnZmFBfqnNGgurYmgttKGn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kj6pPXLf6a7yeTiX6Vk8zE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Sep 2025 10:24:39 +0000</pubDate>                                                                                                                                <updated>Tue, 23 Sep 2025 10:25:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kj6pPXLf6a7yeTiX6Vk8zE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware concept image showing flashing alert symbol with flashing red background and network symbols. ]]></media:description>                                                            <media:text><![CDATA[Malware concept image showing flashing alert symbol with flashing red background and network symbols. ]]></media:text>
                                <media:title type="plain"><![CDATA[Malware concept image showing flashing alert symbol with flashing red background and network symbols. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kj6pPXLf6a7yeTiX6Vk8zE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Small and medium-sized businesses (SMBs) across Europe and North, West, and Central Africa are being targeted by <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>masquerading as <a href="https://www.itpro.com/security/phishing/how-hackers-are-using-legitimate-tools-to-distribute-phishing-links">legitimate tools</a>.</p><p>According to Kaspersky, cyber criminals are disguising malware and potentially unwanted applications (PUAs) as trusted tools such as <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT</a>, <a href="https://www.itpro.com/software/microsoft/microsoft-office">Microsoft Office</a> applications ,and <a href="https://www.itpro.com/collaboration/33418/how-to-get-more-out-of-google-drive">Google Drive</a>. </p><p>Between January and April this year, Austria, Italy, and Germany were among the hardest hit countries in Europe, with the campaign accelerating at pace. </p><div class="product"><a data-dimension112="e8daafb6-682a-4043-a708-c545af5e1a9e" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="e8daafb6-682a-4043-a708-c545af5e1a9e" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="e8daafb6-682a-4043-a708-c545af5e1a9e" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Austria accounted for 40% of all detected cases in which PUAs and malware mimicked legitimate brands, followed by Italy at 25%, Germany at 11%, and Spain (10%). Meanwhile, in Africa, Morocco topped the list, with 41% of all detected PUAs. </p><p>The most common threats affecting SMBs in Europe included backdoors (24%), Trojans (17%), and not-<em>a-virus:Downloaders</em> (16%). All of these are designed to infiltrate networks without raising suspicion, Kaspersky noted. </p><p>In Africa, not-a-virus: Downloaders dominated (55%), followed by <em>DangerousObjects </em>(14%) and <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus">Trojans </a>(13%).</p><p>“Small businesses face enterprise-level threats, often with startup-level budgets," said Marc Rivero, lead security researcher at the Global Research and Analysis Team (GreAT) at Kaspersky. “The key is knowing where to focus their limited resources for maximum protection." </p><p>Kaspersky said these growing threats highlight the need for more robust <a href="https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training">employee awareness training</a>. Enabling staff to spot the telltale signs of cyber criminal activity is crucial to preventing disaster. </p><p>The company also advised enforcing strong authentication and authorization with strict password policies and <a href="https://www.itpro.com/security/two-factor-authentication-2fa/361517/multi-factor-authentication-deployment-guide">multi-factor authentication</a> (MFA), regularly updating software and patching vulnerabilities.</p><p>Meanwhile, organizations should carry out regular training sessions, focusing on safe email practices, secure password management, recognizing phishing attempts, and the proper handling of sensitive data.</p><p>All software should come from official sources – not via search engines – and be installed centrally by the IT team to prevent hidden threats. Similarly, clear access rules should be set for emails, shared folders, and online services, with user activity monitored and access revoked promptly when employees leave the company.</p><p>"The best defense against sophisticated malware isn't the most expensive tool - it's understanding how attackers think and closing the doors they're looking for,” said Rivero.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/warning-issued-as-new-pakistan-based-malware-group-hits-millions-globally">Warning issued as Pakistan-based malware group hits millions globally</a></li><li><a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">The best malware removal tools 2025</a></li><li><a href="https://www.itpro.com/security/malware/malware-as-a-service-explained-what-it-is-and-why-businesses-should-take-note">What is Malware as a Service and why should businesses take note?</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Almost half of US organizations still using Kaspersky, researchers claim ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/almost-half-of-us-organizations-still-using-kaspersky-researchers-claim</link>
                                                                            <description>
                            <![CDATA[ A ban was introduced due to Kaspersky’s supposed links to the Russian government ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fgQJuS4RERGjtg6JnA3CCh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bqfHFJ53ZLkb2TYPWFEnub-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Dec 2024 14:13:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bqfHFJ53ZLkb2TYPWFEnub-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Visitors sit at the stand of Russian antivirus software development company Kaspersky Lab on the opening day of the MWC (Mobile World Congress) in Barcelona on February 28, 2022]]></media:description>                                                            <media:text><![CDATA[Visitors sit at the stand of Russian antivirus software development company Kaspersky Lab on the opening day of the MWC (Mobile World Congress) in Barcelona on February 28, 2022]]></media:text>
                                <media:title type="plain"><![CDATA[Visitors sit at the stand of Russian antivirus software development company Kaspersky Lab on the opening day of the MWC (Mobile World Congress) in Barcelona on February 28, 2022]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bqfHFJ53ZLkb2TYPWFEnub-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Almost half (40%) of US organizations are still using Kaspersky software despite <a href="https://www.itpro.com/security/us-poised-to-ban-sales-of-kaspersky-software-reports"><u>a ban enacted in the summer</u></a>, new research from <a href="https://www.bitsight.com/blog/aftermath-kaspersky-ban"><u>Bitsight has revealed</u></a>. </p><p>Though the ban went into effect months ago, active use of Kaspersky products remains high, with more than 1,000 US organizations observed to be connecting to Kaspersky servers post-ban. </p><p>Bitsight said only 58% of US organizations observed using Kaspersky products appear to have eliminated their usage of the cybersecurity platform. </p><p>Strikingly, given this ban came from the governmental level, Bitsight’s research revealed 19 government agencies in the US were observed to be communicating with Kaspersky update servers as of November 2024.</p><p>Bitsight said its research is based on observing connections and communications between global IP addresses associated with specific organizations and Kaspersky update servers. </p><p>The firm acknowledged its research may have also captured traffic being used to perform security research or intelligence collection.</p><p>Though the US introduced the ban, it has not seen as restrictive a move as in other countries. According to Bitsight’s analysis, the US is the country with the largest number of organizations using Kaspersky.</p><p>By comparison, global usage of Kaspersky has seen a dramatic decrease in organizations operating in countries that do not have formal bans on Kaspersky technology.</p><p>Between April and November 2024, the number of global organizations communicating with Kaspersky dropped from 22,000 firms and 7 million unique IP addresses to 8,000 firms and 2 million unique IP addresses.</p><h2 id="inside-the-kasperky-ban">Inside the Kasperky ban</h2><p>The US government <a href="https://www.itpro.com/security/us-poised-to-ban-sales-of-kaspersky-software-reports"><u>originally banned Kaspersky</u></a> based on supposed links to the Russian government. Lawmakers claimed use of the software could be a risk to national security as it could be used to steal corporate data or install malware.</p><p><a href="https://www.itpro.com/security/cyber-security/367288/is-kaspersky-still-safe-to-use"><u>Fear of Kaspersky had been long-running</u></a> before the ban, with tensions surging after Russia’s invasion of Ukraine and the US, UK, and Germany all issuing warnings about the software. </p><p>Kaspersky has not kept quiet. <a href="https://www.itpro.com/security/kaspersky-hits-back-at-us-software-ban-citing-political-motivations-and-theoretical-concerns"><u>A statement from Kaspersky </u></a>following the ban insisted that allegations of ties to the Russian government are false, and that the ban decision is politically motivated. </p><p>“Kaspersky believes that the Department of Commerce made its decision based on the present geopolitical climate and theoretical concerns, rather than on a comprehensive evaluation of the integrity of Kaspersky’s products and services,” the firm said.</p><p>About a month after news of the ban emerged, it announced that it would be <a href="https://www.itpro.com/security/kaspersky-shuts-american-division-ahead-of-sales-ban"><u>shutting down its operations in the US</u></a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Enterprises are struggling to fill senior cybersecurity roles — and it's causing staff burnout to skyrocket ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/enterprises-are-struggling-to-fill-senior-cybersecurity-roles-and-its-causing-staff-burnout-to-skyrocket</link>
                                                                            <description>
                            <![CDATA[ Many senior roles take months to fill, creating cumbersome workloads for mid-level staff and increased burnout ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XtRSrLQW5sNpuJjA3FZQzb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjeY3QYbwKw2aE2aWn7byL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Oct 2024 10:03:17 +0000</pubDate>                                                                                                                                <updated>Mon, 21 Oct 2024 10:04:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjeY3QYbwKw2aE2aWn7byL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Software developer burnout concept image showing female programmer sitting at a desk looking stressed.]]></media:description>                                                            <media:text><![CDATA[Software developer burnout concept image showing female programmer sitting at a desk looking stressed.]]></media:text>
                                <media:title type="plain"><![CDATA[Software developer burnout concept image showing female programmer sitting at a desk looking stressed.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjeY3QYbwKw2aE2aWn7byL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Four-in-ten cybersecurity teams are understaffed, with senior team members particularly hard to find, according to new research.</p><p>While seven-in-ten junior cybersecurity staff positions are typically filled within six months and only 3% of roles take more than a year to fill, things are very different further up the hierarchy. </p><p>More than half of companies told Kaspersky it takes between four and nine months to find suitable candidates, and 36%, nine months or more. Only 6% of roles are filled in less than three months. </p><p>The good news, though, is that these senior InfoSec professionals tend to stay longer in their roles, with 49% remaining in top-level positions for more than five years. Junior employees have a higher turnover rate, with most staying three to four years and only 3% remaining beyond five years.</p><p>The main reasons for quitting include personal factors such as compensation issues, inadequate working conditions, and lack of management support. </p><p>However, a significant portion of professionals cited the need for continuous skills development as well as growing frustration with not having opportunities to work with the latest technologies and tools.</p><p>Overall, professional dissatisfaction is the leading cause of resignations, with lack of growth opportunities being the main reason, cited by 58%. </p><h2 id="burnout-is-still-pervasive-in-cyber">Burnout is still pervasive in cyber</h2><p>Lack of management support and monotonous work are also significant factors, with both the main reason for leaving for around half of job-seekers. High stress levels and inflexible working policies were also factors.</p><p>Notably, the study from Kaspersky showed burnout is still rampant InfoSec professionals, who feel they're accomplishing very little in the face of monotonous work and constant monitoring of security alerts.</p><p>"To combat burnout, companies must rethink their approach to managing InfoSec teams. They need to find ways to relieve the stress faced by InfoSec professionals, provide them with tools to alleviate pressure, and offer support and feedback," the researchers said. </p><p>"Automation plays a key role in this process, significantly reducing the daily burden on professionals by handling repetitive tasks such as monitoring alerts, analyzing logs, and responding to low-level threats. This shift allows professionals to focus on more complex and rewarding tasks, enhancing job satisfaction and career growth."</p><p>Burnout is rife in the tech profession generally, with nearly three-quarters of software developers experiencing it at some point in their career, according to JetBrains’ 2023 State of the Developer Ecosystem report. </p><p>And it's particularly common in security departments. In a survey last year, CyberArk found nearly two-thirds of staff struggle to contend with growing workloads, and more than two-thirds of C-suite executives said burnout is fueled by heightened threat levels, which is affecting their ability to make critical, high-level decisions. </p><p>Kaspersky recommends that organizations should bring in reward systems and recognition programs to boost morale, along with training, evaluating staff, and providing regular feedback.</p><p>They should ensure management support, rotate employees’ roles, and manage workloads to prevent monotony and reduce stress, while also automating processes for routine tasks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky to shut down US division ahead of sales ban ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/kaspersky-shuts-american-division-ahead-of-sales-ban</link>
                                                                            <description>
                            <![CDATA[ The Russian security company will exit the US and cut staff ahead of a government-imposed sales ban ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CvWquMCxFArLi8G4kq33wd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bqfHFJ53ZLkb2TYPWFEnub-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Jul 2024 10:27:17 +0000</pubDate>                                                                                                                                <updated>Tue, 16 Jul 2024 11:57:46 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bqfHFJ53ZLkb2TYPWFEnub-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Visitors sit at the stand of Russian antivirus software development company Kaspersky Lab on the opening day of the MWC (Mobile World Congress) in Barcelona on February 28, 2022]]></media:description>                                                            <media:text><![CDATA[Visitors sit at the stand of Russian antivirus software development company Kaspersky Lab on the opening day of the MWC (Mobile World Congress) in Barcelona on February 28, 2022]]></media:text>
                                <media:title type="plain"><![CDATA[Visitors sit at the stand of Russian antivirus software development company Kaspersky Lab on the opening day of the MWC (Mobile World Congress) in Barcelona on February 28, 2022]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bqfHFJ53ZLkb2TYPWFEnub-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Russian security company Kaspersky is shutting operations in the US ahead of sanctions that will <a href="https://www.itpro.com/security/us-poised-to-ban-sales-of-kaspersky-software-reports">ban sales of its software nationwide</a>. </p><p>The move comes amid ever-worsening relations between the US and Russia, exacerbated by the war in Ukraine, but Kaspersky has been answering questions about its ties to its home country for years.</p><p>After a series of recent sanctions, Kaspersky confirmed to security site <a href="https://www.zetter-zeroday.com/kaspersky-lab-closing-u-s-division-laying-off-workers-2/"><em>Zero Day</em></a> that it was winding down operations and cutting staff, though the total headcount being laid off is fewer than 50.</p><p>"Kaspersky has been operating in the US for close to 20 years, contributing to the nation’s strategic cybersecurity goals by safeguarding organizations and individuals in the country from ever-evolving cyber threats," a spokesperson for Kaspersky told <em>ITPro</em>.</p><p>"The company has carefully examined and evaluated the impact of the US legal requirements and made this sad and difficult decision as business opportunities in the country are no longer viable."</p><h2 id="kaspersky-x2019-s-slow-march-to-a-full-ban">Kaspersky’s slow march to a full ban</h2><p>Kaspersky was founded in Moscow, Russia in 1997, by Eugene Kaspersky, Natalya Kaspersky, and Alexey De-Monkerik, and first began selling overseas in 2005. It has divisions in the UAE, Turkey, the UK, Mexico, South Africa, Brazil, and Singapore. </p><p>The Russian connection has long been a tough sell. Eugene <a href="https://www.itpro.com/security/26605/eugene-kaspersky-on-shifting-security-spying-and-geopolitics/2">Kaspersky told <em>ITPro</em></a> in 2016 that geopolitics was always a concern for a security lab with "Russian roots", but that the company does its "best not to be connected [to one country], to be international."</p><p>But that didn&apos;t convince the American government. In 2017, the US government ordered all civilian agencies to remove all Kaspersky systems from their networks amid concerns about the relationship between "certain Kaspersky officials and Russian intelligence".</p><p>Concerns were also raised that aspects of Russian law could force the company to intercept communications, the <a href="https://www.dhs.gov/news/2017/09/13/dhs-statement-issuance-binding-operational-directive-17-01">Department for Homeland Security said</a> at the time.</p><p>Later that year, <a href="https://www.reuters.com/article/us-lithuania-russia-idUSKBN1EF23M/">Lithuania</a> followed suit by banning Kaspersky software from sensitive computers at government agencies or those that control critical infrastructure. The next year, the <a href="https://www.reuters.com/article/us-cyber-netherlands-kaspersky-idUSKCN1IF2NV/">Netherlands</a> also began cutting out Kaspersky from government systems, and the US expanded its ban to military systems.</p><p>Kaspersky responded by holding international customers&apos; data in Switzerland rather than Russia, as part of a wider <a href="https://www.kaspersky.com/transparency-center" target="_blank">transparency effort</a>.</p><h2 id="rising-tensions-after-the-ukraine-invasion-xa0">Rising tensions after the Ukraine invasion </h2><p><a href="https://www.reuters.com/technology/exclusive-us-warned-firms-about-russias-kaspersky-software-day-after-invasion-2022-03-31/" target="_blank"><u>Days after the invasion of Ukraine</u></a> by Russia in 2022, the US government privately issued warnings to local companies, suggesting that Kaspersky software could be abused by the Russian government to wreak havoc among American companies or for wider cyber attacks. </p><p>In June, the US government said it would ban new sales of Kaspersky&apos;s <a href="https://www.itpro.com/antivirus/28144/best-antivirus">antivirus</a>, not just for government agencies but across all businesses.</p><p>"Russia has shown it has the capacity and ... the intent to exploit Russian companies like Kaspersky to collect and weaponize the personal information of Americans and that is why we are compelled to take the action that we are taking today," Commerce Secretary Gina Raimondo said in a call with reporters at the time, according to <a href="https://www.reuters.com/technology/biden-ban-us-sales-kaspersky-software-over-ties-russia-source-says-2024-06-20/" target="_blank">Reuters</a>.</p><p>Kaspersky hit back at the move, claiming the decision was <a href="https://www.itpro.com/security/kaspersky-hits-back-at-us-software-ban-citing-political-motivations-and-theoretical-concerns">based entirely on "theoretical concerns"</a>. </p><p>The Russian government, meanwhile, said the sales restriction was nothing to do with security but a "favorite technique of unfair competition from the United States." The US responded by sanctioning 12 Kaspersky employees, including c-level leadership.</p><h2 id="end-of-us-operations-xa0">End of US operations </h2><p>Now, Kaspersky said it would wind down operations by 20 July, the same day the ban on new business comes into effect. All <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">software updates</a>, sales, and resales will be banned as of 29 September. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UqcNuXS5DhrfeyKUzJsrU6" name="When it comes to cyber security, fight fire with fire_listing.jpg" caption="" alt="This CEO's guide from IBM shares how generative AI can fortify your business security" src="https://cdn.mos.cms.futurecdn.net/UqcNuXS5DhrfeyKUzJsrU6.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/the-ceos-guide-to-generative-ai-when-it-comes-to-cyber-security-fight-fire-with-fire"><em>Fortify your security with generative AI</em></a></p></div></div><p>"Starting from July 20, 2024 Kaspersky will gradually wind down its US operations and eliminate US-based positions," the statement from Kaspersky added.</p><p>"The decision and process follows the Final Determination by the US Department of Commerce, prohibiting the sales and distribution of Kaspersky products in the US.</p><p>"Kaspersky’s business remains resilient, and our key priority remains the same – to protect our customers in any country from cyberthreats. Being a global cybersecurity vendor, the company will continue investing in strategic markets and remain committed to serving its customers and partners and ensuring their protection."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Botnets are being sold on the dark web for as little as $99 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/botnets-are-being-sold-on-the-dark-web-for-as-little-as-dollar99</link>
                                                                            <description>
                            <![CDATA[ More than 20 offers for botnets for hire or sale have been discovered on dark web forums and Telegram channels this year ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q3aPKUJyjWLdhBSScAvqo6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/f4U2LiQdUgWVyUnnaT2ToT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Jul 2024 09:12:09 +0000</pubDate>                                                                                                                                <updated>Tue, 09 Jul 2024 13:24:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/f4U2LiQdUgWVyUnnaT2ToT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Botnet concept image showing multiple computers with skull symbols on screen.]]></media:description>                                                            <media:text><![CDATA[Botnet concept image showing multiple computers with skull symbols on screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Botnet concept image showing multiple computers with skull symbols on screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/f4U2LiQdUgWVyUnnaT2ToT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals are offering ready-made botnets on the dark web for as little as $99, according to <a href="https://www.itpro.com/security/kaspersky-hits-back-at-us-software-ban-citing-political-motivations-and-theoretical-concerns">Kaspersky</a>, making <a href="https://www.itpro.com/security/cyber-attacks">cyber attacks</a> cheaper and easier than ever to carry out.</p><p>Botnets like Mirai - which targets online consumer devices such as IP cameras and <a href="https://www.itpro.com/infrastructure/network-internet/367849/a-guide-to-testing-your-wireless-routers-performance">home routers</a> - have individually tailored infection processes, <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>types, infrastructure, and evasion techniques.</p><p>According to recent research from Cloudflare, 4% of HTTP DDoS attacks, and 2% of L3/4 DDoS attacks, were launched by a Mirai-variant botnet during the first quarter of this year.</p><p>"Mirai is one of the most infamous examples of a botnet. It scans the internet for IoT devices with weak default passwords, uses a set of known default credentials to gain access, and infects them," said Alisa Kulishenko, security analyst at Kaspersky Digital Footprint Intelligence.</p><p>"The infected devices then become part of the botnet, which can be controlled remotely to perform various types of cyberattacks."</p><p>Since the beginning of this year, Kaspersky researchers found more than 20 offers for botnets for hire or sale on dark web forums and Telegram channels. The lowest offers started at $99 and the highest reached $10,000, researchers said.</p><p>As well as being available as one-time purchases, botnets can be hired or acquired as leaked source code for between $30 and $4,800 per month, with custom botnet development also available in some cases.</p><p>Access to leaked source code can be obtained for free or a fee of between $10 and $50, based on information from approximately 400 dark web and shadow Telegram posts observed since the beginning of 2024.</p><p>However, Kaspersky said leaked botnets are generally deployed by less sophisticated actors, as they are more likely to be detected by <a href="https://www.itpro.com/security/cyber-security/355132/how-to-protect-your-business-from-cyberattacks">security solutions</a>.</p><p>"Potential earnings from attacks using botnets for hire or sale can exceed the associated costs. They allow for activities such as illegal <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency mining</a> or ransomware attacks, and more," Kulishenko said.</p><p>"Open sources report that an average ransom payment is two million US dollars. In contrast, renting a botnet costs significantly less and can pay off with just one successful attack."</p><p>A threat actor can also commission a botnet to be developed from scratch, with development costs varying widely, but starting at just $3,000.</p><p>"Most of these deals occur privately, through personal messages, and partners are typically chosen based on reputation, such as forum ratings," Kulishenko noted.</p><h2 id="botnet-activity-is-on-the-rise">Botnet activity is on the rise</h2><p>Earlier this year, researchers at NetScout said they&apos;d discovered a sharp rise in global botnet activity, spiking at more than a million devices.</p><p>Meanwhile, a Trustwave report last year found that <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">botnets</a> were responsible for more than 95% of all the malicious traffic on the internet, with the Mirai, Mozi, and Kinsing botnets accounting for almost all exploit attempts that were run over the <a href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security">HTTP or HTTPS</a> protocols.</p><p>Global law enforcement action to tackle botnets has been escalating in recent years, with a series of high-profile takedowns crippling operations. But while these operations often inflict initial damage, <a href="https://www.itpro.com/security/cyber-crime/qakbot-forced-offline-but-history-suggests-it-probably-wont-be-forever">history shows that many come back with a vengeance</a>.</p><p><a href="https://www.itpro.com/security/ransomware/qakbot-threat-still-lingering-despite-fbi-takedown">Qakbot</a>, ranked among one of the most prolific botnets of all time, was taken down last year in a US-led operation. But within weeks of the sting operation, there were signs of recovery.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zPqJCyEu6wpL7hmyg2RA3f" name="The security awareness handbook 2.jpg" caption="" alt="Cartoon of two people looking at a pocketwatch" src="https://cdn.mos.cms.futurecdn.net/zPqJCyEu6wpL7hmyg2RA3f.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Proofpoint)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-security-awareness-handbook"><em>Get insight into the common risks users face</em></a></p></div></div><p>In October 2023, researchers at Cisco Talos warned that Qakbot-affiliated hackers still remained a pervasive threat, with threat actors in fact waging a devastating ransomware campaign that began “just before the takedown”.</p><p>Qakbot’s return isn’t an isolated example, either. <a href="https://www.itpro.com/security/hacking/361340/what-is-emotet">Emotet</a>, another notorious botnet, made a return <a href="https://www.itpro.com/security/malware/358450/europol-takes-down-dangerous-emotet-botnet">after a law enforcement takedown</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Small businesses face continued security threats as trojan attacks surge ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/small-businesses-face-continued-security-threats-as-trojan-attacks-surge</link>
                                                                            <description>
                            <![CDATA[ Cyber attacks on small businesses are still growing at a steady pace ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q97qDDGa4Uq7XmXLffqLNE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/C7CrfvjbGLhrsCT4GpKURh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Jun 2024 05:00:13 +0000</pubDate>                                                                                                                                <updated>Thu, 27 Jun 2024 10:16:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/C7CrfvjbGLhrsCT4GpKURh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud complexity concept art showing scattered binary code with different colored lines of code interwoven on a digital interface.]]></media:description>                                                            <media:text><![CDATA[Cloud complexity concept art showing scattered binary code with different colored lines of code interwoven on a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud complexity concept art showing scattered binary code with different colored lines of code interwoven on a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/C7CrfvjbGLhrsCT4GpKURh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Small and medium sized businesses (SMBs) are increasingly being hit by cyber attacks, according to new research, with Microsoft Excel the number one channel of attack.</p><p>Analysis from Kaspersky shows, the number of infections experienced by SMBs in the first quarter of this year rose by 5% compared to the same period last year.</p><p>More than 2,400 firms encountered malware and unwanted software hiding in or mimicking software products, with 4,110 unique files distributed under the guise of SMB-related software.</p><p>This, the firm said, represents an 8% increase year-on-year and implies that the activity will only continue to increase.</p><p>"Although SMBs might be under the illusion they are not a target, they belong to a huge ecosystem of interconnected assets and cyber criminals will exploit any weakness," said Vasily Kolesnikov, a cybersecurity expert at Kaspersky.</p><p>The most common type of attack continues to be Trojans. These are especially hazardous, Kaspersky said, because unlike viruses they cannot self-replicate and usually mimic legitimate software, allowing them to evade traditional security measures.</p><p>The number of Trojan attacks between January and April this year hit 100,465 - a 7% increase on the same period in 2023.</p><p>The next highest threat came from the DangerousObjects malicious software, with 17,320 attacks recorded – nearly seven thousand more than in 2023, and the fastest-rising threat year on year.</p><p><a href="https://www.itpro.com/business-operations/productivity/363979/google-sheets-vs-microsoft-excel">Microsoft Excel</a> is once again the number one channel of attack, moving from fourth to first place between 2023 and 2024. Microsoft Word is in second place, with <a href="https://www.itpro.com/business-operations/productivity/363985/google-slides-vs-microsoft-powerpoint-online">Microsoft PowerPoint</a> and Salesforce the third-most targeted applications.</p><p>Kolesnikov said threat actors are ramping up attempts to exploit Excel in cyber attacks due to the popular use of the software among small businesses.</p><p>"The ubiquitous use of Microsoft Excel in office environments provides fertile ground for cyber criminals who can hide and manipulate malicious data in large datasets that are then widely shared across a business," Kolesnikov commented.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kzhK2ZDiTgq2ZKCHM9H5BP" name="Global Threat Report 2024 (1).jpg" caption="" alt="Global Threat Report 2024" src="https://cdn.mos.cms.futurecdn.net/kzhK2ZDiTgq2ZKCHM9H5BP.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Crowdstrike)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/global-threat-report-2024"><em>Stay ahead of today’s threats</em></a></p></div></div><p>Human error is still a big threat, however, with <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attacks distributed via various channels, including spoofed emails and social media.</p><p>In recent years, Kaspersky said it&apos;s observed a trend of spreading web pages that mimic the most commonly used Microsoft services, such as <a href="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft 365</a>, Outlook and <a href="https://www.itpro.com/cloud/cloud-storage/363918/onedrive-review">OneDrive</a>.</p><p>This technique exploits the tendency for businesses to use a single software package for all business purposes, making its users more dependent on particular applications and services and thus more susceptible to this attack vector.</p><p>Meanwhile, attackers are using legitimate Facebook infrastructure to compromise corporate social media accounts, with Kaspersky uncovering numerous cases of attackers mimicking genuine social media login pages.</p><p>The company said it&apos;s discovered multiple cases of SMB-oriented spam.</p><p>"It is critical for all SMBs to create clear policies for accessing any corporate assets and ensure that staff are regularly reminded of the importance of following basic cybersecurity rules," Kolesnikov said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Most passwords take a matter of minutes to crack – here’s how you can create strong, hacker-resistant credentials ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/most-passwords-take-a-matter-of-minutes-to-crack-heres-how-you-can-create-strong-hacker-resistant-credentials</link>
                                                                            <description>
                            <![CDATA[ Passwords are still criminally insecure and can be cracked or guessed by hackers with ease, but what precautions can you take to avoid getting breached? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CvkyfEVZ5J89Kh79g4ahaG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iEhgrdA3JJhRvzUkjjC3XA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Jun 2024 10:11:32 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Jun 2024 14:44:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iEhgrdA3JJhRvzUkjjC3XA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man typing in password on keyboard in low light.]]></media:description>                                                            <media:text><![CDATA[Man typing in password on keyboard in low light.]]></media:text>
                                <media:title type="plain"><![CDATA[Man typing in password on keyboard in low light.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iEhgrdA3JJhRvzUkjjC3XA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The majority of <a href="https://www.itpro.com/security/26144/here-are-hackers-10-favourite-passwords">passwords</a> can be easily guessed or cracked by hackers, new research shows, prompting renewed calls from security experts to bolster <a href="https://www.itpro.com/security/basic-password-hygiene-is-still-awful-so-maybe-it-is-time-to-go-passwordless">password security</a> practices. </p><p>In a study conducted by <a href="https://www.itpro.com/641449/kaspersky-flags-up-olympic-cyber-security-threats">Kaspersky</a>, the security firm analyzed 193 million <a href="https://www.itpro.com/security/34222/google-15-of-all-login-attempts-use-compromised-passwords">compromised passwords</a> available on the <a href="https://www.itpro.com/security/the-dark-web-is-absolutely-awash-with-stolen-data-on-british-mps">dark web</a> and the results of the investigation indicated 45% of the passwords could be guessed by hackers within a minute.</p><p>The study calculated that hackers armed with a <a href="https://www.itpro.com/hardware/components/358984/leaks-tease-major-performance-boosts-for-intels-alder-lake-cpus">high-performance laptop CPU</a> would be able to <a href="https://www.itpro.com/botnets/33799/goldbrute-botnet-targeting-windows-rdp-systems-in-brute-force-hacking-spree">brute force</a> an eight-character password composed of lowercase letters and digits in 7 minutes.</p><p>Only 23% of the analyzed passwords met the requirements to be classified as <a href="https://www.itpro.com/security/22197/how-secure-is-your-password">resistant</a>, meaning they would take an attacker over a year to compromise on average.</p><p>Over half (57%) of the examined passwords contained a word from the dictionary, which experts agree significantly reduces a <a href="https://www.itpro.com/software/368004/how-to-test-password-strength-using-these-free-tools">passwords’ strength</a>.</p><p>Furthermore, just 14% of passwords contained ‘signs’ of a strong, difficult-to-crack combination, which would include both uppercase and lowercase letters as well as numbers, and <a href="https://www.itpro.com/security/phishing/361227/phishing-campaign-imitates-verizon-logo-with-a-math-symbol">symbols</a>.</p><p>Speaking to <em>ITPro,</em> Mark Lomas, technical architect at technology services provider Probrand, said passwords have been the <a href="https://www.itpro.com/609750/ibm-websites-are-achilles-heel-of-business-security">Achilles heel</a> in many enterprises’ security posture, and are one of the top targets for threat actors looking to save time gaining initial access.</p><p>“Passwords have long been the weak link in security. It&apos;s often said that in many successful attacks, criminals don&apos;t &apos;hack&apos; in, they just log in. They do so by gaining the password using a variety of techniques,” he explained.</p><p>“These could include <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> to trick someone into handing over a password, stealing credentials if someone has used the same password in multiple places which might have then leaked onto the dark web, for example, or simply by using brute-force attacks.”</p><h2 id="increasing-password-complexity-makes-them-harder-to-manage">Increasing password complexity makes them harder to manage</h2><p>Chris Hauk, consumer privacy advocate at Pixel Privacy, told <em>ITPro </em>businesses need to ensure they are educating their staff on how to create unique and <a href="https://www.itpro.com/internet-security/31668/how-to-master-your-passwords-on-all-your-devices">secure passwords</a>, outlining his criteria for a robust password.</p><p>“Passwords should be lengthy and should at a minimum be 12 characters or more and should be made up of a mix of uppercase and lowercase letters, symbols, and numbers," he explained.</p><p>“Never use guessable passwords, like pet names, birthdays, parents&apos; maiden names, birthdays, or anything else that could be easily determined. <a href="https://www.itpro.com/security/33666/uncrackable-passwords-introduced-to-microsoft-azure">Passphrases</a> (long strings of words or sentences) make passwords both <a href="https://www.itpro.com/security/22197/how-secure-is-your-password">strong and memorable</a>.”</p><p>While creating more complex passwords is advised, this does have certain downsides, according to Joel Rennich, VP of Product Strategy at <a href="https://www.itpro.com/business/acquisition/jumpcloud-acquires-it-asset-management-specialist-resmo">JumpCloud</a>.</p><p>Speaking to <em>ITPro</em>, Rennich noted that increasing <a href="https://www.itpro.com/security/cyber-security/365553/password-complexity-rules-arent-enough-to-protect-employees-from">password complexity</a> makes them far <a href="https://www.itpro.com/security/32680/the-best-passwords-are-the-ones-you-cant-remember">harder to remember</a>, and sometimes encourages users to dumb them down again to make them easier to recall when logging in.</p><p>"As the number and complexity of passwords increases, they become harder for users to remember,” he said. “And while length and complexity requirements align with many organizations’ best practices, too many long passwords could drive users to resort to unsecure methods for remembering them or re-use the same password across multiple <a href="https://www.itpro.com/security/368641/facebook-business-accounts-hijacked-by-infostealer-malware-campaign">business accounts</a>.”</p><p>The solution, according to Rennich, as well as Hauk, is using a password manager that allows users to use unique, <a href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password">complex passwords </a>across a wide range of accounts without the fear of forgetting them and having to go through tiresome password reset processes.</p><p>“To begin with, password managers relieve users of the burden of memorizing passwords and increase the IT department’s control and visibility over users’ passwords and their use,” Rennich argued.</p><p>“<a href="https://www.itpro.com/software/368047/are-password-managers-safe-heres-how-to-use-them">Password managers</a> allow businesses to enforce password creation rules (including stronger passwords that do not need to be remembered), send update reminders, and safely share and manage access to the right resources and applications.”</p><h2 id="stronger-passwords-aren-x2019-t-enough-in-the-modern-threat-landscape">Stronger passwords aren’t enough in the modern threat landscape</h2><p>Using more complex passwords or credential management tools isn’t the only way to prevent compromise, however. Increasingly, organizations globally are adopting passphrases, according to Rick Jones, CEO and co-founder of DigitalXRAID. </p><p>Jones told <em>ITPro</em> that even eight-character passwords are still susceptible to passwords, and called for a more comprehensive industry shift toward passphrases. </p><p>“Statistics show that an eight character password hash can be cracked in a matter of minutes by a password cracking rig, while an 18-character password takes far longer. This dramatic increase should be reason enough to switch to passphrases rather than passwords,” he said. </p><p>Probrand’s Lomas stated that due to the damage they can cause if they fall into the wrong hands, many <a href="https://www.itpro.com/security/369055/gartner-most-businesses-are-dropping-security-vendors-to-improve-cyber-resiliency">security vendors</a> have been trying to transition away entirely from the <a href="https://www.itpro.com/cloud/cloud-security/google-passkeys-now-default-for-users-in-shift-away-from-traditional-authentication">login methods</a> that can be stolen. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GGpVNiG2xZ9QSuMTpCYCZ7" name="CISOs Guide to Gap Analysis.jpg" caption="" alt="CISOs Guide to Gap Analysis" src="https://cdn.mos.cms.futurecdn.net/GGpVNiG2xZ9QSuMTpCYCZ7.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cisos-guide-to-gap-analysis"><em>Identify areas of weakness within your AppSec program</em></a></p></div></div><p>“Vendors have been working to move away from passwords entirely, and towards solutions that rely on login protection factors that can&apos;t be stolen or phished. Various solutions have been pushed forward, but we&apos;re starting to finally see the emergence of some standards around this,” he explained.</p><p>“Solutions like <a href="https://www.itpro.com/security/what-do-passkeys-mean-for-your-business">passkeys</a> for example, are beginning to enter use with online services. In the corporate space, solutions like physical tokens have already been established around standards like FIDO2 WebAuthN.”</p><p>Additional security layers such as <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatiguehttps://www.itpro.com/security/two-factor-authentication-2fa/361517/multi-factor-authentication-deployment-guide">multi-factor authentication</a> (MFA) are also essential for adequate <a href="https://www.itpro.com/security/privacy/368587/identity-theft-what-to-do-if-the-worst-happens">identity security</a>, according to Raj Samani, SVP and chief scientist at Rapid 7.</p><p>“We’ve seen with recent breaches that <a href="https://www.itpro.com/cloud/23294/dropbox-claims-password-leaks-not-due-to-hack?amp">password leaks</a> are rife. As a result, even with good password hygiene, we need to go one step further,” he said. “Multi-factor authentication (MFA) is vital and with 41% of incidents due to missing or unenforced MFA, for many is the biggest security accomplishment which can be made if not already implemented. Implementing this solution in tandem with basic password hygiene can greatly improve an organization’s security posture.” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky hits back at US software ban, citing political motivations and “theoretical concerns” ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/kaspersky-hits-back-at-us-software-ban-citing-political-motivations-and-theoretical-concerns</link>
                                                                            <description>
                            <![CDATA[ Kaspersky said it has “repeatedly demonstrated" its independence from any government interference ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7WxEo9qALDdgPeGrKsDcE8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VLEughczac6HAVBLTYR5ZU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Jun 2024 09:45:10 +0000</pubDate>                                                                                                                                <updated>Fri, 21 Jun 2024 14:08:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VLEughczac6HAVBLTYR5ZU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Eugene Kaspersky, founder and CEO of Kaspersky Labs cyber security vendor.]]></media:description>                                                            <media:text><![CDATA[Eugene Kaspersky, founder and CEO of Kaspersky Labs cyber security vendor.]]></media:text>
                                <media:title type="plain"><![CDATA[Eugene Kaspersky, founder and CEO of Kaspersky Labs cyber security vendor.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VLEughczac6HAVBLTYR5ZU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cyber security</a> vendor Kaspersky has hit out at plans by US lawmakers to ban sales of its <a href="https://www.itpro.com/antivirus/antivirus/27989/is-antivirus-bad-for-security">antivirus</a> software. </p><p>Reports emerged on 20 June that the <a href="https://www.itpro.com/security/us-poised-to-ban-sales-of-kaspersky-software-reports">US government is set to prohibit the sale of Kaspersky products</a> amid concerns over alleged links between the firm and the Russian government.</p><p>Under the plans, which are expected to come into force in late September, inbound sales of Kaspersky software will be banned for US companies. This will include any software updates, resales, and licensing of the product by US suppliers.</p><p>Sales of white-labeled products – those that use Kaspersky software under a different name – will also be barred.</p><p>The move marks the latest flashpoint in a long-running war of words between Kaspersky and US legislators, who have repeatedly argued that Kaspersky has links to the Russian government that present a national security risk.</p><p>Officials have previously suggested that elements of Russian law mean the government could lean on the company for intelligence-gathering purposes.</p><p>In a statement given to <em>ITPro</em>, Kaspersky insisted these allegations are false, and said the US Department of Commerce’s decision to float a product ban is politically motivated.</p><p>“Despite proposing a system in which the security of Kaspersky products could have been independently verified by a trusted third party, Kaspersky believes that the Department of Commerce made its decision based on the present geopolitical climate and theoretical concerns, rather than on a comprehensive evaluation of the integrity of Kaspersky’s products and services,” the firm said.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=60068497&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>The company added that it “does not engage in activities which threaten US national security” and has made “significant contributions” by reporting on –and protecting against –threat actors that have actively targeted US institutions.</p><p>Kaspersky appears to be preparing for a lengthy battle to argue its case against any proposed ban.</p><p>“The company intends to pursue all legally available options to preserve its current operations and relationships,” Kaspersky said.</p><h2 id="kaspersky-says-ban-proposals-will-harm-enterprises">Kaspersky says ban proposals will harm enterprises</h2><p>In its statement, Kaspersky said it has implemented “significant transparency measures that are unmatched by any of its <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> industry peers” to show it’s free of any government interference. </p><p>In 2018, the company announced plans to relocate some of its operations from Russia to Switzerland. The move, which formed part of its Global Transparency Initiative (GTI), took more than two years to complete. </p><p>The company said at the time it chose Switzerland due to its "policy of neutrality"</p><p>Kaspersky suggested that the US&apos; decision to impose a ban "unfairly ignores" evidence of proactive efforts to improve transparency and warned the decision will negatively impact its customers. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nBPYdTxDY4EskWcCVJ3ULo" name="Password auditing guide.jpg" caption="" alt="Password auditing guide" src="https://cdn.mos.cms.futurecdn.net/nBPYdTxDY4EskWcCVJ3ULo.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Specops)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/password-auditing-guide"><em>Stay ahead of today’s threats</em></a></p></div></div><p>The company argued that a ban would ultimately aid threat actors and have a detrimental effect on <a href="https://www.itpro.com/security/uk-leads-international-efforts-to-tackle-hackers-for-hire">international efforts to combat cyber crime</a>.</p><p>“The primary impact of these measures will be the benefit they provide to cybercrime,” the firm said. “International cooperation between cyber security experts is crucial in the fight against malware, and yet this will restrict those efforts.</p><p>“Furthermore, it takes away the freedom that consumers and organizations, large and small, should have to use the protection they want. This will cause a dramatic disruption for our customers, who will be forced to urgently replace technology they prefer and have relied upon for their protection for years.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US poised to ban sales of Kaspersky software – reports ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/us-poised-to-ban-sales-of-kaspersky-software-reports</link>
                                                                            <description>
                            <![CDATA[ Kaspersky has long denied any links to the Russian government ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">M2YktehRXaVazDNPwZMoWh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TSJGJg67PPqdg4HBHmZyBf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Jun 2024 14:53:33 +0000</pubDate>                                                                                                                                <updated>Fri, 21 Jun 2024 09:34:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TSJGJg67PPqdg4HBHmZyBf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kaspersky labs logo pictured against a green background.]]></media:description>                                                            <media:text><![CDATA[Kaspersky labs logo pictured against a green background.]]></media:text>
                                <media:title type="plain"><![CDATA[Kaspersky labs logo pictured against a green background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TSJGJg67PPqdg4HBHmZyBf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US government is set to ban the sale of Kaspersky Lab&apos;s <a href="https://www.itpro.com/security/29665/does-antivirus-software-do-more-harm-than-good">antivirus software</a> in the US, according to reports from <a href="https://www.reuters.com/technology/biden-ban-us-sales-kaspersky-software-over-ties-russia-source-says-2024-06-20/"><u><em>Reuters</em></u></a>.</p><p>Citing sources familiar with the matter, the move is reportedly due to alleged links between the cyber security vendor and the Russian government.</p><p>Lawmakers are worried the use of the software by US firms might pose a serious risk to national security and critical infrastructure as it could be used to steal corporate data or install <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>.</p><p>The move will be made possible using powers introduced by the Trump administration and will see the company added to a trade restriction list, Reuters noted.</p><p>These powers were initially introduced to limit the use of products created by companies operating in “foreign adversary” nations.</p><p>This will, in practice, prevent US suppliers from selling to the company and also prevent inbound sales of Kaspersky software – including updates, any resales, and licensing of the product.</p><p>Sales of white-labeled products – or those that use Kaspersky software sold under a different name – will also be barred, sources told Reuters.</p><p>The ban is expected to come into force by 29 September to provide US firms with ample time to seek alternatives.</p><h2 id="kaspersky-has-long-denied-its-ties-to-the-russian-government">Kaspersky has long denied its ties to the Russian government</h2><p>The move by US lawmakers marks the latest incident in a long-running spat between Kaspersky and Western governments. Critics have previously argued that the security company represents a security risk due to its alleged <a href="https://www.itpro.com/security/cyber-security/367288/is-kaspersky-still-safe-to-use">ties to the Russian government</a>. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NmM5vCXRZZCdkmJwRgQ9nN" name="The security awareness handbook_email.jpg" caption="" alt="A whitepaper from Proofpoint on security awareness, training, with cartoon image of a security awareness class with teacher and student at desk" src="https://cdn.mos.cms.futurecdn.net/NmM5vCXRZZCdkmJwRgQ9nN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Proofpoint)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-security-awareness-handbook"><em>Educate staff on how to identify cyber threats</em></a></p></div></div><p>In 2017, the US Department of Homeland Security banned the firm’s antivirus product from being used on federal networks due to these concerns.</p><p>At the time, the department argued that aspects of Russian law could allow intelligence agencies to strongarm the company into providing assistance to intercept information.</p><p>Following Russia&apos;s invasion of Ukraine in early 2022, the company was declared a “national security risk” to the US and <a href="https://www.itpro.com/security/antivirus/367227/kaspersky-declared-threat-to-us-national-security">placed on an FCC blacklist</a>.</p><p><em>ITPro</em> has approached Kaspersky for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Human errors still a leading cause of cyber incidents, says Kaspersky ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/human-errors-caused-two-cyber-incidents-a-day-in-2023</link>
                                                                            <description>
                            <![CDATA[ The worst-affected industries are government, IT firms, and the financial and industrial sectors ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3GK7a6v3WBPDBwrWh6JCWT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2GhNhXCSPdGYMPqCL4uMS9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 May 2024 10:52:11 +0000</pubDate>                                                                                                                                <updated>Wed, 01 May 2024 13:13:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2GhNhXCSPdGYMPqCL4uMS9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digitized padlock with binary code placed over a circuit board signifying secure software development and security pratices.]]></media:description>                                                            <media:text><![CDATA[Digitized padlock with binary code placed over a circuit board signifying secure software development and security pratices.]]></media:text>
                                <media:title type="plain"><![CDATA[Digitized padlock with binary code placed over a circuit board signifying secure software development and security pratices.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2GhNhXCSPdGYMPqCL4uMS9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There were more than two critical cyber incidents with direct human involvement per day last year, according to new research from Kaspersky.</p><p>The company&apos;s annual <em>Managed Detection and Response (MDR) Analyst Report</em> concludes that nearly a quarter of incidents were driven by humans.</p><p>Just over one-in-five involved various types of cyber exercises which had been previously classified by Kaspersky as targeted attacks, but which were redesignated after explanation by the customer.</p><p>The government sector was hardest-hit, accounting for 22.9% of all detected high-severity incidents. IT companies came second. at 15.4%, closely followed by financial and industrial companies with 14.9% and 11.8% of incidents respectively.</p><p>The most incidents per 10,000 devices were found in mass media organizations, development companies, and government agencies.</p><p>Despite concerns over human-related errors, Kaspersky noted that the percentage of malware attacks resulting in serious consequences dipped slightly last year, accounting for just over 12% of the total reported critical incidents.</p><p>This, the company noted, marks the smallest share of high-severity incidents in recent years.</p><p>This trend can be attributed to the commoditization of attacks through the widespread adoption of existing tools, originally designed for conducting targeted campaigns which, due to deliberate or accidental leaks, have become common.</p><p>These tools are now being repurposed in attempts to implement fully automated attacks, says the firm.</p><p>"In 2023, Kaspersky detected a smaller number of high-severity incidents, but observed a simultaneous increase in the number of medium and low severity ones. This redistribution of occurrences is associated with the detection of malware without visible traces of active human participation in attacks, which can be explained by the commoditization of tools," said Sergey Soldatov, head of security operations center at Kaspersky.</p><p>"However, it’s important to understand that the low number of high-severity incidents does not necessarily indicate low damage. Targeted attacks are now planned more carefully, and become more dangerous. Therefore, we recommend the use of effective automated cybersecurity solutions managed with the help of experienced <a href="https://www.itpro.com/security/359719/what-is-a-soc-audit">SOC</a> analysts."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jsaiXAX2Y3Y7RFbwqo5ima" name="Windows 11 Pro and CDW - Overcoming today's escalating cyberthreats 2.jpg" caption="" alt="Windows 11 Pro and CDW - Overcoming today's escalating cyberthreats" src="https://cdn.mos.cms.futurecdn.net/jsaiXAX2Y3Y7RFbwqo5ima.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Windows 11)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/windows-11-pro-and-cdw-overcoming-todays-escalating-cyberthreats"><em>Discover how Windows 11 Pro devices proactively mitigate risk</em></a></p></div></div><p><a href="https://www.itpro.com/malware/28076/what-is-malware">Malware</a> attacks accounted for just over 12% of incidents - the lowest proportion yet, according to the firm. Most were classified as medium or low severity.</p><p>Fewer than one-in-twenty related to publicly available critical vulnerabilities, while around 4% were the result of successful social engineering with further attack development.</p><p>And fewer than 1% of incidents were linked to insiders, while nearly one in three related to suspicious activity from legitimate accounts with no visible signs of compromise.</p><p>Almost one-in-ten incidents involved <a href="https://www.itpro.com/security/five-eyes-advisory-raises-alarm-over-state-backed-living-off-the-land-attacks">Living Off the Land</a> Binaries - LOLBins - with the figure rising to a third of high-severity incidents. The most popular LOLBins were powershell.exe and rundll32.exe, which were used in 2% of all incidents and in 12% of critical incidents.</p><p>Meanwhile, a relatively high number of incidents were associated with the detection of adding accounts to various privileged groups such as domain admins or enterprise admins.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky names new managing director for Europe ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/leadership/kaspersky-names-new-managing-director-for-europe</link>
                                                                            <description>
                            <![CDATA[ Alfonso Ramirez takes the reins of Kaspersky’s consumer and corporate strategies across the continent ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2P9DdWMAWrD6M4G2j8QvCF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bqfHFJ53ZLkb2TYPWFEnub-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Apr 2024 11:53:07 +0000</pubDate>                                                                                                                                <updated>Wed, 03 Apr 2024 14:01:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bqfHFJ53ZLkb2TYPWFEnub-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Visitors sit at the stand of Russian antivirus software development company Kaspersky Lab on the opening day of the MWC (Mobile World Congress) in Barcelona on February 28, 2022]]></media:description>                                                            <media:text><![CDATA[Visitors sit at the stand of Russian antivirus software development company Kaspersky Lab on the opening day of the MWC (Mobile World Congress) in Barcelona on February 28, 2022]]></media:text>
                                <media:title type="plain"><![CDATA[Visitors sit at the stand of Russian antivirus software development company Kaspersky Lab on the opening day of the MWC (Mobile World Congress) in Barcelona on February 28, 2022]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bqfHFJ53ZLkb2TYPWFEnub-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cyber security</a> specialist Kaspersky has announced the promotion of Alfonso Ramirez to the role of managing director for Europe.</p><p>A seasoned industry veteran, Ramirez brings more than 20 years’ experience to the role, including success in shaping development strategies and driving business growth within the IT business sector.</p><p>He first joined Kaspersky in 2008 as director of consumer business in Iberia, working to position the company’s consumer products in the region, and was later promoted to general manager, where he spent ten years directing the firm’s business strategies across Spain and Portugal.</p><p>Prior to joining Kaspersky, he held various senior sales and marketing positions at multinational companies.</p><p>In his new role as managing director for Europe, Ramirez will leverage this experience to lead Kaspersky’s consumer and corporate strategies across the wider continent.</p><p>“We are thrilled to welcome Alfonso Ramirez to lead our European operations," said Robert Cataldo, Kaspersky’s vice president of global sales. </p><p>"His extensive experience leading our markets in Iberia and strategic acumen will be instrumental in promoting Kaspersky&apos;s technology leadership approach in the region."</p><p>Founded in 1997, Kaspersky provides a portfolio of cyber security and digital <a href="https://www.itpro.com/security/privacy">privacy</a> solutions and services that incorporate <a href="https://www.itpro.com/security/cyber-security/356762/protect-your-end-points">endpoint protection</a>, specialized <a href="https://www.itpro.com/security">security</a> products, as well as its Cyber Immune solutions. The company currently serves more than 400 million customers worldwide, as well as over 220,000 corporate clients.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="oWoz7SrSXnsswimF7CnyyW" name="Ten must-have capabilities for ZTNA_listing.jfif.jpg" caption="" alt="Whitepaper cover with title and logo over image of female colleague wearing glasses looking at a smartphone" src="https://cdn.mos.cms.futurecdn.net/oWoz7SrSXnsswimF7CnyyW.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/want-to-secure-your-hybrid-workforce-with-ztna"><em>Discover how ZTNA can benefit your organization</em></a></p></div></div><p>As new managing director for Europe, Kaspersky said Ramirez will leverage the firm’s broad distribution and partner network to capitalize on business growth and revenue opportunities for all strategic segments – with a particular focus on cyber security for both enterprises and SMBs.</p><p>"I’m honored to embark on this journey to lead the European business,” Ramirez said. “In the ever-expanding threat landscape, companies and individuals alike are increasingly vulnerable to cyber threats and often do not have the right security measures in place.</p><p>“We believe that our award-winning approach is the cornerstone of the future of cyber security, and I am confident in our ability to propel our business to new heights in Europe, contributing to Kaspersky’s mission of building a safer world."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber security training costs surge as firms battle skills gaps ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/careers-and-training/cyber-security-training-costs-surge-as-firms-battle-skills-gaps</link>
                                                                            <description>
                            <![CDATA[ Cyber security training costs are rising alongside a widening skills gap, new research shows, as firms ramp up efforts to get staff in the door ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WzyZHvgV2QWRZZFsy6CnyX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GCMfmsAmSwZcFs3EgeQVC4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 Mar 2024 11:40:43 +0000</pubDate>                                                                                                                                <updated>Tue, 26 Mar 2024 14:10:04 +0000</updated>
                                                                                                                                            <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GCMfmsAmSwZcFs3EgeQVC4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IT leaders discussing cyber security training costs and programs in an open plan office space while colleagues work at computers in foreground.]]></media:description>                                                            <media:text><![CDATA[IT leaders discussing cyber security training costs and programs in an open plan office space while colleagues work at computers in foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[IT leaders discussing cyber security training costs and programs in an open plan office space while colleagues work at computers in foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GCMfmsAmSwZcFs3EgeQVC4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness">Cyber security training</a> costs organizations around $100,000 on average each year, according to research from Kaspersky, highlighting the steep price of battling long-running skills gaps.</p><p>Analysis from the cyber security firm showed nearly half (43%) of firms usually spend between $100,000 and $200,000 per year on information <a href="https://www.itpro.com/business-strategy/careers-training/358117/the-top-online-cyber-security-courses">security courses</a> for staff, while around one-third are spending more.</p><p>Just one-quarter of respondents told Kaspersky they spend less than $100,000 on educational initiatives.</p><p>Despite these efforts though, many cyber security practitioners believe they’re not offered adequate training to contend with an escalating threat landscape. Around 40% of respondents told Kaspersky that training courses were inadequate, or few and far between.</p><p>Some said they are willing to pay for additional training courses out of their pocket to ensure their knowledge and skills are up to date.</p><h2 id="cyber-security-training-costs-aren-x2019-t-the-only-hindrances">Cyber security training costs aren’t the only hindrances</h2><p>According to Kaspersky, the costs of cyber security training isn&apos;t the only issue organizations are contending with in 2024. </p><p>The study found the education/training market is struggling to keep up with current demands, with many failing to deliver the necessary training programs and learning materials on time.</p><p>The shortage of courses covering new challenging spheres was the main problem for those searching for <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> training, cited by more than half of respondents.</p><p>Meanwhile, nearly half said that trainees tend to forget what they&apos;ve learned because they have no opportunity to apply their newly-acquired knowledge.</p><p>The need for special training prerequisites such as <a href="https://www.itpro.com/business-strategy/careers-training/369155/are-coding-bootcamps-worth-it">coding</a> and advanced mathematics, which weren’t actually specified at the pre-registration stage, were also a problem for 45%.</p><h2 id="how-can-firms-bolster-cyber-security-training">How can firms bolster cyber security training?</h2><p>Kaspersky said one of the best strategies for maintaining cyber security skills is to develop high-profile specialists within the company and build internal expertise, rather than simply hunting for new candidates. </p><p>"With a constantly evolving threat landscape, businesses should continually improve the skills of their cybersecurity personnel in order to be well prepared for sophisticated cyberattacks," said Veniamin Levtsov, VP, center of corporate business expertise at Kaspersky.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=56586877&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>"For organizations served by managed service providers, it is also important to maintain a pretty high level of expertise internally and use the same language when discussing the scope of services and service level agreement with them."</p><h2 id="skills-shortages-still-run-rampant">Skills shortages still run rampant</h2><p>According to the report, there is still a significant <a href="https://www.itpro.com/security/the-cyber-security-skills-shortage-what-skills-are-missing">cyber security skills shortage</a>, with 40% of InfoSec professionals noting their organization’s cyber security teams are somewhat or significantly understaffed. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NmM5vCXRZZCdkmJwRgQ9nN" name="The security awareness handbook_email.jpg" caption="" alt="A whitepaper from Proofpoint on security awareness, training, with cartoon image of a security awareness class with teacher and student at desk" src="https://cdn.mos.cms.futurecdn.net/NmM5vCXRZZCdkmJwRgQ9nN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Proofpoint)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-security-awareness-handbook"><em>Educate staff on how to identify cyber threats</em></a></p></div></div><p>These shortages are the worst in Russia, followed by Latin America, the Asia–Pacific region and the Middle East, Turkey and Africa, while the least understaffed regions are Europe and North America.</p><p>Information security research and <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> analysis are the most understaffed roles globally, cited by four-in-ten, while the biggest recruitment challenges are the <a href="https://www.itpro.com/business-strategy/careers-training/370054/cyber-security-certification-vs-degree">discrepancy between certification and practical skills</a> and lack of experience, both cited by around half.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xXqApfaWjb4FwsP7HQiW3o" name="GettyImages-1248990543-cyber-employees-shortage-skills.jpg" caption="" alt="A top-down artwork showing businesspeople walking left and right across blocks with binary code on them, to represent the cyber security skills shortage. None of the businesspeople are on paths that will intersect, and as they walk the blocks change from light blue to dark blue." src="https://cdn.mos.cms.futurecdn.net/xXqApfaWjb4FwsP7HQiW3o.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-cyber-security-skills-shortage-what-skills-are-missing">The cyber security skills shortage: What skills are missing?</a></p></div></div><p>Almost half of security professionals claim it takes more than six months to fill an information security position.</p><p>The good news for cyber security staff is that the ongoing skills shortage is causing salaries to rise, with a recent report from Cybershark Recruitment finding that salaries in 17 out of 20 categories of cyber security work increased last year.</p><p>These rises were highest in critical national infrastructure, digital forensics, identity and access management (IAM), and business continuity management.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber security professionals admit “knowledge gaps” have led to serious security blunders ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/careers-and-training/cyber-security-professionals-admit-knowledge-gaps-have-led-to-serious-security-blunders</link>
                                                                            <description>
                            <![CDATA[ A lack of technical knowledge among some cyber security professionals was a key cause of security incidents ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wjGL9zbkUHwgACnkniKYVM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sPMDjLgEt5yZoUXhC7BwGR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 19 Feb 2024 11:40:24 +0000</pubDate>                                                                                                                                <updated>Mon, 19 Feb 2024 12:24:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sPMDjLgEt5yZoUXhC7BwGR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female cyber security worker in a dark room with screen reflected on glasses. ]]></media:description>                                                            <media:text><![CDATA[Female cyber security worker in a dark room with screen reflected on glasses. ]]></media:text>
                                <media:title type="plain"><![CDATA[Female cyber security worker in a dark room with screen reflected on glasses. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sPMDjLgEt5yZoUXhC7BwGR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over 50% of acting <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> professionals have admitted to making mistakes early in their career due to a lack of technical knowledge, new research suggests. </p><p>The study, conducted globally by Kaspersky, found that this percentage rose to nearly 60% in those with just two-to-five years of experience in cyber security. </p><p>There were several areas in which cyber security professionals reported <a href="https://www.itpro.com/business/careers-and-training/does-a-cyber-security-degree-help-in-the-real-world-industry-professionals-have-mixed-feelings-on-whether-theyre-useful">practical and theoretical knowledge</a> to be missing, according to the study</p><p>43% admitted that they failed to update software, 42% said that they were guilty of using weak and <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">easily-guessed passwords</a>, and 40% of surveyed staff claimed they had neglected to perform <a href="https://www.itpro.com/back-up/29084/how-to-enhance-your-backup-strategy">backups</a> in a timely manner. </p><p>All these mistakes, the professionals said, were made early on in their careers. In North America and the Asia-pacific region, the use of outdated security measures was also cited as a common mistake made by cyber security experts at the beginning of their career. </p><p>Kaspersky said the research highlights the importance of robust training for early-stage cyber security professionals, especially given that over two-thirds (64%) of all security incidents were due to <a href="https://www.itpro.com/cloud/cloud-management/the-top-three-most-likely-reasons-for-a-cloud-outage">human error</a>. </p><h2 id="some-cyber-security-workers-x201c-lack-confidence-x201d">Some cyber security workers “lack confidence”</h2><p>Over the past two years, every organization has fallen victim to “at least one” cyber security incident as a result of underqualified or undertrained staff, according to Kaspersky. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7uMYZojRGWgJ6NNn7NaYrW" name="Cyber_security_Analyst_GettyImages-1469706271.jpg" caption="" alt="Close up shot of a male cyber security analyst looking at a computer screen in dimly lit room." src="https://cdn.mos.cms.futurecdn.net/7uMYZojRGWgJ6NNn7NaYrW.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/careers-and-training/does-a-cyber-security-degree-help-in-the-real-world-industry-professionals-have-mixed-feelings-on-whether-theyre-useful">Does a cyber security degree help in the real world? Industry professionals have mixed feelings on whether they’re useful</a></p></div></div><p>Undertrained staff take longer to get comfortable in their roles, with nearly half (46%) of all cyber security employees stating it took over a year for them to feel confident in their InfoSec positions.  </p><p>While 31% managed to get to grips with the job within one or two years, nearly 10% claimed it took them two or three years, and 6% said it took more than three. </p><p>Company <a href="https://www.itpro.com/business-strategy/recruitment/363725/it-pro-panel-tackling-technical-recruitment">recruitment</a> teams need to shoulder some of the blame as well, though, Kaspersky said Over one-third (34%) of respondents said they had three or more failed interviews before being selected for an InfoSec role.</p><p>This points to knowledge gaps within companies as a whole, suggesting that many businesses don&apos;t know what to look for in a cyber security expert. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="oarBhxg28DH2mSeaEnros9" name="Learn in VR_ The beginner's guide.jpg" caption="" alt="Learn in VR: The beginner's guide whitepaper" src="https://cdn.mos.cms.futurecdn.net/oarBhxg28DH2mSeaEnros9.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Meta)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/virtualisation/learn-in-vr-the-beginners-guide"><em>Discover seven training challenges VR can help you solve</em></a></p></div></div><p><a href="https://www.itpro.com/business/careers-and-training/firms-are-relaxing-qualifications-requirements-to-fill-positions-as-tech-skills-shortages-skyrocket"><u>Recent research from recruitment firm Hays</u></a> found that over three-quarters (78%) of tech employers were willing to employ IT staff without the necessary requirements as an attempt to mitigate the tech skills gap, with the intention of <a href="https://www.itpro.com/business-strategy/34824/the-it-pro-podcast-how-upskilling-can-improve-diversity">upskilling</a> in the future. </p><p>With <a href="https://media.isc2.org/-/media/Project/ISC2/Main/Media/documents/research/ISC2_Cybersecurity_Workforce_Study_2023.pdf?rev=28b46de71ce24e6ab7705f6e3da8637e"><u>current estimates putting that cyber security workforce shortfall at nearly 4 million</u></a>, the skills deficit is placing significant strain on the task of mitigating cyber security risks.</p><p>“It’s no secret that formal training programs often struggle to keep up with industry developments, and that is especially true for the cybersecurity field,” said Marina Alekseeva, chief human resources officer at Kaspersky. </p><p>“The fact that many employees in the market might have limited practical skills or gaps in their knowledge underlines the importance of a comprehensive onboarding process with a focus on peer learning and means companies must pay more attention to the upskilling of their employees,” she added.  </p><p>Kasperysky’s study suggests a program of education which is flexible and adaptable to regularly changing InfoSec demands, while also encouraging the use of practical cyber security exercises and upskilling procedures. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ One quarter of all data breaches due to employees swerving security policies ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/one-quarter-of-all-data-breaches-due-to-employees-swerving-security-policies</link>
                                                                            <description>
                            <![CDATA[ There are a concerning number of cyber security incidents caused by employees acting deliberately ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cRw2j2BJkpG2hSQuFMdjYg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hcF5zrWZhdGYsGxPxBsbKV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Nov 2023 13:48:59 +0000</pubDate>                                                                                                                                <updated>Thu, 23 Nov 2023 16:03:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;
&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2018 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;
&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hcF5zrWZhdGYsGxPxBsbKV-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Concept art showing locked packlocks with one opened coloured in red, signifying a data breach]]></media:description>                                                            <media:text><![CDATA[Concept art showing locked packlocks with one opened coloured in red, signifying a data breach]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art showing locked packlocks with one opened coloured in red, signifying a data breach]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hcF5zrWZhdGYsGxPxBsbKV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Many employees are deliberately circumventing their organization’s security procedures, according to new research from Kaspersky.</p><p>Analysis from the firm found that a considerable portion of cyber incidents are attributed to workers disregarding security protocols. In the last two years, for example, 26% of cyber incidents occurred after a staff member violated procedures. </p><p>The issue has reached such a scale that the level of danger breaches of this nature pose to businesses is almost equal to that of external threats, such as hacking, Kaspersky warned.</p><p>Both IT and non-IT employees were found to be circumventing security procedures, the study found. Around 13% of cyber security incidents since 2021 were caused by intentional information security violations from IT security officers, for example. </p><p>In terms of the specific actions causing these policy violations, the study revealed employees in 12% of polled organizations had intentionally used unauthorized devices to access sensitive data.</p><p>Additionally, other businesses reported 12% of their staff were found to have sent sensitive information to their personal email address. </p><p>Potentially the most alarming finding from Kaspersky’s research is that 20% of malicious actions were made by staff for personal gain. </p><p>This also implies another portion of intentional breaches were caused by employees who simply did not want to follow sometimes tedious security procedures.</p><h2 id="accidental-breaches-are-still-the-most-common-security-incidents-affecting-firms">Accidental breaches are still the most common security incidents affecting firms</h2><p>Despite the concerning findings around intentional policy violations, the report shows the majority (38%) of cyber security incidents are still caused by accidental human error.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="fAHt6viqxDskbCXU4yw6XP" name="digital-safety-ai-security-padlock-GettyImages-1397398956.jpg" caption="" alt="Digital shield emerging form a motherboard to denote safety and security" src="https://cdn.mos.cms.futurecdn.net/fAHt6viqxDskbCXU4yw6XP.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/why-cisa-is-extending-cyber-support-to-resource-poor-organizations">Why CISA is extending cyber support to ‘resource poor’ organizations</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security-professionals-are-exhausted-and-its-putting-firms-at-greater-risk-of-attack">Cyber security professionals are exhausted, and it&apos;s putting firms at greater risk of attack</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/ico-threatens-to-name-and-shame-cookie-consent-rogues">ICO threatens to name and shame cookie consent rogues</a></p></div></div><p>Breaking these incidents down by the actions that caused them, Kaspersky found downloading malware to be the leading cause of incidents by non-IT personnel, accounting for 28% of accidental breaches. </p><p>A quarter of respondents said using weak <a href="https://www.itpro.com/security/basic-password-hygiene-is-still-awful-so-maybe-it-is-time-to-go-passwordless"><u>passwords</u></a>, or failing to update them regularly was to blame for the incident, and 24% said they were responsible for a breach when they visited an unsecured website. </p><p>Accidental breaches were not solely caused by non-IT staff, however, 14% of cyber incidents caused by unintentional human error were attributed to senior IT professionals.</p><p>Ensuring all employees, regardless of department or seniority, have robust cyber hygiene habits is critical for an organization to implement an effective security posture, according to Kaspersky.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="z5o5av8Qme7nhYwTzVLsuC" name="Everything is connected_thumb.jpg" caption="" alt="Red whitepaper cover with title and logo" src="https://cdn.mos.cms.futurecdn.net/z5o5av8Qme7nhYwTzVLsuC.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><em>Learn more about how the ransomware epidemic influences global supply chains<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370165/uncovering-the-ransomware-threat-from-global-supply-chains">DOWNLOAD NOW</a></p></div></div><p>Alexey Vovk, Kaspersky’s head of information security, underlined the necessity of a holistic approach to security and compliance in addressing the risks posed by employee behavior. </p><p>“Along with external cybersecurity threats, there are many internal factors that can lead to incidents in any organization. As statistics show, employees from any department, whether it&apos;s non-IT specialists or IT Security professionals, can negatively influence cybersecurity both intentionally and unintentionally,” he said. </p><p>“That is why, it is important to consider methods of preventing information security policy violations when ensuring security, i.e. to implement an integrated approach to cybersecurity.</p><p>“As the numbers are alarming, it is necessary to create a cybersecurity culture in an organization from the get-go by developing and enforcing security policies, as well as raising cybersecurity awareness among employees. Thus, the staff will approach the rules more responsibly and clearly understand the possible consequences of their violations.” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 80% of C-suites aren’t acting on worries that workers already use generative AI ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/80-of-c-suites-arent-acting-on-worries-that-workers-already-use-generative-ai</link>
                                                                            <description>
                            <![CDATA[ The disconnect between fears around generative AI and a willingness to use it in place of employees could have profound implications for business security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RoPwgpZ8MBpR8Exot5C6Vi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4CRggHd4bDGURffEJrUDC4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 Oct 2023 14:42:47 +0000</pubDate>                                                                                                                                <updated>Thu, 26 Oct 2023 16:17:50 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is a staff writer at ITPro. He is a subject expert on artificial intelligence and business networks and additionally covers a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;
&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs and extensive daily coverage of the most significant announcements, as well as analysis pieces and podcasts.&lt;/p&gt;
&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;
&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;
&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4CRggHd4bDGURffEJrUDC4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Business person looking our of the boardroom windows onto the cityscape]]></media:description>                                                            <media:text><![CDATA[Business person looking our of the boardroom windows onto the cityscape]]></media:text>
                                <media:title type="plain"><![CDATA[Business person looking our of the boardroom windows onto the cityscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4CRggHd4bDGURffEJrUDC4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Executives are increasingly worried that employees are using generative artificial intelligence (AI) at work without explicit permission, but are failing to act on these concerns according to a new report.</p><p>Almost all (95%) of the C-suite executives surveyed in a new Kaspersky report said they think popular AI tools such as <a href="https://www.itpro.com/technology/artificial-intelligence/how-chatgpt-has-already-found-its-way-into-business"><u>ChatGPT</u></a> are being used within their business, while 59% expressed serious concerns that their use could lead to a leak of confidential data.</p><p>There have already been cases in which employee use of AI tools has led to sensitive data leakage. In April, <em>TechRadar Pro </em><a href="https://www.techradar.com/news/samsung-workers-leaked-company-secrets-by-using-chatgpt" target="_blank"><u>reported</u></a> Samsung workers inadvertently handed trade secrets to OpenAI by <a href="https://www.itpro.com/technology/artificial-intelligence/chatgpt-gives-wrong-answers-to-programming-questions-more-than-50-of-the-time"><u>using ChatGPT for programming help</u></a> on source code.</p><p>Cyber security firm Kaspersky took in responses from 1,863 C-suite executives across the UK, France, Germany, Greece, Italy, Netherlands, Romania, and Spain between 25  September and 2 October 2023.</p><p>Results showed that executive anxieties stemmed largely from a pervasive lack of trust and understanding of how generative AI tools use data: most of the respondents (91%) said they want more insight into how generative AI works.</p><p>Despite all this, just 22% of surveyed executives said they had even had discussions about putting rules in place for generative AI.</p><p>A quarter (25%) of executives said they will allow employees to use generative AI as they are currently, and a further 6% stated that they have no strong feelings about whether employees use the technology or not.</p><p>The number of executives actively intending to implement generative AI solutions at their business also remained high, with 50% stating they would use the technology to automate tiring manual tasks and 44% hoping they can use it to lighten the workload at their own level.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9jRiDv3ZrwPArvTWH6TC3Z" name="2023 ThreatLabz state of ransomware report.jpg" caption="" alt="2023 ThreatLabz state of ransomware report" src="https://cdn.mos.cms.futurecdn.net/9jRiDv3ZrwPArvTWH6TC3Z.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover findings, predictions, and best practices that will shape future ransomware defence strategies.<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/2023-threatlabz-state-of-ransomware-report">DOWNLOAD NOW</a></p></div></div><p>Almost a quarter (24%) of executives stated they were eager to automate their IT and cyber security teams using generative AI, even as fears around the technology persist among the majority of respondents.</p><p>"One might assume that the prospect of sensitive data loss and losing control of critical business units might give the C-suite pause for thought, but our findings reveal that almost a quarter of industry bosses are currently considering the delegation of some of their most important functions to AI,” said David Emm, principal security researcher at Kaspersky.</p><p>“Before this happens, it is imperative that a comprehensive understanding of data management and the implementation of robust policies precede any further integration of [generative] AI into the corporate environment.”</p><p>How and where employees are using generative AI was a point for speculation among respondents.</p><p>More than half (53%) had suspicions that generative AI is already being used to entirely replace some tasks within certain departments in secret, with 25% suggesting it is being used in the IT department and 19% suspecting their marketing teams.</p><p>The tasks that employees are suspected of using AI for include writing emails, with 49% of executives identifying this as a common use for generative AI tools, as well as for finding efficient ways to get through to-do lists.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=57309321&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>Both are in line with the range of AI productivity tools being offered by public cloud providers such as <a href="https://www.itpro.com/technology/artificial-intelligence/duet-ai-vs-copilot-all-the-similarities-and-differences"><u>Duet AI and Copilot</u></a>, produced by Google and Microsoft respectively. While both of these services have been built with the enterprise in mind and have additional data security measures, public-facing or free generative AI services may come with no such guarantees.</p><p>Within the suspected use cases, it is clear that C-suite executives see generative AI tools as a path to productivity gains and that there is pressure to adopt the technology or fall behind. Just under half (49%) were either ‘very’ or ‘fairly’ concerned about losing a competitive advantage if they did not use generative AI more.</p><p>Recent research by Gartner found that among businesses adopting generative AI solutions, more than a third are <a href="https://www.itpro.com/technology/artificial-intelligence/ai-security-tools-see-mounting-investment-as-businesses-scramble-to-mitigate-generative-ais-issues"><u>investing in AI application security solutions</u></a> as a mitigation strategy against <a href="https://www.itpro.com/technology/artificial-intelligence/microsoft-knows-ai-has-many-problems-heres-how-it-plans-to-fix-them"><u>AI flaws</u></a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky traces spyware attack on staff iOS devices back to 2019 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/kaspersky-traces-spyware-attack-on-staff-ios-devices-back-to-2019</link>
                                                                            <description>
                            <![CDATA[ It's currently unclear who is behind the spyware attack on the Russian-based cyber security firm ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TQzZqWRbayRMvW4DubGcLj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rCZWb4KQCTDwQB3y4xjNAf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Jun 2023 11:52:29 +0000</pubDate>                                                                                                                                <updated>Tue, 13 Jun 2023 08:09:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rCZWb4KQCTDwQB3y4xjNAf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The silhouette of a person looking at their phone, in front of text reading &#039;Kaspersky&#039; on a light blue background.]]></media:description>                                                            <media:text><![CDATA[The silhouette of a person looking at their phone, in front of text reading &#039;Kaspersky&#039; on a light blue background.]]></media:text>
                                <media:title type="plain"><![CDATA[The silhouette of a person looking at their phone, in front of text reading &#039;Kaspersky&#039; on a light blue background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rCZWb4KQCTDwQB3y4xjNAf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Russian cyber security firm Kaspersky Lab has discovered covert spyware on its staff’s iPhones that dates back to at least 2019.</p><p>The advanced persistent threat (APT) campaign, which Kaspersky has dubbed Operation Triangulation, involves the infection of iOS devices through the iMessage app in order to steal user data.</p><p>Researchers said they discovered evidence of the campaign targeting its own staff dating as far back as 2019, and that it, at the time of writing, remains an ongoing threat.</p><p>Kaspersky believes the intention of the attack was to place <a href="https://www.itpro.com/spyware/30001/what-is-spyware">spyware</a> on devices belonging to senior employees at the cyber security company.</p><p>The attack is thought to begin with a hidden iMessage being sent to victims, which contains a malicious attachment. This initial payload is then triggered on a device without user knowledge through a zero-click vulnerability.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CZGRPmo3S5zynJBv3QLkjb" name="ThreatLabz State of Phishing Report_thumb.jfif.jpg" caption="" alt="Whitepaper cover with title over image of colleagues chatting in an office with red circular digital icons around them" src="https://cdn.mos.cms.futurecdn.net/CZGRPmo3S5zynJBv3QLkjb.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><strong>ThreatLabz 2023 Phishing Report</strong></p><p class="fancy-box__body-text"><em>Helping you realize the tactics used in phishing attacks, in order to prevent costly data breaches</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/threatlabz-2023-phishing-report"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Once active, the package connects to the attackers’ command and control (C2) server to download a much larger payload. This exfiltrates personal data, microphone recordings, geolocation information, and photos sent on messaging apps.</p><p>“Our experts have discovered an extremely complex, professional targeted cyberattack that uses Apple’s mobile devices,” <a href="https://www.kaspersky.com/blog/triangulation-attack-on-ios/48353/" target="_blank"><u>wrote</u></a> Kaspersky Lab CEO Eugene Kaspersky.</p><p>“The purpose of the attack is the inconspicuous placing of spyware into the iPhones of employees of at least our company – both middle and top management.”</p><p>Although the closed nature of <a href="https://www.itpro.com/mobile/30409/android-vs-ios-which-mobile-os-is-right-for-you"><u>iOS</u></a> has impeded efforts to analyze the Triangulation payload, initial research showed that it exploits iOS flaws to perform privilege escalation.</p><p>This allows it to run code with root privileges, in which the malware effectively gains total control over a system with the power to amend or remove even core system files.</p><p>Kaspersky Lab discovered Operation Triangulation while conducting a scan of its Wi-Fi <a href="https://www.itpro.com/network-internet/34780/network-monitoring-what-every-admin-should-be-looking-out-for"><u>network traffic</u></a>.</p><p>Malicious activity can be identified in network traffic including network interaction between iMessage and the domain ‘*.ess.apple.com’, connections to a series of known C2 domains, or the download of an encrypted, 242 Kb iMessage attachment.</p><p>Another indicator of compromise for Operation Triangulation that has already been found is the appearance of a process titled ‘BackupAgent’ in a device’s data usage lines. Infected devices are also unable to update to the latest version of iOS.</p><p>Researchers are confident that the firm is not the main target of Operation Triangulation, but stopped short of speculation over who may be. Further investigation will look at the international spread of the campaign.</p><p>Eugene Kaspersky noted that this is not the first time his company has fallen victim to a targeted malware campaign.</p><p>He cited <a href="https://www.itpro.com/malware/24793/what-is-duqu-20"><u>Duqu 2.0</u></a> as one example, an APT which was discovered on Kaspersky Lab systems in 2015. This sophisticated worm exploited zero-day vulnerabilities in Windows to steal data without detection and did so for three months before being rooted out.</p><p>The threat actors behind the sophisticated attack have not yet been identified. </p><p><em>Reuters</em> <a href="https://www.reuters.com/technology/russias-fsb-says-us-nsa-penetrated-thousands-apple-phones-spy-plot-2023-06-01/" target="_blank"><u>reported</u></a> that Russia’s Federal Security Service (FSB) accused the US National Security Agency (NSA) of committing the attacks in collaboration with Apple, without evidence.</p><p>Some have compared the activity of the spyware to <a href="https://www.itpro.com/security/spyware/361639/apple-sues-nso-group-over-pegasus-attacks-on-its-customers"><u>NSO Group’s Pegasus</u></a>, the spyware that authoritarian governments used to <a href="https://www.itpro.com/security/spyware/360276/journalists-human-rights-activists-targeted-with-pegasus-spyware"><u>target high-profile business and media figures</u></a> through covert observation and data theft.</p><p>However, in a Twitter thread Eugene Kaspersky reported that the activity of Operation Triangulation does not overlap with that of known iOS malware such as Pegasus.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">Important: The activity observed in Operation Triangulation does not overlap with already known iOS campaigns, such as Pegasus, Predator or Reign.<a href="https://twitter.com/e_kaspersky/status/1664267502229262337">June 1, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>Kaspersky researcher Georgy Kucherin also <a href="https://twitter.com/kucher1n/status/1664320524166610944" target="_blank"><u>tweeted</u></a> that the spyware does not persist, and that attackers “have to reinfect the device when it reboots”. </p><p>This could raise hopes that regular phone reboots would work as a measure against prolonged device infection. </p><p>Evidence of the attack chain suggests that disabling iMessage would protect iOS devices from Operation Triangulation but that once infected, devices have to undergo a factory reset and manual reinstallation of iOS and the user environment.</p><p>As infected devices cannot update, a reboot does nothing to make a device less vulnerable to subsequent reinfection.</p><p>Eugene Kaspersky speculated in a <a href="https://twitter.com/e_kaspersky/status/1664306959166717954" target="_blank">tweet</a> that the iOS <a href="https://www.itpro.com/security/spyware/368468/apple-launching-lockdown-mode-ios16-pegasus-spyware"><u>Lockdown Mode</u></a> security feature could protect against initial infection, but this has not yet been proven.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky could face another round of US punishments on national security grounds ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/370418/kaspersky-could-face-another-round-of-us-punishments-on-national-security-grounds</link>
                                                                            <description>
                            <![CDATA[ The embattled Moscow-based company has fended countless allegations of Kremlin collaboration for more than a decade ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r47EZsU4mYP24rRZrEeqmQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gVGBMu6JHqBv6rA6dFynFa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Apr 2023 11:15:21 +0000</pubDate>                                                                                                                                <updated>Wed, 12 Apr 2023 16:35:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gVGBMu6JHqBv6rA6dFynFa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kaspersky Internet Security software]]></media:description>                                                            <media:text><![CDATA[Kaspersky Internet Security software]]></media:text>
                                <media:title type="plain"><![CDATA[Kaspersky Internet Security software]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gVGBMu6JHqBv6rA6dFynFa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US is reportedly considering enforcement action against cyber security firm Kaspersky.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TzriL8GCKKzhvYPMPhhawT" name="TzriL8GCKKzhvYPMPhhawT.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TzriL8GCKKzhvYPMPhhawT.jpg" mos="https://cdn.mos.cms.futurecdn.net/TzriL8GCKKzhvYPMPhhawT.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to build a cyber-resilient business ready to innovate and thrive</strong></p><p class="fancy-box__body-text">Outperform your peers in your successful business outcomes</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370146/how-to-build-a-cyber-resilient-business-read-to-innovate-and-thrive"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The news comes a year after Kaspersky was declared a ‘national security risk’ to the US and placed on an FCC blacklist following Russia’s invasion of Ukraine.</p><p>What type of enforcement action Kaspersky could receive is currently unknown, but measures typically include cease and desist orders, corrective action directives, prohibition orders, and more.</p><p>This means it could potentially be bundled with TikTok in the products under consideration for a nationwide ban.</p><p>The US already banned the use of Kaspersky security products across the federal government back in 2017 over concerns that it could aid Russian spying efforts, with or without Kaspersky’s cooperation.</p><p>Moscow-headquartered Kaspersky has consistently and vehemently denied the numerous allegations regarding fears it could be used as a spying tool by the Russian government.</p><p>It did not reply to <em>ITPro’s</em> request for comment.</p><p>Sources speaking to the <em>Wall Street Journal</em>, which first reported <a href="https://www.wsj.com/articles/biden-administration-weighs-action-against-russian-cybersecurity-firm-b84afcd7">the story</a>, did not provide details of when the Biden administration’s decision would be made.</p><p>The US Commerce Department’s Bureau of Industry and Security <a href="https://www.reuters.com/world/us/us-weighs-action-against-russian-cybersecurity-firm-kaspersky-lab-wsj-2023-04-07">told</a> <em>Reuters</em> that the department “is committed to fully exercising its authorities to protect Americans' sensitive data, and to working with Congress in a bipartisan way to adapt to evolving risks".</p><h2 id="is-kasperksy-a-national-security-risk">Is Kasperksy a national security risk?</h2><p>Much like the fears surrounding Huawei and ZTE, the national security concerns surrounding Kaspersky are largely theoretical. </p><p>At least, no concrete evidence that it has been used for Russian spying has ever been made available to the public.</p><p>Nevertheless, Kaspersky could potentially soon face the same restrictions as the aforementioned Chinese firms. </p><p>Concerns around Huawei and ZTE started in 2018 after the National Cyber Security Centre (NCSC) said they both presented <a href="https://www.itpro.com/network-internet/32299/government-warns-uk-telecoms-security-risks-5g-supply-chain" data-original-url="https://www.itpro.com/network-internet/32299/government-warns-uk-telecoms-security-risks-5g-supply-chain">a national security risk</a>, given their equipment’s heavy presence in the nation’s telecoms network.</p><p>This led to an <a href="https://www.itpro.com/mobile/5g/356451/what-does-the-huawei-ban-mean-for-uk-businesses" data-original-url="https://www.itpro.com/mobile/5g/356451/what-does-the-huawei-ban-mean-for-uk-businesses">order to rip and replace Huawei’s equipment from said network</a>, favouring other vendors like Nokia and Ericsson.</p><p>The US also imposed similar restrictions which, in November 2022, culminated in a blanket ban on sales and imports of Huawei and ZTE products in the country. </p><p>Efforts to uproot Chinese telecoms equipment from the US first began during Barrack Obama’s presidency and were continued throughout Donald Trump’s and now Joe Biden’s administrations.</p><p>Huawei and ZTE have both strenuously denied the allegations brought against them.</p><p>The underlying reasoning for these national security concerns is that the Chinese government could theoretically order companies to relinquish data to authorities, offering no chance for refusal. </p><p>This means providers of telecoms equipment could theoretically send data on essentially the entire population of a nation, as well as the businesses operating within its borders.</p><p>Kaspersky co-founder, Eugene Kaspersky, has well-known historical ties to Russia’s intelligence services.</p><p>Russia has similar government collaboration laws as China in that domestic businesses must comply with orders from the security services (FSB). </p><p>Coupled with the alleged ongoing link between the security firm’s co-founder and Russian intelligence, this seemingly presents enough cause to warrant such decisive measures.</p><p>In an exclusive interview with <em>ITPro</em> back in 2016, Eugene Kaspersky said that if the company were to discover evidence of state-sponsored spying, it may be forced to remain silent on the matter.</p><p>“If it's [found] working for a customer, we must ask ‘’can we disclose this information or not’. If they agree to disclose this information, we do. If not, unfortunately, we must be silent about it,” he said. </p><p>“In some cases, we can see there's something anomalous going on ourselves, and we find it and we analyse it, we find the victims and report the victims not directly to the victim, but to the nation's organisation responsible for security so we share the information. But, we share only the pieces of information that are related to that nation, we don't share everything to everyone.”</p><h2 id="what-s-happened-in-the-kaspersky-story-so-far">What’s happened in the Kaspersky story so far?</h2><p>Eugene Kaspersky co-founded his namesake security firm in 1997 after previously working as a software engineer for the Soviet Ministry of Defence’s intelligence branch.</p><p>Accusations of potential collaboration between the company’s CEO and the Kremlin began even before Kaspersky was formed, back in 1994 when the civilian IT firm for which Eugene Kaspersky worked at the time first started winning US contracts, he has previously <a href="https://www.ft.com/content/3db0fb72-06f0-11e2-92b5-00144feabdc0#axzz3t6mslhSv">said</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/367251/ncsc-kaspersky-warning" data-original-url="/security/antivirus/367251/ncsc-kaspersky-warning">NCSC warns businesses against using Kaspersky products</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/367227/kaspersky-declared-threat-to-us-national-security" data-original-url="/security/antivirus/367227/kaspersky-declared-threat-to-us-national-security">Kaspersky declared threat to US national security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/366989/germany-warns-kaspersky-software-cyber-security-risk" data-original-url="/security/cyber-security/366989/germany-warns-kaspersky-software-cyber-security-risk">Germany advises against using Kaspersky software due to hacking risk</a></p></div></div><p>Ever since, the company has repeatedly denied the allegations that have been brought against it. From turning a blind eye to cyber attacks that benefitted Russia, to appointing a large number of its executives with Russian military or intelligence backgrounds.</p><p>One of the key turning points for the company came in 2017 when, in the US, the Trump administration banned the company’s products across federal government IT environments, citing security risks.</p><p>Kasperksy tried to <a href="https://www.itpro.com/security/32482/kaspersky-loses-court-of-appeals-battle-to-reverse-us-government-ban" data-original-url="https://www.itpro.com/security/32482/kaspersky-loses-court-of-appeals-battle-to-reverse-us-government-ban">appeal the decision</a> but its case ultimately failed.</p><p>Eugene Kaspersky said the decision was based on “subjective and non-technical public sources like uncorroborated and often anonymously sourced media reports”. </p><p>Months earlier, <em>Bloomberg</em> <a href="https://www.bloomberg.com/news/articles/2017-07-11/kaspersky-lab-has-been-working-with-russian-intelligence">reported</a> claims that Kaspersky had been working with the Russian intelligence services and had built products for them - more allegations the company’s co-founder branded “unfounded” and “total BS”.</p><p>Perhaps the most significant shift in attitude, at least globally speaking, came last year following the Russian invasion of Ukraine.</p><p>A <em>Reuters</em> <a href="https://www.reuters.com/technology/exclusive-us-warned-firms-about-russias-kaspersky-software-day-after-invasion-2022-03-31">report</a> suggested that the US government started warning domestic companies about the potential risks of running Kaspersky software the day after the invasion.</p><p>The US later added the company to the FCC’s blacklist, <a href="https://www.itpro.com/security/antivirus/367227/kaspersky-declared-threat-to-us-national-security" data-original-url="https://www.itpro.com/security/antivirus/367227/kaspersky-declared-threat-to-us-national-security">branding it a national security risk</a>, despite the company officially denouncing the war.</p><p>The UK’s NCSC and Germany’s equivalent agency, the BSI, also both separately <a href="https://www.itpro.com/security/antivirus/367251/ncsc-kaspersky-warning" data-original-url="https://www.itpro.com/security/antivirus/367251/ncsc-kaspersky-warning">advised organisations to avoid using Kaspersky’s products</a>, with the latter <a href="https://www.itpro.com/security/cyber-security/366989/germany-warns-kaspersky-software-cyber-security-risk" data-original-url="https://www.itpro.com/security/cyber-security/366989/germany-warns-kaspersky-software-cyber-security-risk">claiming it could be used to facilitate offensive cyber operations</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Free decryptor released for Conti ransomware variant infecting hundreds of organisations ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/370291/free-decryptor-released-conti-ransomware-variant-infecting-hundreds</link>
                                                                            <description>
                            <![CDATA[ Hundreds of organisations and state institutions are believed to have been impacted by the strain ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iJ3XSJGZjNHgeeAtTq6nHZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9y74aNb3WuKxNCmStPT7Sa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Mar 2023 13:04:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9y74aNb3WuKxNCmStPT7Sa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image showing a red circuit board containing a square chip with a glowing skull etched into it]]></media:description>                                                            <media:text><![CDATA[Abstract image showing a red circuit board containing a square chip with a glowing skull etched into it]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image showing a red circuit board containing a square chip with a glowing skull etched into it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9y74aNb3WuKxNCmStPT7Sa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky has unveiled an updated free decryptor tool to support victims of a modified strain of Conti ransomware. </p><p>The ransomware strain, tracked by some researchers as MeowCorp, is one of several modified strains based on Conti source code leaked in March 2022, and has been used to target a range of companies and state institutions.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370265/rubrik-confirms-data-breach-but-evades-cl0p-ransomware-allegations" data-original-url="/security/ransomware/370265/rubrik-confirms-data-breach-but-evades-cl0p-ransomware-allegations">Rubrik confirms data breach but evades Cl0p ransomware allegations</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370260/ring-no-indication-ransomware-cl0p-claims-attack" data-original-url="/security/ransomware/370260/ring-no-indication-ransomware-cl0p-claims-attack">Ring: 'No indication of ransomware event' after ALPHV claims attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370154/free-mortalkombat-ransomware-decryptor-tool-released-by-bitdefender" data-original-url="/security/ransomware/370154/free-mortalkombat-ransomware-decryptor-tool-released-by-bitdefender">Bitdefender releases free MortalKombat ransomware decryptor tool</a></p></div></div><p>This latest tool was developed following an investigation into a new portion of leaked Conti data published on forums. Analysis of the leak uncovered 258 private keys, source code, and some pre-compiled decryptors, researchers noted. </p><p>“The leaked private keys are located in 257 folders (only one of these folders contains two keys). Some of them contain previously generated decryptors and several ordinary files: documents, photos, etc,” the company said in a <a href="https://usa.kaspersky.com/about/press-releases/2023_kaspersky-releases-tool-for-decrypting-conti-based-ransomware">statement</a> this week. </p><p>“Presumably the latter are test files – a couple of files that the victim sends to the attackers to make sure that the files can be decrypted.” </p><p>Kaspersky said the decryption code and all 258 keys were added to the latest build of its RakhniDecryptor utility. In addition, the tool has been added to Kaspersky’s long-running <em>No Ransom</em> site. </p><h2 id="hundreds-of-organisations-impacted">Hundreds of organisations impacted </h2><p>First observed in 2019, Conti's eponymous <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> strain was among the most prolific throughout 2020, accounting for more than 13% of all ransomware victims across that period. </p><p>When <a href="https://www.itpro.com/security/ransomware/364177/conti-source-code-leaked-by-ukrainian-researcher" data-original-url="https://www.itpro.com/security/ransomware/364177/conti-source-code-leaked-by-ukrainian-researcher">Conti source code was leaked</a> last year, a slew of new modifications and strains emerged and were used to devastating effect by cyber criminal gangs. </p><p>Leaked keys for the MeowCorp variant were uncovered by Kaspersky researchers in December 2022. However, Fedor Sinitsyn, lead malware analyst at Kaspersky, told <em>IT</em> <em>Pro</em> that this strain could have been active for some time. </p><p>"Our research indicates that the private keys were operational between the 13th of November 2022 and the 5th of February 2023, and the last decryptor we identified was on the 9th of February," he said.</p><p>"It is vital that organisations take proactive measures to protect their systems against such attacks, including regular data backups and robust cybersecurity measures."</p><p>The analysis found that 34 folders “explicitly named companies and government agencies” impacted by the strain. </p><p>Sinitsyn said that 257 companies had fallen victim to the ransomware strain, the majority of which have not been disclosed by threat actors.</p><p>"Our analysis reveals that 257 companies have fallen prey to this malicious software, with 34 of the victims/organisations identified by name," he said. "The identities of the remaining 223 victims currently remain concealed by the threat actors."</p><p>The release of this decryptor tool follows a number of similar moves by cyber security companies and government agencies globally. </p><p>Earlier this month, <a href="https://www.itpro.com/security/ransomware/370154/free-mortalkombat-ransomware-decryptor-tool-released-by-bitdefender" data-original-url="https://www.itpro.com/security/ransomware/370154/free-mortalkombat-ransomware-decryptor-tool-released-by-bitdefender">Bitdefender released a free decryption tool</a> for the MortalKombat ransomware strain which has risen to prominence over the last several months. </p><p>Similarly, in February CISA unveiled a recovery script for organisations that have fallen victim to the <a href="https://www.itpro.com/security/cyber-attacks/370005/warning-issued-over-ransomware-attacks-targeting-vmware-esxi-servers" data-original-url="https://www.itpro.com/security/cyber-attacks/370005/warning-issued-over-ransomware-attacks-targeting-vmware-esxi-servers">rampant ESXiArgs ransomware</a> which emerged at the beginning of the month. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'CryWiper' trojan disguises as ransomware, says Kaspersky ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/369633/crywiper-trojan-disguises-as-ransomware-kaspersky</link>
                                                                            <description>
                            <![CDATA[ The destructive wiper mocks up files as if encrypted, while in reality overwriting all but core system files ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dgqqaXAYjFmByeU4WSZ7Fm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4x8LJKuPeaTUDqefPN5aAD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Dec 2022 12:46:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4x8LJKuPeaTUDqefPN5aAD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Toy horse on a digital screen to symbolise the attack of the Trojan virus]]></media:description>                                                            <media:text><![CDATA[Toy horse on a digital screen to symbolise the attack of the Trojan virus]]></media:text>
                                <media:title type="plain"><![CDATA[Toy horse on a digital screen to symbolise the attack of the Trojan virus]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4x8LJKuPeaTUDqefPN5aAD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new wiper trojan, disguised as a ransomware payload, has been discovered in the wild by researchers, raising questions about the reason for its existence and the identity of its operators.</p><p>CryWiper, named for the distinctive ‘.cry’ extension which it appends onto files, appears on first impression to be a new ransomware strain. Victims’ devices are seemingly encrypted and a ransom note is left demanding money be sent to a <a href="https://www.itpro.com/strategy/28296/what-is-bitcoin" data-original-url="https://www.itpro.com/strategy/28296/what-is-bitcoin">bitcoin</a> wallet address. However, the files are actually corrupted beyond recovery.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eNyWocwZkU6AFRW4cbpF2B" name="eNyWocwZkU6AFRW4cbpF2B.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/eNyWocwZkU6AFRW4cbpF2B.png" mos="https://cdn.mos.cms.futurecdn.net/eNyWocwZkU6AFRW4cbpF2B.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Getting board-level buy-in for security strategy</strong></p><p class="fancy-box__body-text">Why cyber security needs to be a board-level issue</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy" data-original-url="/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy">FREE DOWNLOAD</a></p></div></div><p>Kaspersky researchers laid out findings that prove the malware is actually a wiper that corrupts all but the most critical system files, overwriting each with data produced through a pseudo-random number generator. </p><p>Once on a victim’s system, CryWiper sends the name of the victim’s device to a command and control (C2) server, waiting for an activation command to launch an attack.</p><p>This follows a similar methodology to ransomware, with functions performed including the deletion of volume shadow copy to prevent files from being restored and scheduling itself in Windows Task Scheduler to ensure that it restarts every five minutes.</p><p>CryWiper also ceases MS SQL, MySQL, MS Active Directory, and MS Exchange services, so that files associated with them are not prevented from being corrupted.</p><p>Researchers <a href="http://www.kaspersky.com/blog/crywiper-pseudo-ransomware/46480">noted</a> that it disables connection to infected devices through <a href="https://www.itpro.com/mobile/remote-access/368105/what-is-rdp" data-original-url="https://www.itpro.com/mobile/remote-access/368105/what-is-rdp">remote desktop protocol (RDP)</a> too, and posited that this is to frustrate the efforts of security teams responding to the incident.</p><p>This marks a divergence from typical ransomware behaviour, as payloads generally maintain RDP access in order to facilitate lateral attacks across networks.</p><p>A wiper is a <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> strain designed to destroy systems indiscriminately, or otherwise cause chaos and destruction on a victim’s device. Wipers have been widely used in <a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far" data-original-url="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far">Russia’s cyber war against Ukraine</a>, and form part of a malware arsenal that has formed the backbone of the growing <a href="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national" data-original-url="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national">threat against critical national infrastructure (CNI)</a>.</p><p>An email address provided in the ransom text file has been in use since 2017, linking it to several former <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">ransomware families</a>. No conclusive identification has yet been made linking any of the groups.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools" data-original-url="/security/malware/28083/best-free-malware-removal-tools">6 of the best free malware removal tools in 2023</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369506/ransomware-why-do-businesses-still-pay-up" data-original-url="/security/ransomware/369506/ransomware-why-do-businesses-still-pay-up">Ransomware: Why do businesses still pay up?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369328/prestige-ransomware-targets-ukraine-poland-businesses" data-original-url="/security/ransomware/369328/prestige-ransomware-targets-ukraine-poland-businesses">Microsoft warns of 'Prestige' ransomware targeting business in Ukraine, Poland</a></p></div></div><p>In a Russian-language <a href="https://securelist.ru/novyj-troyanec-crywiper/106114">blog post</a> unpacking the technical details of the malware, Kaspersky researchers drew further similarities between CryWiper and another wiper observed attacking public infrastructure in Ukraine earlier this year, known as IsaacWiper.</p><p>Both wipers use the same pseudo-random generator, ‘Mersenne Vortex’, and are the only two to do so due to the relative complexity of the algorithm compared to other options.</p><p>“It’s not common practice, however, deploying destructive payloads that contain ransom notes, with no intention to receive a ransom has been seen before,” said Andy Norton, European cyber risk officer at Armis.</p><p>“<a href="https://www.itpro.com/malware/34381/what-is-notpetya" data-original-url="https://www.itpro.com/malware/34381/what-is-notpetya">NotPetya</a> is an example of a previous wiper attack. Plausible deniability is one reason to add false flags to malware payloads, another tactic is to invent fictitious threat actor groups, such as the 'Cutting Sword of Justice' again with the reason to deflect attribution of the attack.”</p><p>At the time of writing, Kaspersky has only observed targeted CryWiper attacks within the Russian Federation. Given the unknown nature of the group behind CryWiper, as well as the strategic intent of the trojan at this stage, businesses should remain alert to the telltale signs of the payload.</p><p>To avoid compromise, Kaspersky recommends close oversight of remote network connections, the use of <a href="https://www.itpro.com/security/27098/best-vpn-services" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">VPN</a> tunnels for RDP access, as well as strong rather than <a href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">common passwords</a>, and <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication (2FA)</a> where possible.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky finds most effective phishing emails imitate corporate messages, delivery notifications ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/368367/kaspersky-finds-most-effective-phishing-emails-imitate-corporate-messages-delivery-notifications</link>
                                                                            <description>
                            <![CDATA[ Almost one in five employees clicked links in business related emails, but most emails containing threats or promising money were identified as phishing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9Hk9tSQ1JeM49tgUKPgiSS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jQqJ7cTgccfCCohQaaLvBe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Jun 2022 14:49:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jQqJ7cTgccfCCohQaaLvBe-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A fishing hook rests on top of a stack of credit cards, while a padlock sits in the background out of focus]]></media:description>                                                            <media:text><![CDATA[A fishing hook rests on top of a stack of credit cards, while a padlock sits in the background out of focus]]></media:text>
                                <media:title type="plain"><![CDATA[A fishing hook rests on top of a stack of credit cards, while a padlock sits in the background out of focus]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jQqJ7cTgccfCCohQaaLvBe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky Lab has used phishing simulator data in a study that has revealed employees are most likely to click on a phishing link within an email if the subject line and sender appear to relate to work or a missed delivery.</p><p>The most effective phishing email in the study carried the subject line “Failed delivery attempt - Unfortunately, our courier was unable to deliver your item,” with 18.5% of people sent the email clicking the link it provided.</p><p>Using the Kaspersky Security Awareness Platform, system administrators can mimic phishing emails and send them without warning to employees. The results can then be tracked to indicate the level of security awareness amongst employees.</p><p>Other effective subject lines included “Emails not delivered due to overloaded mail servers,” “Online employee survey: What would you improve about working at the company,” and “Reminder: New company-wide dress code,” all of which prompted 17.5-18% of recipients to click their links. The most effective sender names included “Mail delivery service,” “The Google support team,” and “HR Department.”</p><p>Kaspersky’s study was conducted between January 2021 and May 2022 and included the results of over 29,000 employees from 100 countries. With phishing emails behind an <a href="https://www2.deloitte.com/my/en/pages/risk/articles/91-percent-of-all-cyber-attacks-begin-with-a-phishing-email-to-an-unexpected-victim.html">estimated 91%</a> of all cyberattacks, the importance of understanding those campaigns that employees will fall for the easiest cannot be overstated.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas" data-original-url="/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">The rise of phishing as a service (PhaaS) and how to tackle it</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/367737/what-makes-for-the-most-deceptive-phishing-attacks" data-original-url="/security/phishing/367737/what-makes-for-the-most-deceptive-phishing-attacks">What makes for the most deceptive phishing attacks?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" data-original-url="/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">Five giveaways that show an email is a phishing attack</a></p></div></div><p>Conversely, emails that contained threats or promised rewards for clicking links were less likely to prompt clicks with “I hacked your computer and know your search history” and another promising $1,000 only gained 2% and 1% of clicks respectively.</p><p>Educating employees on the <a href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" data-original-url="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">telltale signs</a> of a phishing campaign can be an effective measure against cyberattacks. Communicating the importance of verifying links and sender addresses, checking attachments aren’t executable files, and flagging up any suspected phishing attacks to your company's IT department can greatly improve safety.</p><p>On an administrative level, IT teams should remain vigilant against novel attacks that might circumvent existing security filters. Simulations such as those achievable through Kaspersky Security Awareness Program can provide useful insights into how susceptible employees are to tricks by threat actors.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="d25pnmHteqMFEXehyV5g2n" name="d25pnmHteqMFEXehyV5g2n.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/d25pnmHteqMFEXehyV5g2n.png" mos="https://cdn.mos.cms.futurecdn.net/d25pnmHteqMFEXehyV5g2n.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Securing endpoints amid new threats</strong></p><p class="fancy-box__body-text">Ensuring employees have the flexibility and security to work remotely</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/367650/securing-endpoints-amid-new-threats" data-original-url="/technology/367650/securing-endpoints-amid-new-threats">FREE DOWNLOAD</a></p></div></div><p>“Since the methods used by cybercriminals are constantly changing, the simulation has to reflect up-to-date social engineering trends, alongside common cybercrime scenarios,” stated Elena Molchanova, Head of Security Awareness Business Development at Kaspersky.</p><p>“It is crucial that simulated attacks are carried out regularly and supplemented with appropriate training – so users will develop a strong vigilance skill that will allow them [to] avoid falling for targeted attacks or so-called spear phishing.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky Free review: Effective and lightweight – everything you want from a free antivirus solution ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/antivirus/368179/kaspersky-free-review-effective-and-lightweight-everything-you-want-from</link>
                                                                            <description>
                            <![CDATA[ It’ll be a real shame if politics means people missing out on this top-class security tool ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7YVseFThdABESAaykq8u5S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JaTcpxne5ktuJYFE8JMeS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jun 2022 15:03:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Darien Graham-Smith ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nZP8qH6BDshBkBZo9Kvhbe.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JaTcpxne5ktuJYFE8JMeS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of Kaspersky Free&amp;#039;s main dashboard]]></media:description>                                                            <media:text><![CDATA[A screenshot of Kaspersky Free&amp;#039;s main dashboard]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of Kaspersky Free&amp;#039;s main dashboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JaTcpxne5ktuJYFE8JMeS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky Lab makes no secret of its Russian origins, and in the current climate <a href="https://www.itpro.com/security/cyber-security/367288/is-kaspersky-still-safe-to-use" data-original-url="https://www.itpro.com/security/cyber-security/367288/is-kaspersky-still-safe-to-use">you might be wary of trusting it with your security</a>. In the past few years though the company has taken steps to put its operations beyond reach of the Kremlin: data storage and processing are now handled in Switzerland, while additional “transparency centres” in Brazil, Canada, Malaysia and Spain allow governments and other institutions to review the company’s code and practices.</p><p>There’s no question about Kaspersky’s malware-blocking credentials, though. In the latest independent tests by <a href="https://www.av-comparatives.org">AV-Comparatives.org</a> the Kaspersky engine achieved a superb online protection score of 99.98% – slightly better than <a href="https://www.itpro.com/security/antivirus/361689/microsoft-defender-effective-effortless-protection-for-zero-cost" data-original-url="https://www.itpro.com/security/antivirus/361689/microsoft-defender-effective-effortless-protection-for-zero-cost">Microsoft Defender</a> on 99.96%. It racked up fewer false positives too: against a set of more than 10,000 items, Kaspersky wrongly raised the alarm just twice, while Defender missed the mark five times. <a href="https://www.av-test.org/en">AV-Test.org</a> confirms the engine’s effectiveness: in its tests for January and February 2022, Kaspersky provided impeccable 100% protection against both <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">new “zero-day”</a> and widespread threats.</p><p>The user experience is delightfully clean. Although Kaspersky’s main business is commercial security products, the Kaspersky Free Windows client has no adverts or non-functional buttons – a real breath of fresh air. </p><p>Instead there are just a few buttons for the major functions. From the Home page you can quickly scan your computer for malware and check online to see whether your personal credentials have been compromised; on the Security page you’ll also find buttons to download emergency boot media, and to scan your Windows configuration for suspicious or corrupted settings.</p><p>That may sound a bit minimal, but there’s more going on behind the scenes. Kaspersky Free also quietly takes care of web and email scanning, while the System Watcher component keeps an eye out for <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware" data-original-url="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">ransomware-like behaviour</a> and automatically offers to undo potentially harmful activity. If anything, these components are perhaps a bit <em>too</em> unobtrusive: unless you delve into the program settings you might never realise that they’re enabled. Still, that’s better than AVG’s approach, which puts big fake buttons in its interface purely to tell you that these features <em>aren’t</em> available in the free suite.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JA5nbrycaXyBFeuRc3DVj" name="" alt="A screenshot of Kaspersky Free's performance dashboard" src="https://cdn.mos.cms.futurecdn.net/JA5nbrycaXyBFeuRc3DVj.jpg" mos="https://cdn.mos.cms.futurecdn.net/JA5nbrycaXyBFeuRc3DVj.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/367661/panda-free-antivirus-review-a-free-security-tool-with-a-personality-all" data-original-url="/security/antivirus/367661/panda-free-antivirus-review-a-free-security-tool-with-a-personality-all">Panda Free Antivirus review: A free security tool with a personality all of its own</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/desktop-software/26635/how-to-turn-on-windows-defender" data-original-url="/desktop-software/26635/how-to-turn-on-windows-defender">How to turn on Windows Defender</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/367781/mcafee-appoints-greg-johnson-as-new-ceo" data-original-url="/business-strategy/careers-training/367781/mcafee-appoints-greg-johnson-as-new-ceo">McAfee appoints Greg Johnson as new CEO</a></p></div></div><p>A few other tools are hidden away under Settings. A Privacy Cleaner scans your system for records of recently accessed files, cookies, caches and so forth, while an optional on-screen keyboard helps defeat keyloggers. The resource consumption options let you tweak things like automatic scans, to help minimise battery drain or avoid possible interference with games.</p><p>That’s not a huge issue, as Kaspersky Free is fairly lightweight. In AV-Test.org’s performance tests, it slowed down web browsing on a standard PC by 14% – that’s some way behind Defender’s 5% impact, but better than <a href="https://www.itpro.com/security/antivirus/367693/avast-one-essential-review-a-great-free-antivirus-solution-with-some" data-original-url="https://www.itpro.com/security/antivirus/367693/avast-one-essential-review-a-great-free-antivirus-solution-with-some">Avast One Essential</a> on 17% and well ahead of <a href="https://www.itpro.com/security/cyber-security/355934/avg-antivirus-free-review" data-original-url="https://www.itpro.com/security/cyber-security/355934/avg-antivirus-free-review">AVG AntiVirus Free’s 28%</a>. Similarly, Kaspersky had a 10% impact on application launch speed, versus 6% from Defender and 12% from Avast and AVG.</p><p>One thing that Kaspersky Free lacks is centralised administration; you can connect up to three installations under an individual email address, but it’s not designed to be managed across businesses. Even if you can live with that, it’s understandable if you’re still <a href="https://www.itpro.com/security/antivirus/367251/ncsc-kaspersky-warning" data-original-url="https://www.itpro.com/security/antivirus/367251/ncsc-kaspersky-warning">uncomfortable rolling out a Russian security solution</a>. But with its excellent protection, generous feature set and unobtrusive design, Kaspersky Free has enough going for it to deserve serious consideration.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is Kaspersky still safe to use or does it pose a cyber security threat? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/367288/is-kaspersky-still-safe-to-use</link>
                                                                            <description>
                            <![CDATA[ Western nations have, once again, warned against using the Russian cyber security firm's products, but how reasonable are their claims? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q8pUSzfRrRLzNGg8J7T355</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gVGBMu6JHqBv6rA6dFynFa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Apr 2022 15:37:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gVGBMu6JHqBv6rA6dFynFa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kaspersky Internet Security software]]></media:description>                                                            <media:text><![CDATA[Kaspersky Internet Security software]]></media:text>
                                <media:title type="plain"><![CDATA[Kaspersky Internet Security software]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gVGBMu6JHqBv6rA6dFynFa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky is one of the oldest names in the antivirus game, founded in 1997, but has recently gone through several rounds in the PR boxing ring. This is in no small part due to the geography of its head office – Moscow, Russia. </p><p>Questions around Kaspersky have been raised over the last few years, including whether the firm has ties to the Russian government in any capacity, and whether the products are vulnerable. While these concerns have rumbled for some time, Russia’s invasion of Ukraine has thrown them into the spotlight. </p><p><a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">Cyber security</a> authorities from countries including the UK and the US have lined up in recent days to dissuade businesses from using Kaspersky’s products. This may prompt many organisations into asking whether Kaspersky’s products are, ultimately, safe to use. Arriving at a definitive answer, though, is far from straightforward.</p><h2 id="serious-allegations-severe-real-world-consequences">Serious allegations, severe real-world consequences</h2><p>Since the invasion, Germany, the US, and the UK have all released separate advisories warning businesses of the alleged risks of using <a href="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable" target="_blank" data-original-url="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable">Kaspersky’s products</a>. The perceived heightened risk of Kaspersky, now war has broken out, essentially stems from the legal obligation for Russian-based businesses to comply with requests from the Russian Federal Security Service (FSB). A similar law exists in China and has largely underpinned the West’s discomfort around companies like <a href="https://www.itpro.com/mobile/5g/356451/what-does-the-huawei-ban-mean-for-uk-businesses" target="_blank" data-original-url="https://www.itpro.com/mobile/5g/356451/what-does-the-huawei-ban-mean-for-uk-businesses">Huawei</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable" data-original-url="/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable">Kaspersky Internet Security review: Powerful, highly configurable protection</a></p></div></div><p>Such highly official and serious stances, adopted by several governments in a coordinated manner, are rare, and send an explicit message. Germany <a href="https://www.itpro.com/security/cyber-security/366989/germany-warns-kaspersky-software-cyber-security-risk" data-original-url="https://www.itpro.com/security/cyber-security/366989/germany-warns-kaspersky-software-cyber-security-risk">was the first to go public</a> with its concerns that Kaspersky could be compelled into carrying out <a href="https://www.itpro.com/security/cyber-warfare/361305/counting-the-consequences-of-cyberattacks" target="_blank" data-original-url="https://www.itpro.com/security/cyber-warfare/361305/counting-the-consequences-of-cyberattacks">cyber attacks</a> against Russia’s enemies, at the behest of the Kremlin. Within days, both the US <a href="https://www.itpro.com/security/antivirus/367251/ncsc-kaspersky-warning" data-original-url="https://www.itpro.com/security/antivirus/367251/ncsc-kaspersky-warning">and UK</a> also released their own statements suggesting similar scenarios and warning businesses against using the company’s products. The US went a step further, though, by making Kaspersky the first Russian addition to the FCC’s blacklist, joining the likes of <a href="https://www.itpro.com/infrastructure/network-internet/356299/us-officially-designates-huawei-and-zte-as-national-security" target="_blank" data-original-url="https://www.itpro.com/infrastructure/network-internet/356299/us-officially-designates-huawei-and-zte-as-national-security">Huawei and ZTE</a>, officially <a href="https://www.itpro.com/security/antivirus/367227/kaspersky-declared-threat-to-us-national-security" data-original-url="https://www.itpro.com/security/antivirus/367227/kaspersky-declared-threat-to-us-national-security">branding it a threat to US national security</a>.</p><p>What Kaspersky is most aggrieved with is the lack of evidence each government has presented in its respective advisories. A Kaspersky spokesperson, indeed, <a href="https://www.itpro.com/security/cyber-security/366989/germany-warns-kaspersky-software-cyber-security-risk" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/366989/germany-warns-kaspersky-software-cyber-security-risk">told <em>IT Pro</em> in March</a> these advisories were “not based on any technical assessment of Kaspersky products” and “made on political grounds” – a statement the firm has reiterated since.</p><h2 id="a-history-of-alleged-russian-ties">A history of alleged Russian ties</h2><p>To suggest Kaspersky has been viewed with suspicion in recent years would be an understatement. Despite analyst house Gartner <a href="https://www.nytimes.com/2012/06/04/technology/cyberweapon-warning-from-kaspersky-a-computer-security-expert.html?pagewanted=all" target="_blank">saying in 2012</a> there’s no material evidence to suggest Kaspersky is malicious in its products or behaviours, or has ties to the Russian government, that did little to quell a wave of allegations against the company since.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gSCksczWaVZioTtDeALM4D" name="gSCksczWaVZioTtDeALM4D.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/gSCksczWaVZioTtDeALM4D.png" mos="https://cdn.mos.cms.futurecdn.net/gSCksczWaVZioTtDeALM4D.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Introducing the zero trust edge model for security and network services</strong></p><p class="fancy-box__body-text">Get a better understanding of emerging zero trust solutions</p><p class="fancy-box__body-text">FREE DOWNLOAD</p></div></div><p>The US has been particularly persistent in scrutinising Kaspersky, across several administrations, but it arguably all came to a head in 2017. High-profile US media organisations made a number of serious allegations against the company at the time which set in motion a catastrophic chain of events for Kaspersky.</p><p>Chief among them was the <em>Wall Street Journal</em> <a href="https://www.wsj.com/articles/russian-hackers-stole-nsa-data-on-u-s-cyber-defense-1507222108" target="_blank">alleging</a> in October 2017 the company’s products were used by Russian state-affiliated hackers to steal hacking tools used by an NSA contractor. Kaspersky vehemently denied these allegations, countering with the assertion the NSA contractor in question <a href="https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak" target="_blank" data-original-url="https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak">accidentally leaked their tools to Kaspersky</a> during the course of normal use of its antivirus product.</p><p>Weeks later, the UK’s MI6 expressed concern over Barclays distributing Kaspersky software to more than two million of its online banking customers free of charge. These concerns soon led to Barclays halting its free software initiative, and prompted the NCSC to issue a warning against using Kasperky products at the government level.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/364045/mwc-ukrainian-protesters-call-for-russian-tech-boycott" data-original-url="/security/cyber-warfare/364045/mwc-ukrainian-protesters-call-for-russian-tech-boycott">MWC 2022: Ukrainian protesters call for Russian tech boycott</a></p></div></div><p>Before the year was out, the Trump administration later approved a law banning Kaspersky products across federal and military systems – an order over which Kaspersky unsuccessfully tried to sue the US government.</p><p>The move catalysed a global shift in attitude towards the cyber security company. Following the announcement, Lithuania announced a similar ban, as did the Dutch government six months later. The EU <a href="https://www.europarl.europa.eu/doceo/document/A-8-2018-0189_EN.pdf?redirect" target="_blank">officially branded</a> Kaspersky “malicious” and the company, arguably, has since never managed to shake this onslaught of negative PR. </p><p>Its tainted image also hasn’t been helped by the fact that its CEO, Eugene Kaspersky, was a former member of the Russian military and was also educated by a KGB-sponsored school through which he earned a technical degree.</p><h2 id="what-does-this-mean-for-kaspersky-products">What does this mean for Kaspersky products?</h2><p>With numerous strands to this tale, there’s a lot to unpack. What’s notable is the lack of evidence made public supporting the recent allegations against Kaspersky. Although the claims haven’t been substantiated publicly, governments often withhold such information on national security grounds.</p><p>It might also be argued this situation has been fuelled by longstanding geopolitical tensions between the US and its allies, and the Russian and Chinese governments. Both Kaspersky and <a href="https://www.itpro.com/policy-legislation/33650/huawei-placed-on-trade-blacklist-by-us-gov" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/33650/huawei-placed-on-trade-blacklist-by-us-gov">Huawei were banned by the Trump administration</a> on the basis of alleged ties to the Kremlin and the Chinese state respectively. The principles of these bans were eventually mirrored in domestic laws and initiatives elsewhere. Both the UK and US said Huawei’s infrastructure <a href="https://www.itpro.com/business/policy-legislation/358092/us-telecoms-asked-to-remove-huawei-equipment" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/358092/us-telecoms-asked-to-remove-huawei-equipment">needed to be ripped out</a> to preserve national security, while concerns around Kaspersky, as we’ve mentioned, go back to 2017 when the NCSC warned against using Kaspersky products at the government level – something it recently repeated in <a href="https://www.itpro.com/security/antivirus/367251/ncsc-kaspersky-warning" target="_blank" data-original-url="https://www.itpro.com/security/antivirus/367251/ncsc-kaspersky-warning">March 2022</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/361305/counting-the-consequences-of-cyberattacks" data-original-url="/security/cyber-warfare/361305/counting-the-consequences-of-cyberattacks">Counting the consequences of cyber attacks</a></p></div></div><p>Kaspersky defended itself when the US initially banned it in 2017, but it’s curious it didn’t launch legal action against the <em>Wall Street Journal</em> after the newspaper alleged it stole NSA hacking tools. You could argue that Kaspersky didn’t want to damage its reputation by taking on a well-respected member of the free press, but if the claims were wholly untrue, then you would expect it to follow up in some way on the grounds of defamation.</p><p>Without access to information or intelligence likely held back from the public, it’s difficult to say with certainty if Kaspersky products are safe to use, just as we cannot definitively say Huawei is trustworthy either. Governments, when pressed for proof, have been unwilling to provide it in either case. All we can say is it’s notable many Western governments have united in the calls against using Kaspersky products, although the firm has consistently denied any explicit links to the Russian state.</p><p>The legal obligation to comply with Russian government orders, though, is true – and a significant reason why cyber security agencies are, only now, warning businesses against using it. With more than 400 million users and 240,000 corporate clients, the legal requirement for a cyber security company as prevalent as Kaspersky to comply with Kremlin orders is, indeed, troubling, even if hypothetical or unlikely. Because of this, it might be wise to err on the side of caution.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Germany advises against using Kaspersky software due to hacking risk ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/366989/germany-warns-kaspersky-software-cyber-security-risk</link>
                                                                            <description>
                            <![CDATA[ The Moscow-headquartered cyber security company has a history of being targeted for its alleged links to the Russian state ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7Eu9GkGNHvz9Eb9yyFRxs1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gQazJ4LBT464ds8gqECT7W-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Mar 2022 10:15:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gQazJ4LBT464ds8gqECT7W-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The BSI HQ building in Bonn, Germany]]></media:description>                                                            <media:text><![CDATA[The BSI HQ building in Bonn, Germany]]></media:text>
                                <media:title type="plain"><![CDATA[The BSI HQ building in Bonn, Germany]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gQazJ4LBT464ds8gqECT7W-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Germany’s Federal Office for Information Security (BSI) has warned against using Kaspersky antivirus security products due to the company being headquartered in Russia. </p><p>The BSI said it recommends switching away from any Kaspersky product to another vendor because the company could be forced by the Russian state to carry out <a href="https://www.itpro.com/security/34794/what-threat-do-nation-state-hackers-pose-to-businesses" data-original-url="https://www.itpro.com/security/34794/what-threat-do-nation-state-hackers-pose-to-businesses">offensive cyber operations</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">Kaspersky’s attempt to overturn US government ban thrown out of court <a data-analytics-id="inline-link" href="https://www.itpro.com/antivirus/30983/kaspersky-hits-back-at-twitter-ban-with-open-letter" data-original-url="/antivirus/30983/kaspersky-hits-back-at-twitter-ban-with-open-letter">Kaspersky hits back at Twitter ban with open letter</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31326/kaspersky-halts-all-european-security-projects-in-response-to-eu-ban" data-original-url="/security/31326/kaspersky-halts-all-european-security-projects-in-response-to-eu-ban">Kaspersky halts all European security projects in response to EU ban</a></p></div></div><p>It also said Kaspersky could carry out such offensive operations in cyber space through its own will, can use its own products as a tool in attacks on its own customers, or be spied on without its knowledge. </p><p>Because of these factors, the BSI said there is a “considerable risk of a successful IT attack” as a result of current <a href="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war" data-original-url="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war">conflicts between Russia, the EU, NATO, and Germany</a>. </p><p>It believes organisations that are tied to critical infrastructure or have other special security interests are particularly at risk of attacks linked to Kaspersky’s antivirus software and the BSI will advise any organisation that believes it may be affected.</p><p>“Antivirus software, including the associated real-time capable cloud services, has extensive system authorisations and, due to the system (at least for updates), must maintain a permanent, <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypted</a>, and non-verifiable connection to the manufacturer's servers,” the BSI said in a <a href="https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2022/220315_Kaspersky-Warnung.html">statement</a>. </p><p>“Therefore, trust in the reliability and self-protection of a manufacturer as well as his authentic ability to act is crucial for the safe use of such systems. If there are doubts about the reliability of the manufacturer, virus protection software poses a particular risk for the IT infrastructure to be protected.”</p><p>Kaspersky has denied any allegations that it is linked to the Russian state, or any other government across the globe, saying the BSI’s decision has not been made on the basis of technical analysis of its products.</p><p>“We believe this decision is not based on a technical assessment of Kaspersky products – that we continuously advocated for with the BSI and across Europe – but instead is being made on political grounds,” a Kaspersky spokesperson told <em>IT Pro</em>. “We will continue to assure our partners and customers in the quality and integrity of our products, and we will be working with the BSI for clarification on its decision and for the means to address its and other regulators’ concerns.</p><p>“At Kaspersky, we believe that transparency and the continued implementation of concrete measures to demonstrate our enduring commitment to integrity and trustworthiness to our customers is paramount. Kaspersky is a private global cybersecurity company and, as a private company, does not have any ties to the Russian or any other government.</p><p>“We believe that peaceful dialogue is the only possible instrument for resolving conflicts. War isn’t good for anyone.”</p><h2 id="history-of-persecution">History of persecution</h2><p>This isn’t the first time Kaspersky has been targeted by a country based on its alleged links to the Russian government, claiming that said links compromise its ability to safeguard the national security of countries other than Russia. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tGeTN4mPXPFxbgRdDp4pPW" name="tGeTN4mPXPFxbgRdDp4pPW.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/tGeTN4mPXPFxbgRdDp4pPW.jpg" mos="https://cdn.mos.cms.futurecdn.net/tGeTN4mPXPFxbgRdDp4pPW.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Edge-to-cloud security webinar</strong></p><p class="fancy-box__body-text">Safeguards your IoT devices that require Zero Trust</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/365581/edge-to-cloud-security-webinar" data-original-url="/security/365581/edge-to-cloud-security-webinar">FREE DOWNLOAD</a></p></div></div><p>In 2017, the US accused Kaspersky of being able to surveil its customers, of which the US government was one, leading to its products being banned from use in federal government departments that year. </p><p>Kaspersky said at the time that it believed the decision was not being made on the basis of facts and had its appeals to overturn the ban thrown out of court. The cyber security company also launched a lawsuit against the Trump administration a week after the ban was imposed.</p><p>The UK’s National Cyber Security Centre (NCSC) also followed the US in advising all UK government departments against using Kaspersky security products. The EU labelled the company’s software products as “malicious”, leading to an <a href="https://www.itpro.com/security/31326/kaspersky-halts-all-european-security-projects-in-response-to-eu-ban" data-original-url="https://www.itpro.com/security/31326/kaspersky-halts-all-european-security-projects-in-response-to-eu-ban">EU-wide ban</a>.</p><p>Following the wave of government bans, <a href="https://www.itpro.com/antivirus/30983/kaspersky-hits-back-at-twitter-ban-with-open-letter" data-original-url="https://www.itpro.com/antivirus/30983/kaspersky-hits-back-at-twitter-ban-with-open-letter">Twitter also prevented Kaspersky from placing ads on the social media platform</a>, claiming its business model conflicts with its Twitter Ads business practices. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Products of the Year 2021: The year’s best hardware and software ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hardware/361881/the-it-pro-products-of-the-year-2021-the-years-best-hardware-and-software</link>
                                                                            <description>
                            <![CDATA[ Our pick of the best products from the past 12 months ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">toPW4PztjRHXhnvDGAe3Vr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fFLcnYfeuZediF4PqJmdKA-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 31 Dec 2021 09:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Networks]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/fFLcnYfeuZediF4PqJmdKA-1280-80.png">
                                                            <media:credit><![CDATA[Keumars Afifi-Sabet/IT Pro]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IT Pro Product of the Year Awards 2021]]></media:description>                                                            <media:text><![CDATA[IT Pro Product of the Year Awards 2021]]></media:text>
                                <media:title type="plain"><![CDATA[IT Pro Product of the Year Awards 2021]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fFLcnYfeuZediF4PqJmdKA-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The past twelve months have brought challenges for almost all businesses, but they’ve also brought some terrific products. New generations of servers and appliances have arrived, offering levels of horsepower and capacity that would have seemed outlandish just a few years ago. At the same time, value has continued to climb, bringing new possibilities within reach of an SMB budget.</p><p>There’s been plenty of exciting developments for end users too. Stunning laptops, tablets and phones have turned our heads, along with powerful printers, scanners and screens. And while threats like phishing and ransomware haven’t gone away, the latest generation of security software is here to keep us safe.</p><p>As always, there’s no such thing as a perfect product – every business and every individual will have their own needs and preferences. But we’ve put together our selection of the greatest releases of the past twelve months, to reveal the standout products across a wide range of categories, and to celebrate the manufacturers who’ve driven innovation forward in 2021.</p><h2 id="best-laptop-2021">Best laptop 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="n5ekzj27BkFuHS8eWuu2Ai" name="" alt="LG Gram 17" src="https://cdn.mos.cms.futurecdn.net/n5ekzj27BkFuHS8eWuu2Ai.jpg" mos="https://cdn.mos.cms.futurecdn.net/n5ekzj27BkFuHS8eWuu2Ai.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-lg-gram-17"><span>WINNER: LG Gram 17</span></h3><p>Weighing just 1.35kg, the Gram 17 is barely heavier than many 14in laptops – yet it has a huge, bright 17in display that’s fantastic for productivity and on-the-go presentations.</p><p>There’s plenty of horsepower here too, with an 11th-generation Intel Core i7 processor and 16GB of RAM on board. With nearly 13 hours of battery life it won’t conk out half-way through the day, and a spacious keyboard and trackpad mean it’s also a pleasure to work on for extended periods. Throw in Thunderbolt 4 and Wi-Fi 6 and you have an excellent do-it-all, go-anywhere computer for a very reasonable £1,599 exc VAT.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/laptops/359449/lg-gram-17-review-slim-and-sophisticated" data-original-url="https://www.itpro.com/hardware/laptops/359449/lg-gram-17-review-slim-and-sophisticated">LG Gram 17 review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hEr7oSf3KPynR2db7vDgAg" name="" alt="The Razer Book 13 front view" src="https://cdn.mos.cms.futurecdn.net/hEr7oSf3KPynR2db7vDgAg.jpg" mos="https://cdn.mos.cms.futurecdn.net/hEr7oSf3KPynR2db7vDgAg.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Keumars Afifi-Sabet/IT Pro)</span></figcaption></figure><h3 class="article-body__section" id="section-highly-commended-razer-book-13"><span>HIGHLY COMMENDED: Razer Book 13</span></h3><p>Razer made its name with gaming laptops, but the company’s first business-friendly model is a big hit. It looks stylish yet serious, with a superb screen that challenges the MacBook Pro for brightness and colour quality. Performance is top-notch too, thanks to an Intel Core i7-1165G7 processor, and there’s a great selection of ports, including full-sized USB and HDMI connectors. At 1.4kg it’s a little weighty for a 13in laptop, but overall it’s a great, capable choice for an everyday working companion.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/laptops/359288/razer-book-13-review-taking-on-the-big-guns" data-original-url="https://www.itpro.com/hardware/laptops/359288/razer-book-13-review-taking-on-the-big-guns">Razer Book 13 review</a></strong></em></p><h2 id="best-chromebook-2021">Best Chromebook 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="AFpm85oNDCFf4kLvfXpQWZ" name="" alt="A photograph of the Acer Chromebook Spin 713 in presentation mode" src="https://cdn.mos.cms.futurecdn.net/AFpm85oNDCFf4kLvfXpQWZ.jpg" mos="https://cdn.mos.cms.futurecdn.net/AFpm85oNDCFf4kLvfXpQWZ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-acer-chromebook-spin-713"><span>WINNER: Acer Chromebook Spin 713</span></h3><p>There are plenty of sub-£500 Chromebooks on the market, but Acer’s Chromebook Spin 713 feels like something much more expensive. Its 13.5in QHD screen has a comfortable 3:2 aspect ratio, and it flips all the way around so you can work in laptop, stand or tablet mode. Unusually, there’s an HDMI output too, giving you additional working options.</p><p>Wi-Fi 6 and Bluetooth 5 round out the feature set, and with a total weight of just 1.2kg the Spin 713 is deliciously portable too. It would have been nice if Acer had given that beautiful screen an anti-glare coating, but when the rest of the package is this good we can live with a few reflections.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/laptops/360016/acer-chromebook-spin-713-review-a-high-end-package-with-a-budget-price" data-original-url="https://www.itpro.com/hardware/laptops/360016/acer-chromebook-spin-713-review-a-high-end-package-with-a-budget-price">Acer Chromebook Spin review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="p4bHBnpLkge6x6UrxznS75" name="" alt="The Lenovo IdeaPad Flex 5 Chromebook" src="https://cdn.mos.cms.futurecdn.net/p4bHBnpLkge6x6UrxznS75.jpg" mos="https://cdn.mos.cms.futurecdn.net/p4bHBnpLkge6x6UrxznS75.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-lenovo-ideapad-flex-5"><span>HIGHLY COMMENDED: Lenovo IdeaPad Flex 5</span></h3><p>The Flex 5 is another Chromebook with a 360º-rotating screen, though its 16:9 aspect ratio is best suited to conventional laptop-style usage. It’s slimmer and lighter than the Acer Spin 713, and its bright display is less reflective. Connectivity is well covered with both USB Type-A and Type-C ports, along with Wi-Fi 6; if you’re looking for a no-nonsense Chrome OS workhorse, you won’t be disappointed.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/laptops/360057/lenovo-ideapad-flex-5-chromebook-review-a-dependable-workhorse" data-original-url="https://www.itpro.com/hardware/laptops/360057/lenovo-ideapad-flex-5-chromebook-review-a-dependable-workhorse">Lenovo IdeaPad Flex 5 review</a></strong></em></p><h2 id="best-tablet-2021">Best tablet 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rXfG5769dJSR8tHg229Zhg" name="" alt="A photograph of the 12.9in Apple iPad Pro on table with some plants" src="https://cdn.mos.cms.futurecdn.net/rXfG5769dJSR8tHg229Zhg.jpg" mos="https://cdn.mos.cms.futurecdn.net/rXfG5769dJSR8tHg229Zhg.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-apple-ipad-pro-12-9in"><span>WINNER: Apple iPad Pro 12.9in</span></h3><p>With Apple’s mighty M1 processor, the iPad Pro is fully as powerful as a MacBook Pro. And it has several advantages over the laptop: at 680g it’s less than half the weight, and the touchscreen makes for a slick, tactile experience. The 120Hz mini-LED display is stunning, and a battery life of around 13 and a half hours means you can keep working all through the day and beyond.</p><p>No doubt, the 12.9in format is bulky for a tablet, while the optional keyboard pushes up the weight – and the price, which is already steep at £916 exc VAT for the base model. Even so, this is unquestionably the best tablet on the market: it doesn’t just excel at tablet tasks, it redefines what a tablet can do.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/tablets/361463/apple-ipad-pro-129in-2021-review-a-giant-leap-for-apple-silicon" data-original-url="https://www.itpro.com/hardware/tablets/361463/apple-ipad-pro-129in-2021-review-a-giant-leap-for-apple-silicon">Apple iPad Pro 12.9in review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LAnrB5XpQSofRYiyKsmmpE" name="" alt="A photograph of the Nokia T20 standing up on a table" src="https://cdn.mos.cms.futurecdn.net/LAnrB5XpQSofRYiyKsmmpE.jpg" mos="https://cdn.mos.cms.futurecdn.net/LAnrB5XpQSofRYiyKsmmpE.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-nokia-t20"><span>HIGHLY COMMENDED: Nokia T20</span></h3><p>It’s short on flashy gimmicks, but Nokia’s T20 feels like a professional tablet. The aluminium build is strong and sturdy, performance and features are up to par, and while we felt the 10.4in screen looked a little cold, its 5:3 aspect ratio is very comfortable to work on. The most impressive part is the price – just £150 exc VAT for the Wi-Fi 5 edition, or £167 exc VAT for the LTE model.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/tablets/361736/nokia-t20-review-a-simple-sturdy-android-tablet-at-an-smb-friendly-price" data-original-url="https://www.itpro.com/hardware/tablets/361736/nokia-t20-review-a-simple-sturdy-android-tablet-at-an-smb-friendly-price">Nokia T20 review</a></strong></em></p><h2 id="best-smartphone-2021">Best smartphone 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZeHBHn7BP4mEyj6b8sjCf8" name="" alt="A photograph of the Apple iPhone 13 standing against a white background" src="https://cdn.mos.cms.futurecdn.net/ZeHBHn7BP4mEyj6b8sjCf8.jpg" mos="https://cdn.mos.cms.futurecdn.net/ZeHBHn7BP4mEyj6b8sjCf8.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Bobby Hellard/Future)</span></figcaption></figure><h3 class="article-body__section" id="section-winner-apple-iphone-13"><span>WINNER: Apple iPhone 13</span></h3><p>The iPhone 13 improves on last year’s iPhone 12 models with better cameras and a bigger battery, adding nearly two hours of daily performance in our tests. You get more storage in the standard model too, up from 64GB to 128GB, and the latest Apple A15 Bionic CPU for true Android-smashing performance.</p><p>All the usual iPhone strengths are here, including an excellent screen and a vast library of high-quality apps for work or play. It’s hardly an adventurous update from the iPhone 12, but if you’re choosing a new smartphone today – and aren’t already enmeshed in the Android ecosystem – then the iPhone 13 is the obvious choice.</p><p><em><strong>Read our full <a href="https://www.itpro.com/mobile/mobile-phones/361428/apple-iphone-13-review" data-original-url="https://www.itpro.com/mobile/mobile-phones/361428/apple-iphone-13-review">Apple iPhone 13 review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="V4i2AftiV8cg3rsnmcRKu" name="" alt="OnePlus 9 Pro smartphone" src="https://cdn.mos.cms.futurecdn.net/V4i2AftiV8cg3rsnmcRKu.jpg" mos="https://cdn.mos.cms.futurecdn.net/V4i2AftiV8cg3rsnmcRKu.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-oneplus-9-pro"><span>HIGHLY COMMENDED: OnePlus 9 Pro</span></h3><p>Standing 163mm tall, the OnePlus 9 Pro is large, but it’s perhaps the most beautiful Android smartphone we’ve seen, with a tiny bezel and beautifully textured case. Its 120Hz AMOLED display is a joy to behold, and a collaboration with Hasselblad ensures excellent photo and video quality. Performance is very strong too, courtesy of a top-tier Snapdragon 888 processor; at £829 exc VAT it’s not a budget option, but you get what you pay for.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/359792/oneplus-9-pro-review-an-instant-cult-classic" data-original-url="https://www.itpro.com/hardware/359792/oneplus-9-pro-review-an-instant-cult-classic">OnePlus 9 Pro review</a></strong></em></p><h2 id="best-desktop-server-2021">Best desktop server 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ajJKrfg9ebt9d2K7dPSsuS" name="" alt="HPE MicroServer Gen10 Plus front and rear" src="https://cdn.mos.cms.futurecdn.net/ajJKrfg9ebt9d2K7dPSsuS.jpg" mos="https://cdn.mos.cms.futurecdn.net/ajJKrfg9ebt9d2K7dPSsuS.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-hpe-proliant-microserver-gen10-plus"><span>WINNER: HPE ProLiant MicroServer Gen10 Plus</span></h3><p>The MicroServer Gen10 Plus really can fit happily on a desktop, as its square chassis measures a mere 245mm along each side. Yet it’s powerful enough to run a wide range of business services, with your choice of a dual-core 3.8GHz Pentium Gold G5420 CPU or a quad-core 3.4GHz Xeon E-2224. Four integrated LFF SATA drive bays allow for plenty of storage.</p><p>The small size means there’s not much scope for internal expansion, but you do get a single PCI-E x16 slot, and remote management can be added via the cheap iLO5 enablement kit. With the entry-level diskless system starting at just £395 exc VAT, it’s an excellent SMB-friendly deal.</p><p><em><strong>Read our full <a href="https://www.itpro.com/infrastructure/server-storage/358198/hpe-proliant-microserver-gen10-plus-review-pint-sized" data-original-url="https://www.itpro.com/infrastructure/server-storage/358198/hpe-proliant-microserver-gen10-plus-review-pint-sized">HPE ProLiant MicroServer Gen10 Plus review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dzomLTUuXSzPATGmMZRWcA" name="" alt="A photograph of the front and rear of the Dell EMC PowerEdge T550" src="https://cdn.mos.cms.futurecdn.net/dzomLTUuXSzPATGmMZRWcA.jpg" mos="https://cdn.mos.cms.futurecdn.net/dzomLTUuXSzPATGmMZRWcA.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-dell-emc-poweredge-t550"><span>HIGHLY COMMENDED: Dell EMC PowerEdge T550</span></h3><p>The T550 is a real “tower of power” – we tested it with a 12-core 2.1GHz Xeon Silver 4310 CPU, but if you need more grunt it can handle twin CPUs with up to 32 cores each. It also supports up to 24 SFF or eight LFF drives, and a maximum of 1TB of DDR4 RAM. Dell’s comprehensive iDRAC9 remote management platform comes as standard, making this an ideal answer to demanding workloads.</p><p><em><strong>Read our full <a href="https://www.itpro.com/infrastructure/server-storage/361505/dell-emc-poweredge-t550-review-power-to-the-people" data-original-url="https://www.itpro.com/infrastructure/server-storage/361505/dell-emc-poweredge-t550-review-power-to-the-people">Dell EMC PowerEdge T550 review</a></strong></em></p><h2 id="best-1u-server-2021">Best 1U server 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nP4JqwijA3fNPS7ThV759i" name="" alt="A photograph of the Dell EMC PowerEdge R650" src="https://cdn.mos.cms.futurecdn.net/nP4JqwijA3fNPS7ThV759i.jpg" mos="https://cdn.mos.cms.futurecdn.net/nP4JqwijA3fNPS7ThV759i.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-dell-emc-poweredge-r650"><span>WINNER: Dell EMC PowerEdge R650</span></h3><p>Dell’s latest PowerEdge R650 design crams an amazing amount of potential into a 1U chassis. It supports Xeon Scalable CPUs with up to 40 cores and a massive 4TB of memory, with space inside for up to ten SFF drives and 16 Intel Optane modules to accelerate performance.</p><p>If that’s not enough, you also get three PCI-E Gen4 x16 slots and an OCP 3.0 edge slot, plus Dell’s BOSS card for fast booting from SSD media. And as usual with Dell, the iDRAC9 controller provides terrific remote management. It’s not a budget option – our review unit came to £15,417 exc VAT – but the PowerEdge R650 is an incredibly powerful and space-efficient server.</p><p><em><strong>Read our</strong></em> <em><strong>full <a href="https://www.itpro.com/infrastructure/server-storage/361379/dell-emc-poweredge-r650-review-a-slim-and-mighty-server" data-original-url="https://www.itpro.com/infrastructure/server-storage/361379/dell-emc-poweredge-r650-review-a-slim-and-mighty-server">Dell EMC PowerEdge R650 review</a></strong></em></p><h3 class="article-body__section" id="section-highly-commended-broadberry-cyberserve-xeon"><span>HIGHLY COMMENDED: Broadberry CyberServe Xeon</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JjqLzWqHp3FUrMojVcPBBM" name="" alt="Broadberry CyberServe Xeon E-RS100-E10 front and rear" src="https://cdn.mos.cms.futurecdn.net/JjqLzWqHp3FUrMojVcPBBM.jpg" mos="https://cdn.mos.cms.futurecdn.net/JjqLzWqHp3FUrMojVcPBBM.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>This low-profile server offers a solid chunk of power for just under £1,000. That gets you a quad-core Intel Xeon E-2224 CPU with 16GB of RAM – upgradeable to 128GB – and you’re free to fit your own drives in the four SFF bays and twin M.2 SSD slots. The single PCI-E Gen3 x16 slot can be used to add 10GbE networking, and the Asus motherboard supports web-based management, including full OS remote control and virtual media services as standard.</p><p><em><strong>Read our full <a href="https://www.itpro.com/infrastructure/server-storage/358798/broadberry-cyberserve-xeon-e-rs100-e10-review-a-cracking" data-original-url="https://www.itpro.com/infrastructure/server-storage/358798/broadberry-cyberserve-xeon-e-rs100-e10-review-a-cracking">Broadberry CyberServe Xeon E-RS100-E10 review</a></strong></em></p><h2 id="best-2u-server-2021">Best 2U server 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="A5cATCdywU9gM53RyE6wf5" name="" alt="A photograph of the Broadberry CyberServe SP2 208-8I G3" src="https://cdn.mos.cms.futurecdn.net/A5cATCdywU9gM53RyE6wf5.jpg" mos="https://cdn.mos.cms.futurecdn.net/A5cATCdywU9gM53RyE6wf5.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-broadberry-cyberserve-sp2-208-8i-g3"><span>WINNER: Broadberry CyberServe SP2 208-8I G3</span></h3><p>The CyberServe SP2 208-8I G3 is designed for a hardcore server role. The system we tested came with a pair of 36-core Xeon Scalable Platinum CPUs, 512GB of DDR4 RAM, five 960GB SATA SSDs and eight 128GB Intel Optane PMEM 200 modules. This allows for insanely fast storage access – and to help you make the most of it, the system comes with not one but two dual-port Intel 100GbE network cards.</p><p>You can upgrade even further by going up to 26 SFF drives in total, plus eight NVMe drives, and the spacious 2U design allows for six free PCI-E Gen4 slots. It’s a magnificent hardware package, and while the £21,895 price tag won’t be within everyone’s budget, it’s superb value for what you get.</p><p><em><strong>Read our full <a href="https://www.itpro.com/infrastructure/server-storage/360442/broadberry-cyberserve-sp2-208-8i-g3-review-optane-a-gogo" data-original-url="https://www.itpro.com/infrastructure/server-storage/360442/broadberry-cyberserve-sp2-208-8i-g3-review-optane-a-gogo">Broadberry CyberServe SP2 208-8I G3 review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LZuQSY9iT93kVmEphmKHg6" name="" alt="Dell EMC PowerEdge R750" src="https://cdn.mos.cms.futurecdn.net/LZuQSY9iT93kVmEphmKHg6.jpg" mos="https://cdn.mos.cms.futurecdn.net/LZuQSY9iT93kVmEphmKHg6.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-dell-emc-poweredge-r750"><span>HIGHLY COMMENDED: Dell EMC PowerEdge R750 </span></h3><p>Dell’s PowerEdge R750 comes in three versions – the R750xa is built for GPU-based workloads, while the R750xs is a cost-optimised version aimed at specific roles. The standard R750 is a great all-rounder though: the configuration we tested offered two 28-core 2GHz Xeon Scalable Gold 6330 CPUs and 1TB of RAM, upgradeable to a whopping 8TB using 256GB DIMMs. For storage you can choose between a 12-bay LFF backplane or a 16-bay SFF one, and add up to 24 NVMe SSDs. In short, there’s enough power and flexibility here for any business.</p><p><em><strong>Read our full <a href="https://www.itpro.com/infrastructure/server-storage/359410/dell-emc-poweredge-r750-review-a-third-gen-xeon-scalable" data-original-url="https://www.itpro.com/infrastructure/server-storage/359410/dell-emc-poweredge-r750-review-a-third-gen-xeon-scalable">Dell EMC PowerEdge R750 review</a></strong></em></p><h2 id="best-storage-array-2021">Best storage array 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hGcbyak3sfv84GF6zADJPa" name="" alt="HPE MSA 2060 Storage" src="https://cdn.mos.cms.futurecdn.net/hGcbyak3sfv84GF6zADJPa.jpg" mos="https://cdn.mos.cms.futurecdn.net/hGcbyak3sfv84GF6zADJPa.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-hpe-msa-2060-storage"><span>WINNER: HPE MSA 2060 Storage</span></h3><p>With numerous hardware upgrades over the last generation, this is HPE’s fastest dedicated storage array ever. It’s also laden with powerful features: thin provisioning, snapshots and volume copies are all supported, along with striped SSD caches, RAID10, 5 and 6 options and HPE’s own MSA-DP+ array format, designed for improved performance and faster rebuild times.</p><p>The MSA 2060 even offers zero-configuration data tiering, automatically shunting data between regular SAS drives, fast solid-state storage and low-priority ML-SAS volumes according to usage. And it’s all configured and managed from a simple web portal, so there’s no need to be a storage expert to get the best from it.</p><p><em><strong>Read our full <a href="https://www.itpro.com/infrastructure/server-storage/358765/hpe-msa-2060-storage-review-storage-tiering-for-dummies" data-original-url="https://www.itpro.com/infrastructure/server-storage/358765/hpe-msa-2060-storage-review-storage-tiering-for-dummies">HPE MSA 2060 Storage review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="cvpHBtHNxm4abWfZtZh67b" name="" alt="A photograph of the Qnap TS-h2490FU QuTS hero edition" src="https://cdn.mos.cms.futurecdn.net/cvpHBtHNxm4abWfZtZh67b.jpg" mos="https://cdn.mos.cms.futurecdn.net/cvpHBtHNxm4abWfZtZh67b.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-qnap-ts-h2490fu-quts-hero-edition"><span>HIGHLY COMMENDED: Qnap TS-h2490FU QuTS Hero Edition</span></h3><p>When performance is a priority, pure NVMe storage is the way to go. This impressive appliance can take up to 24 hot-plug U.2 drives, while Qnap’s 128-bit ZFS-based OS provides enterprise-class data integrity, with compression and deduplication options provided as standard. It’s all based on a powerful AMD EPYC processor, and it comes with a pair of dual-port 25GbE network cards, to ensure you can get the full performance from your storage.</p><p><em><strong>Read our full <a href="https://www.itpro.com/server-storage/network-attached-storage-nas/359573/qnap-ts-h2490fu-quts-hero-edition-review-smash" data-original-url="https://www.itpro.com/server-storage/network-attached-storage-nas/359573/qnap-ts-h2490fu-quts-hero-edition-review-smash">Qnap TS-h2490FU QuTS Hero Edition review</a></strong></em></p><h2 id="best-nas-drive-2021">Best NAS drive 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rmLT3wZG8jv7CfrAWBdiEV" name="" alt="The Qnap TS-h973AX" src="https://cdn.mos.cms.futurecdn.net/rmLT3wZG8jv7CfrAWBdiEV.jpg" mos="https://cdn.mos.cms.futurecdn.net/rmLT3wZG8jv7CfrAWBdiEV.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-qnap-ts-h973ax"><span>WINNER: Qnap TS-h973AX</span></h3><p>Though it looks unassuming, Qnap’s TS-h973AX runs the company’s advanced QuTS hero OS, which offers an impressive range of native storage features. Those include fast, near-unlimited snapshots, transparent self-healing of data corruption and inline data deduplication and compression to make the most efficient use of your storage. Five LFF SATA bays plus four SFF bays provide plenty of room for expansion, while 10GbE and twin 2.5GbE network ports provide high-speed connections to the outside world.</p><p>In our tests the TS-h973AX provided fast read and write speeds, and there’s a whole library of apps to expand its capabilities, including backup and virtualisation tools. Costing just over £1,000 exc VAT for the diskless enclosure, it’s well within reach of smaller businesses.</p><p><em><strong>Read our full <a href="https://www.itpro.com/server-storage/network-attached-storage-nas/359766/qnap-ts-h973ax-review-our-top-choice-desktop-nas" data-original-url="https://www.itpro.com/server-storage/network-attached-storage-nas/359766/qnap-ts-h973ax-review-our-top-choice-desktop-nas">Qnap TS-h973AX review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="E4D2DMuj8mBzoZEq3cP2Ef" name="" alt="A photograph of the Qnap TS-873A" src="https://cdn.mos.cms.futurecdn.net/E4D2DMuj8mBzoZEq3cP2Ef.jpg" mos="https://cdn.mos.cms.futurecdn.net/E4D2DMuj8mBzoZEq3cP2Ef.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-qnap-ts-873a"><span>HIGHLY COMMENDED: Qnap TS-873A</span></h3><p>Looking for a simple storage solution? The eight-bay TS-873A makes a great platform for Qnap’s lightweight, simple to manage QTS OS. Alternatively, for more advanced data-protection functions you can install the full QuTS hero OS and make use of all the same features as the TS-h973AX, above. Either way, it’ll run the full range of Qnap apps, and dual 2.5GbE ports help keep data flowing swiftly in and out.</p><p><em><strong>Read our full <a href="https://www.itpro.com/server-storage/network-attached-storage-nas/360351/qnap-ts-873a-review-a-supremely-versatile" data-original-url="https://www.itpro.com/server-storage/network-attached-storage-nas/360351/qnap-ts-873a-review-a-supremely-versatile">Qnap TS-873A review</a></strong></em></p><h2 id="best-printer-2021">Best printer 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2C5hu6dGJn7jYZg35bpg9a" name="" alt="A photograph of the Epson EcoTank ET-5880" src="https://cdn.mos.cms.futurecdn.net/2C5hu6dGJn7jYZg35bpg9a.jpg" mos="https://cdn.mos.cms.futurecdn.net/2C5hu6dGJn7jYZg35bpg9a.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-epson-ecotank-et-5880"><span>WINNER: Epson EcoTank ET-5880</span></h3><p>Forget about overpriced cartridges – this A4 MFP uses bottled ink that works out to just 0.2p per mono page and 0.8p for colour. That alone will make it attractive to busy offices, but the ET-5880 has other strengths too, including a swish 10.9cm touchscreen, 802.11n wireless connectivity and excellent colour output. It comes with a pair of 250-sheet paper cassettes, so you won’t be continually restocking it, and the integrated scanner has its own 50-page duplex ADF.</p><p>The one caveat is a print speed of 25ppm in standard quality mode: that’s not exactly slow, but it’s unexceptional for a modern office printer. Even so, the Epson’s user-friendliness and phenomenally low running costs make it our top choice for 2021.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/peripherals/360489/epson-ecotank-et-5880-review-phenomenally-low-running-costs" data-original-url="https://www.itpro.com/hardware/peripherals/360489/epson-ecotank-et-5880-review-phenomenally-low-running-costs">Epson EcoTank ET-5880 review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="vkJ27eixRPDnpGLJxFiTtC" name="" alt="A photograph of the Kyocera Ecosys M6235cidn" src="https://cdn.mos.cms.futurecdn.net/vkJ27eixRPDnpGLJxFiTtC.jpg" mos="https://cdn.mos.cms.futurecdn.net/vkJ27eixRPDnpGLJxFiTtC.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-kyocera-ecosys"><span>HIGHLY COMMENDED: Kyocera Ecosys</span></h3><p>This freestanding laser MFP won’t suit the smallest offices, but it offers a 35ppm print speed and a wide range of downloadable apps to extend its printing and scanning functions. It’s easy to operate, with a big 7in touchscreen, a range of mobile apps and a clear web-based management console. The clincher is the price: the basic model with wired networking and a single 250-page sheet feeder costs just £696 exc VAT, and low-cost consumables work out to a very reasonable 1p per mono page.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/peripherals/360559/kyocera-ecosys-m6235cidn-review-worth-splashing-out-on" data-original-url="https://www.itpro.com/hardware/peripherals/360559/kyocera-ecosys-m6235cidn-review-worth-splashing-out-on">Kyocera Ecosys M6235cidn review</a></strong></em></p><h2 id="best-scanner-2021">Best scanner 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ycDrKkgsvj9ZQJTVSsvuGL" name="" alt="A photograph of the Fujitsu ScanSnap iX1600" src="https://cdn.mos.cms.futurecdn.net/ycDrKkgsvj9ZQJTVSsvuGL.jpg" mos="https://cdn.mos.cms.futurecdn.net/ycDrKkgsvj9ZQJTVSsvuGL.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-fujitsu-scansnap-ix1600"><span>WINNER: Fujitsu ScanSnap iX1600</span></h3><p>This desktop scanner has a great set of features, including integrated Wi-Fi, a 50-sheet ADF, double-sided scanning and a 4.3in colour touchscreen. It’s fast too: we were impressed to see it rip through our pile of test documents at 43ppm, creating 200dpi scans that were perfectly clear and clean enough for OCR and archival.</p><p>Even better, this hardware is partnered by one of the best software suites around. You can scan to a huge range of applications and cloud services, send scans directly to an email address or beam them to a mobile device. For anyone who needs to scan and share documents in a digital or cloud-first environment, the Fujitsu ScanSnap iX1600 is a terrific choice.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/peripherals/360909/fujitsu-scansnap-ix1600-review-unparalleled-cloud-support" data-original-url="https://www.itpro.com/hardware/peripherals/360909/fujitsu-scansnap-ix1600-review-unparalleled-cloud-support">Fujitsu ScanSnap iX1600 review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JBAkJtk47CLnAGsxDdprgK" name="" alt="Canon imageFormula DR-S130 angled view" src="https://cdn.mos.cms.futurecdn.net/JBAkJtk47CLnAGsxDdprgK.jpg" mos="https://cdn.mos.cms.futurecdn.net/JBAkJtk47CLnAGsxDdprgK.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-canon-imageformula-dr-s130"><span>HIGHLY COMMENDED: Canon imageFormula DR-S130</span></h3><p>With its output tray folded away the DR-S130 takes up barely any more desk space than a sheet of A4. Yet it scans at a swift 30ppm, and thanks to Canon’s CaptureOnTouch V4 Pro software it can perform all the same scan functions as much pricier, bulkier models. You can set up profiles for different job types, run single- and double-sided scans, perform OCR and save the output in your choice of format and location. The only thing it can’t do is scan directly to cloud services, but for most individuals and SMBs it’ll fit the bill admirably.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/peripherals/358607/canon-imageformula-dr-s130-review-a-great-choice-for-remote-workers" data-original-url="https://www.itpro.com/hardware/peripherals/358607/canon-imageformula-dr-s130-review-a-great-choice-for-remote-workers">Canon imageFormula DR-S130 review</a></strong></em></p><h2 id="best-monitor-2021">Best monitor 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kYiAHzPtXj7Gck9rUuNEig" name="" alt="Dell UltraSharp 25 USB-C monitor" src="https://cdn.mos.cms.futurecdn.net/kYiAHzPtXj7Gck9rUuNEig.jpg" mos="https://cdn.mos.cms.futurecdn.net/kYiAHzPtXj7Gck9rUuNEig.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-dell-ultrasharp-25-usb-c"><span>WINNER: Dell UltraSharp 25 USB-C</span></h3><p>We don’t see a lot of 25in monitors, but the format works well for desktop productivity, and the Dell UltraSharp lives up to its name with a crisp 2,560 x 1,440 resolution. It also delivers excellent coverage of both the sRGB and DCI-P3 colour spaces, with an HDR400 certification for extended-range colour.</p><p>The final trump card is connectivity: the USB Type-C connector can handle both incoming video and outgoing power, so you can hook your laptop up to the big screen and charge it at the same time. It’s also possible to daisy-chain a second display via the DisplayPort connector, or to swivel the panel round through 90º and work in portrait mode. In short, it’s one of the cleverest monitors we’ve seen.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/monitors/361686/dell-ultrasharp-25-usb-c-review-a-cut-above" data-original-url="https://www.itpro.com/hardware/monitors/361686/dell-ultrasharp-25-usb-c-review-a-cut-above">Dell UltraSharp 25 USB-C review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="S4NEx95ZkrzyG35GATAjdb" name="" alt="Acer ConceptD CP5271UV" src="https://cdn.mos.cms.futurecdn.net/S4NEx95ZkrzyG35GATAjdb.jpg" mos="https://cdn.mos.cms.futurecdn.net/S4NEx95ZkrzyG35GATAjdb.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-acer-conceptd-cp5271uv"><span>HIGHLY COMMENDED: Acer ConceptD CP5271UV</span></h3><p>The CP5271UV is an exceptionally versatile monitor. It offers custom display modes for print editing, video and games, and also supports high-end features including HDR600 for deep-colour content, dynamic refresh rates up to 170Hz and an incandescent peak brightness of 480cd/m2. It makes a great office monitor too, with integrated gigabit Ethernet and four USB 3.1 ports. At £667 exc VAT it’s considerably more expensive than your typical desktop display, but if you're in the market for a high-end screen it’s a steal.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/monitors/359177/acer-conceptd-cp5271uv-review-a-great-value-buy" data-original-url="https://www.itpro.com/hardware/monitors/359177/acer-conceptd-cp5271uv-review-a-great-value-buy">Acer ConceptD CP5271UV review</a></strong></em></p><h2 id="best-endpoint-security-suite-2021">Best endpoint security suite 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DN7YMQWkKGScDFqVLfGXhh" name="" alt="Sophos Intercept X Advanced screenshot" src="https://cdn.mos.cms.futurecdn.net/DN7YMQWkKGScDFqVLfGXhh.png" mos="https://cdn.mos.cms.futurecdn.net/DN7YMQWkKGScDFqVLfGXhh.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-sophos-intercept-x-advanced"><span>WINNER: Sophos Intercept X Advanced</span></h3><p>There’s a lot of hype around artificial intelligence, but it does have real applications: Sophos’ Intercept X suite uses machine-learning techniques to recognise malware and neutralise zero-day threats. It also includes a full range of traditional protections, defeating ransomware by intercepting encryption attacks and silently restoring the original file, and preventing data leaks by blocking the transmission of certain types of information.</p><p>The Advanced subscription adds an analysis centre, where you can forensically review attempted attacks, allowing you to identify and plug the gaps in your armour. It’s easy to deploy and manage too: a central web console lets you email out installer links to all clients, and then administer policies and settings for the whole site.</p><p><em><strong>Read our full <a href="https://www.itpro.com/security/endpoint-security/361685/sophos-intercept-x-advanced-review-ai-powered-protection" data-original-url="https://www.itpro.com/security/endpoint-security/361685/sophos-intercept-x-advanced-review-ai-powered-protection">Sophos Intercept X Advanced review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sjU4CWxujUtVPZS4tA7a9e" name="" alt="A screenshot of Kaspersky Endpoint Security Cloud Plus" src="https://cdn.mos.cms.futurecdn.net/sjU4CWxujUtVPZS4tA7a9e.jpg" mos="https://cdn.mos.cms.futurecdn.net/sjU4CWxujUtVPZS4tA7a9e.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-kaspersky-endpoint-security-cloud-plus"><span>HIGHLY COMMENDED: Kaspersky Endpoint Security Cloud Plus</span></h3><p>Kaspersky’s highly flexible licensing lets you protect workstations, laptops, servers and mobile devices all within a single subscription. As well as blocking viruses and intrusion attempts, the software can watch over your network for suspicious activity, and manage Windows Updates from a central portal. The premium Plus subscription adds the Security for Microsoft 365 component, which integrates into Exchange Online, OneDrive, SharePoint Online and Teams, providing monitoring and protection for your services as well as your endpoints.</p><p><em><strong>Read our full <a href="https://www.itpro.com/security/361632/kaspersky-endpoint-security-cloud-plus-review-one-security-solution-to-rule-them" data-original-url="https://www.itpro.com/security/361632/kaspersky-endpoint-security-cloud-plus-review-one-security-solution-to-rule-them">Kaspersky Endpoint Security Cloud Plus review</a></strong></em></p><h2 id="best-antivirus-suite-2021">Best antivirus suite 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="f4chyD96aSYGdEHEtxvmNS" name="" alt="A screenshot of Kaspersky Internet Security's main dashboard" src="https://cdn.mos.cms.futurecdn.net/f4chyD96aSYGdEHEtxvmNS.jpg" mos="https://cdn.mos.cms.futurecdn.net/f4chyD96aSYGdEHEtxvmNS.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-kaspersky-internet-security"><span>WINNER: Kaspersky Internet Security</span></h3><p>Kaspersky is no stranger to our awards, and this latest version of its security suite shows why – in multiple independent tests it scored perfect 100% protection scores without a single false positive. Other notable features include browser protection, ransomware blocking, defences against webcam hijacking and even a fully featured firewall.</p><p>Do you need to pay for this type of protection? It’s true that Windows’ built-in security modules are nowadays very effective on their own. However, Kaspersky is much easier to configure, especially when it comes to customising firewall rules. It also has less of an impact on system performance, which makes the modest £15/yr subscription fee easy to swallow.</p><p><em><strong>Read our full</strong></em> <a href="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable" data-original-url="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable"><strong><em>Kaspersky Internet Security</em> </strong><em><strong>review</strong></em></a></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jXGjknMrApJvm3bqNAC798" name="" alt="A screenshot of Avast Antivirus Free" src="https://cdn.mos.cms.futurecdn.net/jXGjknMrApJvm3bqNAC798.jpg" mos="https://cdn.mos.cms.futurecdn.net/jXGjknMrApJvm3bqNAC798.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-avast-antivirus-free"><span>HIGHLY COMMENDED: Avast Antivirus Free</span></h3><p>Avast is our favourite free antivirus solution for several reasons. First, it does a great job of blocking malware: independent labs have found its protection on par with Microsoft Defender and ahead of several paid-for suites. What’s more, it’ll run on older editions of Windows – which is ideal if you still have legacy machines running Windows 7 or 8.1 that can’t be upgraded. You do have to put up with a few in-application adverts for Avast’s paid-for products, but if you can’t use Windows’ built-in protections – or just don’t want to – then Avast Antivirus Free makes a lightweight and effective alternative.</p><p><em><strong>Read our full Avast Antivirus Free review</strong></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky Endpoint Security Cloud Plus review: One security solution to rule them all  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/361632/kaspersky-endpoint-security-cloud-plus-review-one-security-solution-to-rule-them</link>
                                                                            <description>
                            <![CDATA[ Kaspersky is easy to manage, good value and tough on malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mvxtBGznwX6nZKgoKTZeNC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sjU4CWxujUtVPZS4tA7a9e-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Nov 2021 11:19:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sjU4CWxujUtVPZS4tA7a9e-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of Kaspersky Endpoint Security Cloud Plus]]></media:description>                                                            <media:text><![CDATA[A screenshot of Kaspersky Endpoint Security Cloud Plus]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of Kaspersky Endpoint Security Cloud Plus]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sjU4CWxujUtVPZS4tA7a9e-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky’s Endpoint Security Cloud Plus (ESCP) offers some of the most flexible licensing terms in the business. While some vendors expect you to purchase separate licence packs for different types of devices, each Kaspersky user licence covers one workstation, laptop or server, plus two iOS or Android mobile devices.</p><p>The service is designed to protect up to 1,000 Windows and Mac workstations and Windows servers, and is managed entirely in the cloud. The extensive roster of security features includes <a href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus" data-original-url="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus">anti-malware</a>, threat and <a href="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022" data-original-url="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022">ransomware protection</a>, a client firewall, network vulnerability scanning and an attack blocker. </p><p>On top of all this, the Plus subscription we tested adds <a href="https://www.itpro.com/security/cyber-security/356762/protect-your-end-points" data-original-url="https://www.itpro.com/security/cyber-security/356762/protect-your-end-points">endpoint device controls</a>, URL-based web filtering, vulnerability assessments, <a href="https://www.itpro.com/security/34257/it-pro-panel-why-is-patch-management-so-difficult" data-original-url="https://www.itpro.com/security/34257/it-pro-panel-why-is-patch-management-so-difficult">patch management</a> and encryption. It also adds the ability to block any email, file-sharing, messaging or social networking cloud services in use by your clients, while the standard licence only lets you monitor activity.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/361556/f-secure-elements-endpoint-protection-review-a-strong-business-oriented" data-original-url="/security/antivirus/361556/f-secure-elements-endpoint-protection-review-a-strong-business-oriented">F-Secure Elements Endpoint Protection review: A strong business-oriented security solution</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable" data-original-url="/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable">Kaspersky Internet Security review: Powerful, highly configurable protection</a> Avast Antivirus Free review: Our free favourite for older Windows PCs</p></div></div><p>A final benefit of the Plus licence is the Security for <a href="https://www.itpro.com/software/microsoft-office/360636/microsoft-to-raise-prices-for-office-365-and-microsoft-365" data-original-url="https://www.itpro.com/software/microsoft-office/360636/microsoft-to-raise-prices-for-office-365-and-microsoft-365">Microsoft 365</a> component. This provides dedicated security services for Exchange Online, OneDrive, SharePoint Online and Teams, with its data discovery tool highlighting files identified as containing sensitive information.</p><p>Deployment starts with creating a Business Hub account and defining your company. You’re then taken to the ESCP web portal, where wizards guide you through adding users, enabling cloud discovery and scheduling updates and scans. </p><p>Then you just need to get the software onto clients – and this too is painless, as you can email invitations to users directly from the cloud portal. We found the client software took around five minutes to install, then a further 15 minutes to fully register itself with the portal and update its signature database.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yRN9Kd5c4gj3hJKRycUxsm" name="" alt="A screenshot of Kaspersky Endpoint Security Cloud Plus" src="https://cdn.mos.cms.futurecdn.net/yRN9Kd5c4gj3hJKRycUxsm.jpg" mos="https://cdn.mos.cms.futurecdn.net/yRN9Kd5c4gj3hJKRycUxsm.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>A default security profile is applied to each new device so full protection starts immediately, but it’s easy enough to create custom ones. There’s a huge range of options on offer, with clearly distinguished settings for Windows, Mac, Android and iOS devices. </p><p>For example, file, web and network threat protection are available for Windows and Mac devices, while Android users get standard antivirus measures. Since iOS is so locked down, the only options available here are access controls, which let you choose what mobile features are accessible, set screen lock and password policies and specify which networks can be connected to.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ebWTwtZnKEPD3hvMervZkk" name="ebWTwtZnKEPD3hvMervZkk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" mos="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The truth about cyber security training</strong></p><p class="fancy-box__body-text">Stop ticking boxes. Start delivering real change.</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361094/the-truth-about-cyber-security-training" data-original-url="/security/cyber-security/361094/the-truth-about-cyber-security-training">FREE DOWNLOAD</a></p></div></div><p>It’s also worth noting that cloud discovery is only available for Windows devices. It works well, though: after you’ve given it a few hours to build up a picture of your network traffic, the portal shows a handy readout of the top five services and the devices using them.</p><p>Another Windows-centric feature is patch management. All available updates are displayed in the portal, and you can set a daily or weekly schedule to apply them all, or only those you’ve approved.</p><p>To make use of the Security for Microsoft 365 component you need to create a new workspace in your cloud account, which presents a separate portal. After granting access to our account, we were able to create profiles to protect our Exchange Online mailboxes from spam, phishing and malicious attachments, and apply anti-malware policies to our files in OneDrive and SharePoint Online.</p><p>The data discovery service, meanwhile, works with Exchange, OneDrive and SharePoint data, sending an alert to selected users if it finds confidential information. As with the ESCP portal, plenty of information is presented, with detection statistics for Exchange mailboxes, OneDrive files and SharePoint data.</p><p>Businesses seeking both device security and protection within Microsoft 365 will find Kaspersky Endpoint Security Cloud Plus has all the angles covered. You do need to use separate portals to manage everything, but there’s a huge range of security features on offer, and Kaspersky’s licensing scheme makes it very affordable.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Office 365 phishing campaign used stolen Kaspersky Amazon SES token to fool victims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/361427/new-office-365-phishing-campaign-used-stolen-kaspersky-amazon-ses-token-to</link>
                                                                            <description>
                            <![CDATA[ Credentials stolen from users after legitimate-looking email arrives in inboxes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Vb97CJp8yQUak6GtXbtis</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZGxfQLTpzq86aFbUf5kxM5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Nov 2021 16:01:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZGxfQLTpzq86aFbUf5kxM5-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kaspersky&amp;#039;s antivirus software on a smartphone in someone&amp;#039;s pocket]]></media:description>                                                            <media:text><![CDATA[Kaspersky&amp;#039;s antivirus software on a smartphone in someone&amp;#039;s pocket]]></media:text>
                                <media:title type="plain"><![CDATA[Kaspersky&amp;#039;s antivirus software on a smartphone in someone&amp;#039;s pocket]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZGxfQLTpzq86aFbUf5kxM5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IT <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> firm Kaspersky has warned users that a new phishing campaign is using one of its stolen Amazon Simple Email Service (SES) tokens to make emails appear legitimate.</p><p>In an <a href="https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021_phishing">advisory</a> issued on Monday, the firm said it saw a huge increase in spear-phishing emails designed to steal Office 365 credentials. The advisory added that this campaign relies on a phishing kit researchers named “Iamtheboss” used in conjunction with another phishing kit known as “MIRCBOOT.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable" data-original-url="/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable">Kaspersky Internet Security review: Powerful, highly configurable protection</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/361224/mysterysnail-zero-day-elevation-of-privilege-exploit-in-windows" data-original-url="/security/zero-day-exploit/361224/mysterysnail-zero-day-elevation-of-privilege-exploit-in-windows">Kaspersky exposes MysterySnail zero-day exploit in Windows</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/information-security-infosec/360139/passwords-generated-by-kaspersky-password-manager-can" data-original-url="/security/information-security-infosec/360139/passwords-generated-by-kaspersky-password-manager-can">Kaspersky Password Manager generates passwords that can be 'cracked in seconds'</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/357251/amazons-flying-security-drone-is-a-security-risk-warns-kaspersky" data-original-url="/security/hacking/357251/amazons-flying-security-drone-is-a-security-risk-warns-kaspersky">Kaspersky blasts Amazon's indoor drone as a 'major security risk'</a></p></div></div><p>“The activity may be associated with multiple cybercriminals. The phishing e-mails are usually arriving in the form of “Fax notifications” and lure users to fake websites collecting credentials for Microsoft online services,” the advisory stated. “These emails have various sender addresses, including but not limited to noreply@sm.kaspersky.com. They are sent from multiple websites including Amazon Web Services infrastructure.”</p><p>In investigations, Kaspersky researchers determined some emails were sent using Amazon’s Simple Email Service (SES) and legitimate SES token. Amazon Simple Email Service (SES) is an email service that enables developers to send mail from within any application. </p><p>They said that this access token was issued to a third-party contractor during the testing of the website 2050.earth. The site is also hosted in Amazon infrastructure. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TgYwXSHV6efgCB2UrGXGXc" name="TgYwXSHV6efgCB2UrGXGXc.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TgYwXSHV6efgCB2UrGXGXc.png" mos="https://cdn.mos.cms.futurecdn.net/TgYwXSHV6efgCB2UrGXGXc.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Prevent fraud and phishing attacks with DMARC</strong></p><p class="fancy-box__body-text">How to use domain-based message authentication, reporting, and conformance for email security</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359475/prevent-fraud-and-phishing-attacks-with-dmarc" data-original-url="/security/cyber-security/359475/prevent-fraud-and-phishing-attacks-with-dmarc">FREE DOWNLOAD</a></p></div></div><p>“Upon discovery of these phishing attacks, the SES token was immediately revoked. No server compromise, unauthorized database access, or any other malicious activity was found at 2050.earth and associated services,” said the advisory.</p><p>The advisory encouraged users to execute caution and be vigilant even if the email seems to come from a familiar brand or email address.</p><p>MIRCBOOT is a phishing kit <a href="https://www.microsoft.com/security/blog/2021/09/21/catching-the-big-fish-analyzing-a-large-scale-phishing-as-a-service-operation">recently discovered</a> by researchers at Microsoft as part of a large-scale phishing-as-a-service operation known as BulletProofLink. This follows the software-as-a-service model, which requires attackers to pay an operator to wholly develop and deploy large portions or complete phishing campaigns from false sign-in page development, website hosting, and credential parsing and redistribution.</p><p>Earlier this month, a Russian cyber crime group was targeting the <a href="https://www.itpro.com/security/32330/bank-of-england-to-test-finance-sectors-cyber-security" data-original-url="https://www.itpro.com/security/32330/bank-of-england-to-test-finance-sectors-cyber-security">financial sector</a> with malware delivered by Microsoft Office macros. The attack used <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> emails to mount the first phase of its attack, using an Excel document that uses a macro. </p><p>Last month, <a href="https://www.itpro.com/security/phishing/361042/hackers-spoof-zix-in-credential-phishing-attack" data-original-url="https://www.itpro.com/security/phishing/361042/hackers-spoof-zix-in-credential-phishing-attack">hackers spoofed</a> Zix to steal Office 365, Google Workspace, and Microsoft Exchange data. Security researchers from Armorblox said the attack affected around 75,000 users, with small groups of cross-departmental employees targeted in each customer environment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky Internet Security review: Powerful, highly configurable protection ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable</link>
                                                                            <description>
                            <![CDATA[ Easy to use, efficient and accurate malware defense for users who want to personalise their protection ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">74d4mgodk5JrBJrFjdC82V</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/f4chyD96aSYGdEHEtxvmNS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 Oct 2021 11:15:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ K.G. Orphanides ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/sZCck6JUYUwhUf9f8q9pWc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/f4chyD96aSYGdEHEtxvmNS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of Kaspersky Internet Security&amp;#039;s main dashboard ]]></media:description>                                                            <media:text><![CDATA[A screenshot of Kaspersky Internet Security&amp;#039;s main dashboard ]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of Kaspersky Internet Security&amp;#039;s main dashboard ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/f4chyD96aSYGdEHEtxvmNS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky Internet Security is a long-standing entry in our antivirus awards list, and its performance this time around hasn’t disappointed. We’ve reviewed the Windows version, running under Windows 10, but you can use your Kaspersky licenses to protect any combination of Windows, macOS, Android and iOS devices.</p><p>As well as the expected real-time malware detection and schedule scans, KIS provides a useful selection of features. There’s a browser protection module, ransomware defense that prevents unauthorized changes from being made to selected directories, private browsing and ad blocking, webcam protection, an interruption-free gaming mode, and online monitoring to check the protection status of all devices associated with your Kaserpersky account. Unusually for an antivirus suite in this price range, Kaspersky Internet Security also includes a fully-featured firewall. </p><p>You also get the free version of Kaspersky’s Secure Connection VPN, with a 300MB per day bandwidth cap, installed as a standalone utility. The other standalone components are an optional free subscription to Kaspersky Password Manager, and the free Safe Kids parental controls. None of these stand out against <a href="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for" data-original-url="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for">the market leaders</a> in their sectors, however. As they aren’t really integrated into the KIS client, you won’t feel their absence if you do away with them.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/356467/kaspersky-endpoint-security-cloud-review-merciless-against" data-original-url="/security/endpoint-security/356467/kaspersky-endpoint-security-cloud-review-merciless-against">Kaspersky Endpoint Security Cloud review: Merciless against malware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/361224/mysterysnail-zero-day-elevation-of-privilege-exploit-in-windows" data-original-url="/security/zero-day-exploit/361224/mysterysnail-zero-day-elevation-of-privilege-exploit-in-windows">Kaspersky exposes MysterySnail zero-day exploit in Windows</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/33558/kaspersky-endpoint-security-for-business-advanced-review-on-prem-security" data-original-url="/endpoint-security/33558/kaspersky-endpoint-security-for-business-advanced-review-on-prem-security">Kaspersky Endpoint Security for Business Advanced review: On-prem security done right</a></p></div></div><p>When it comes to the protection afforded by its anti-malware engine, you can’t go wrong with Kaspersky’s products. KIS netted perfect protection scores without a single false positive in the most recent tests by <a href="https://www.av-test.org">AV-Test</a> and <a href="https://selabs.uk">SE Labs</a>. <a href="https://www.av-comparatives.org">AV Comparatives</a>’ July/August 2021 data shows that it blocked an impressive 99.70% of malware in real-world exposure tests, once again without any false positives. Not quite perfect, but an impressive performance however you cut it, matching that of Microsoft’s impressive integrated Defender.</p><p>Where Kaspersky provides a real advantage is in its interface and performance. KIS has been a great choice for minimal impact on system resources for years, and currently out-performs built-in Microsoft Defender Antivirus on Windows 10 PCs, notably when it comes to how long it takes to install software, although Kaspersky had a greater impact on website opening times.</p><p>Perhaps the best feature of Kaspersky Internet Security is the fantastic interface it provides for actually controlling it. While in practice, most of the same things KIS does can be achieved using Windows’ integrated tools, it’s just easier to do with Kaspersky.</p><p>Its firewall in particular is designed to be lived with and used, making it easy to add and edit rules, while the Microsoft Defender firewall remains comparatively unfriendly to work with. Application controls are also a welcome addition, although they tend to block unsigned software by default, requiring an exception to run.</p><p>Kaspersky Internet Security is pretty cost-effective, starting at £14.58 exc VAT for a one year, one device subscription from Kaspersky’s website. Further discounts are sometimes available, and you can buy packaged codes at physical and online shops at prices as low as £11 inc VAT.</p><p>Watch out for renewals, though - that single-user subscription goes up to £29.16 exc VAT on the second year, and your auto-renewing subscription is set up automatically if you buy your license via the official Kaspersky site. That’s still a decent price for 12 months of malware protection, but you should make sure you’re aware of it and that you want to renew automatically rather than buying codes elsewhere.</p><p>It’s also worth noting that, <a href="https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak" data-original-url="https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak">since 2017</a>, some US businesses and both UK and UK government departments won’t allow their colleagues or contractors to run Kaspersky software on devices used for work. Kaspersky subsequently moved significant parts of its operation from Russia to Switzerland.</p><p>We’d prefer it if KIS put a little less emphasis on promoting Kaspersky’s other products after we’d already paid for this one, but that’s a minor complaint about an otherwise outstanding antivirus suite.</p><p>Kaspersky Internet Security is our favourite paid-for anti-malware solution, providing a great user interface and outstanding protection against malware and minimal impact on performance, improving even on Windows’ very credible integrated malware defence.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky Endpoint Security Cloud review: Merciless against malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/356467/kaspersky-endpoint-security-cloud-review-merciless-against</link>
                                                                            <description>
                            <![CDATA[ Easily managed and good value, Kaspersky is a great choice for small businesses ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ceSWnTxB1gSFDFyjmQiFsd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/if2maW39KfP47PVMiNDGgj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Jul 2020 07:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 04 Aug 2021 09:27:10 +0000</updated>
                                                                                                                                            <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/if2maW39KfP47PVMiNDGgj-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/if2maW39KfP47PVMiNDGgj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky offers an endpoint protection answer for every business. Large firms that want total control can choose <a href="https://www.itpro.com/endpoint-security/33558/kaspersky-endpoint-security-for-business-advanced-review-on-prem-security" data-original-url="https://www.itpro.com/endpoint-security/33558/kaspersky-endpoint-security-for-business-advanced-review-on-prem-security">its on-site Endpoint Security for Business products</a>, while smaller companies that don’t want to run their own host server have two cloud-managed solutions to choose from.</p><p>We tested Kaspersky’s Endpoint Security Cloud, which is managed entirely from a cloud portal and protects ten to 150 Windows systems and Macs. Licensing is flexible, with each user licence supporting one workstation, laptop or server, plus two iOS or Android mobile devices.</p><p>The standard service includes protection against <a href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus" data-original-url="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus">all types of malware and ransomware</a>, a client firewall, a network attack blocker and <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">vulnerability scanning</a>. There’s also a new cloud discovery feature that lets you keep an eye on email, file-sharing, messaging and social networking services being accessed by users.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/356418/avast-business-antivirus-pro-plus-review-a-balanced-security" data-original-url="/security/endpoint-security/356418/avast-business-antivirus-pro-plus-review-a-balanced-security">Avast Business Antivirus Pro Plus review: A balanced security suite</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/antivirus/28144/best-antivirus" data-original-url="/antivirus/28144/best-antivirus">Best antivirus for Windows 10</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/web-browser/356333/why-im-leading-a-browser-double-life" data-original-url="/network-internet/web-browser/356333/why-im-leading-a-browser-double-life">Why I’m leading a browser double life</a></p></div></div><p>If you need more, you can move up to the Plus version, which adds <a href="https://www.itpro.com/desktop-software/19337/office-365-review" data-original-url="https://www.itpro.com/desktop-software/19337/office-365-review">Office 365</a> protection, URL-based web filtering, endpoint device controls, encryption and patch management. The Plus service lets you block specific cloud services too, while the regular tier only monitors them.</p><p>We found deployment pleasingly simple: the agent can be downloaded and installed directly from the web portal, or you can email a download link to users. Either way, it takes around five minutes to set up, with a further 15-minute wait while the client registers its licence.</p><p>Once that’s done, protection starts immediately with a default security policy that enables everything Kaspersky has to offer. If you want to customise your coverage, it’s easy to create your own policies, organise clients into groups and grant admin rights to specific users. For Windows systems there are three levels of file and web threat protection on offer, and you can choose whether to scan emails for dodgy content and enable network threat protection. If you have the Plus version, you can browse all detected cloud services and decide whether to block any. Macs get file, web and network threat protection, but mail and cloud discovery are off the menu.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="fFKswJof4wF588y3AKuczY" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/fFKswJof4wF588y3AKuczY.jpg" mos="https://cdn.mos.cms.futurecdn.net/fFKswJof4wF588y3AKuczY.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>It’s a varied offering for mobile users too. Android devices benefit from <a href="https://www.itpro.com/android/28184/the-best-antivirus-for-android-phones" data-original-url="https://www.itpro.com/android/28184/the-best-antivirus-for-android-phones">antivirus protection</a> plus web and app controls, while for iOS it’s more about access security: the portal lets you create APNs certificates, allowing you to choose what device features are accessible, set a <a href="https://www.itpro.com/mobile/34615/how-to-reset-your-iphone-passcode" data-original-url="https://www.itpro.com/mobile/34615/how-to-reset-your-iphone-passcode">screen lock and password policy</a>, apply simple website keyword blocking and restrict which networks can be joined.</p><p>As you’d hope, the whole system is highly responsive to threats. When we tried introducing malware to some of our test Windows 10 systems, the local client blocked them immediately, with email alerts landing in our administrative mailbox barely ten seconds later.</p><p>The web portal is very informative. A graph displays the top five categories of cloud services in use and lets you drill down to see exactly who’s using what; our only slight niggle is that this took several hours to populate with details on detected services. Below, more graphs show device protection status, the OS spread, detected threats and the results of daily vulnerability scans. There’s a good set of predefined reports too, covering protection status, threats, database updates and cloud discovery, which can be exported in CSV and PDF formats.</p><p>If your business is of a suitable size, Kaspersky Endpoint Security Cloud is great value, especially since each licence includes protection for two mobile devices. The cloud discovery component can be a little slow, but endpoint protection doesn’t get any stronger than this and the cloud portal is very easy to work with.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky grants healthcare bodies free security software  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/355081/kaspersky-grants-healthcare-bodies-free-security-software</link>
                                                                            <description>
                            <![CDATA[ Six months of fully-licensed software includes cloud security and Microsoft Office 365 protection ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2T8qDkcv3nd3qxpHTJSxJh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZkawEhf6S4Tr4Yrru98FwE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Mar 2020 15:27:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZkawEhf6S4Tr4Yrru98FwE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kaspersky logo on a screen]]></media:description>                                                            <media:text><![CDATA[Kaspersky logo on a screen]]></media:text>
                                <media:title type="plain"><![CDATA[Kaspersky logo on a screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZkawEhf6S4Tr4Yrru98FwE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/hardware/printers" data-original-url="https://www.itpro.com/security/32977/kaspersky-internet-security-2019-review-unbeatable-value">Kaspersky</a> has offered medical organisations free enterprise security software for six months to stay protected from <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> threats as they begin to grapple with the brunt of the coronavirus outbreak.</p><p>The full product licenses span a host of B2B products, including endpoint and cloud infrastructure protection platforms such as Kaspersky Endpoint Security for Business Advanced, and Kaspersky Hybrid Cloud Security. </p><p>Healthcare bodies can also take advantage of six months’ usage of the firm’s software as a service (SaaS) endpoint protection product, dubbed Endpoint Security Cloud Plus, as well as its <a href="https://www.itpro.com/desktop-software/19337/office-365-review" data-original-url="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft Office 365</a> protection suite. </p><p>The Russian firm has extended the offer just as healthcare organisations, and wider businesses, face a wave of threats tied with the global pandemic. </p><p>Hackers, for example, are exploiting the general confusion around the outbreak to launch phishing attacks by posing as bodies like the Centre for Disease Control (CDC) and the World Health Organisation (WHO). These are similar to the kinds of attacks that were <a href="https://www.itpro.com/security/23358/fake-who-email-about-ebola-spreads-malware" data-original-url="https://www.itpro.com/security/23358/fake-who-email-about-ebola-spreads-malware">launched during the Ebola outbreak</a>.</p><p>Healthcare systems have also been facing a wave of serious threats, including the NHS in Cumbria, which alone has been <a href="https://www.itpro.com/security/28975/is-healthcare-safe-from-cyber-attacks" data-original-url="https://www.itpro.com/security/28975/is-healthcare-safe-from-cyber-attacks">hit by more than 150 cyber attacks in the last five years</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/printers" data-original-url="/security/32977/kaspersky-internet-security-2019-review-unbeatable-value">Kaspersky Internet Security 2019 review: Unbeatable value</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/33953/nhs-must-spend-now-to-prevent-devastation-of-wannacry-20" data-original-url="/security/33953/nhs-must-spend-now-to-prevent-devastation-of-wannacry-20">NHS must spend now to prevent devastation of ‘WannaCry 2.0’</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/355048/government-may-trace-covid-19-patients-using-mobile-phone-data" data-original-url="/security/privacy/355048/government-may-trace-covid-19-patients-using-mobile-phone-data">UK government may trace COVID-19 patients using mobile phone data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-operations/354999/prime-minister-boris-johnson-calls-for-tech-to-support" data-original-url="/business/business-operations/354999/prime-minister-boris-johnson-calls-for-tech-to-support">Prime Minister Boris Johnson calls for tech to support coronavirus battle</a></p></div></div><p>“In this critical situation, healthcare institutions are under immense pressure and carry huge responsibility while saving people’s lives and fighting against the infection,” said VP of Kaspersky’s global sales network Evgeniya Naumova.</p><p>“Doctors, nurses and all medical staff take on most of the load and therefore need any support possible. We feel that it is our duty to support the medical community.”</p><p>The offer has been made so these organisations can channel their efforts into fighting the pandemic instead of worrying about their security setup over the next six months. Hospitals and medical institutions, in particular, will need to ensure the stability of equipment, and that data is freely flowing from system to system, and that staff can access it.</p><p>Kaspersky has also outlined a set of measures that healthcare organisations can take to raise their cyber resilience, including <a href="https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training" data-original-url="https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training">implementing awareness training</a> for both medical and administrative staff.</p><p>The company has also recommended that hospitals re-examine their security systems to ensure they’re updated and configured properly, which includes turning on any firewalls and <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> protection.</p><p>Hospitals urgently hiring more staff, meanwhile, including nurses and doctors, are also being advised to keep a handle on the growing number of endpoints that will come as a result. </p><p>In the same vein, medical devices should be properly configured and updated, including crucial equipment like ventilators, with the supply of these critical devices likely to ramp up significantly in the coming weeks and months.</p><p>Organisations around the world are taking measures to refocus their energy and efforts into frontline healthcare. NHS Trusts, for instance, have been <a href="https://www.itpro.com/security/cyber-security/355041/critical-nhs-cyber-security-checks-suspended-due-to-coronavirus" data-original-url="https://www.itpro.com/security/cyber-security/355041/critical-nhs-cyber-security-checks-suspended-due-to-coronavirus">granted a six-month delay to complete critical cyber security checks</a> in order to focus their efforts on treating patients.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky Endpoint Security for Business Advanced review: On-prem security done right ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/endpoint-security/33558/kaspersky-endpoint-security-for-business-advanced-review-on-prem-security</link>
                                                                            <description>
                            <![CDATA[ Excellent device protection for modern businesses ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qa1B29YqKJikSsWJ49Z29u</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MNp5HMZZsjdpmZSTPxY2JF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 May 2019 13:06:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MNp5HMZZsjdpmZSTPxY2JF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MNp5HMZZsjdpmZSTPxY2JF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky's Endpoint Security for Business (ESB) has been the foundation of its on-premises solutions for many years and the latest version introduces tougher security measures than ever before. The new intelligent adaptive anomaly control component watches out for abnormal user behavior and along with the ability to scan inbound and outbound HTTPS traffic, the web protection components have a keen nose for sniffing out mining malware.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/31943/kaspersky-small-office-security-6-review" data-original-url="/software/31943/kaspersky-small-office-security-6-review">Kaspersky Small Office Security 6 review</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/printers" data-original-url="/security/33162/panda-free-antivirus-review-bamboo-zle-the-hackers">Panda Free Antivirus review: Bamboo-zle the hackers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/printers" data-original-url="/security/32999/bitdefender-internet-security-2019-review-still-one-of-the-best">Bitdefender Internet Security 2019 review: Still one of the best</a></p></div></div><p>ESB comes in three flavours with the Select edition including the Security Center management console, anti-malware, file server and mobile protection as well as device, web and application controls. The Advanced edition on review adds the adaptive anomaly control, encryption and patch management plus remote software installation, while the Total edition bolsters this with mail server, gateway and collaboration security.</p><p>Prices for the Advanced version on review start at 760 per year for 10 seats. Platform support is extensive as ESB can protect Windows, Mac and Linux workstations and servers and includes iOS and Android mobile device management (MDM) services using Exchange ActiveSync or its own iOS MDM server.</p><h2 id="kaspersky-endpoint-security-for-business-advanced-review-management-and-deployment">Kaspersky Endpoint Security for Business Advanced review: Management and deployment</h2><p>ESB deployment starts by installing the Security Center 11 component on the designated host Windows workstation or server. It expects to have a SQL database made available and for testing, we installed Microsoft's SQL Server 2014 Express SP2.</p><p>Functioning as an MMC (Microsoft Management Console) snap-in, the Security Center 11 console receives a fresh lick of paint but retains the same intuitive format as previous versions. The ESB web console, on the other hand, sees a complete redesign and, along with vastly improved status dashboards and reporting, now provides full access to ESB's settings allowing it to be used instead of the Security Center if required.</p><p>You're spoilt for workstation deployment choices; ESB can search network subnets, workgroups and Active Directory (AD) domains. The ESB console places all discovered systems in an 'unassigned' list where we selected our Windows test workstations, pushed the Network Agent and Endpoint Security components to them with one job and watched ESB move them to the default managed group.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mnWmpeAtmZgHR9UtJMKb9a" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/mnWmpeAtmZgHR9UtJMKb9a.png" mos="https://cdn.mos.cms.futurecdn.net/mnWmpeAtmZgHR9UtJMKb9a.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The automatic installation option is even faster. All unassigned systems can be added to a console group with this feature enabled and ESB will do all the hard work for you. Group structures based on selected workgroups or AD domains can be created where you leave the discovery routine to populate them and then run the entire deployment.</p><h2 id="kaspersky-endpoint-security-for-business-advanced-review-group-policies">Kaspersky Endpoint Security for Business Advanced review: Group policies</h2><p>The System Center creates a base set of security policies for the default group so all our test clients were protected immediately. You can create custom groups and apply new policies to define how a client's Network Agent and Endpoint Security components behave when they join a group.</p><p>ESB's group policies are a powerful feature as they allow you to centrally manage all endpoint security and threat protection features and stop end users fiddling with the client settings or uninstalling them. Policies can be modified from the System Center or web console and we found changes took around 10 seconds to be pushed out to our clients.</p><p>Choosing a group reveals all member systems, with each assigned colour-coded icons for at-a-glance status indicators. Selecting a client shows their properties in a right-hand pane while a drop down menu provides access to options such as running tasks, forcing synchronizations and viewing hardware and software inventories.</p><p>A useful support feature is the ability to fire up a remote control session with a selected client using RDP or Windows desktop sharing. Another valuable feature is ESB's integral vulnerability and patch management component which checked our clients, showed all required updates and offered to automatically deploy them.</p><h2 id="kaspersky-endpoint-security-for-business-advanced-review-threat-protection-features">Kaspersky Endpoint Security for Business Advanced review: Threat protection features</h2><p>Policies provide easy access to all security features and we found it simple to customize the various components. Advanced threat protection includes access to Kaspersky's Security Network for reputation-based scanning, behavioral detection for ransomware protection and exploit protection.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="W9uRfUkeYu8NHkhwTzxJ2c" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/W9uRfUkeYu8NHkhwTzxJ2c.png" mos="https://cdn.mos.cms.futurecdn.net/W9uRfUkeYu8NHkhwTzxJ2c.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Essential threat protection features include a memory resident file scanner, transparent scanning of email and web traffic, a client firewall and network attack detection. Many components can be modified easily just by using a slider bar to choose from three levels.</p><p>Policy security controls go even further as these allow you to enforce black and white application lists and decide what hardware devices can be used on client systems. The web content filtering component can't match the efficacy of UTM hardware appliances but Kaspersky has increased the number of available URL categories from 15 to 28.</p><p>Adaptive anomaly control is also enabled in this policy section and can be applied to Office app, WMI, script and PowerShell activities. We found it initially spends a few days in training mode after which it creates smart rules based on its findings, and you can quickly load reports to see training progress and whether any rules have been triggered.</p><p>Reporting is a real strength, too. ESB comes with a wide choice of predefined reports for viewing anything from infected computers and endpoint inventory to detected threats and web browsing behavior. We could easily create custom reports using these as templates, schedule them to run regularly and create tasks to have them emailed to us.</p><h2 id="kaspersky-endpoint-security-for-business-advanced-review-verdict">Kaspersky Endpoint Security for Business Advanced review: Verdict</h2><p>Kaspersky's Endpoint Security for Business is a great choice for companies that prefer on-premises to cloud management. It's easy to deploy, offers a choice of MMC snap-in or web browser management access and delivers an unbeatable range of security measures for hardening your endpoints against malware.</p><h2 id="verdict">Verdict</h2><p>An on-premises endpoint protection solution suitable for a wide range of businesses that’s good value, easy to manage and packed to the rafters with tough security measures</p><p>Security Center 11: Windows 7/Server 2012 upwards</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky loses Court of Appeals battle to reverse US government ban ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/32482/kaspersky-loses-court-of-appeals-battle-to-reverse-us-government-ban</link>
                                                                            <description>
                            <![CDATA[ The court maintains the threat of the Russian-based antimalware company is real ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eQX6okAHU9pEJWzokfVTjV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pRDu8iYQjogvCLxqPKuWbE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Dec 2018 10:31:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pRDu8iYQjogvCLxqPKuWbE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kaspersky sign on a white post]]></media:description>                                                            <media:text><![CDATA[Kaspersky sign on a white post]]></media:text>
                                <media:title type="plain"><![CDATA[Kaspersky sign on a white post]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pRDu8iYQjogvCLxqPKuWbE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>After a lengthy battle with the US government spanning over a year, Kaspersky Lab has lost its battle at the Washington DC Court of Appeals over the government's decision to ban its software from all federal government computers.</p><p>The court upheld the initial ruling made by a district court forbidding Kaspersky to bring a lawsuit against the US government following its "unconstitutional" claims which "relied on subjective, non-technical public sources such as uncorroborated and often anonymously sourced media reports, related claims and rumours", <a href="https://usa.kaspersky.com/about/press-releases/2017_kaspersky-lab-appeals-us-department-of-homeland-security-debarment" target="_blank">Kaspersky said</a> in 2017.</p><p>The judges who upheld the district court's decision cited Congress's right to block the purchase of software provided by a specific vendor providing there is a genuine security risk associated with it.</p><p>"With or without Kaspersky's willing cooperation, explained the experts, the Russian government could use Kaspersky products as a backdoor into federal information systems," the court <a href="https://regmedia.co.uk/2018/11/30/kasperskyappealdecision.pdf" target="_blank">stated</a>. "Then, having gained privileged and undetected access, Russia could make all manner of mischief."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/antivirus/30983/kaspersky-hits-back-at-twitter-ban-with-open-letter" data-original-url="/antivirus/30983/kaspersky-hits-back-at-twitter-ban-with-open-letter">Kaspersky hits back at Twitter ban with open letter</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31134/kaspersky-to-relocate-infrastructure-to-switzerland-for-transparency" data-original-url="/security/31134/kaspersky-to-relocate-infrastructure-to-switzerland-for-transparency">Kaspersky to relocate infrastructure to Switzerland for transparency</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29105/kaspersky-launches-free-antivirus-worldwide" data-original-url="/security/29105/kaspersky-launches-free-antivirus-worldwide">Kaspersky launches free antivirus worldwide</a></p></div></div><p>Kaspersky's main argument centred around the punitive nature of the ban, claiming that the court's decision was less about protecting the government's safety, but punishing a firm with alleged ties with Russia's FSB.</p><p>"Since the company's inception over 21 years ago, it has always abided by the highest ethical business practices, and through our recently launched Global Transparency Initiative, Kaspersky Lab is exemplifying its ongoing commitment to assuring the integrity and trustworthiness of its products. Kaspersky Lab reaffirms that it has never, nor will ever, engage in cyber offensive activities, and the Court's decision does not conclude otherwise," the company said in a follow-up <a href="https://usa.kaspersky.com/about/press-releases/2018_kaspersky-lab-s-statement-regarding-u-s-court-of-appeals-decision--november-30-2018" target="_blank">statement</a>.</p><p>The order to ban Kaspersky from US government computers was originally made in 2017 by the Department of Homeland Security. All government departments and agencies were to develop plans to discontinue present and future use of Kaspersky's software from their computers within 90 days of the directive being issued.</p><p>"This action is based on the information security risks presented by the use of Kaspersky products on federal information systems," said the DHS in a <a href="https://www.dhs.gov/news/2017/09/13/dhs-statement-issuance-binding-operational-directive-17-01" target="_blank">statement</a>. "Kaspersky anti-virus products and solutions provide broad access to files and elevated privileges on the computers on which the software is installed, which can be exploited by malicious cyber actors to compromise those information systems.</p><p>"The Department is concerned about the ties between certain Kaspersky officials and Russian intelligence and other government agencies, and requirements under Russian law that allow Russian intelligence agencies to request or compel assistance from Kaspersky and to intercept communications transiting Russian networks."</p><p>The ban wasn't just an explosive response to Russia's influence on the 2016 presidential election, back in 2014 the anti-malware software company was accused of providing a backdoor into federal departments' systems after a top-secret exploit code was stolen in an NSA leak.</p><p>The software is also used by Russia's FSB and allegations were immediately pointed at them but Kaspersky refuted these claims, citing pirated Microsoft Office software installed by an employee as the cause.</p><p>The keygen used to create a counterfeit Office key was, in fact, a trojan which dropped a backdoor in the system; Kaspersky was turned off in order to illegally install the software thus allowing the FSB to access the system via the backdoor.</p><p>Most recently, the <a href="https://www.itpro.com/security/31326/kaspersky-halts-all-european-security-projects-in-response-to-eu-ban" target="_blank" data-original-url="https://www.itpro.com/security/31326/kaspersky-halts-all-european-security-projects-in-response-to-eu-ban">EU</a> published a cyber security <a href="http://www.europarl.europa.eu/sides/getDoc.do?pubRef=-//EP//NONSGML+REPORT+A8-2018-0189+0+DOC+PDF+V0//EN">report</a> in June 2018, calling for a comprehensive review of all IT software and equipment used by all member states in an attempt to stop "an unprecedented threat" of "politically motivated, state-sponsored cyber attacks". It labelled Kaspersky as software that had "been confirmed as malicious".</p><p>Earlier on in the year, Kaspersky attempted to make amends and rebuild a strong reputation for themselves, increasing the reward for its <a href="https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs" target="_blank" data-original-url="https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs">bug bounty program</a> to $100,000 per critical vulnerability found in its own systems. Despite this peace offering, the EU remained unconvinced and labelled the Moscow-based company's software as 'malicious' anyway later in the year.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky hits back at Twitter ban with open letter ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/antivirus/30983/kaspersky-hits-back-at-twitter-ban-with-open-letter</link>
                                                                            <description>
                            <![CDATA[ Eugene Kaspersky quotes Game of Thrones in letter claiming his firm is being unfairly censored ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">97X3ywQBaSuwhzBKNF9Atu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oiEJKZTiHZ27bVwM2PyKNT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Apr 2018 10:36:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oiEJKZTiHZ27bVwM2PyKNT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oiEJKZTiHZ27bVwM2PyKNT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky Lab founder Eugene Kaspersky has responded to Twitter's advertising ban on his company with <a href="https://www.kaspersky.com/blog/ek-on-twitter-ads/22106" target="_blank">an open letter</a> invoking Game of Thrones that accuses the social network of "playing into the hands of cybercriminals".</p><p>Twitter alerted the company in January to the fact that it would "off-board advertising from all accounts owned by Kaspersky Lab", with the stated reason for the ban being that Kaspersky Lab's business model "inherently conflicts with acceptable Twitter Ads business practices" - a possible reference to <a href="https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs" target="_blank" data-original-url="https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs">accusations that Kaspersky has helped Russian spying efforts</a>, which Kaspersky has robustly denied.</p><p>After asking Twitter for its reasoning around the ban back in February, founder and CEO Eugene Kaspersky published an open letter to Twitter chief Jack Dorsey and the rest of Twitter's leadership team last week, asking the company to explain why the ban has been enacted and what other security companies can do to prevent suffering similar bans.</p><p>"Understandably, you've been busy dealing with public and political pressure. As a response to all this pressure, social media platforms - Twitter in particular - need to somehow adapt their rules and policies," Kaspersky wrote. "But please, dear Twitter managers, I think it's of the utmost importance that any and all changes you do introduce in response to existing challenges are divulged in full and applied in a transparent manner."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs" data-original-url="/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs">Kaspersky offers hackers $100,000 for spotting bugs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29224/the-cyber-security-threat-in-charts" data-original-url="/security/29224/the-cyber-security-threat-in-charts">The cyber security threat in six charts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak" data-original-url="/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak">Kaspersky claims pirated Office software was behind NSA exploit leak</a> Kaspersky’s attempt to overturn US government ban thrown out of court</p></div></div><p>Kaspersky argued that the majority of the company's promoted tweets are informative, educational posts about cyber security awareness, tips and research, and that even the purely marketing tweets it promotes are still in line with the behaviour of the rest of the IT industry, as is its business model.Kaspersky's letter - as well as several of the executive's tweets - implied that Twitter's actions amount to censorship.</p><p>In fact, he headed his letter with a quote from Game of Thrones character Tyrion Lannister: "When you tear out a man's tongue, you are not proving him a liar, you're only telling the world that you fear what he might say." Elsewhere he wrote: "Twitter is playing into the hands of cybercriminals when it hinders the delivery of important information on protection from cyberthreats."</p><p>Kaspersky is fighting back on multiple fronts against bans and blocks enforced by governments, filing a lawsuit against the Trump administration after mounting US pressure saw <a href="https://www.itpro.com/technology/blockchain" target="_blank" data-original-url="https://www.itpro.com/antivirus/28647/USKasperskyBan">it prohibit public sector bodies from using Kaspersky Lab software</a>,while in the UK, the National Cyber Security Centre <a href="https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs" target="_blank" data-original-url="https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs">issued guidance</a> advising all government departments to avoid Russian antivirus firms.</p><p>Despite the ongoing furore though, figures from market research firm B2B International showed that the majority of businesses have not been put off using Kaspersky Lab's products, and the company last year maintained an average Net Promoter Score (which measures how likely customers are to recommend your company) of 49, in line with the upper echelons of the software market. More customers are also using Kaspersky as their main security provider compared to 2016.</p><p>Kaspersky said that the company will be donating all the money it had planned to spend on Twitter advertising over the course of 2018 (which amounted to more than 75,700 in 2017) to the Electronic Frontier Foundation, noting pointedly that the organisation does "a lot to fight censorship online".</p><p><em>IT Pro</em> has contacted Twitter to try and find out the reasons behind Kaspersky's ban, but did not receive a response in time for publication.</p><p><em>Picture: Shutterstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky offers hackers $100,000 for spotting bugs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs</link>
                                                                            <description>
                            <![CDATA[ The new rewards form part of the antivirus firm's attempts to counteract spying accusations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8CC2Rx7S9kByMZKLpJxNyy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KAE3tGXMEcRfgDxLP9qFH4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 Mar 2018 09:38:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KAE3tGXMEcRfgDxLP9qFH4-1280-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bright blue code appearing on screen to denote hacking]]></media:description>                                                            <media:text><![CDATA[Bright blue code appearing on screen to denote hacking]]></media:text>
                                <media:title type="plain"><![CDATA[Bright blue code appearing on screen to denote hacking]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KAE3tGXMEcRfgDxLP9qFH4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky has upped its bug bounty programme to $100,000 for the discovery and disclosure of critical vulnerabilities in its applications, as part of its efforts to rebuild trust following allegations of spying.</p><p>The move comes at a time when the Moscow-based antivirus company faces international pressure over its alleged connections with the Russian government, leading to many high profile boycotts of its products, <a href="https://www.itpro.com/technology/blockchain" target="_blank" data-original-url="https://www.itpro.com/antivirus/28647/USKasperskyBan">including by the US government</a>, while the UK's national infosecurity authority has recommended government bodies avoid using Russian antivirus tools.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29963/parliaments-intelligence-committee-considering-russia-investigation" data-original-url="/security/29963/parliaments-intelligence-committee-considering-russia-investigation">Parliament's intelligence committee considering Russia investigation</a> Kaspersky’s attempt to overturn US government ban thrown out of court <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak" data-original-url="/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak">Kaspersky claims pirated Office software was behind NSA exploit leak</a></p></div></div><p>Kaspersky's top prize reward those finding 'remote code execution' bugs that allow malware to take over a user's system by using Kaspersky's automatic database update channel. The discovery of any other remote execution bugs will be eligible for rewards between $5,000 and $20,000 depending on their severity, while bugs allowing for elevation of privileges, or the leak of sensitive data, can be worth up to $5,000.</p><p>The new scheme is applicable to any vulnerabilities found in Kaspersky Internet Security 2019 and Kaspersky Endpoint Security 11, running on the desktop version of Windows 8.1 or later.</p><p>CEO Eugene Kaspersky said: "Finding and fixing bugs is a priority for us as a software company. We invite security researchers to make sure there are no vulnerabilities in our products. The immunity of our code and highest levels of protection that we offer customers is a core principal of our business - and a fundamental pillar of our Global Transparency Initiative."</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/971011134764584960"></a></p></blockquote><div class="see-more__filter"></div></div><p>Kaspersky has worked alongside bug bounty coordination platform Hackerone since the launch of the scheme in 2016, resulting in 70 bug reports qualifying for rewards.</p><p>The company's Global Transparency Initiative, announced in October last year, was an attempt to prove to the international security community that it was working to maintain the integrity of its software and rebuke claims that its tools could be unwittingly exploited by the Russian government to target foreign states.</p><p>As part of that initiatives launch, Kaspersky invited independent security analysts to review the source code in its products, and upped its bug bounty to $75,000. The results of that review have yet to be released, but the company has said it will share those with <em>IT Pro</em> when they are available.</p><p>Since then, the US government has moved to make it illegal to use Kaspersky software in any department or agency of the federal government, prompting <a href="https://www.itpro.com/technology/blockchain" target="_blank" data-original-url="https://www.itpro.com/antivirus/28647/USKasperskyBan">a legal challenge</a> from the antivirus firm after it claimed the decision harmed its reputation and commercial operations.</p><p>The UK's National Cyber Security Centre issued warnings to government departments in December advising they ditch Kaspersky products, as well as other Russian antivirus tools, as they pose a potential risk to national security.</p><p>Kaspersky has always maintained its innocence and independence from the Russian government.</p><p><em>Picture: Bigstock</em></p><p><strong>04/12/2017:NCSC: Kaspersky antivirus could risk national security</strong></p><p>The UK's National Cyber Security Centre (NCSC) has issued fresh warnings to all government departments against using Russian-based antivirus software, as fears mount that they could pose a risk to national security.</p><p>Official <a href="https://www.ncsc.gov.uk/guidance/managing-risk-cloud-enabled-products" target="_blank">NCSC advice</a>, updated over the weekend, claims that software such as Kaspersky Lab's antivirus suite could be exploited by the Russian government, at a time when the company is being investigated in the US.</p><p>Although the company denies any wrongdoing or any ties with Moscow, and <a href="https://www.itpro.com/technology/blockchain" target="_blank" data-original-url="https://www.itpro.com/antivirus/28647/USKasperskyBan">planned to open up its source code for independent review</a>, the US has since moved to ban the software from all government departments.</p><p>The source code review is currently ongoing, although the company has stated it would update<em>IT Pro</em>with the findings when they are available.</p><p>Until now, the UK government has been quiet about its use of Russian-based products, however, <a href="https://www.ncsc.gov.uk/information/letter-permanent-secretaries-regarding-issue-supply-chain-risk-cloud-based-products" target="_blank">in a letter</a> addressed to department secretaries last Friday, NCSC CEO Ciaran Martin said that Russian products "should not be chosen".</p><p>"The NCSC advises that Russia is a highly capable cyber threat actor which uses cyber as a tool of statecraft," he wrote. "This includes espionage, disruption and influence operations. Russia has the intent to target UK central government and the UK's critical national infrastructure."</p><p>The advice, which also provides guidance for <a href="https://www.ncsc.gov.uk/blog-post/managing-supply-chain-risk-cloud-enabled-products" target="_blank">best security practices</a> with cloud services, suggests that the government is willing to work alongside the likes of Kaspersky rather than seek an outright ban.</p><p>"We are in discussions with Kaspersky Lab, by far the largest Russian player in the UK, about whether we can develop a framework that we and others can independently verify, which would give the government assurance about the security of their involvement in the wider UK market," the letter added.</p><p>It added that the initial guidance was only aimed at central government departments, and it doesn't recommend any action in by public bodies outside of Westminster, nor does it suggest companies or the public stop using Kaspersky products.</p><p>However, as a result of the updated guidelines, Barclays has stopped offering the option of free Kaspersky software to its new customers as a "precautionary decision", and has advised those who have yet to install the suite to look for an alternative provider.</p><p>"Even though this new guidance isn't directed at members of the public, we have taken the decision to withdraw the offer," said a Barclays spokesperson, speaking to the <a href="http://www.bbc.co.uk/news/uk-42202191" target="_blank"><em>BBC</em></a>.</p><p>A spokesperson for Kaspersky Lab told <em>IT Pro</em> that the company was "disappointed" by Barclay's decision to discontinue giving free versions of its software to new customers, although was keen to reiterate that the NCSC is not discouraging people from using its products.</p><p>Simon Edwards, European cyber security architect at Trend Micro, said that any vulnerability in antivirus products is likely to be targeted at government, rather than the public.</p><p>"Reading into the research carried out by the US, it would seem that the vulnerability posed by Kaspersky was one that could only be used by the most sophisticated of attackers (i.e. state-sponsored)," said Edwards, speaking to <em>IT Pro</em>. "Therefore, if the organisation feels that they could be targeted by such a threat actor (i.e. government agencies), then there is a potential risk that should be addressed."</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/936945686779715584"></a></p></blockquote><div class="see-more__filter"></div></div><p>The NCSC's new stance comes a week after the newly formed Intelligence and Security Committee <a href="https://www.itpro.com/security/29963/parliaments-intelligence-committee-considering-russia-investigation" target="_blank" data-original-url="https://www.itpro.com/security/29963/parliaments-intelligence-committee-considering-russia-investigation">announced</a> it was considering launching an investigation into Russian meddling against the UK.</p><p>Many MPs, including Labour's Mary Creagh, have suggested that Russia was behind a series of fake social media accounts created to try and influence the Brexit referendum result by spreading fake news.</p><p>CEO Eugene Kaspersky said in a tweet: "Let me stress: there is *no* ban for KL products in the UK. We are in touch with <a href="https://twitter.com/ncsc" dir="ltr" target="_blank">@NCSC</a> regarding our Transparency Initiative and I am sure we will find the way to work together."</p><p>This initiative involves openingthree "Transparency Centres" in Asia, Europe and the US by 2020.</p><p><em>Picture: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Flaw in Telegram app could spread malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/30525/flaw-in-telegram-app-could-spread-malware</link>
                                                                            <description>
                            <![CDATA[ Multipurpose malware delivered to desktops to carry out cryptocurrency mining ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qECKfxwLDQ3aALi6VPQ643</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Yq7K6GpcaqC9RfbMAbLFDQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 13 Feb 2018 12:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Yq7K6GpcaqC9RfbMAbLFDQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware under a magnifying glass]]></media:description>                                                            <media:text><![CDATA[Malware under a magnifying glass]]></media:text>
                                <media:title type="plain"><![CDATA[Malware under a magnifying glass]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Yq7K6GpcaqC9RfbMAbLFDQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have discovered a zero-day flaw in the Telegram desktop app that could enable hackers to infect systems with malware that can be used either as a backdoor or to mine cryptocurrency.</p><p>According to researchers at Kaspersky Labs, the vulnerability has been actively exploited since March 2017 for the cryptocurrency mining functionality, mining currencies such as Monero and Zcash.</p><p>Researchers said that the Telegram zero-day vulnerability was based on the RLO (right-to-left override) unicode method. It is generally used for coding languages that are written from right to left, like Arabic or Hebrew. Besides that, however, it can also be used by malware creators to mislead users into downloading malicious files disguised, for example, as images.</p><p>Hackers used a hidden unicode character in the file name that reversed the order of the characters, thus renaming the file itself. As a result, users downloaded hidden malware which was then installed on their systems. Kaspersky Lab said it had reported the vulnerability to Telegram and, at the time of publication, the zero-day flaw has not since been observed in the products.</p><p>Researchers also found several scenarios of zero-day exploitation in the wild by threat actors. The vulnerability was exploited to deliver cryptocurrency mining malware to mine several types of cryptocurrency including Monero, Zcash, Fantomcoin and others. While analysing criminals' servers, researchers found archives containing a Telegram local cache that had been stolen from victims.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining" data-original-url="/digital-currency/30249/what-is-cryptocurrency-mining">What is cryptocurrency mining?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/networking/25627/im-app-telegram-shuts-down-78-isis-accounts" data-original-url="/networking/25627/im-app-telegram-shuts-down-78-isis-accounts">IM app Telegram shuts down 78 ISIS accounts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/digital-currency/30516/cryptocurrency-miners-the-latest-tool-for-cyber-criminals" data-original-url="/digital-currency/30516/cryptocurrency-miners-the-latest-tool-for-cyber-criminals">Cryptocurrency miners: the latest tool for cyber criminals</a></p></div></div><p>Kaspersky also said that upon successful exploitation of the vulnerability, a backdoor that used the Telegram API as a command and control protocol was installed, resulting in criminals gaining remote access to the victim's computer. After installation, it started to operate in a silent mode, which allowed hackers to remain unnoticed in the network and execute different commands including the further installation of spyware tools.</p><p>Researchers said that artefacts discovered during the research indicate that the malware is Russian in origin.</p><p>"The popularity of instant messenger services is incredibly high, and it's extremely important that developers provide proper protection for their users so that they don't become easy targets for criminals," said Alexey Firsh, malware analyst, Targeted Attacks Research at Kaspersky Lab.</p><p>"We have found several scenarios of this zero-day exploitation that, besides general malware and spyware, was used to deliver mining software such infections have become a global trend that we have seen throughout the last year. Furthermore, we believe there were other ways to abuse this zero-day vulnerability."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Third-party cyber security breaches 'cost enterprises £1.3m' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29873/third-party-cyber-security-breaches-cost-enterprises-13m</link>
                                                                            <description>
                            <![CDATA[ Kaspersky warns third-party IT suppliers are your biggest business risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4Ww1e8fHFdjdwsPunrDhSw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/G3hDdZ7EVEA5669KdffBPQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Nov 2017 10:27:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Roland Moore-Colyer ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/G3hDdZ7EVEA5669KdffBPQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Open padlock on circuit board]]></media:description>                                                            <media:text><![CDATA[Open padlock on circuit board]]></media:text>
                                <media:title type="plain"><![CDATA[Open padlock on circuit board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/G3hDdZ7EVEA5669KdffBPQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak" target="_blank" data-original-url="https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak"></a><a href="https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak" target="_blank" data-original-url="https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak">Security firm Kaspersky Lab</a> has warned that cyber attacks against third-party IT services suppliers are costing enterprises 1.3 million a year.</p><p>The issues stems from vulnerabilities or poor cyber security in third-parties' infrastructure and the services they provide, which when breached affects both the supplier and their customers.</p><p>Security breaches in third-party infrastructure alone cost enterprises around 1.2 million, Kaspersky said.</p><p>"Raising IT security budgets is only part of the solution, as the most staggering losses stem from the incidents involving third parties and their cyber-failures," said Alessio Aceti, head of the enterprise business division at Kaspersky Lab.</p><p>"While cyber security incidents involving third parties prove to be harmful to businesses of all sizes, their financial impact on a company has the potential to result in twice as much damage.</p><p>"This is because of a wider global challenge with threats moving fast, but businesses and legislation changing slowly. When regulations like GDPR become enforceable and catch up with businesses before they manage to update their policies, the fines for non-compliance will further add to the bill."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/627976/kaspersky-on-getting-hacked" data-original-url="/627976/kaspersky-on-getting-hacked">Kaspersky on getting hacked</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29630/the-future-of-cyber-security" data-original-url="/security/29630/the-future-of-cyber-security">The future of cyber security</a></p></div></div><p>And the situation is potentially set to get more complex as governments across the globe push to introduce new legislation on data regulation and cyber security.</p><p>Kaspersky also pointed out that despite cyber security receiving a higher proportion of IT budgets, overall budgets for technology have come down, which could mean that investment in cyber security software and services is actually being reduced.</p><p>This can be seen as concerning given the cost of security and <a href="https://www.itpro.com/security/29839/heathrow-airport-investigates-usb-stick-security-breach" target="_blank" data-original-url="https://www.itpro.com/security/29839/heathrow-airport-investigates-usb-stick-security-breach">data breaches to an enterprise</a> has gone up, according to Kaspersky.</p><p>All this suggests that companies investing in security should proceed with caution, making sure the services they procure and use are robust enough to resist and recover from cyber attacks. And they should remember that investment in security services is far less costly than dealing with the consequences of a cyber attack or data breach.</p><p><em>Picture: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>