<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/nsa" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Nsa ]]></title>
                <link>https://www.itpro.com/tag/nsa</link>
        <description><![CDATA[ All the latest nsa content from the ITPro team ]]></description>
                                    <lastBuildDate>Mon, 02 Feb 2026 12:40:40 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ What security teams need to know about the NSA's new zero trust guidelines ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/what-security-teams-need-to-know-about-the-nsas-new-zero-trust-guidelines</link>
                                                                            <description>
                            <![CDATA[ The new guidelines aim to move an organization from discovery to target-level implementation of zero trust practices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Y5v4AuNEvJ47NT68HRhdQ6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/g5X65gMXSQmxvDLDVikQVH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Feb 2026 12:40:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/g5X65gMXSQmxvDLDVikQVH-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo and insignia of the United States National Security Agency (NSA) pictured on a smartphone screen held in hand above a laptop keyboard and screen.]]></media:description>                                                            <media:text><![CDATA[Logo and insignia of the United States National Security Agency (NSA) pictured on a smartphone screen held in hand above a laptop keyboard and screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo and insignia of the United States National Security Agency (NSA) pictured on a smartphone screen held in hand above a laptop keyboard and screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/g5X65gMXSQmxvDLDVikQVH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US National Security Agency (NSA) has released Phase One and Phase Two of its Zero Trust Implementation Guidelines.</p><p>The <a href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4393480/nsa-releases-phase-one-and-phase-two-of-the-zero-trust-implementation-guidelines/" target="_blank"><u>guidelines</u></a> cover what's needed to achieve the Department of War's (DoW) targets for <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero trust</a> maturity. </p><p>Phase One and Phase Two aim to move an organization from discovery to target-level implementation by mapping out the activities, requirements, precursors and successors that are needed. </p><p>According to the NSA, the phased design of the guidelines means they're modular and highly customizable, allowing the implementation of both foundational and advanced activities, as well as the ability to tailor them to align with individual goals and constraints.</p><p>They build on the NSA's Primer and Discovery Phases, released earlier this month, and are aligned with existing federal frameworks, including the DoW CIO’s Zero Trust Framework.</p><h2 id="what-the-zero-trust-guidelines-get-right">What the zero trust guidelines get right</h2><p>Brian Soby, <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO </a>and co-founder of AppOmni, said there's a lot that the guidelines get right, adding that the move represents a positive step in helping organizations shore up <a href="https://www.itpro.com/security/identity-security-is-more-important-than-ever-heres-why">identity security</a>. </p><p>"The guidance pushes maturity beyond 'authenticate, then trust', toward ongoing decisions driven by what the user is doing, what privileges are being requested, and what resources are being touched," he said. </p><p>"That matters because the attacks that are winning right now are post-auth. Device posture and login checks are necessary, but against modern SaaS compromise they can be largely performative if you cannot detect abuse happening inside the session, inside the application."</p><p>Soby also praised the way that zero trust is presented as an operating model, not a product. </p><p>Policies are required to be centrally defined, consistently applied, continuously assessed, and enforced through co-ordinated policy decision points and policy enforcement points. </p><p>This includes requirements for real-time monitoring and automation to adapt as conditions change.  </p><p>When it comes to User and Entity Behavior Analytics (UEBA), Soby noted the guidance takes the right approach, focusing on behavior baselining, analytics, and context enrichment so that anomalies are detected based on behavioral patterns and resource access, not just simplistic indicators like login location.</p><p>"That's the right direction. ‘We saw a new IP’ is a weak signal,” he commented. “The higher-signal story is what happened in the application: Privilege use, data access, configuration changes, creation of integrations, unusual exports, and lateral movement across <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS </a>capabilities. </p><p>"The higher-signal story is what happened in the application: Privilege use, data access, configuration changes, creation of integrations, unusual exports, and lateral movement across SaaS capabilities."</p><h2 id="why-some-zero-trust-efforts-fall-flat">Why some zero trust efforts fall flat</h2><p>Soby warned that most zero trust implementation projects are missing the core points. A key factor here is that they focus too heavily on <a href="https://www.itpro.com/security/what-is-zero-trust-network-access-ztna">zero trust network access (ZTNA)</a> considerations, and ZTNA-only architectures are often easier to bypass.</p><p>Meanwhile, organizations fail to recognize that each application is its own policy decision point and policy enforcement point.</p><p>“This is the core point that gets ignored. The guidance treats policy decision points and policy enforcement points as essential building blocks that must be coordinated. The problem is that many organizations pretend the only real decision and enforcement happens at the identity provider or a proxy," he said. </p><p>"In reality, every application, SaaS or otherwise, is itself a policy decision point and policy enforcement point. The application decides what a user, integration, service account, or agent can do, and it enforces that decision.”</p><p>Soby noted this is “especially true” in cases where identities don’t “traverse the enterprise front door” - for example, with customers, partners, and external collaborators. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ten cloud security tips every IT leader should know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/10-cloud-security-tips-every-it-leader-should-know</link>
                                                                            <description>
                            <![CDATA[ Cloud security threats have increased dramatically in recent years - these steps could help keep threat actors at bay ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HGb6dURAaDtkXBDvZrnrV8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nYTQnscZmBWjF97ciGDC9T-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Mar 2024 05:00:56 +0000</pubDate>                                                                                                                                <updated>Thu, 11 Apr 2024 08:40:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Ranger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gFeXmAxutpTpGN7c98ZAwJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nYTQnscZmBWjF97ciGDC9T-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud security concept image showing digitized cloud symbol on a circuit board with data flowing out of the cloud.]]></media:description>                                                            <media:text><![CDATA[Cloud security concept image showing digitized cloud symbol on a circuit board with data flowing out of the cloud.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud security concept image showing digitized cloud symbol on a circuit board with data flowing out of the cloud.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nYTQnscZmBWjF97ciGDC9T-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US National Security Agency (NSA) has released a cloud security guide aimed at helping organizations protect themselves against a growing wave of threats. </p><p><a href="https://www.itpro.com/627952/what-is-cloud-computing">Cloud computing</a> continues to grow as organizations move their applications and data out of their own <a href="https://www.itpro.com/infrastructure/data-centres">data centers</a> and into the cloud. </p><p>Research from Gartner predicts that, by 2028, as much as 70% of IT workloads will be running in a cloud environment, up from just 25% in 2023.</p><p>While cloud computing can be <a href="https://www.itpro.com/software/fast-code-or-secure-code-you-cant-have-both">more secure than applications hosted on-premise</a>, that doesn’t mean it is without its own particular risks, which are often underestimated.</p><h2 id="cloud-security-tips-you-need-to-know">Cloud security tips you need to know</h2><p>As organizations continue to migrate more of their data and services to cloud environments, attackers will increasingly attempt to compromise those environments, the agency said.</p><p>“Using the cloud can make IT more efficient and more secure, but only if it is implemented right,” said Rob Joyce, NSA’s Director of Cybersecurity.</p><p>“Unfortunately, the aggregation of critical data makes cloud services an attractive target for adversaries.”</p><p>The NSA’s top ten cloud security mitigation strategies aim to inform cloud customers of the most important practices they can adopt.</p><h3 class="article-body__section" id="section-understand-who-is-responsible-for-security"><span>Understand who is responsible for security</span></h3><p>Problems can arise when customers assume the cloud service provider (CSP) is securing something – when it’s actually the customer’s job. The NSA said customers must understand the CSP’s shared responsibility model which identifies who is responsible for security.</p><p>That model will vary from service to service (it may be different for <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS</a>, <a href="https://www.itpro.com/cloud/platform-as-a-service-paas/362593/what-is-paas">PaaS</a>, or <a href="https://www.itpro.com/cloud/infrastructure-as-a-service-iaas/362605/what-is-iaas">IaaS</a>) and will also vary by supplier, so pay close attention to documentation.</p><p>“Direct engagement with the CSP may sometimes be necessary to understand their service,” the NSA notes.</p><h3 class="article-body__section" id="section-secure-your-accounts"><span>Secure your accounts</span></h3><p><a href="https://www.itpro.com/security/identity-and-access-management-iam/358827/what-is-customer-identity-and-access-management">Identity and access management</a> (IAM) are critical to securing cloud resources. </p><p>Attackers will attempt to gain access to cloud services in many ways, perhaps by using phishing techniques to steal passwords, or by scooping up exposed credentials, or by beating weak authentication practices.</p><p>Once in, they can use over-generous account privileges to get further into the system.</p><p>To prevent this, cloud users should use identity and access management technologies including multifactor authentication and properly managed temporary credentials.</p><p>“Access control policies should be carefully configured to ensure users are granted the least privileges necessary,” the NSA said.</p><h3 class="article-body__section" id="section-think-about-your-key-management"><span>Think about your key management</span></h3><p>Cloud suppliers will offer a number of ways of handling key management. </p><p>These can range from relying on the cloud vendor for fully delegated server-side encryption, to a full <a href="https://www.itpro.com/security/370143/what-you-need-to-know-about-googles-new-client-side-encryption-gmail">client-side encryption</a> method: often organizations will rely on the CSP for at least a portion of key management, <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">encryption</a>, and decryption.</p><p>Whichever route they choose, users need to understand the risks and benefits to each option and their roles and responsibilities.</p><h3 class="article-body__section" id="section-use-network-segmentation-and-encryption"><span>Use network segmentation and encryption</span></h3><p>The NSA said that <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">Zero Trust</a> network security practices should be used to protect organizational data.</p><p>End-to-end encryption of all data in transit to, from, and within the cloud is also key to protecting data in the cloud, the recommendations said.</p><p>“Be aware that data passed between customer resources in the cloud may traverse the internet, and take precautions to encrypt such data,” the guidance said.</p><h3 class="article-body__section" id="section-concentrate-on-data-security-in-the-cloud"><span>Concentrate on data security in the cloud</span></h3><p>Data stored in the cloud can be an attractive target for attackers looking either to steal or ransom it. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LE525phAaz3QtGZPb6iZXV" name="Cloud-enabled manufacturing_listing.jpg" caption="" alt="A whitepaper with blue industrial image on cover, on how to achieve cloud-enabled manufacturing" src="https://cdn.mos.cms.futurecdn.net/LE525phAaz3QtGZPb6iZXV.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-management/cloud-enabled-manufacturing"><strong>Develop an outcome-driven approach to cloud-based manufacturing</strong></a></p></div></div><p>That means using encryption and data access policies such as role-based access control and attribute-based access controls to protect information.</p><p>Both user and system accounts should only be given the minimal level of access needed to perform tasks by their cloud administrators, the NSA guidance said.</p><p>“Object storage is one of the most exploited data storage methods because of its popularity and how easily it can be misconfigured. Applying proper access policies to Object storage will prevent unintentional data exposure,” it said.</p><p>The NSA said organizations should consider enabling “soft delete” features to reduce the impact of accidental or malicious deletions.</p><h3 class="article-body__section" id="section-don-t-forget-your-software-pipeline"><span>Don’t forget your software pipeline</span></h3><p>Continuous integration and continuous delivery (CI/CD) pipelines are frequently deployed in the cloud, which makes them highly valuable targets for attackers.  </p><p>Organizations should make sure they are using strong identity and access management policies, keeping tools up to date, auditing logs and implementing security scanning.</p><h3 class="article-body__section" id="section-think-about-implementing-infrastructure-as-code"><span>Think about implementing Infrastructure as Code</span></h3><p>Infrastructure as Code (IaC) automates the deployment of cloud resources and this can reduce the chance of misconfigurations and “ghost assets” introduced by human error, the agency said. </p><p>After deploying IaC, organizations should dynamically test deployed resources, ensure access and version controls are enabled, avoid manual changes, and continuously log and monitor resources, the NSA said.</p><h3 class="article-body__section" id="section-remember-the-added-complication-of-hybrid-multi-cloud"><span>Remember the added complication of hybrid multi-cloud</span></h3><p><a href="https://www.itpro.com/hybrid-cloud/29668/what-is-hybrid-cloud">Hybrid cloud</a> and <a href="https://www.itpro.com/cloud/34476/what-is-multi-cloud">multi-cloud</a> environments bring a new set of security challenges with them. </p><p>The risk is that using multiple clouds creates silos and <a href="https://www.itpro.com/business-strategy/careers-training/368825/how-can-cios-help-to-close-the-tech-skills-gap">skill gaps</a>, which may lead to “configuration discrepancies, unnecessary data flows, insecure IAM, loss of visibility, and exploitable security gaps,” the NSA said.</p><p>The agency added that standardizing vendor-agnostic cloud tools helps organizations to maintain and monitor multiple environments.</p><h3 class="article-body__section" id="section-be-aware-of-managed-service-provider-msp-security-risks"><span>Be aware of Managed Service Provider (MSP) security risks</span></h3><p>Using an MSP effectively increases an organization’s attack surface, so you need to make sure that security is a priority when choosing an MSP. </p><p>That means picking providers that comply with the security standards and practices important to you. Organizations should audit MSP accounts and operations in the environment, with a focus on privileged accounts.</p><h3 class="article-body__section" id="section-use-cloud-logs-to-spot-trouble"><span>Use cloud logs to spot trouble</span></h3><p>Cloud systems involve many users accessing shared resources and services. This can make it hard for defenders to see what is really going on. </p><p>But while cloud services do offer logging services, their default settings vary, so it’s important to make sure these are configured so that hackers cannot roam with impunity.</p><p>The NSA said security professionals can use tools, such as security information and event management (SIEM) systems, log analysis software, and anomaly detection services, to analyze the logs for indicators of compromise.</p><p>That might include unusual login attempts, network traffic patterns, and anomalous system events.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are lying low in networks to wage critical infrastructure attacks - here’s how they do it ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hackers-are-lying-low-in-networks-to-wage-critical-infrastructure-attacks-heres-how-they-do-it</link>
                                                                            <description>
                            <![CDATA[ Hackers are researching key IT workers in their bid to gain access to vital systems ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ikan2R37XrSC4LeXH32pDc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YyGBvWw3cPHjSsLW3VAW9B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 10 Feb 2024 04:00:38 +0000</pubDate>                                                                                                                                <updated>Wed, 27 Mar 2024 11:41:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Ranger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gFeXmAxutpTpGN7c98ZAwJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YyGBvWw3cPHjSsLW3VAW9B-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber security concept art showing a virtual circuit board with a shield symbol]]></media:description>                                                            <media:text><![CDATA[Cyber security concept art showing a virtual circuit board with a shield symbol]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber security concept art showing a virtual circuit board with a shield symbol]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YyGBvWw3cPHjSsLW3VAW9B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers backed by China are breaking into the networks of US companies so they are able to launch destructive cyber attacks against critical infrastructure in the event of a major crisis or conflict.</p><p>In their attempts to gain access to systems the attackers are paying particular attention to network and IT staff who often hold the keys to the system.</p><p>The warning from the National Security Agency (NSA), FBI and the US Cybersecurity and Infrastructure Agency (CISA) is a remarkably detailed breakdown of how a Chinese state-backed group, known as Volt Typhoon, has compromised the networks of multiple critical infrastructure organizations across communications, energy, transportation systems, and water sectors.</p><p>The agencies said the hackers had maintained their access and footholds within some network for “at least” five years. Some victim companies are smaller organizations with few security skills, which provide critical services to larger organizations.</p><p>The hackers’ targets and behavior isn’t typical of cyber espionage or intelligence gathering operations, the agencies said – leading them to believe that the hackers are instead positioning themselves so they can disrupt operations across critical infrastructure in the event of potential geopolitical tensions or military conflicts with China.</p><p>What is striking about this is how careful they are and how much research they do.</p><p>According to the advisory, the <a href="https://www.itpro.com/security/why-cisa-is-extending-cyber-support-to-resource-poor-organizations">Volt Typhoon</a> group conducts extensive pre-compromise reconnaissance to learn about the target organization, its network, and its staff.</p><p>That includes searches for network information and “especially for information on key network and IT administrators”. In some instances, the agencies said they had observed <a href="https://www.itpro.com/security/cyber-attacks/asus-cisco-netgear-devices-exploited-in-ongoing-chinese-hacking-campaign">Volt Typhoon</a> actors targeting the personal emails of key network and <a href="https://www.itpro.com/business/uk-it-staff-working-nearly-as-much-overtime-as-law-enforcement">IT staff</a>.</p><p>They said the hackers have been observed strategically targeting the web browsing data of network administrators, “focusing on both browsing history and stored credentials” to help them target personal email addresses for further information – for example to discover any possible network modifications that may impact the threat actor’s persistence within victim networks.</p><p>The reconnaissance the attackers conduct helps them to gain access and also helps them avoid scrutiny.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Worpszw9DBAJpegyshYd5C" name="Secure access to private applications in AWS.jpg" caption="" alt="Secure access to private applications in AWS whitepaper" src="https://cdn.mos.cms.futurecdn.net/Worpszw9DBAJpegyshYd5C.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Netskope)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/secure-access-to-private-applications-in-aws"><em>Provide workers with a more secure way to access business-critical applications</em></a></p></div></div><p>“The intelligence gathered by Volt Typhoon actors is likely leveraged to enhance their operational security. For example, in some instances, Volt Typhoon actors may have abstained from using compromised credentials outside of normal working hours to avoid triggering security alerts on abnormal account activities,” the agencies said.</p><p>Targeting the accounts of IT staff is a common tactic for hackers because these accounts usually have much wider access than standard user accounts; this is why administrator accounts are usually more carefully protected by techniques such as multifactor authentication.</p><p>However, the level of research being done in these attacks reflects how this group is working to a different agenda to many others - and is a reminder to all organizations to make sure they have protection in place across these accounts.</p><p>The advisory said organizations should deliver security training tailored to network IT personnel/administrators and other key staff.</p><p>“For example, communicate that Volt Typhoon actors are known to target personal email accounts of IT staff, and encourage staff to protect their personal email accounts by using strong passwords and implementing <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">MFA</a>,” it said.</p><p>The advisory also gives more detail on how the hackers achieve their access to the networks and manage to stay hidden so long.</p><p>They gain initial access to the network by exploiting known or zero-day vulnerabilities in public-facing network appliances. These flaws might be in <a href="https://www.itpro.com/networking/27835/best-wi-fi-routers">routers</a>, virtual private networks and firewalls. After this they connect to the victim’s network via <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368117/best-enterprise-vpn-of-2022">VPN</a> for follow-on activities.</p><p>In particular, the hackers want to gain administrator credentials within the network. They often do this by exploiting privilege escalation vulnerabilities in the operating system or network services, or by stealing credentials unwisely stored on a public-facing network appliance.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="j3qKLuBJWSTwFybkYhYiMH" name="Security_Alert_Stock_Image_GettyImages-1403439566 (1).jpg" caption="" alt="Warning symbol in yellow pictured on a digital blue background signifying a security alert" src="https://cdn.mos.cms.futurecdn.net/j3qKLuBJWSTwFybkYhYiMH.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/office-staff-think-theyre-in-safe-hands-with-cyber-security-teams-but-communication-could-be-better">Office staff think they’re in safe hands with cyber security teams, but communication could be better</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/the-verizon-data-breach-that-exposed-63000-employees-is-a-reminder-of-how-a-simple-mistake-can-have-costly-implications">The Verizon data breach that exposed 63,000 employees is a reminder of how a simple mistake can have costly implications</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-hidden-cost-of-ransomware-is-more-painful-than-many-realize">The hidden cost of ransomware is more painful than many realize</a></p></div></div><p>The attackers try to find out more about the network including the “discreet extraction” of security event logs and the <a href="https://www.itpro.com/uk/tag/active-directory">Active Directory</a> database which contains data on user accounts, passwords in hashed form, and other sensitive data. They probably then use offline password cracking techniques to decipher these hashes, in order to gain further network access.</p><p>The agencies said the hackers are focused on gaining access to operational technology assets.</p><p>“This access enables potential disruptions, such as manipulating heating, ventilation, and air conditioning (HVAC) systems in server rooms or disrupting critical energy and water controls, leading to significant infrastructure failures (in some cases, Volt Typhoon actors had the capability to access camera surveillance systems at critical infrastructure facilities).”</p><p>The group is careful to stay hidden, limiting their activity after breaking inn, “suggesting their objective is to maintain persistence rather than immediate exploitation,” the advisory said, with the hackers revisiting targets over a number of years to confirm their access.</p><p>In one incident at an organization in the water industry, the attackers connected to the network via a VPN with administrator credentials they obtained and opened an RDP session with the same credentials to move laterally.</p><p>Over a nine-month period, they moved to a file server, a domain controller, an Oracle Management Server, and a <a href="https://www.itpro.com/security/everything-you-need-to-know-about-the-vmware-vcenter-server-vulnerability">VMware vCenter</a> server. The aim was, most likely, to gain access to the nearby operational technology assets involved with water treatment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ASUS, Cisco, Netgear devices exploited in ongoing Chinese hacking campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/asus-cisco-netgear-devices-exploited-in-ongoing-chinese-hacking-campaign</link>
                                                                            <description>
                            <![CDATA[ Critical national infrastructure is the target of sustained attempts from state-sponsored hackers, according to Five Eyes advisories ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4rZgNYQA8qHZazZPioTpAW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FRayTvQKar4rQVZNj8Mzrf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 May 2023 09:53:27 +0000</pubDate>                                                                                                                                <updated>Thu, 25 May 2023 11:31:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FRayTvQKar4rQVZNj8Mzrf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Black laptop being used by a person out of shot, denoting an anonymous hacker, against a bright backdrop of a Chinese flag]]></media:description>                                                            <media:text><![CDATA[Black laptop being used by a person out of shot, denoting an anonymous hacker, against a bright backdrop of a Chinese flag]]></media:text>
                                <media:title type="plain"><![CDATA[Black laptop being used by a person out of shot, denoting an anonymous hacker, against a bright backdrop of a Chinese flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FRayTvQKar4rQVZNj8Mzrf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations globally have been urged to remain vigilant amid an ongoing hacking campaign that leverages office networking devices to target critical national infrastructure (CNI) assets. </p><p>Research from Microsoft this week revealed that attacks carried out by Volt Typhoon, a Chinese state-sponsored group that commonly focuses on espionage and intelligence gathering, are specifically <a href="https://www.itpro.com/security/ransomware/370327/ex-ncsc-ceo-ciaran-martin-ransomware-cni"><u>targeting CNI organizations</u></a>. </p><p>Microsoft said Volt Typhoon relies “almost exclusively” on living-off-the-land (LOTL) techniques and hands-on-keyboard activity. </p><p>LOTL attacks typically see attackers compromise a victim’s system and use the systems and tools that are already installed to achieve their goals, rather than executing their own code or malware payloads, for example.</p><p>“To achieve their objective, the threat actor puts strong emphasis on stealth in this campaign,” said Microsoft, which assisted the Five Eyes investigation. </p><p>“They issue commands via the command line to (1) collect data, including credentials from local and network systems, (2) put the data into an archive file to stage it for exfiltration, and then (3) use the stolen valid credentials to maintain persistence.”</p><p>As part of the campaign, Volt Typhoon has been observed blending into normal network activity by routing traffic through compromised small office and home office (SOHO) network equipment. This includes <a href="https://www.itpro.com/infrastructure/network-internet/369507/what-is-a-router"><u>routers</u></a>, firewalls, and <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368103/best-business-vpn-in-2022"><u>VPN hardware</u></a>.</p><p>Microsoft confirmed that a number of devices, including those manufactured by ASUS, <a href="https://www.itpro.com/security/cyber-attacks/cisco-reveals-exploit-code-is-publicly-available-for-critical-switch-vulnerabilities"><u>Cisco</u></a>, D-Link, Netgear, and Zyxel are at risk and urged owners of these devices to ensure interfaces are not exposed to the public internet to mitigate threats. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YXFRHbAWK6pCoyVSsdrjKg" name="The Total Economic Impact™ of Mimecast_listing.jpg" caption="" alt="Whitepaper cover with title and green clicker board image top right" src="https://cdn.mos.cms.futurecdn.net/YXFRHbAWK6pCoyVSsdrjKg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The Total Economic Impact™ of Mimecast</strong></p><p class="fancy-box__body-text"><em>Cost savings and business benefits enabled by using Mimecast with Microsoft 365</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/359472/the-total-economic-impacttm-of-mimecast"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“Owners of network <a href="https://www.itpro.com/internet-of-things-iot/34509/how-edge-computing-can-benefit-businesses"><u>edge devices</u></a> should ensure that management interfaces are not exposed to the public internet in order to reduce their attack surface,” the firm said in a <a href="https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/" target="_blank"><u>blog post</u></a>. </p><p>“By proxying through these devices, Volt Typhoon enhances the stealth of their operations and lowers overhead costs for acquiring infrastructure.”</p><p>Marc Burnard, senior consultant for information security research at Secureworks, said that targeting network devices is a common tactic employed by threat actors such as Volt Typhoon, which is also tracked as ‘Bronze Silhouette’.</p><p>This enables the group to ‘blend in’ to network traffic and operate behind the scenes with impunity, thereby gaining a stronger foothold and compromising additional assets. </p><p>“From our first-hand <a href="https://www.secureworks.com/blog/chinese-cyberespionage-group-bronze-silhouette-targets-us-government-and-defense-organizations" target="_blank"><u>observations</u></a>, we determine the group to have a consistent focus on operational security including a minimal intrusion footprint, defense evasion techniques, and use of compromised infrastructure,” he said. </p><p>“Think of a spy going undercover, their goal is to blend in and go unnoticed. This is exactly what Bronze Silhouette does by mimicking usual network activity.”</p><p>Burnard added that these tactics highlight the group’s “operational maturity and adherence to a modus operandi” that focuses specifically on reducing the likelihood of detection. </p><h2 id="five-eyes-response-to-chinese-hacking-threat">Five Eyes response to Chinese hacking threat</h2><p>The campaign by Volt Typhoon has prompted Five Eyes security agencies to issue an urgent warning to critical infrastructure organizations. </p><p>The UK’s National Cyber Security Centre (NCSC) issued a joint statement with the equivalent authorities from the US, Canada, Australia, and New Zealand calling for heightened vigilance amid the ongoing attacks. </p><p>“It is vital that operators of critical national infrastructure take action to prevent attackers hiding on their systems, as described in this joint advisory with our international partners,” said Paul Chichester, director of operations at the NCSC. </p><p>“We strongly encourage UK essential service providers to follow our guidance to help detect this malicious activity and prevent persistent compromise.”</p><p>According to Microsoft, the purpose of the campaign by Volt Typhoon appears to have broader geopolitical goals amid rising tensions between the US and China. </p><p>The group has been active since mid-2021, the firm revealed, and has already targeted critical infrastructure organizations in the United States and Guam, a key site for US military activities in the Pacific. </p><p>“Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US reveals bespoke tool that took down Russian malware operation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/us-reveals-bespoke-tool-that-took-down-russian-malware-operation</link>
                                                                            <description>
                            <![CDATA[ Snake had been used to steal NATO countries’ data for 20 years ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">H94cnpW3JDSQ2e9PusRHoD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BuNf6dqPhYc8MnEixdbo79-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 May 2023 12:02:00 +0000</pubDate>                                                                                                                                <updated>Wed, 17 May 2023 13:44:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BuNf6dqPhYc8MnEixdbo79-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A green snake coiling out of a tree stares down the lens]]></media:description>                                                            <media:text><![CDATA[A green snake coiling out of a tree stares down the lens]]></media:text>
                                <media:title type="plain"><![CDATA[A green snake coiling out of a tree stares down the lens]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BuNf6dqPhYc8MnEixdbo79-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Department of Justice (DoJ) has revealed details of a joint operation in which Western agencies used a custom tool to destroy a decades-old Russian malware operation.</p><p>Use of a tool named ‘PERSEUS’ nullified a worldwide network of devices that had been infected with the Snake malware by threat actors in the group Turla.</p><p>A number of agencies including the NSA, FBI, and the Cybersecurity and Infrastructure Security Agency (CISA) led the operation codenamed ‘Medusa’.</p><p>Snake had been used to exfiltrate sensitive information from devices across 50 or more countries, including NATO governments and journalists, but the FBI-created PERSEUS was used to force the malware to overwrite its data without damaging infected devices.</p><p>Turla has been linked directly with the Federal Security Service of the Russian Federation (FSB) and has used Snake since 2003.</p><p>“For 20 years, the FSB has relied on the Snake malware to conduct cyber espionage against the United States and our allies – that ends today,” said Matthew G. Olsen, assistant attorney general, at the Justice Department’s National Security Division. </p><p>“The Justice Department will use every weapon in our arsenal to combat Russia’s malicious cyber activity, including neutralizing malware through high-tech operations, making innovative use of legal authorities, and working with international allies and private sector partners to amplify our collective impact.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aciHQVJDYgcjpVWvmP9mYF" name="How to reduce the risk of phishing and ransomware_listing.jpg" caption="" alt="Whitepaper cover with title over shaded green letter O" src="https://cdn.mos.cms.futurecdn.net/aciHQVJDYgcjpVWvmP9mYF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>How to reduce the risk of phishing and ransomware</strong></p><p class="fancy-box__body-text"><em>Top security concerns and tips for mitigation</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/360247/how-to-reduce-the-risk-of-phishing-and-ransomware"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Snake is able to function on Windows, macOS, and Linux under a high level of stealth, and has been operated in a tactical manner to hit specific targets.</p><p>It was found and destroyed on multiple US-based systems through a search warrant authorizing remote access to computers believed to have been compromised by the malware.</p><p>On some occasions, Turla was observed to have sent Snake to victims multiple times to ensure infection and exfiltration of data.</p><p>A joint cyber security <a href="https://media.defense.gov/2023/May/09/2003218554/-1/-1/1/JOINT_CSA_HUNTING_RU_INTEL_SNAKE_MALWARE_20230509.PDF" target="_blank"><u>advisory</u></a> by the agencies described the malware as “the most sophisticated cyber espionage tool in the FSB’s arsenal”.</p><p>The malware’s network communications are encrypted and fragmented, and it has its own <a href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security"><u>HTTP</u></a> and <a href="https://www.itpro.com/network-internet/internet-protocol-version-6-ipv6/360855/what-is-tcpip"><u>TCP</u></a> protocols that have allowed it to operate unseen on top legitimate networks.</p><p>In the wild, it has been found intercepting each client-to-server packet in a TCP session to check for Snake-specific instructions.</p><p>Snake can redirect all relevant packets to its own process function while redirecting all other packets to their respective applications to avoid detection.</p><p>Turla, based in Russia, has previously <a href="https://www.itpro.com/security/34667/russian-hacking-group-masquerades-as-iranian-spy-network"><u>hijacked Iranian cyber espionage resources</u></a> to launch masked attacks on Western victims.</p><p>Researchers at Microsoft Threat Intelligence, which tracks Turla under the name Secret Blizzard, also included findings that the group engaged in <a href="https://www.itpro.com/security/ransomware/off-the-shelf-ransomware-is-spurring-a-new-era-in-the-ukraine-war"><u>cyber warfare across Ukraine</u></a> in its <a href="https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RW10mGC" target="_blank"><u>report</u></a> marking a year since Russia’s invasion.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=53232388&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>The DoJ has urged organizations to review its joint advisory for advice on Snake detection and remediation.</p><p>It noted that a keylogger has often been deployed with Snake, which <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers"><u>hackers could use to steal passwords</u></a> even after the first malware package has been nullified.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Move away from memory-unsafe languages like C and C++, NSA urges ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/development/programming-languages/369499/move-away-from-memory-unsafe-languages-c</link>
                                                                            <description>
                            <![CDATA[ The US agency advises organisations to begin using languages like Rust, Java, and Swift ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tPS56AFfKBZzgV12gZeCQo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NWJ4mV8N7BGMLhyEAsb85U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Nov 2022 11:40:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NWJ4mV8N7BGMLhyEAsb85U-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up shot of a computer screen showing lines of programming code]]></media:description>                                                            <media:text><![CDATA[A close up shot of a computer screen showing lines of programming code]]></media:text>
                                <media:title type="plain"><![CDATA[A close up shot of a computer screen showing lines of programming code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NWJ4mV8N7BGMLhyEAsb85U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Security Agency (NSA) has recommended only using 'memory safe' languages, like C#, Go, Java, Ruby, Rust, and Swift, in order to avoid exploitable memory-based vulnerabilities.</p><p>The agency explained that memory issues in software make up a large portion of exploitable vulnerabilities. Due to this concern, the authority has advised developers to consider moving from <a href="https://www.itpro.com/careers/29133/the-top-programming-languages-you-need-to-learn" target="_blank" data-original-url="https://www.itpro.com/careers/29133/the-top-programming-languages-you-need-to-learn">programming languages</a> with little or no memory protection, like C and C++, to a memory safe language. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/368476/why-are-ransomware-gangs-pivoting-to-rust" data-original-url="/security/ransomware/368476/why-are-ransomware-gangs-pivoting-to-rust">Why are ransomware gangs pivoting to Rust?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/careers/29133/the-top-programming-languages-you-need-to-learn" data-original-url="/careers/29133/the-top-programming-languages-you-need-to-learn">The top programming languages you need to learn for 2022</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/367965/why-should-you-learn-java" data-original-url="/software/development/367965/why-should-you-learn-java">Why should you learn Java?</a></p></div></div><p>Memory-safe languages provide various degrees of memory usage protections, and the agency recommended using code hardening defences, like tool analysis or operating system configurations, as well. By doing this, many memory vulnerabilities can be prevented, mitigated, or made harder for cyber actors to take advantage of.</p><p>The US security agency underlined that exploitable <a href="https://www.itpro.com/security/exploits/360411/top-30-most-exploited-vulnerabilities" target="_blank" data-original-url="https://www.itpro.com/security/exploits/360411/top-30-most-exploited-vulnerabilities">software vulnerabilities</a> are still frequently based on memory issues. This includes overflowing a memory buffer or leveraging issues with how software allocates and deallocates memory.</p><p>Popular languages, like C or C++, provide a lot of freedom and flexibility when it comes to memory management, said the NSA. Here, the programmer must perform the checks on memory references and if they make a mistake, it can lead to exploitable memory-based vulnerabilities.</p><p>“While the use of added protections to non-memory safe languages and the use of memory safe languages do not provide absolute protection against exploitable memory issues, they do provide considerable protection,” stated the NSA. “Therefore, the overarching software community across the private sector, academia, and the US Government have begun initiatives to drive the culture of <a href="https://www.itpro.com/business-strategy/careers-training/356509/how-to-become-a-software-developer" target="_blank" data-original-url="https://www.itpro.com/business-strategy/careers-training/356509/how-to-become-a-software-developer">software development</a> towards utilising memory safe languages.”</p><p>The NSA did say software analysis tools are able to detect instances of memory management issues, while operating environment options can provide protection too. However, it underlined the protection offered by memory safe software languages can prevent or mitigate most memory management issues. </p><p>Despite the warning, however, transitioning to memory safe languages, for many businesses, is not practical. “There are trillions of lines of <a href="https://www.itpro.com/software/development/367576/low-code-vs-no-code" target="_blank" data-original-url="https://www.itpro.com/software/development/367576/low-code-vs-no-code">code</a> being used today written in C/C++ making it impossible to consider rewriting it all into a memory safe language,” said professor John Goodacre, director of the UKRI’s Digital Security by Design (DSbD) challenge and professor of computer architectures at the University of Manchester.</p><p>“Even when new code uses such languages, it's inevitable that it will be relying on code written in an unsafe language through its use of libraries or an operating system. Further, many of the higher-level languages are sandboxes by their runtime making them unsuitable for many classes of applications.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aEmv5MrbN2xZ8yZE62obSm" name="aEmv5MrbN2xZ8yZE62obSm.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/aEmv5MrbN2xZ8yZE62obSm.jpg" mos="https://cdn.mos.cms.futurecdn.net/aEmv5MrbN2xZ8yZE62obSm.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>IBM FlashSystem 5000 and 5200 for mid-market enterprises</strong></p><p class="fancy-box__body-text">Manage rapid data growth within limited IT budgets</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/server-storage/360178/ibm-flashsystem-5000-and-5200-for-mid-market-enterprises" data-original-url="/infrastructure/server-storage/360178/ibm-flashsystem-5000-and-5200-for-mid-market-enterprises">FREE DOWNLOAD</a></p></div></div><p>Goodacre explained that in DBsD, an <a href="https://www.itpro.com/business/policy-legislation/361187/new-ps2-million-scheme-will-teach-uk-tech-sector-to-fight-cyber" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/361187/new-ps2-million-scheme-will-teach-uk-tech-sector-to-fight-cyber">initiative supported by the British government</a>, a new approach known as CHERI has been applied to both Arm and Risc-V prototype chips. He said this makes the hardware itself memory safe and brings memory safety to existing software and offers resilience and security features for new code.</p><p>“The risk from memory unsafe code is significant with around 70% of ongoing reported vulnerabilities rooted in such issues,” said Goodacre. “Moving to CHERI enabled hardware will not only block exploitation of these memory safety vulnerabilities, but it also offers developers new capabilities that reduce the risk that bugs find their way into production, increasing developer productivity.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US gov issues fresh warning over Russian threat to critical infrastructure  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-warfare/361959/us-gov-warning-russia-cyber-threat-critical-infrastructure</link>
                                                                            <description>
                            <![CDATA[ The FBI, NSA and CISA have urged network defenders to be on "heightened alert" for Russian cyber attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">omMfg9zrthAfdCiuTdJt4Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yPzxswssTPkPFJgn9ipMaP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Jan 2022 11:55:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yPzxswssTPkPFJgn9ipMaP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract silhouette of a computer hacker in front of a Russian flag]]></media:description>                                                            <media:text><![CDATA[Abstract silhouette of a computer hacker in front of a Russian flag]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract silhouette of a computer hacker in front of a Russian flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yPzxswssTPkPFJgn9ipMaP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security specialists at the US government have warned critical infrastructure network defenders to "adopt a heightened state of awareness" against Russian state-sponsored cyber attacks.</p><p>The Federal Bureau of Investigation (FBI), <a href="https://www.itpro.com/security/cyber-security/361593/cisa-unveils-government-cyber-security-response-playbooks" data-original-url="https://www.itpro.com/security/cyber-security/361593/cisa-unveils-government-cyber-security-response-playbooks">Cyber Security and Infrastructure Security Agency</a> (CISA), and the National Security Agency (NSA) issued a <a href="https://www.cisa.gov/uscert/ncas/alerts/aa22-011a">joint advisory</a> on Tuesday providing an overview of the commonly used tactics and techniques used by Russian state-backed threat actors so the security community can take a more proactive stance on threat hunting.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/360093/us-and-uk-security-agencies-warn-against-russian-global-brute-force" data-original-url="/security/cyber-warfare/360093/us-and-uk-security-agencies-warn-against-russian-global-brute-force">US, UK security agencies warn against Russian ‘global brute force campaign’</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="/security/28170/what-is-cyber-warfare">What is cyber warfare?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361593/cisa-unveils-government-cyber-security-response-playbooks" data-original-url="/security/cyber-security/361593/cisa-unveils-government-cyber-security-response-playbooks">CISA unveils government cyber security response playbooks</a></p></div></div><p>The trio of federal agencies said these Russian hackers typically exploit flaws in popular enterprise products, listing known issues in products including Cisco routers (<a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1653">CVE-2019-1653</a>), Oracle WebLogic (<a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14882">CVE-2020-14882</a>), Citrix (<a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19781">CVE-2019-19781</a>), Pulse Secure (<a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11510">CVE-2019-11510</a>), and Microsoft Exchange (<a href="https://nvd.nist.gov/vuln/detail/CVE-2020-0688">CVE-2020-0688</a>).</p><p>"Russian state-sponsored APT actors have also demonstrated sophisticated tradecraft and cyber capabilities by compromising third-party infrastructure, compromising third-party software, or developing and deploying custom malware," the joint advisory reads. "The actors have also demonstrated the ability to maintain persistent, undetected, long-term access in compromised environments - including cloud environments - by using legitimate credentials.</p><p>"In some cases, Russian state-sponsored cyber operations against critical infrastructure organisations have specifically targeted operational technology (OT)/industrial control systems (ICS) networks with destructive <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a>."</p><p>Organisations are recommended to apply a range of mitigations to ensure functional resilience and lower the risk of compromise. These include measures such as confirming reporting processes, minimising personnel gaps in security coverage, following industry best practices for identity and access management, and proactively monitoring threat feeds for patches.</p><p>Because Russian threat actors have a history of lingering in networks undetected for long periods of time, the FBI, NSA, and CISA recommend all <a href="https://www.itpro.com/security/cyber-security/361518/83-of-critical-infrastructure-companies-have-experienced-breaches-in" data-original-url="https://www.itpro.com/security/cyber-security/361518/83-of-critical-infrastructure-companies-have-experienced-breaches-in">critical infrastructure</a> organisations to also implement robust log collection and retention, to aid incident investigations, and to proactively look for behavioural irregularities such as password spray attempts and detecting use of compromised credentials.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=46862322&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><p>The trio of agencies also highlighted a number of incidents in recent history where Russian state-sponsored hackers have been found to attack local governments and critical infrastructure. </p><p>From September 2020 to "at least" December 2020, Russian attackers targeted "dozens" of state, local, tribal, and territorial governments, as well as aviation networks, succeeding in extracting data from multiple victims.</p><p>They also pointed to Russia's instruction campaign in the US' energy sector between 2011 and 2018, deploying malware specially crafted for critical infrastructure environments and stealing data related to the industry. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zXqLgU99ufE8JGYcRWws9N" name="zXqLgU99ufE8JGYcRWws9N.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/zXqLgU99ufE8JGYcRWws9N.jpg" mos="https://cdn.mos.cms.futurecdn.net/zXqLgU99ufE8JGYcRWws9N.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Okta digital trust index</strong></p><p class="fancy-box__body-text">Exploring the human edge of trust</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/361514/the-okta-digital-trust-index" data-original-url="/policy-legislation/data-protection/361514/the-okta-digital-trust-index">FREE DOWNLOAD</a></p></div></div><p>"When the FBI, CISA and NSA team up to issue a joint alert about Russian state-sponsored APTs, every security team on the planet needs to sit up and take notice," said Dr Süleyman Özarslan, co-founder of Picus Security to <em>IT Pro</em>. "This alert highlights the seriousness and prevalence of ongoing malicious cyber operations by Russian state-sponsored APT actors. It should also be of great assistance to the cybersecurity community in reducing the risk posed by these threats."</p><p>The advisory comes as US officials join Russia's representatives in Geneva to discuss Russia's potential invasion of Ukraine, a country which was also on the receiving end of Russian hackers targeting critical infrastructure between 2015 and 2016, the advisory noted.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1480967928862412800"></a></p></blockquote><div class="see-more__filter"></div></div><p>Cyber security expert and former CISA director Chris Krebs suggested the timing of the advisory's publication could be interpreted as a warning to US organisations to prepare for the Geneva talks to go south, which they <a href="https://www.reuters.com/world/europe/prospects-dim-us-russia-start-tense-talks-over-ukraine-crisis-2022-01-10">reportedly</a> are after eight hours of discussions.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA issues guidance on encrypted DNS usage ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/network-internet/domain-name-system-dns/358349/nsa-issues-guidance-on-encrypted-dns-usage</link>
                                                                            <description>
                            <![CDATA[ The US National Security Agency  warns enterprises not to use third-party DNS resolvers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">p3Tj8ftff1qq3JJ6SZjezt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cYu38bmsjHKoetLAYxKNTk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Jan 2021 18:59:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cYu38bmsjHKoetLAYxKNTk-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The logo of the National Security Agency in front of the US flag]]></media:description>                                                            <media:text><![CDATA[The logo of the National Security Agency in front of the US flag]]></media:text>
                                <media:title type="plain"><![CDATA[The logo of the National Security Agency in front of the US flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cYu38bmsjHKoetLAYxKNTk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Security Agency (NSA) has issued <a href="https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/2471956/nsa-recommends-how-enterprises-can-securely-adopt-encrypted-dns">guidance</a> for enterprises whose users encrypt their <a href="https://www.itpro.com/domain-name-system-dns/30228/what-is-dns" data-original-url="https://www.itpro.com/domain-name-system-dns/30228/what-is-dns">Domain Name System</a> (DNS) requests. It’s advised administrators to block external DNS providers supporting a key encryption standard called DNS over HTTPS (DoH).</p><p>DoH encrypts requests made using the DNS protocol, which resolves web addresses to IP addresses, so browsers and other software know where to find them. DNS requests are traditionally unencrypted, meaning anyone snooping on a network connection, like a public Wi-Fi hotspot, could monitor someone's browsing habits and hijack their destinations.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/608241/qa-dns-inventor-paul-mockapetris" data-original-url="/608241/qa-dns-inventor-paul-mockapetris">Q&A: DNS inventor Paul Mockapetris</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/605103/apple-fixes-dns-security-flaw" data-original-url="/605103/apple-fixes-dns-security-flaw">Apple fixes DNS security flaw</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/605259/dns-researcher-claims-35-ways-to-exploit-flaw" data-original-url="/605259/dns-researcher-claims-35-ways-to-exploit-flaw">DNS researcher claims 35 ways to exploit flaw</a></p></div></div><p>DoH encrypts those requests using the same HTTPS protocol that websites use to encrypt and verify browser sessions, blocking snoopers. However, the NSA warns it can provide a false sense of security. </p><p>For example, it only encrypts the initial request, not the traffic sent afterward, meaning a snooper could still detect the IP addresses a victim is visiting and infer their browsing habits that way. </p><p>The agency also warns that the DNS resolver, which serves the DNS request, still decrypts the request to fulfill it.</p><p>There’s another danger in using external DNS resolvers that support DoH, the advisory says. Querying them directly bypasses any protections an enterprise DNS resolver has in place, such as filtering malicious websites.</p><p>The NSA suggests companies block unauthorized external DoH resolvers and only use their enterprise DNS resolvers when supporting DoH. It also recommends breaking and inspecting any traffic encrypted using TLS to block unauthorized DoH requests.</p><p>DoH is likely to gain more traction thanks to increased support from browser vendors. Mozilla <a href="https://www.itpro.com/network-internet/domain-name-system-dns/354861/firefox-activates-dns-over-https-for-us-users-by" data-original-url="https://www.itpro.com/network-internet/domain-name-system-dns/354861/firefox-activates-dns-over-https-for-us-users-by">launched</a> default DoH support for US users in February 2020, and Microsoft has also <a href="https://www.itpro.com/infrastructure/network-internet/355643/microsoft-testing-in-built-windows-10-dns-over-https-client" data-original-url="https://www.itpro.com/infrastructure/network-internet/355643/microsoft-testing-in-built-windows-10-dns-over-https-client">tested</a> support using its Windows 10 client.</p><p>Last May, the Department of Homeland Security's Cybersecurity & Infrastructure Security Agency (CISA) warned federal <a href="https://www.itpro.com/strategy/28223/cio-job-description-what-does-a-cio-do" data-original-url="https://www.itpro.com/strategy/28223/cio-job-description-what-does-a-cio-do">CIOs</a> that they were legally bound to use its internal EINSTEIN network security system for resolving DNS queries, even though it didn’t yet support encrypted requests. However, CISA issued a request for information last year to explore an upgrade to its DNS resolver, which would support DNS encryption.</p><p>DoH isn't the only DNS encryption option available. Another, called DNS over TLS, uses the Transport Layer Security mechanism to encrypt DNS requests. </p><p><a href="https://www.itpro.com/network-internet/domain-name-system-dns/358061/cloudflare-and-apple-launch-new-dns-over-https-tool" data-original-url="https://www.itpro.com/network-internet/domain-name-system-dns/358061/cloudflare-and-apple-launch-new-dns-over-https-tool">Oblivious DoH</a> (ODoH), another standard proposed by CloudFlare and Apple, would improve security by introducing a proxy between the client and the resolver to obfuscate request traffic. </p><p>The NSA noted that it didn’t address DNS over TLS or ODoH in its guidance. </p><p>The NSA guidance failed to mention another technology, dnscrypt-proxy. Dnscrypt-proxy is based on the OpenDNS-developed dnscrypt encryption technology, which achieves similar outcomes to ODoH.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA warns smartphone users of ‘large scale data tracking’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/356662/nsa-warns-against-the-scale-of-smartphone-location-tracking</link>
                                                                            <description>
                            <![CDATA[ Common features like Bluetooth and Wi-Fi can reveal sensitive details about users like their daily routines ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3DcPtKtVPbZXWn6NqpoN5d</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/m47AS7NnQAXztVohLBdDeb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Aug 2020 11:06:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/m47AS7NnQAXztVohLBdDeb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person holding a smartphone with a busy city centre backdrop]]></media:description>                                                            <media:text><![CDATA[Person holding a smartphone with a busy city centre backdrop]]></media:text>
                                <media:title type="plain"><![CDATA[Person holding a smartphone with a busy city centre backdrop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/m47AS7NnQAXztVohLBdDeb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Security Agency (NSA) has advised those involved in sensitive lines of work, as well as the privacy-conscious, to deactivate many common smartphone features to prevent leaking insights from their location data.</p><p>Equipment such as wireless sniffers can be used to track your location data through any combination of GPS and wireless signals such as Wi-Fi and <a href="https://www.itpro.com/621118/bluetooth-40-devices-to-appear-by-end-of-year" target="_blank" data-original-url="https://www.itpro.com/621118/bluetooth-40-devices-to-appear-by-end-of-year">Bluetooth</a>, even if mobile phone service is deactivated, the NSA has claimed. </p><p>Even if all wireless radios are disabled on your smartphone, various sensors on your device provide sufficient data to calculate location, while Bluetooth settings in some devices mean it can never truly be disabled, betraying your data. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354540/nsa-hands-serious-flaw-to-microsoft-rather-than-use-it" data-original-url="/security/cyber-security/354540/nsa-hands-serious-flaw-to-microsoft-rather-than-use-it">NSA hands serious flaw to Microsoft rather than use it</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/21218/nsa-and-gchq-tracked-google-cookies" data-original-url="/security/21218/nsa-and-gchq-tracked-google-cookies">NSA and GCHQ tracked Google cookies</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/21425/nsa-accused-of-collecting-200-million-text-messages-a-day" data-original-url="/security/21425/nsa-accused-of-collecting-200-million-text-messages-a-day">NSA accused of collecting 200 million text messages a day</a></p></div></div><p>The risk extends beyond smartphones, to <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot" target="_blank" data-original-url="https://www.itpro.com/cloud-computing/28037/what-is-iot">Internet of Things (IoT) devices</a> and fitness trackers as well as smart medical devices and built-in vehicle communications. Apps and social media services, meanwhile, may collect and aggregate data that exposes a user’s information. Many of these request permission for location and other resources that are not needed for their functioning. </p><p>“Location data can be extremely valuable and must be protected. It can reveal details about the number of users in a location, user and supply movements, daily routines (user and organizational), and can expose otherwise unknown associations between users and locations,” <a href="https://media.defense.gov/2020/Aug/04/2002469874/-1/-1/0/CSI_LIMITING_LOCATION_DATA_EXPOSURE_FINAL.PDF" target="_blank">the advisory said</a>.</p><p>“Mitigations reduce, but do not eliminate, location tracking risks in mobile devices. Most users rely on features disabled by such mitigations, making such safeguards impractical. Users should be aware of these risks and take action based on their specific situation and risk tolerance.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aEQjbkE6tScQXP3S6AMYPg" name="aEQjbkE6tScQXP3S6AMYPg.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/aEQjbkE6tScQXP3S6AMYPg.jpg" mos="https://cdn.mos.cms.futurecdn.net/aEQjbkE6tScQXP3S6AMYPg.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Staying ahead of the game in the world of data</strong></p><p class="fancy-box__body-text">Create successful marketing campaigns by understanding your customers better</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/data-insights/356263/staying-ahead-of-the-game-in-the-world-of-data" data-original-url="/business-strategy/data-insights/356263/staying-ahead-of-the-game-in-the-world-of-data">FREE DOWNLOAD</a></p></div></div><p>The organisation, speaking to the sensitive nature of the work done by US security officials and others in sensitive roles, added that users should apply mitigations to the greatest possible extent.</p><p>Those concerned about compromising their location data should disable location services as well as Bluetooth and Wi-Fi when these services aren’t needed. Airplane mode should also be enabled when devices aren’t in use.</p><p>In addition, apps should be given as few permissions as possible, including setting privacy settings to ensure apps are not using or sharing location data. Users should also avoid using apps related to location if possible since these inherently expose user location data. </p><p>Among other changes, advertising permissions should also be disabled to the greatest possible extent and the advertising ID should be reset on a regular basis, weekly at a minimum. This is in addition to <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/356334/run-a-vpn-on-any-device" target="_blank" data-original-url="https://www.itpro.com/network-internet/virtual-private-network-vpn/356334/run-a-vpn-on-any-device">using a virtual private network (VPN)</a>, turning off features that allow you to track a lost or stolen device, and minimise web browsing.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA hands serious flaw to Microsoft rather than use it ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/354540/nsa-hands-serious-flaw-to-microsoft-rather-than-use-it</link>
                                                                            <description>
                            <![CDATA[ Patch Windows 10 now, as the NSA has spotted a bug impacting security certificates ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ozNRu7NDc4Y9ax1xzC5giY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jan 2020 10:24:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NSA data]]></media:description>                                                            <media:text><![CDATA[NSA data]]></media:text>
                                <media:title type="plain"><![CDATA[NSA data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Update your <a href="https://www.itpro.com/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them" data-original-url="https://www.itpro.com/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them">Windows 10</a> computers now — the latest set of patches from Microsoft includes one for a scary flaw that was handed over by the US National Security Agency (NSA).</p><p>Ahead of this month's Patch Tuesday, <a href="https://www.itpro.com/security/vulnerability/354524/microsoft-to-patch-extraordinarily-serious-cryptographic-flaw" data-original-url="https://www.itpro.com/security/vulnerability/354524/microsoft-to-patch-extraordinarily-serious-cryptographic-flaw">rumours swirled of a serious cryptographic flaw</a>. Yesterday the source of the discovery was revealed to be the NSA, which not only spotted the vulnerability but handed it over to Microsoft rather than making use of it itself. That's a departure from how the NSA would normally treat such discoveries and indicates not only the seriousness of the bug but also <a href="https://twitter.com/briankrebs/status/1217125030452256768">a desire to</a> "turn over a new leaf" and start sharing its research into security rather than <a href="https://www.itpro.com/security/20559/nsa-and-gchq-accused-taking-part-sustained-web-encryption-cracking-campaign" data-original-url="https://www.itpro.com/security/20559/nsa-and-gchq-accused-taking-part-sustained-web-encryption-cracking-campaign">undermining it for surveillance purposes</a>. </p><p>Indeed, the NSA <a href="https://twitter.com/briankrebs/status/1217128563620700160">said</a> it wasn't the first time it had reported a vulnerability to Microsoft, but it previously refused credit. </p><p>The serious flaw in Microsoft's CrytpoAPI could be used to spoof a code-signing certificate to digitally sign malicious code, making it look as though it was from a trusted source. "The user would have no way of knowing the file was malicious, because the digital signature would appear to be from a trusted provider," Microsoft notes in the <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601">security notice</a>. "A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software."</p><p>The NSA said that the flaw undermines trust in the widely used <a href="https://www.itpro.com/security/31775/what-is-public-key-infrastructure-pki" target="_blank" data-original-url="https://www.itpro.com/security/31775/what-is-public-key-infrastructure-pki">Public Key Infrastructure</a> (PKI) and could impact everything from <a href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security" target="_blank" data-original-url="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security">HTTPS</a> connections and signed emails to signed code, across companies, home users and governments. "This kind of vulnerability may shake our belief in the strength of cryptographic authentication mechanisms and make us question if we can really rely on them. Fortunately, we can," Neal Ziring, Technical Director at the NSA Cybersecurity Directorate, said in a <a href="https://www.nsa.gov/News-Features/News-Stories/Article-View/Article/2056772/a-very-important-patch-tuesday">blogpost</a>. "[The flaw] reflects a weakness in the implementation of one subtle aspect of PKI certificate validation. The technology and standards are sound; it is one implementation that needs repair."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QBq2mgdJP8fxdvLAt5bw6R" name="QBq2mgdJP8fxdvLAt5bw6R.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/QBq2mgdJP8fxdvLAt5bw6R.png" mos="https://cdn.mos.cms.futurecdn.net/QBq2mgdJP8fxdvLAt5bw6R.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Patch management best practices</strong></p><p class="fancy-box__body-text">Reduce your patch management workload</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/network-security/354135/patch-management-best-practices" data-original-url="/security/network-security/354135/patch-management-best-practices">FREE DOWNLOAD</a></p></div></div><p>Thankfully, Microsoft and the NSA both said there was no evidence that the flaw had been spotted or used by hackers. "This month we addressed the vulnerability <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601">CVE-2020-0601</a> in the usermode cryptographic library, CRYPT32.DLL, that affects Windows 10 systems," said Mechele Gruhn, Principal Security Program Manager at the Microsoft Security Research Centre, in a <a href="https://msrc-blog.microsoft.com/2020/01/14/january-2020-security-updates:-cve-2020-0601">blog post</a>. "This vulnerability is classed Important and we have not seen it used in active attacks."</p><p>However, now that the details are public, we can expect that to change. "The consequences of not patching the vulnerability are severe and widespread," the NSA <a href="https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF">said in a statement</a>. "Remote exploitation tools will likely be made quickly and widely available. Rapid adoption of the patch is the only known mitigation at this time and should be the primary focus for all network owners."</p><p>The flaw impacts Windows Server as well as Windows 10, which is used on 400 million computers globally — but the patch is already available as part of Microsoft's monthly updates. “Customers who have already applied the update, or have automatic updates enabled, are already protected,” said Jeff Jones, a senior director at Microsoft, in a statement.</p><p>Of course, patching takes time for larger organisations. The NSA recommended via a statement that companies prioritise endpoints that are essential or widely used, such as web servers or DNS servers, as well as those with a high risk of exploitation, in particular those directly exposed to the internet and those used by privileged accounts. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/354524/microsoft-to-patch-extraordinarily-serious-cryptographic-flaw" data-original-url="/security/vulnerability/354524/microsoft-to-patch-extraordinarily-serious-cryptographic-flaw">Microsoft to patch ‘extraordinarily serious’ cryptographic flaw</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354440/the-scariest-security-horror-stories-of-2019" data-original-url="/security/cyber-security/354440/the-scariest-security-horror-stories-of-2019">The scariest security horror stories of 2019</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/20559/nsa-and-gchq-accused-taking-part-sustained-web-encryption-cracking-campaign" data-original-url="/security/20559/nsa-and-gchq-accused-taking-part-sustained-web-encryption-cracking-campaign">NSA and GCHQ accused of taking part in sustained web encryption-cracking campaign</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them" data-original-url="/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them">17 common Windows 10 problems and how to fix them</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/27717/how-to-fix-a-stuck-windows-10-update" data-original-url="/operating-systems/27717/how-to-fix-a-stuck-windows-10-update">How to fix a stuck Windows 10 update</a></p></div></div><p>While the notification of the flaw by the NSA will be welcome to Microsoft and its users, whether this signals a new era of cooperation remains to be seen. Chris Morales, Head of Security Analytics at Vectra, notes that different motivations could be in play, regardless of the agency's plans to "turn over a new leaf". "Kudos to the NSA for informing Microsoft and to Microsoft for quickly reacting," he said. "I’d be interested to understand what makes this exploit worth reporting to Microsoft instead of keeping for their personal arsenal as they have in the past.</p><p>"It could be because <a href="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow" target="_blank" data-original-url="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow">many of those previous tools leaked</a> and have caused widespread damage across multiple organisations," he said. "It could be because there was a concern other would find this vulnerability themselves and it was dangerous enough to warrant remediation instead of weaponising. Or it just could be the NSA already has enough other methods for compromising a Windows system and doesn’t need it." </p><p>If it is a sign of cooperation to come, then it's to be welcomed and shows how the government can help security, said Allan Liska, Senior Solutions Architect at Recorded Future. "This reporting is also likely a direct result of the revamped Vulnerability Equities Process (VEP) at NSA," he adds. "The goal of the revamped program is to prioritise public interest in reporting security flaws and protecting core systems and infrastructure. Certificate signing is critical to the trust of software applications in both the public and private sectors, so this reporting certainly meets the “critical” threshold." He noted it's not known how long the NSA has been aware of the vulnerability, but it was reported to Microsoft a few weeks ago.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 100GB of secret NSA data found on unsecured AWS S3 bucket ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/30060/100gb-of-secret-nsa-data-found-on-unsecured-aws-s3-bucket</link>
                                                                            <description>
                            <![CDATA[ The data related to a failed NSA cloud collaboration project ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9LXeGpcpPk9NsiPpBS9FhR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SqKEWgGvLCoVy67jqodyEM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Nov 2017 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SqKEWgGvLCoVy67jqodyEM-1280-80.jpg">
                                                            <media:credit><![CDATA[Big Stock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bucket leaking water]]></media:description>                                                            <media:text><![CDATA[Bucket leaking water]]></media:text>
                                <media:title type="plain"><![CDATA[Bucket leaking water]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SqKEWgGvLCoVy67jqodyEM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The NSA has been hit by yet another data leak, as over 100GB of sensitive, classified data was exposed through shoddy security practises.</p><p>The leak came from a virtual copy of a hard drive belonging to US Intelligence and Security Command (INSCOM), an intelligence organisation operating within both the US Army and the NSA.</p><p>The virtual disk image was discovered by UpGuard cyber risk research director Chris Vickery on an unprotected public Amazon S3 server, meaning that anyone who knew the web address where the data was stored could freely access it.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/30038/three-key-pillars-of-threat-visibility" data-original-url="/endpoint-security/30038/three-key-pillars-of-threat-visibility">Three key pillars of threat visibility</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-breaches/30010/uber-hack-a-lesson-in-how-not-to-handle-a-data-breach" data-original-url="/data-breaches/30010/uber-hack-a-lesson-in-how-not-to-handle-a-data-breach">Uber hack: A lesson in how not to handle a data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="/security/29982/what-is-two-factor-authentication">What is two-factor authentication?</a></p></div></div><p>Unsecured S3 buckets are a frequent cause of embarrassing data breaches for many companies and government organisations. The personal details of <a href="https://www.itpro.com/security/29071/two-million-dow-jones-customer-details-exposed-via-cloud" target="_blank" data-original-url="https://www.itpro.com/security/29071/two-million-dow-jones-customer-details-exposed-via-cloud">two million Dow Jones customers</a> were exposed in a similar fashion earlier this year, as were customers of <a href="https://www.itpro.com/security/29694/accenture-exposes-137gb-of-client-data-on-unsecured-aws-buckets" target="_blank" data-original-url="https://www.itpro.com/security/29694/accenture-exposes-137gb-of-client-data-on-unsecured-aws-buckets">Accenture</a> and the <a href="https://www.itpro.com/security/29019/three-million-wwe-fan-accounts-exposed-online" target="_blank" data-original-url="https://www.itpro.com/security/29019/three-million-wwe-fan-accounts-exposed-online">WWE</a>.</p><p>"Regrettably, this cloud leak was entirely avoidable," UpGuard said in <a href="https://www.upguard.com/breaches/cloud-leak-inscom" target="_blank">a blog post</a> announcing the discovery, "the likely result of process errors within an IT environment that lacked the procedures needed to ensure something as impactful as a data repository containing classified information not be left publicly accessible."</p><p>"Plainly put, the digital tools needed to potentially access the networks relied upon by multiple Pentagon intelligence agencies to disseminate information should not be something available to anybody entering a URL into a web browser," the post said. "Although the UpGuard Cyber Risk Team has found and helped to secure multiple data exposures involving sensitive defense intelligence data, this is the first time that clearly classified information has been among the exposed data."</p><p>The drive in question contained a trove of data related to a US military project codenamed 'Red Disk', a failed cloud collaboration and content sharing platform designed to let field troops access real-time intelligence data from the Pentagon, including satellite and drone imagery.</p><p>The drive also included hashed passwords for internal systems, as well as private keys belonging to third-party INSCOM defence contractors for accessing "distributed intelligence systems". Multiple areas of the drive were marked 'Top Secret', with some sections even bearing the 'NOFORN' designation, indicating that they were to be kept secret even from the US government's foreign intelligence allies.</p><p><em>IT Pro</em> has reached out to the NSA to ask why the appropriate protections were not taken, and will update this piece when we hear back.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky claims pirated Office software was behind NSA exploit leak ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak</link>
                                                                            <description>
                            <![CDATA[ The company has released the early results of its investigation into the 2014 incident ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i5xdSE58TtSU17LD75bTFX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 Oct 2017 12:09:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NSA data]]></media:description>                                                            <media:text><![CDATA[NSA data]]></media:text>
                                <media:title type="plain"><![CDATA[NSA data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky has refuted claims its software could be used by the Russian government to spy on US intelligence operatives, indicating that pirated Microsoft Office software is to blame instead.</p><p>Following allegations that Russia's FSB intelligence agency used its antivirus software to infiltrate the PC of an NSA contractor and steal top-secret exploit code, the Russian security firm released the preliminary results of its own investigation into the incident.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">Kaspersky’s attempt to overturn US government ban thrown out of court <a data-analytics-id="inline-link" href="https://www.itpro.com/antivirus/28144/best-antivirus" data-original-url="/antivirus/28144/best-antivirus">Best antivirus for Windows 10</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27748/kaspersky-total-security-2017-review" data-original-url="/security/27748/kaspersky-total-security-2017-review">Kaspersky Total Security 2017 review</a></p></div></div><p>According to the company's detailed timeline, Kaspersky's antivirus software detected samples of malware created by the Equation group - a highly-sophisticated hacking group widely suspected of <a href="https://www.itpro.com/security/24064/kaspersky-uncovers-hard-drive-hackers-with-stuxnet-links" target="_blank" data-original-url="https://www.itpro.com/security/24064/kaspersky-uncovers-hard-drive-hackers-with-stuxnet-links">ties to the NSA</a> - on the PC of a US user in September 2014.</p><p>"Following these detections, the user appears to have downloaded and installed pirated software on his machines, as indicated by an illegal Microsoft Office activation key generator," the company explained. "To install and run this keygen, the user appears to have disabled the Kaspersky products on his machine ... Executing the keygen would not have been possible with the antivirus enabled."</p><p>This keygen, the company claimed, was in fact a Trojan, which dropped a "full blown backdoor" onto the subject's PC, which "may have allowed third parties access to the user's machine".</p><p>After the user re-enabled their anti-virus installation, the software blocked the backdoor. It also began detecting previously unknown variants of the Equation malware, including a 7zip archive. This archive was promptly sent back to Kaspersky Lab HQ for analysis, at which point it was found to contain "multiple malware samples and source code for what appeared to be Equation malware".</p><p>Upon discovery, this was reported to CEO Eugene Kaspersky. The company said that the archive and its contents were deleted from all of Kaspersky's systems and was not shared with anyone else. It also stated that "Kaspersky Lab has never created any detection of non-weaponized (non-malicious) documents in its products based on keywords like 'top secret' and 'classified'."</p><p>In short, the company appears to be implying that its software was turned off by an NSA contractor in order to install a pirated version of Office 2013, which contained a backdoor. This backdoor could then have been used by the FSB to gain access to the NSA's Equation exploits, as opposed to the exploits being turned over by Kaspersky Lab itself exploits which were promptly deleted from its files, the company said, when it discovered what they were.</p><p>This story has drawn a mixed response from the cybersecurity community; F-Secure chief research officer Mikko Hypponen has subtly hinted that the lure of keeping hold of sophisticated nation-state malware may have been too much for Kaspersky to resist.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/923212609528172544"></a></p></blockquote><div class="see-more__filter"></div></div><p>Ex-black hat-turned-pen-tester Kevin Mitnick, however, said that the company's account more plausible than alternative explanations.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/923455299670835202"></a></p></blockquote><div class="see-more__filter"></div></div><p>"The investigation is still ongoing," Kaspersky stated, "and the company will provide additional technical information as it becomes available. We are planning to share full information about this incident, including all technical details with a trusted third party as part of our Global Transparency Initiative for cross-verification."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Canada's spy agency releases its own anti-malware tool to the public ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29770/canadas-spy-agency-releases-its-own-anti-malware-tool-to-the-public</link>
                                                                            <description>
                            <![CDATA[ The CSE says its scalability makes it an ideal fit for enterprise applications ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5cbHE1H18LMPyn98Lrxo2v</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WnSsR7AE2r2NRM6srdT94g-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Oct 2017 10:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WnSsR7AE2r2NRM6srdT94g-1280-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Canadian flag with binary code on it]]></media:description>                                                            <media:text><![CDATA[Canadian flag with binary code on it]]></media:text>
                                <media:title type="plain"><![CDATA[Canadian flag with binary code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WnSsR7AE2r2NRM6srdT94g-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Canada's cyber defence agency has made the source code for its internal malware prevention tool publicly available to help in the fight against online threats.</p><p>The <a href="https://www.cse-cst.gc.ca/en/assemblyline" target="_blank">Communications Security Establishment</a>, which is essentially Canada's equivalent to GCHQ in the UK, has released its "Assemblyline" tool as "an opportunity for the cyber security community to take what CSE has developed and build upon it to benefit all Canadians".</p><p>The tool is described as a highly configurable early warning system that is able to alert agents to malicious files when they are received.</p><p>An example given by the CSE describes how a financial officer may receive an email from an external sender that includes a password-protected zip file containing a word document and spreadsheet. This email may then be passed on to three colleagues within the department.</p><p>"Assemblyline will start by examining the initial email," the CSE explained in a statement. "It automatically recognizes the various file formats and triggers the analysis of each file. In this example, the Word document contains embedded malware, although the financial officer is unaware of this. The whole file is given a score when the analysis of each file is complete."</p><p>High scores will trigger alerts to a security analyst, who would then manually examine a file and disarm the malware to prevent it spreading further.</p><p>The main benefit of the system is its scalability, according to the CSE, as the tool is able to automatically rebalance workloads depending on the volume of data, making it an ideal catch-all solution for enterprises.</p><p>"Assemblyline was built using public domain and open-source software; however the majority of the code was developed by CSE," the statement added. "It does not contain any commercial technology, but it is easily integrated into existing cyber defence technologies. As open-source software, businesses can modify Assemblyline to suit their requirements."</p><p>The complete program is available on <a href="https://bitbucket.org/cse-assemblyline" target="_blank">bitbucket</a> to anyone who owns an account.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/25752/gchq-releases-open-source-analysis-tools-on-github" data-original-url="/government-it-strategy/25752/gchq-releases-open-source-analysis-tools-on-github">GCHQ releases open source analysis tools on Github</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29322/if-youre-surprised-the-nsa-can-hack-your-computer-you-need-a-reality-check" data-original-url="/security/29322/if-youre-surprised-the-nsa-can-hack-your-computer-you-need-a-reality-check">If you're surprised the NSA can hack your computer, you need a reality check</a></p></div></div><p>It's relatively uncommon for a national security agency to willingly share its tools with the world. The UK's GCHQ released the source code for its graph database program <a href="https://www.itpro.com/government-it-strategy/25752/gchq-releases-open-source-analysis-tools-on-github" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/25752/gchq-releases-open-source-analysis-tools-on-github">Gaffer</a> in 2015, which is able to sift through vast amounts of data and analyse information to determine patterns.</p><p>At the time GCHQ promised further contributions to the open source community, but has yet to release any more of its toys to the public.</p><p>The National Security Agency in the US also has 32 projects running on GitHub, although these are mostly outdated programs, or specialist tools such as a GPS tracker, and are fairly useless as business tools. For the NSA's most high profile projects, you'll need to turn to the <a href="https://www.itpro.com/security/27273/cisco-customers-targeted-using-leaked-nsa-hacking-tools" target="_blank" data-original-url="https://www.itpro.com/security/27273/cisco-customers-targeted-using-leaked-nsa-hacking-tools">Shadow Brokers</a>. </p><p><em>Image: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US security secrets stolen in Russian NSA hack: reports ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-leakage/29651/us-security-secrets-stolen-in-russian-nsa-hack-reports</link>
                                                                            <description>
                            <![CDATA[ Hacking tools allegedly snatched when worker loaded them onto home computer ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4pLoUkho22dYB8ArKEwDHX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Oct 2017 09:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NSA data]]></media:description>                                                            <media:text><![CDATA[NSA data]]></media:text>
                                <media:title type="plain"><![CDATA[NSA data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Russian state-sponsored hackers stole highly classified US cyber security information from the NSA in 2015, it has been claimed.</p><p>According reports from the <em><a href="https://www.wsj.com/articles/russian-hackers-stole-nsa-data-on-u-s-cyber-defense-1507222108" target="_blank">Wall Street Journal</a></em> and <em><a href="https://www.washingtonpost.com/world/national-security/russian-government-hackers-exploited-antivirus-software-to-steal-us-cyber-capabilities/2017/10/05/a01bf546-a9fc-11e7-92d1-58c702d2d975_story.html?hpid=hp_hp-more-top-stories-2_nsahack-740pm%3Ahomepage%2Fstory&utm_term=.0d3f8ddd0355" target="_blank">Washington Post</a></em>, the breach occurred when a person working in the US spy agency's "elite hacking unit" Tailored Access Operations (TAO) loaded the information onto their home computer.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29234/shadow-broker-exploit-dumps-five-million-cyber-attacks" data-original-url="/security/29234/shadow-broker-exploit-dumps-five-million-cyber-attacks">Shadow Broker exploit dumps five million cyber attacks</a></p></div></div><p>TAO is the division of the NSA that "develops tools to penetrate computers overseas to gather foreign intelligence", according to the <em>Washington Post's</em> sources. In particular, the information taken by the person involved included hacking tools that were being developed to replace those considered compromised in the Snowden leaks.</p><p>It's currently unclear if the individual was an independent contractor, as claimed by the <em>WSJ</em>, or an employee, as claimed by the <em>Washington Post</em>, but they are unified in their claim that Kaspersky Lab antivirus software installed on the individual's computer was used as the conduit to identify and access the material.</p><p>Kaspersky Lab has hit back at the allegations, reiterating it "does not have inappropriate ties to any government, including Russia, and the only conclusion seems to be that Kaspersky Lab is caught in the middle of a geopolitical fight".</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/916016575853064193"></a></p></blockquote><div class="see-more__filter"></div></div><p>The statement also hints at what some independent security researchers had speculated that its software detected the programmes brought home by the individual and classified them as threats, uploading their signatures and other information to its database of threats.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/915989588690182145"></a></p></blockquote><div class="see-more__filter"></div></div><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/915990527509762050"></a></p></blockquote><div class="see-more__filter"></div></div><p>The <em>Washington Post</em> claims the incident, which resulted in the person being removed from their post in November 2015, is still under investigation.</p><p>This is the latest in a series of embarrassing breaches for the NSA. While the leaks from Edward Snowden in May 2013 may be the most famous, another contractor Harold Martin was arrested last year in relation to a separate 2013 breach. Then, in 2016, hacking group Shadow Brokers stole a vast cache of hacking tools, once again linked to TAO, from the NSA and leaked them to the public.</p><p>These latest reports haven't been confirmed by the NSA, however, with the agency telling <em><a href="https://www.reuters.com/article/us-usa-cyber-nsa/russian-hackers-stole-u-s-cyber-secrets-from-nsa-media-reports-idUSKBN1CA2DO" target="_blank">Reuters</a></em>: "[We] never to comment on our affiliates or personnel issues."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ If you're surprised the NSA can hack your computer, you need a reality check ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29322/if-youre-surprised-the-nsa-can-hack-your-computer-you-need-a-reality-check</link>
                                                                            <description>
                            <![CDATA[ We’ve reached a situation where OSes are so complex, they're impossible to secure ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">j2APV7RPu5H6rUdoXbfC8N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 27 Aug 2017 17:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jon Honeyball ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NSA data]]></media:description>                                                            <media:text><![CDATA[NSA data]]></media:text>
                                <media:title type="plain"><![CDATA[NSA data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Colour me shocked. It appears the NSA has been collecting a treasure trove of hacks for Windows, both desktop and servers, covering all versions of the OS bar Windows 10. And this toolbox of capabilities, which also included ways to get into banking and other related systems, has leaked to the public.</p><p>I suspect your jaw isn't gaping in surprise. What's followed has been just as predictable.</p><p>First, there's shock that the NSA might have built such a collection of exploits. Sorry, what do you expect the NSA to be doing? Creating toolkits that can be used against undesirables is what it exists for. Injecting custom spyware onto the laptop of a terrorist could bring up incredibly useful intelligence information, after all.</p><p>Then there's the public horror that the NSA didn't tell Microsoft about the exploits. Why is anyone surprised? Sure, it's good practice for security researchers to tell Microsoft (or Apple, Facebook, Google, whoever) that they've uncovered a security hole. There are processes in place by which such reports are made, the vendor is given time to patch things and issue an update, and then the exploit is made public once the patch has been issued. It's all very gentlemanly, and some companies even offer financial rewards.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28751/shadowbrokers-offers-cisos-zero-day-details-for-21000" data-original-url="/security/28751/shadowbrokers-offers-cisos-zero-day-details-for-21000">ShadowBrokers offers CISOs zero-day details for $21,000</a></p></div></div><p>Would I expect the NSA to tell Microsoft about the exploits? Of course not. Keeping such flaws hidden from Microsoft meant they were exploitable for as long as possible.</p><p>No-one is suggesting the NSA, or any other equivalent organisation, is using these tools against the wider population. I don't think there have been mass deployments of EmeraldThread or EternalRomance or EclipsedWing or any of the other rather charming codenames. (Nasty1 and Nasty2 and ReallyNasty3 just don't have the same ring to them.)</p><p>But then we come onto the real problems. The tools have now been released into the wild, and it doesn't take much effort to download them. This means there will be a flood of script kiddies trying them out and targeting everyone from NASA to the takeaway down the street. That's a whole pile of grief no-one needed.</p><p>It would be interesting to analyse which antivirus packages would protect you against these exploits. My hunch, backed by discussions with friends in the industry, is almost none. As they say about financial results, past performance is no guarantee of future results.</p><p>Even so, now the toolkit has leaked, it's of much less use to the NSA, and any other organisations that might have had access to it. That can't be a good thing. Don't confuse that statement with any desire on my part to see government-mandated encryption backdoors being forced into end user applications. I see a difference between what an organisation such as the NSA or GCHQ does and the far more widespread misuse of data-snooping that we have seen in the UK. And my distrust of the ability of government departments, including the NHS, to keep massive datasets secure has almost no limits.</p><p>Then we come to Microsoft's interesting claim that these exploits have been patched already, but only very recently. One wonders whether the NSA told Microsoft about the leak once it knew its toolkit was compromised and Microsoft went into top gear to get fixes out as soon as possible.</p><p>It does mean, of course, that the old mantra about running only the most current and fully patched versions of applications and operating systems is as true today as it has ever been. Microsoft rather coyly states that "Of the three remaining exploits, EnglishmanDentist', EsteemAudit', and ExplodingCan', none reproduces on supported platforms, which means that customers running Windows 7 and recent versions of Windows or Exchange 2010 and newer versions of Exchange are not at risk." So if you're on XP, you're on your own.</p><p>It's also true that we've managed to get ourselves into a situation where OSes are so complex that it is now effectively impossible to ensure they are secure. The approach taken by Apple's iOS, forcing a walled garden approach on the developers and the execution of code, is arguably the most secure widespread end user platform available. But that still doesn't mean that the core OS itself is secure. Is open source the answer? Maybe, but exploits are found there too.</p><p>You may be thinking I'll use this final paragraph to deliver the answer. Sadly, there isn't one. If GCHQ or the NSA want to access my computers, they will either hack their way in, use a backdoor that we don't know about, or just turn up with a warrant and remove every device fitted with a mains plug. And there is nothing I, or you, can do.</p><p><em>This article originally appeared in PC Pro.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Shadow Broker exploit dumps five million cyber attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29234/shadow-broker-exploit-dumps-five-million-cyber-attacks</link>
                                                                            <description>
                            <![CDATA[ Kaspersky: Hacking tool leaks fuel cyber criminal activity ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3GcT6hq5CqMmSAyrmPNWxw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zjXhJtx6YKyN8eFuKFXqLk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Aug 2017 10:43:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zjXhJtx6YKyN8eFuKFXqLk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[shadowy hands over a keyboard]]></media:description>                                                            <media:text><![CDATA[shadowy hands over a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[shadowy hands over a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zjXhJtx6YKyN8eFuKFXqLk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>More than five million cyber attacks originated from a series of exploit archives dumped onto the internet between April and June this year, according to Kaspersky Lab.</p><p>Its software blocked more than five million attacks based on hacking group <a href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" target="_blank" data-original-url="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers' exploit dumps</a>, but the rate of attacks using these tools is growing; more than 80% were detected during the last 30 days of the quarter.</p><p>"The threat landscape of Q2 provides yet another reminder that a lack of vigilance is one of the most significant cyber dangers," said Kaspersky Lab security expert Alexander Liskin.</p><p>"While vendors patch vulnerabilities on a regular basis, many users don't pay attention to this, which results in massive-scale attacks once the vulnerabilities are exposed to the broad cyber criminal community."</p><p>Shadow Brokers has already had a huge impact of the security landscape. The mysterious group began releasing huge troves of offensive malware and cyber weapons last year, many of which were allegedly created and used by US intelligence agencies such as the NSA.</p><p>The latest dump, which occurred in April this year, included a number of highly sophisticated tools. It was considered by many experts to be one of the most dangerous and damaging leaks in cyber security history.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" data-original-url="/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers: Microsoft Windows flaws were already patched</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" data-original-url="/security/29172/marcus-hutchins-wannacry-kronos-charges">WannaCry 'hero' Marcus Hutchins 'was coerced' into Kronos confession</a></p></div></div><p>Alongside codenamed exploits including DarkPulsar, OddJob and FuzzBunch, the dump included the EternalBlue exploit targeting elements of the Windows OS. This malware in particular was an instrumental part of the WannaCry ransomware that nearly crippled organisations including the NHS, before it was stopped by <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" target="_blank" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">security researcher Marcus Hutchins</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The NSA is sharing projects on GitHub ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/strategy/28889/the-nsa-is-sharing-projects-on-github</link>
                                                                            <description>
                            <![CDATA[ Some of the projects are  outdated, but could prove useful to some open source developers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3A3qw4XYpRWSpsjf6ur26V</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 21 Jun 2017 08:07:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NSA data]]></media:description>                                                            <media:text><![CDATA[NSA data]]></media:text>
                                <media:title type="plain"><![CDATA[NSA data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Security Agency (NSA) has opened an account on open source code repository GitHub, meaning developers are able to contribute to and use many of the organisation's innovations in their projects.</p><p>Although the NSA is the most secretive of US intelligence agencies, it currently has 32 projects listed on its NSA Technololgy Transfer Program GitHub account (first spotted by <em><a href="https://thenextweb.com/dd/2017/06/19/nsa-yes-nsa-github-account-now/#.tnw_6PxCPtKP" target="_blank">The Next Web</a></em>), of which most are flagged as "coming soon".</p><p>A lot of the projects that are available were developed quite some time ago and are not likely to be recent things the NSA is working on, but closed items that are no longer being used. However, that doesn't mean they won't be useful to other organisations looking to boost their code.</p><p><em>The Next Web</em> flags SELinux (Security-Enhanced Linux) as one such project that has been part of the Linux kernal for years and although it may not be helpful for most companies, a tool such as qgis-latlontools-plugin, which is described as "QGIS tools to capture and zoom to coordinates (including MGRS), using decimal, DMS, and WKT notation. Provides external map support and MGRS conversion routines," could be useful for mapping applications, using the plugin to extract coordinates from a map, for example.</p><p>It's unlikely many of the NSA's high profile projects will appear on its <a href="https://github.com/nationalsecurityagency">GitHub account</a> anytime soon, but this is certainly a step forward in the NSA's attempts to be more transparent and open about what it's doing.</p><p>The first indicator of this was in 2013 when it opened a Twitter account, just after Edward Snowden issued security leaks regarding the NSA's questionable tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/27125/was-an-insider-behind-the-nsa-hack" data-original-url="/hacking/27125/was-an-insider-behind-the-nsa-hack">Was an insider behind the NSA hack?</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Shadow Brokers: Microsoft Windows flaws were already patched ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched</link>
                                                                            <description>
                            <![CDATA[ NSA allegedly had the ability to breach bank messaging system ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cs6KQ162MT9ze24wYEri7M</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Apr 2017 10:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Microsoft]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NSA data]]></media:description>                                                            <media:text><![CDATA[NSA data]]></media:text>
                                <media:title type="plain"><![CDATA[NSA data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US spy agency the NSA allegedly had the tools to hack into interbank messaging system SWIFT via third party providers, according to documents released by hacking group Shadow Brokers last Friday.</p><p>SWIFT has since said there is no evidence suggesting its core messaging services or network have been compromised after <em><a href="http://www.reuters.com/article/us-usa-cyber-swift-idUSKBN17H0NX" target="_blank">Reuters</a></em> reported that the Shadow Group documents indicated that the NSA had accessed SWIFT through service providers (service bureaux) that offer access to the system in the Middle East and Latin America.</p><p>In a <a href="https://www.swift.com/news-events/press-releases/media-faq_shadow-brokers" target="_blank">media FAQ</a>, the organisation said: "SWIFT is in close contact with the service bureaux concerned to verify that they are aware of the allegations and have appropriate preventative measures in place." The Belgium-based organisation allows over 200 organisations to send messages about financial transactions to each other and sends payment orders between institutions' accounts.</p><p>The tools were linked to vulnerabilities discovered in versions of Microsoft's Windows operating system. Cybersecurity expert Matt Suiche, of Comae Technologies, detailed in <a href="https://blog.comae.io/the-nsa-compromised-swift-network-50ec3000b195" target="_blank">a blog post</a> that "<a href="https://www.itpro.com/operating-systems/28475/vista-finally-the-end-is-nigh" target="_blank" data-original-url="https://www.itpro.com/operating-systems/28475/vista-finally-the-end-is-nigh">Windows Vista/2008 is out of support since Monday [12 April]</a>, and Windows XP/2003 has been unsupported for more than [three] years. This means that security vulnerabilities found on those systems will never be corrected."</p><p>However, Microsoft said in <a href="https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk" target="_blank">a security update</a> that all but three of the published exploits had already been patched. Those three, 'EnglishmanDentist', 'EsteemAudit', and 'ExplodingCan', don't work on Windows operating systems that are still in support. But Microsoft has not announced how it learned of the vulnerabilities, though it <a href="https://technet.microsoft.com/en-us/library/security/mt745121.aspx?f=255&MSPPError=-2147217396&ranMID=24542&ranEAID=TnL5HPStwNw&ranSiteID=TnL5HPStwNw-29f96ktlrn_p545DGk0Twg&tduid=(5509548f0b30eec10d425a34c50e611b)(256380)(2459594)(TnL5HPStwNw-29f96ktlrn_p545DGk0Twg)()" target="_blank">usually gives credit</a> to those who find bugs.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/853172582555824128"></a></p></blockquote><div class="see-more__filter"></div></div><p>SWIFT said: "The allegations suggest there may have been attempts to gain unauthorised access to data at two service bureaux. The exploits do not target SWIFT's infrastructure or data. There is no impact on SWIFT's infrastructure or data, and there is no evidence to suggest that there has been any unauthorised access to SWIFT's network or messaging services.</p><p>"Customers should pay close attention their own security and take security into consideration when selecting a service bureau and working with other third party providers."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/21218/nsa-and-gchq-tracked-google-cookies" data-original-url="/security/21218/nsa-and-gchq-tracked-google-cookies">NSA and GCHQ tracked Google cookies</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27385/symantec-another-hacking-group-is-targeting-swift-users" data-original-url="/security/27385/symantec-another-hacking-group-is-targeting-swift-users">Symantec: Another hacking group is targeting SWIFT users</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Yahoo email scandal could derail Safe Harbour replacement ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/27346/yahoo-email-scandal-could-derail-safe-harbour-replacement</link>
                                                                            <description>
                            <![CDATA[ Reports of mass email surveillance prompt fears of rights infringements ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ioP4zsbjSFtxUPEyfyd3mU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/u8Gx3V3T7W54QxUHCzxabS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Oct 2016 14:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/u8Gx3V3T7W54QxUHCzxabS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/u8Gx3V3T7W54QxUHCzxabS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Yahoo's alleged scanning of user emails on behalf of the US government could undermine the newly agreed Privacy Shield data regulations if they turn out to be true.</p><p>Ireland's data protection commissioner, which is the lead European regulator on privacy issues for Yahoo, is making inquiries as to whether any European citizens may have been affected.</p><p>"Any form of mass surveillance infringing on the fundamental privacy rights of EU citizens would be viewed as a matter of considerable concern," the regulator said in a statement.</p><p>According to both<em><a href="http://uk.reuters.com/article/uk-yahoo-nsa-ireland-idUKKCN1251NP?il=0">Reuters</a></em>and<em><a href="http://www.thetimes.co.uk/article/watchdog-to-look-at-yahoo-over-email-search-cj6t2vbct">The Times</a>(subscription required)</em>, European politicians have called on the European Commission to investigate the matter, with lawyers saying a legal challenge to the Privacy Shield agreement, <a href="https://www.itpro.com/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield" data-original-url="https://www.itpro.com/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield">which was settled on earlier this year</a>, is now more likely.</p><p>In the US, the legality of Yahoo's reported actions has also been called into question.</p><p>Patrick Toomey, a staff attorney with the American Civil Liberties Union (ACLU), told<em>IT Pro</em>: "Based on [<em>Reuters's</em> initial report] the order issued to Yahoo appears to be unprecedented and unconstitutional. The government appears to have compelled Yahoo to conduct precisely the type of general, suspicionless search that the Fourth Amendment was intended to prohibit."</p><p>In this country, however, it has been claimed this behaviour may not be illegal even if UK citizens were among the subjects of the alleged spying.</p><p>Privacy International legal officer Camilla Graham Wood told<em>IT Pro</em>: "The information on the scanning of emails by Yahoo remains sparse. It is important to note that similar powers exist in the United Kingdom, in the form of the Investigatory Powers Bill. There has been little public debate about how intrusive such powers are. The fault lies with the Government in failing to clearly inform the public about the broad spectrum of powers that will be authorised by the Investigatory Powers Bill.</p><p>"We do not know if the UK Government has already requested that companies scan their customers' emails on a bulk scale, but we do know that this will be possible under the Investigatory Powers Bill, if we look at powers such as Technical Capability Notices."</p><p><em>IT Pro</em> contacted two telcos known to have used Yahoo's email services, either in the past or currently Sky and BT to find out if their customers may be among those who allegedly had their data scanned.</p><p>A BT spokesman said: "Yahoo have stated they are a law abiding company and comply with the laws of the United States." Sky did not respond to <em>IT Pro</em>'s request for comment.</p><p>According to <em><a href="http://www.nytimes.com/2016/10/06/technology/yahoo-email-tech-companies-government-investigations.html">The New York Times</a></em>, Yahoo was forced by a secret court order adapted existing software, which scans for spam and images of child abuse being sent to Yahoo Mail addresses, "to search for messages containing a computer 'signature' tied to the communications of a state-sponsored terrorist organisation", citing "several people familiar with the matter".</p><p>"With some modifications, the system stored and made available to the [FBI] a copy of any messages it found that contained the digital signature," the<em>NYT</em> reported.</p><p>"The order was unusual because it involved the systematic scanning of all Yahoo users' emails rather than individual accounts," the newspaper added.</p><p>Several other tech companies, including Google, Facebook, Microsoft and Twitter said they had never received this kind of request and that if they had, or do in the future, they would fight the order in court.</p><p><strong>05/10/2016: Yahoo 'snooped on users' emails and passed data to the NSA'</strong></p><p>Yahoo has secretly been scanning its customers' emails and sending information contained in them to the NSA, <a href="http://www.reuters.com/article/us-yahoo-nsa-exclusive-idUSKCN1241YT">according to a<em>Reuters</em> report</a>.</p><p>Three former Yahoo employees and a fourth person "appraised of the events" allegedly told<em>Reuters</em> the beleaguered company last year "secretly created a software programme to search all [Yahoo Mail] customers' incoming emails for specific information provided by the US intelligence officials".</p><p>The details of the case are a little hazy beyond this information <em>Reuters</em> was unable to determine what keywords or information were being scanned for, what information (if any) was handed over, or whether any other email providers were asked to comply with the same order.</p><p>However, the news agency's sources did indicate that the decision to comply with the request was one of the reasons the company's then-CIO, Alex Stamos, resigned in June 2015.</p><p>In a statement to <em>Reuters</em>, a spokesperson said: "Yahoo is a law abiding company, and complies with the laws of the United States."</p><p>The situation has riled both privacy campaigners and the tech community at large.</p><p>Jim Killick, executive director of the Open Rights Group, told<em>IT Pro</em>: "This could be very damaging for Yahoo and will no doubt affect the trust its customers have in their services. Surveillance should be carried out through a transparent legal framework and only in response to warrants.</p><p>"While there may be a need for companies to scan incoming emails for malware and spam ... they should not indiscriminately spy on customers who are not suspected of any crime. Yet again we need more transparency about how companies are working with law enforcement and security agencies."</p><p>Rafael Laguna, CEO of Open-Xchange said: "The integrity of Yahoo as an email provider is in tatters. As a user, <a href="https://www.itpro.com/security/27288/canadian-pleads-guilty-to-yahoo-hack" data-original-url="https://www.itpro.com/security/27288/canadian-pleads-guilty-to-yahoo-hack">if you're not having your details leaked online</a> you can be sure the US government is rifling through your emails and attachments. This utter disregard for the consent of law abiding citizens is shocking but it is something the NSA and GCHQ increasingly believe they can do with impunity."</p><p>Only last month Yahoo confirmed a hack in late 2014 obtained 500 million people's usernames and passwords, with the search giant blaming a "nation state actor".</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/27288/canadian-pleads-guilty-to-yahoo-hack" data-original-url="/security/27288/canadian-pleads-guilty-to-yahoo-hack">Canadian pleads guilty to Yahoo hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27296/yahoo-hack-what-your-business-needs-to-know-and-why-you-shouldnt-panic" data-original-url="/security/27296/yahoo-hack-what-your-business-needs-to-know-and-why-you-shouldnt-panic">Yahoo hack: what your business needs to know - and why you shouldn't panic</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco customers targeted using leaked NSA hacking tools ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/27273/cisco-customers-targeted-using-leaked-nsa-hacking-tools</link>
                                                                            <description>
                            <![CDATA[ Networking giant says there isn’t a workaround for the issue ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vDpsQbQEFbosGPis4BQvDs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QuF5R6vL3xkkxUAYNY8XSd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Sep 2016 10:44:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sooraj Shah ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QuF5R6vL3xkkxUAYNY8XSd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man typing code on a laptop]]></media:description>                                                            <media:text><![CDATA[Man typing code on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[Man typing code on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QuF5R6vL3xkkxUAYNY8XSd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers have targeted some Cisco customers using a new vulnerability found thanks to leaked NSA cyber tools.</p><p>The tools were released in August by a hacker group dubbed ShadowBrokers and are confirmed to belong to the Equation Group which has strong ties with the NSA. It is the second such vulnerability to be found by Cisco as a result of the data dump made by the hackers; Cisco has already fixed a flaw in the SNMP implementation in its ASA firewalls.</p><p>Cisco has warned its customers that all versions of its IOS, IOS XE and IOS XR software are vulnerable to one of the many exploits released on August 15. The networking firm hasn't revealed which of its customers may have already been breached but the issue impacts firewalls, routers and switches made by the firm, enabling hackers to get hold of critical and confidential information from its customers.</p><p>"The vulnerability is due to insufficient condition checks in the part of the code that handles IKEv1 security negotiation requests. An attacker could exploit this vulnerability by sending a crafted IKEv1 packet to an affected device configured to accept IKEv1 security negotiation requests," the firm said in a security advisory blog.</p><p>But despite stating that its incident response team was aware of exploitation of the vulnerabilities of those customers running affected platforms, Cisco hasn't yet developed a patch for the flaw and has said no workarounds are available. Instead, it has released IPS signatures and Snort rules to mitigate the risks for its customers.</p><p>The exploit is called BENIGNCERTAIN and is made up of three binaries, each of which can be exploited to obtain RSA private key data and VPN configuration details if used against Cisco PIX firewalls.</p><p>Cisco isn't the only networking company to have exploits revealed. The ShadowBrokers data dump included exploits for Juniper and Fortinet, amongst others.</p><p>French Caldwell, former Gartner fellow and chief evangelist at GRC apps company <a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__www.metricstream.com_&d=DQMFAg&c=gOrgfQB8xVH7F0lP7MQhi8CyVXMBvYqNyP3LuSSb8Lw&r=B32zI-r_AuWxReogaS5UatIEiSqNFs32rpHR0Ax-nJ8&m=YEaOArANvDfMFON-uO3vojuiHlPN6mgTY6SAgAt6DEM&s=G2cZcHfynW8YqltqTGSPf4U5c4B-VoBG9kFBGxI2s84&e=">MetricStream</a>, warned other spy agencies particularly the other Five Eyes members that they too are vulnerable to a similar hack.</p><p>"If the NSA was hacked, the chances that they too have been targeted are certainly more than 50-50," he said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Was an insider behind the NSA hack? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hacking/27125/was-an-insider-behind-the-nsa-hack</link>
                                                                            <description>
                            <![CDATA[ Linguistic analysis casts doubt on "Russian hacker" claims ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aA7hgcyoJD73p7HWjpaway</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Aug 2016 09:03:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The perpetrator of the Shadow Brokers breach at the NSA may in fact by an English-speaking insider at the American agency, rather than a Russian hacker collective, as first presumed.</p><p>Earlier this month, attackers revealed they had managed to gain access to cyber weapons from the Equation Group, widely thought to be the NSA's own state hacking collective. They circulated 300 files online detailing zero-day exploits - several of which <a href="https://www.itpro.com/security/27114/cisco-confirms-shadow-brokers-vulnerabilities-are-real" target="_blank" data-original-url="https://www.itpro.com/security/27114/cisco-confirms-shadow-brokers-vulnerabilities-are-real">have been confirmed as genuine</a> - and auctioned off a second, encrypted cache to the highest bidder.</p><p>It was initially theorised that the hackers were foreign operatives with the most popular theory being that they were Russian. This was spurred on by the fact that <a href="https://archive.is/rdYpc" target="_blank">the Pastebin post from the perpetrators</a> was in broken English.</p><p>However, linguistic analysis by Shlomo Aragon, professor of Computer Science and director of the Linguistic Cognition Laboratory at the Illinois Institute of Technology (IIT) suggested that the author of the post is actually a native English-speaker trying to disguise the fact they are anglophone.</p><p>"The texts contain a variety of different grammatical errors that are not usual in the English of US native speakers," writes Aragon in <a href="https://taia.global/2016/08/shadowbroker-is-a-native-english-speaker-trying-to-appear-non-native" target="_blank">a post on Taia Global</a>. These include the omission of definite and indefinite articles ("a" and "the"), the omission of infinitive "to" (e.g., "I want get" instead of "I want to get") and confusion of tenses.</p><p>However, he points out that, while there are grammatical errors, there are no spelling errors, irrespective of how complex the word is. Additionally, the grammatical errors are inconsistent and the author uses plenty of idioms, even though they do contain mistakes in grammar. This has let Aragon to the conclusion that "the author is most likely a native speaker of US English who is attempting to sound like a non-native speaker by inserting a variety of random grammatical errors".</p><p>Separately, others have come to the conclusion that the perpetrator is an NSA insider.</p><p>Cyber security professional and white hat hacker Matt Suiche said in <a href="https://medium.com/@msuiche/shadowbrokers-the-insider-theory-ded733b39a55#.8cj8a1mwi" target="_blank">a post on Medium</a> that a former NSA analyst had come to him with this theory, speaking on the condition of anonymity.</p><p>After discussions with this source, several points were put forward suggesting the "hackers" were in fact a single person working from within the NSA. These include the fact that the name ShadowBrokers originally comes from the computer game Mass Effect, and that the NSA Tailored Access Operations (TAO) group, where the cyber weapons stolen are thought to come from, apparently has a "big gaming culture"</p><p>Also, the depository containing the NSA TAO toolkit is reportedly stored on a separate network that is not connected to the internet at all (which would impede someone trying to hack from the outside).</p><p>The "TAO Team had severe concerns about how easy it was to just walk out with the data on a USB drive" and a native English-speaker could easily fake broken English to make themselves sound Russian (although Suiche does not go into as much detail as Aragon in terms of analysis).</p><p>However, Suiche does concede "this is only a possible scenario" and "the discussion is open".</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/27114/cisco-confirms-shadow-brokers-vulnerabilities-are-real" data-original-url="/security/27114/cisco-confirms-shadow-brokers-vulnerabilities-are-real">Cisco confirms Shadow Brokers vulnerabilities are real</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Juniper Networks to ditch alleged NSA eavesdropping code ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/networking/25829/juniper-networks-to-ditch-alleged-nsa-eavesdropping-code</link>
                                                                            <description>
                            <![CDATA[ New security systems without the code will be shipped in first half of this year ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vcJ38gRsUJp6Sj7eNuLhdZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hPV3oeC6bRSaxEdMbWwvdP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 Jan 2016 13:22:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hPV3oeC6bRSaxEdMbWwvdP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[eye binary code]]></media:description>                                                            <media:text><![CDATA[eye binary code]]></media:text>
                                <media:title type="plain"><![CDATA[eye binary code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hPV3oeC6bRSaxEdMbWwvdP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Juniper Networks is dropping a piece of security code believed to have been developed by the US National Security Agency (NSA) for eavesdropping.</p><p>The company announced in December that it had found two backdoors in software that relies on Dual Elliptic Curve (Dual EC) technology, which appeared in 2012 and 2014.</p><p>Hovav Shacham, one of the researchers at the University of California, San Diego, who discovered the vulnerability, said the one introduced in 2014 was quite straightforward, according to <em><a href="http://in.reuters.com/article/us-spying-juniper-idINKBN0UN07520160109" target="_blank">Reuters</a></em>.</p><p>However, the 2012 code altered the mathematical constant in the company's Netscreen products, allowing the creator to eavesdrop on communications, Shacham and his team claimed.</p><p>A separate curve constant, required for some federal contracts and provided by the NSA, was exposed in the documents released by whistleblower Edward Snowden to be the key to the backdoor.</p><p>Questions about DEC were raised back in 2007, but Juniper decided to use it anyway the following year. The company issued a patch back in December 2015, which reverted back to this 2008 code, however it is now set to remove the technology all together.</p><p>While no culprit has been officially named, Nicholas Weaver, from the International Computer Science Institute and UC Berkley, told <em>Reuters</em> that the NSA is a logical suspect for the development of the original 2008 backdoor, which may have been displaced in the 2012 and 2014 incidences by either top-level hackers or other countries' spy agencies.</p><p><a href="http://forums.juniper.net/t5/Security-Incident-Response/Advancing-the-Security-of-Juniper-Products/ba-p/286383" target="_blank">In a blog post,</a> Juniper Networks said: "After a detailed review, there is no evidence of any other unauthorised code in ScreenOS [the software used in Netscreen] nor have we found any evidence of unauthorised code in Junos OS [the primary Juniper OS]."</p><p>"After review of commentary from security researchers and through our own continued analysis, we have identified additional changed Juniper will make to ScreenOS," the company continued.</p><p>It then added: "We will replace Dual_EC and ANSI X9.31 in ScreenOS 6.3 with the same random number generation technology currently employed accross our broad portfolio of Junos OS products. We intend to make these changes in a subsequent ScreenOS oftware release, which will be made available in the first half of 2016.</p><p>"The investigation into the origin of the unauthorised code continues."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ can control your smartphone, Edward Snowden says ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/25398/gchq-can-control-your-smartphone-edward-snowden-says</link>
                                                                            <description>
                            <![CDATA[ The US whistleblower said GCHQ can track the location, power management and conversations using 'Smurf' tools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5ShEdoQNATnHm2oSpzevbr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dp3vwfsfpSJLQJES7D7iXe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 Oct 2015 07:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Phones]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dp3vwfsfpSJLQJES7D7iXe-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[&amp;quot;Privacy&amp;quot; written atop a circuit board]]></media:description>                                                            <media:text><![CDATA[&amp;quot;Privacy&amp;quot; written atop a circuit board]]></media:text>
                                <media:title type="plain"><![CDATA[&amp;quot;Privacy&amp;quot; written atop a circuit board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dp3vwfsfpSJLQJES7D7iXe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US whistleblower Edward Snowden has revealed that UK intelligence agency GCHQ has the tools to hack into and control phones without the owners being aware they are being tracked.</p><p>He explained that authorities can implement tools - called Dreamy Smurf, Nosey Smurf, Paranoid Smurf and Tracker Smurf - by sending a smartphone an encrypted text message.</p><p>"Dreamy Smurf is the power management tool which means turning your phone on and off without you knowing," Snowden said."Nosey Smurf is the 'hot mic' tool. For example if it's in your pocket, [GCHQ] can turn the microphone on and listen to everything that's going on around you - even if your phone is switched off because they've got the other tools for turning it on."</p><p>He explained that Tracker Smurf is a geo-location tool that could potentially allow GCHQ to follow smartphone users better than using standard cellular location towers.</p><p>Paranoid Smurf is a self-protection tool that can be used to stop you getting rid of the other tools on a device. If you spot something strange is going on with your device and take it to a phone shop to fix the problem, for example, Paranoid Smurf would hide the evidence so technicians wouldn't find anything wrong.</p><p>Snowden spoke to the BBC's Panorama programme from his base in Russia, where he ran away to after leaking other snooping allegations about the GCHQ and US's National Security Agency (NSA).</p><p>The NSA also have a similar set of tools to use in the fight against terrorism, Snowden said. The US security organisation reportedly spent $1bn on the tools to respond to terrorists' increased use of smartphones.</p><p>Although he did not specifically say the GCHQ and NSA wanted to partake in mass surveillance, they have both invested in software that would allow them to hack into devices in order to track what you're saying, what you're doing and where you are.</p><p>"They want to own your phone instead of you," he said.</p><p>The UK government commented: "All of GCHQ's work is carried out in accordance with a strict legal and policy framework, which ensures that our activities are authorised, necessary and proportionate, and that there is rigorous oversight, including from the secretary of state, the interception and intelligence services commissioners and the Parliamentary Intelligence and Security Committee. All our operational processes rigorously support this position."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AT&T and NSA collaborated on "vast" surveillance program ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/25150/att-and-nsa-collaborated-on-vast-surveillance-program</link>
                                                                            <description>
                            <![CDATA[ Documents reveal the two organisations have been working together for decades ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oX1vfyM5nP6rXPv2PpwmfR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8fYaZzGGEmNDiU8we4i5FE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2015 07:51:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8fYaZzGGEmNDiU8we4i5FE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8fYaZzGGEmNDiU8we4i5FE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US telecoms giant AT&T has been working with the National Security Agency (NSA) for decades to help it carry out mass internet surveillance, according to recent reports.</p><p>Leaked NSA documents dated between 2003 and 2013 reveal AT&T has been 'highly collaborative' and had 'an extreme willingness to help' the spy agency to track US citizens.</p><p>The <em><a href="http://www.nytimes.com/2015/08/16/us/politics/att-helped-nsa-spy-on-an-array-of-internet-traffic.html?_r=1">New York Times</a></em> and ProPublica said AT&T gave the NSA access to billions of the American public's emails as they flowed through its US network and also provided the technical expertise needed by the NSA to tap into communications at the UN's headquarters in New York.</p><p>The budget for carrying out such operations was double that of other large surveillance operations, part of which was spent on installing equipment in 17 of AT&T's US-based internet hubs. This is much more than the NSA implemented on competitor Verizon's network, which, it has been claimed, shows a closer relationship between AT&T and the spy agency.</p><p>Although ProPublica didn't mentioned AT&T as the company involved in such a high-level of spying, the evidence presented by the NSA pointed directly at the telecoms giant, which has mobile, internet and other network-based services in the US.</p><p>AT&T spokesman, Brad Burns told the New York Times: "We do not voluntarily provide information to any investigating authorities other than if a person's life is in danger and time is of the essence."</p><p>Former agency contractor Edward Snowden provided the NSA's documents to the New York Times and ProPublica. They also revealed Verizon, one of America's other largest telcos had been working with the spy agency on a project called Stormbrew that involved pulling data from the company's fibre-optic cables.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA and GCHQ have been spying on you for 50 years ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/25092/nsa-and-gchq-have-been-spying-on-you-for-50-years</link>
                                                                            <description>
                            <![CDATA[ Journalist reveals very first mass surveillance programme, Project Echelon ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gFLV1PgvD5BUfMshKcq839</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2015 10:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NSA data]]></media:description>                                                            <media:text><![CDATA[NSA data]]></media:text>
                                <media:title type="plain"><![CDATA[NSA data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A spy programme known as Project Echelon has been tapping into billions of phone calls a year for the last half-century, according to a campaigning journalist writing for <a href="https://firstlook.org/theintercept/2015/08/03/life-unmasking-british-eavesdroppers" target="_blank"><em>The Intercept</em></a>.</p><p>The scheme was jointly-run by US agency NSA and British agency GCHQ, and signalled the advent of mass surveillance by ushering in an age of "Big Brother"-style snooping, according to one source.</p><p>Starting in 1966, the project leapt into life when the NSA fronted the money for the GCHQ to build a station in Bude, Cornwall, capable of intercepting satellite communications from Intelsat, the first commercial communications satellite network.</p><p>Journalist Duncan Campbell and fellow reporter Jim Bamford located a second site in Yakima, America, that intercepted US-Asia communications.</p><p>Campbell wrote: "At the dawn of the era of mass surveillance, almost 50 years ago, the ECHELON stations at Bude and Yakima were the global mass surveillance system."</p><p>The Echelon system was automated, and able to sift through vast swathes of data from these satellites to sort and categorise it all.</p><p>Speaking to a former Lockheed (now Lockheed Martin) employee in the late 1980s who was responsible for managing NSA databases at a new site in California, Campbell learned how Echelon was spying on politicians, and his source also shared plans for the IT system underpinning the project.</p><p>He wrote: "The plans showed how ECHELON, also called Project P415, intercepted satellite connections, sorting phone calls, telex, telegraph and computer signals.</p><p>"Although the internet was then in early infancy, what was carried digitally was covered. The way ECHELON had been designed, she said, demonstrated the targeting of U.S. political figures was not an accident."</p><p>Campbell added that the scale of the operation had shocked him.</p><p>"The NSA and its partners had arranged for everything we communicated to be grabbed and potentially analyzed," he said. "ECHELON was at the heart of a massive, billion-dollar expansion of global electronic surveillance for the 21st century."</p><p>However, Campbell's expose of the spying programme in 1988 was ignored for 11 years, until the European Parliament commissioned an investigation in 1999.</p><p>Though the parliament mandated extensive action against mass surveillance in 2001, a few days later the Twin Towers were destroyed in the 9/11 terrorist attack.</p><p>"Any plans for limiting mass surveillance were buried with the victims of 9/11," wrote Campbell.</p><p>Since Edward Snowden's revelations about the NSA laid bare the extent of spying programmes against US and European citizens, public interest has spiked in privacy, and some of the documents leaked actually confirmed Campbell's reports.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ and NSA try to crack Kaspersky software and others ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/24846/gchq-and-nsa-try-to-crack-kaspersky-software-and-others</link>
                                                                            <description>
                            <![CDATA[ Snowden files reveal reverse-engineering attempts on popular consumer anti-virus firms, as well as web forum surveillance ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mFrYoGvLDquVFaMceynYRr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pRDu8iYQjogvCLxqPKuWbE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Jun 2015 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pRDu8iYQjogvCLxqPKuWbE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kaspersky sign on a white post]]></media:description>                                                            <media:text><![CDATA[Kaspersky sign on a white post]]></media:text>
                                <media:title type="plain"><![CDATA[Kaspersky sign on a white post]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pRDu8iYQjogvCLxqPKuWbE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GCHQ and the NSA stand accused of reverse-engineering consumer anti-virus software in order to hide their operations, it has been revealed.</p><p>Hacking efforts by UK spy body GCHQ have been stymied in the past by security vendors such as Kaspersky Labs, according to <a href="https://www.documentcloud.org/documents/2106826-gchq-application-for-renewal-of-warrant-gpw-1160.html#document/p1" target="_blank">a warrant renewal request</a> published by The Intercept.</p><p>The warrant states that the Russian AV company in particular continues to "pose a challenge" to GCHQ, and that the agency's goal is to be able to "exploit such software and to prevent detection of [their] activities".</p><p>In order to circumvent this type of security, the agency examined various elements of it for vulnerabilities, using a technique known as Software Reverse Engineering.</p><p>As part of the "computer network exploitation" tactics covered by the warrant, GCHQ likewise examined popular forum software vBulletin, which the document claims is "widely used to run terrorist web forums".</p><p>It is also, however, used to run and maintain a huge majority of legitimate forums such as NEOGAF and SomethingAwful, and SRE methods have previously yielded the recovery of an unspecified number of user credentials.</p><p>As these SRE techniques could potentially constitute "an infringement of copyright", GCHQ requires a legally-protecting warrant from the government that must be renewed every six months.</p><p>It was one such renewal request, dated from 2008, that was published today as part of <a href="https://www.itpro.com/hacking/24814/bruce-schneier-russia-hacked-nsa-for-snowden-docs" target="_blank" data-original-url="https://www.itpro.com/hacking/24814/bruce-schneier-russia-hacked-nsa-for-snowden-docs">the Snowden files</a>. It is unclear whether this practise of reverse-engineering security software is still common, as well as what GCHQ hoped to achieve in the process.</p><p>The warrant also notes that the agency's success in reverse-engineering strategies have led to developing capabilities against Cisco routers. This allows UK spies entry into the Pakistan Internet Exchange, where they have "access to almost any user of the internet inside Pakistan".</p><p>The NSA has also been undertaking similar projects. In a briefing from 2010, also part of the Snowden files, the US spy agency's "Project CAMBERDADA" was revealed to be intercepting malware-flagging email traffic between end-users and anti-virus vendors.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="8fYaZzGGEmNDiU8we4i5FE" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/8fYaZzGGEmNDiU8we4i5FE.jpg" mos="https://cdn.mos.cms.futurecdn.net/8fYaZzGGEmNDiU8we4i5FE.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>This information is used to compile a list of malware that vendors like Kaspersky have not yet adapted to combat. The agency's Tailored Access Operation unit then "repurpose the malware", allowing them piggyback access to machines and networks.</p><p>Kaspersky has been a notable opponent of state-sponsored intrusion. The Russian company had a hand in detecting and flagging multiple examples of suspected government malware such as the Gauss, Flame and Stuxnet viruses.</p><p>Earlier this month, the company discovered that it had itself been hit by <a href="https://www.itpro.com/malware/24793/what-is-duqu-20" target="_blank" data-original-url="https://www.itpro.com/malware/24793/what-is-duqu-20">the Duqu 2.0 worm</a>, which founder Eugene Kaspersky believes to be a "nation-state sponsored campaign".</p><p>The company said in a statement that "we find it extremely worrying that government organizations are targeting security companies instead of focusing their resources against legitimate adversaries."</p><p>It decried the fact that government divisions are "actively working to subvert security software that is designed to keep us all safe."</p><p>Along with Kaspersky Labs, a total of 23 vendors were listed in the presentation on a slide jauntily titled "more targets!" These included Bit-Defender, Avast, Avira and Checkpoint, with examples from multiple US-allied countries although none from within the US itself, or the UK.</p><p>However, while this may come as a shock to some, others in the infosec community are less than astonished. Ben Johnson, Chief Security Strategist for Bit9 + Carbon Black, points out that "AV tools can be bought and pulled apart by anyone".</p><p>He notes the logic of GCHQ's operations, asking "is it really a surprise that intelligence agencies try to circumvent technologies that might prevent them from collecting information? Or test these technologies for weaknesses?" </p><p>He likens this probing of vendor proficiency to real-world combat tactics; "In the hacker world as well as the military world before conducting any operation it is vital to test offensive tools against defensive capabilities".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bruce Schneier: Russia hacked NSA for Snowden docs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hacking/24814/bruce-schneier-russia-hacked-nsa-for-snowden-docs</link>
                                                                            <description>
                            <![CDATA[ Security expert says Snowden not to blame for Russia and China getting hands on secret files ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bh7CYapkQMzQ4XoaCBwPsL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Jun 2015 11:42:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Edward Snowden picture]]></media:description>                                                            <media:text><![CDATA[Edward Snowden picture]]></media:text>
                                <media:title type="plain"><![CDATA[Edward Snowden picture]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>China and Russia have copies of Edward Snowden's leaked documents by hacking the NSA itself before the whistleblower even arrived in Russia, according to security expert Bruce Schneier.</p><p>He believes lax security controls at the US spy agency, rather than Snowden residing in Russia, being responsible for allowing foreign countries to get their hands on top secret documents.</p><p>The countries also have sophisticated hacking capabilities that far outstrip journalists' abilities to protect the leaked documents, <a href="http://www.wired.com/2015/06/course-china-russia-snowden-documents" target="_blank">Schneier wrote in <em>Wired</em> yesterday</a>.</p><p>"The vulnerability is not Snowden; it's everyone who has access to the files," wrote Schneier.</p><p>"China and Russia had access to all the files that Snowden took well before Snowden took them because they've penetrated the NSA networks where those files reside.</p><p>"Remember that Snowden was able to wander through the NSA's networks with impunity."</p><p>He pointed to <a href="https://www.itpro.com/security/24353/was-russia-really-behind-white-house-hack" target="_blank" data-original-url="https://www.itpro.com/security/24353/was-russia-really-behind-white-house-hack">Russia's alleged hack of the White House network earlier this year</a>, as well as suspected hacks from China on US government databases.</p><p>He added that journalists protecting the files after receiving them from Snowden would have struggled to fend off government-backed cyber hackers.</p><p>"It's been open season on the computers of the journalists Snowden shared documents with since this story broke in July 2013," he claimed.</p><p>"While they have been taking extraordinary pains to secure those computers, it's almost certainly not enough to keep out the world's intelligence services." </p><p>Schneier's article was written in response to a <em>Sunday Times</em> front page story <a href="https://archive.is/BkuMM#selection-729.1-741.1" target="_blank">claiming MI6 has had to pull spies out of operations</a> because Russia had cracked more than one million encrypted documents held by Snowden.</p><p>The story has since been <a href="http://www.theguardian.com/us-news/2015/jun/14/snowden-files-read-by-russia-and-china-five-questions-for-uk-government" target="_blank">widely panned by media</a>, with other journalists pointing out inaccuracies such as the claim Snowden had fled to Russia in fact, he had been in Moscow en route to South America when the US revoked his passport, allowing Russia to hold him in transit.</p><p>Moreover, he said he left his documents with a contact in Hong Kong, pouring doubt on the article's claim he had the files when he landed in Russia.</p><p>Schneier said: "It's a terrible article, filled with factual inaccuracies and unsubstantiated claims about both Snowden's actions and the damage caused by his disclosure."</p><p>The cryptographer said he had no doubt Snowden had encrypted the documents before landing in Russia, just as the whistleblower has claimed, because it's sensible and easy to do.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US House votes to stop NSA’s mass surveillance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/24609/us-house-votes-to-stop-nsa-s-mass-surveillance</link>
                                                                            <description>
                            <![CDATA[ USA Freedom Act passed by House of Representatives with overwhelming support ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">puAkCqYps59YVr2RQxokg9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jXMz2SopKWuBpQRDCMisJb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 May 2015 10:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jXMz2SopKWuBpQRDCMisJb-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jXMz2SopKWuBpQRDCMisJb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US House of Representatives has voted to end the NSA's widespread surveillance of American citizens.</p><p>Members voted 338 to 88 to support the USA Freedom Act, a measure that amends and extends parts of 2001's much-discussed USA Patriot Act.</p><p>One of its clauses is the banning of the NSA from bulk-collecting US citizens' phone records, emails and web addresses.</p><p>According to Representative Goodlatte, the Judiciary Committee chair, one of the bill's driving forces, the NSA's blanket surveillance "has not ceased, and will not cease, unless and until Congress acts to shut it down".</p><p>This mass-scale data collection was the source of much controversy when it was revealed by <a href="https://www.itpro.com/mobile/23900/edward-snowden-claims-iphones-have-built-in-spyware" target="_blank" data-original-url="https://www.itpro.com/mobile/23900/edward-snowden-claims-iphones-have-built-in-spyware">Edward Snowden</a> in 2013.</p><p>The ex-NSA contractor leaked huge amounts of info related to programmes like PRISM and MYSTIC, and fled to Russia to avoid government sanctions.</p><p>The methods and scale of these spying operations led to a federal appeals court <a href="https://www.itpro.com/mobile/24574/nsa-phone-spying-was-illegal-rules-us-court" target="_blank" data-original-url="https://www.itpro.com/mobile/24574/nsa-phone-spying-was-illegal-rules-us-court">deeming them illegal</a> last week, and both rulings have been met with support from privacy<a href="https://www.itpro.com/mobile/24574/nsa-phone-spying-was-illegal-rules-us-court" target="_blank" data-original-url="https://www.itpro.com/mobile/24574/nsa-phone-spying-was-illegal-rules-us-court"> advocate groups.</a></p><p>Although the bill has now been passed by the House, it must still be ratified by the Senate in order to make it onto the statute books, having already received presidential approval.</p><p>However, current Senate majority leader Mitch McConnell has previously introduced bills designed to extends the NSA's powers rather than curtail them.</p><p>There are those in the Senate in favour of the bill, though, and both Senators Rand Paul and Ron Wyden have previously threatened to filibuster extensions of Patriot Act powers.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA phone spying was illegal, rules US court ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/24574/nsa-phone-spying-was-illegal-rules-us-court</link>
                                                                            <description>
                            <![CDATA[ Patriot Act does not cover bulk data collection, says Court of Appeals ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xrZcw7V3F7yGQtatruKWrx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 May 2015 10:58:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The NSA's bulk collection of phone data is illegal, the US Court of Appeals has ruled, overturning a landmark 2013 ruling.</p><p>The interception of phone call data, which began in 2006, is thought to have targeted European companies and world leaders including German chancellor Angela Merkel.</p><p>However, <a href="https://www.itpro.com/mobile/19949/nsa-snooping-phone-records-us-citizens" target="_blank" data-original-url="https://www.itpro.com/mobile/19949/nsa-snooping-phone-records-us-citizens">the existence of the programme did not become apparent until two years ago</a>, when whistleblower Edward Snowden leaked details to the public.</p><p>The US government argued successfully in the first instance that section 215 of the Patriot Act permitted bulk collection of call metadata, which reveals who or what device is making or receiving calls, but not the content of these conversations.</p><p>In the new hearing, though, judge Gerard Lynch determined this was not the case and that the actions of the NSA were illegal.</p><p>However, he did not rule the behaviour was illegal under the constitution, as claimed by the American Civil Liberties Union.</p><p>Consequently it has not ordered the intelligence organisation to stop the practice but urged the US Congress to take action.</p><p>Section 215 of the Patriot Act, and the permission for the NSA's bulk phone data collection given by a secret national security court, are valid until 1 June this year, after which time the US government must vote on whether or not to extend it.</p><p><a target="_blank" href="http://www.bbc.co.uk/news/world-us-canada-32620742">According to <em>the BBC</em></a>, leaders of the House of Representatives, the lower house in US government, would prefer to pass a bill ending the bulk collection of phone records, but statements made by the leader of the upper house, the Senate, have reportedly pointed towards a desire to extend the Patriot Act and bulk phone data collection.</p><p>The full text of the Court of Appeals' ruling can be read <a target="_blank" href="http://pdfserver.amlaw.com/nlj/NSA_ca2_20150507.pdf">here</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Edward Snowden's in the White House, according to Google Maps ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/24405/edward-snowdens-in-the-white-house-according-to-google-maps</link>
                                                                            <description>
                            <![CDATA[ Cyber expert Bryan Seely placed Edward Snowden in the White House through Google Maps loophole ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mpaJYKb7sUjfFgqHNozPMz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YeU7MGKoLnyMeEnB6Y3soH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Apr 2015 08:49:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YeU7MGKoLnyMeEnB6Y3soH-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[White House]]></media:description>                                                            <media:text><![CDATA[White House]]></media:text>
                                <media:title type="plain"><![CDATA[White House]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YeU7MGKoLnyMeEnB6Y3soH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Edward Snowden isn't in Russia after all, if you believe Google Maps, which thought he'd set up shop in the White House until recently.</p><p>Anyone hovering over the President's home on the mapping tool would see 'Edwards Snow Den' slap bang in the middle of the building.</p><p>In fact, it was hacker Bryan Seely who was responsible for Maps' mistake, exploiting a loophole in its listings process.</p><p>To set up the listing, Seely said he created a business in Google that he could send and receive mail to. Google then sent a postcard to the address with a verification code.</p><p>He then deleted this address from his account, using another Google account to claim the business. By going through the phone verification process, he found he could move the business to wherever he liked - in this case to the White House.</p><p>Although Edwards Snow Den is listed as having a Seattle phone number, he managed to change all the other details without too much trouble, which obviously caused a lot of chatter.</p><p><a href="https://www.itpro.com/security/23880/google-risks-microsofts-wrath-with-new-windows-81-bug-disclosure" target="_blank" data-original-url="https://www.itpro.com/security/23880/google-risks-microsofts-wrath-with-new-windows-81-bug-disclosure">As Microsoft knows</a>, if Google ever finds a public security vulnerability in any other company, it gives them 90 days to correct the flaw. Yet Google has had over a year to close this hole that allows anyone to post a place on Google Maps, and hadn't dealt with it.</p><p>Previously, Seely has set up other businesses linked to the FBI and Secret Service. He wanted to use the method again to show that Google hadn't fixed the loophole.</p><p>Seely said that although Google does a lot of things right and is a great company, when it doesn't takes things like this seriously, it's disappointing. "It's disheartening. It's like finding out your favorite company is a piece of sh**," he told <a href="https://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=1&cad=rja&uact=8&ved=0CCIQqQIwAA&url=http%3A%2F%2Fsearchengineland.com%2Fgoogle-maps-loophole-snowden-whitehouse-218682&ei=YXYvVavoNoHeaI_1geAJ&usg=AFQjCNHqdDJoWzDg2gzPtDClh1dIFqqzfg&sig2=OLU6iP3FZTI2Igii316NEw&bvm=bv.91071109,d.bGQ" target="_blank"><em>Search Engine Land</em></a>.</p><p>Not only does it make Google look bad, it also misleads customers into thinking they are genuine businesses and could be used maliciously by others.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Amnesty International takes Gov to court over spying ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/24378/amnesty-international-takes-gov-to-court-over-spying</link>
                                                                            <description>
                            <![CDATA[ Ten human rights orgs take government to the European Court of Human Rights to stop surveillance ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4ZfSeiq4eBXSz5iWXBMoo7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Apr 2015 08:29:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spyglass]]></media:description>                                                            <media:text><![CDATA[Spyglass]]></media:text>
                                <media:title type="plain"><![CDATA[Spyglass]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.amnesty.org/articles/news/2015/04/amnesty-international-takes-uk-government-to-european-court-of-human-rights-over-mass-surveillance" target="_blank">Amnesty International</a> is taking the government to the European Court of Human Rights over its mass surveillance of UK citizens.</p><p>The organisation claims the government's practice of mass surveillance goes against human rights, and has issued the legal challenge with another nine bodies.</p><p>All object to the government's methods of interception, collection, inspection, distribution and retention of communications "without any judicial authorisation," their filing said.</p><p>Their complaint is based on revelations leaked by ex-NSA contractor <a href="https://www.itpro.com/security/22857/edward-snowden-awarded-three-year-russian-permit" target="_blank" data-original-url="https://www.itpro.com/security/22857/edward-snowden-awarded-three-year-russian-permit">Edward Snowden</a>, who revealed information on secret US data collection programmes like <a href="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power" target="_blank" data-original-url="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power">PRISM</a>, collecting communications data including emails, text messages, phone calls and social media without permission.</p><p><a href="https://www.amnesty.org/en/documents/ior60/1415/2015/en" target="_blank">The court filing</a> mentioned Tempora, Upstream and PRISM as three of the mass surveillance programmes it was hoping to stop, saying the operations were making it increasingly difficult for Amnesty International to carry out its work.</p><p>While based in the US, the PRISM and Upstream programmes extended to UK-held data. Meanwhile Tempora is the UK's own GCHQ programme, giving spooks access to vast swathes of data on millions of people.</p><p>"It is thanks only to Edward Snowden's revelations, and the scant disclosures we and the other claimants have been able to prise from the government, that we know anything whatsoever about what the intelligence services are up to," said James Welch, Legal Director for Liberty.</p><p>The filing also detailed how a closed hearing took place, outlining Amnesty International and the other applicants' concerns, but none of the bodies were invited to attend because of the sensitive nature of the country's security.</p><p>Nick Williams, Amnesty International's legal counsel said: "The UK government's surveillance practices have been allowed to continue unabated and on an unprecedented scale, with major consequences for people's privacy and freedom of expression. No-one is above the law and the European Court of Human Rights now has a chance to make that clear."</p><p>Carly Nyst, legal director of Privacy International, added: "Mass surveillance is a violation of our fundamental rights. Intercepting millions of communications every day, and secretly receiving millions more from the NSA by the back door is neither necessary nor proportionate."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Facebook hit by class action lawsuit focused on data privacy ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy</link>
                                                                            <description>
                            <![CDATA[ Court case starts today to decide whether the social network is guilty of breaking EU law ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2W7KJdYGDY3e137WB4UpYD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/is77CKW8CLpExxLiWeuTJT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Apr 2015 10:54:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/is77CKW8CLpExxLiWeuTJT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Facebook Like sign]]></media:description>                                                            <media:text><![CDATA[Facebook Like sign]]></media:text>
                                <media:title type="plain"><![CDATA[Facebook Like sign]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/is77CKW8CLpExxLiWeuTJT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A privacy lawsuit brought against Facebook by 25,000 people begins today, with the social network being accused of illegally tracking user data.</p><p><a href="https://www.itpro.com/networking/22836/facebook-under-scrutiny-for-privacy-policy" target="_blank" data-original-url="https://www.itpro.com/networking/22836/facebook-under-scrutiny-for-privacy-policy">The class action case</a> also alleges that the tech giant took part in the NSA's PRISM programme, which raked personal data from the servers of major US companies with their apparent agreement.</p><p>While Facebook denies any involvement, the claimants hope the case will improve tech companies' attitudes to data protection.</p><p>Campaigner Max Schrems said <a href="http://www.afp.com/en/news/david-v-goliath-austrian-activist-take-facebook-court" target="_blank">in an <em>AFP</em> interview</a>: "We are asking Facebook to stop mass surveillance, to [have] a proper privacy policy that people can understand, but also to stop collecting data of people that are not even Facebook users.</p><p>"There is a wide number of issues in the lawsuit and we hope to kind of win all of them and to get a landmark case against US data-gathering companies."</p><p>Schrems claims Facebook has taken a "Wild West" approach to data protection, and the case concerns its treatment of non-US data stored on its Dublin servers.</p><p>The compensation requested by claimants - 360 per user adds up to 9 million.</p><p>Judges will decide whether Facebook is guilty of breaking EU law in its policy on data use, sharing data with external apps and tracking users on external pages, among other issues.</p><p>Facebook hasn't commented publicly on the case, but CEO Mark Zuckerberg denied any involvement in the <a href="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power" target="_blank" data-original-url="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power">NSA PRISM scheme</a> back in 2013.</p><p>The campaign is being financed by litigation firm Roland Prozessfinanz and the company's 20 per cent fee will be deducted from the total damages awarded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wikimedia accuses NSA and US DoJ of stifling freedom of speech ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/24206/wikimedia-accuses-nsa-and-us-doj-of-stifling-freedom-of-speech</link>
                                                                            <description>
                            <![CDATA[ The Foundation is taking legal action against the NSA and the US Department of Justice ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">weuFWsA2QMUTWBewDSZeRT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4xj8ZPXCcEyoFNsXbKn6k9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Mar 2015 09:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4xj8ZPXCcEyoFNsXbKn6k9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[legal hammer]]></media:description>                                                            <media:text><![CDATA[legal hammer]]></media:text>
                                <media:title type="plain"><![CDATA[legal hammer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4xj8ZPXCcEyoFNsXbKn6k9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Wikimedia Foundation is suing the NSA and US Department of Justice because it believes the spy agency's mass surveillance programmes violate freedom of speech laws.</p><p>Eight organisations have signed the documents, calling for the NSA to shut down its large-scale surveillance operation that tracks data flowing to and from the US to protect its 500 million monthly users.</p><p>Lila Tretikov, executive director of the Wikimedia Foundation, said in a blog post on the <a href="http://www.nytimes.com/2015/03/10/opinion/stop-spying-on-wikipedia-users.html?_r=0">New York Times</a>: "The NSA's mass surveillance of Internet traffic on American soil often called "upstream" surveillance violates the Fourth Amendment, which protects the right to privacy, as well as the First Amendment, which protects the freedoms of expression and association.</p><p>"We also argue that this agency activity exceeds the authority granted by the <a href="http://topics.nytimes.com/top/reference/timestopics/subjects/f/foreign_intelligence_surveillance_act_fisa/index.html?inline=nyt-classifier">Foreign Intelligence Surveillance Act</a> that Congress amended in 2008."</p><p>The blog post goes on to explain that Wikipedia's users have the right to browse and upload articles to Wikipedia anonymously and without prejudice. The NSA snooping on its users could break confidentiality, especially in countries where governments are repressive and this could lead Wikipedia's users not to post topical information to the website.</p><p>"By tapping the backbone of the internet, the NSA is straining the backbone of democracy. By violating our users' privacy, the NSA is threatening the intellectual freedom that is central to people's ability to create and understand knowledge," she continued.</p><p>"Privacy is an essential right. It makes freedom of expression possible, and sustains freedom of inquiry and association. It empowers us to read, write and communicate in confidence, without fear of persecution. Knowledge flourishes where privacy is protected."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA & GCHQ SIM card hack: Gemalto denies encryption keys stolen through hack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/24092/nsa-gchq-sim-card-hack-gemalto-denies-encryption-keys-stolen-through-hack</link>
                                                                            <description>
                            <![CDATA[ Special mobile unit was set up in 2010 to steal encryption keys ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2vQCZeEWZ3jQitAEuBYocQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 25 Feb 2015 10:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Khidr Suleman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>SIM card maker Gemalto has shared details of its investigation into claims British and US securities services hacked the company to steal billions of encryption keys.</p><p><strong>Privacy International blasts security services</strong></p><p>"GCHQ has lost it's way. In stealing the SIM card encryption keys of millions of mobile phone users they have shown there are few lines they aren't willing to cross," the charity told <em>IT Pro</em>.</p><p>"Hacking into law-abiding companies, spying on their employees and stealing their data should never be considered 'fair game.' </p><p>"The mentality of 'Act first, worry about the law later' has to come to an end. Unrestrained, unregulated Government spying of this kind is the antithesis of the rule of law and they must be held accountable for their actions."</p><p>The two agencies are said to have joined forces to set up a specialist Mobile Handset Exploitation Team (MHET) in April 2010, documents by <em><a href="https://firstlook.org/theintercept/2015/02/19/great-sim-heist/https:/firstlook.org/theintercept/2015/02/19/great-sim-heist" target="_blank" data-original-url="https://firstlook.org/theintercept/2015/02/19/great-sim-heist/https://firstlook.org/theintercept/2015/02/19/great-sim-heist">The Intercept</a></em> revealed. The unit's mission was to target vulnerabilities in mobile devices.</p><p>Operatives worked to infiltrate Dutch company Gemalto, which produces 2 billion SIM cards a year and serves 450 telecoms operators across the globe, it was claimed.</p><p>A top secret slide (below) confirmed the NSA and GCHQ had gained access to Gelmato's network and mined the private communications of engineers and sales employees.</p><p>The claims are the latest in a long line of revelations to have been made public by NSA whistleblower Edward Snowden.</p><p>By stealing encryption keys, the intelligence agencies were able to monitor mobile communications without approval from telecom companies and foreign governments, all without being traced.</p><p>In a statement published on 25 February, the organisation said it has reason to believe the NSA and GCHQ were behind a series of attempts made in 2010 and 2011 to hack into the company and its network. </p><p>"At the time we were unable to identify the perpetrators but we now think they could be related to the NSA and GCHQ operation," the statement reads. </p><p>"These intrusions only affected the outer parts of our networks - our office networks - which are in contact with the outside world.</p><p>"The SIM encryption keys and other customer data in general, are not stored on these networks," the statement added.</p><p>Therefore, it denied claims the security services were able to steal the SIM encryption keys because the NSA and GCHQ appear to have only succeeded in breaching its office networks.</p><p>Instead, Gemalto's investigation into the matter has suggested the NSA and GCHQ may have targeted other parts of its SIM card supply chain to get access to the encryption keys, rather than via its own network.</p><p>Furthermore, it also denies that it ever sold SIM cards to four out of the 12 operators listed in the leaked documents.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="F3FfKGoHAmboAJq59jFDFm" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/F3FfKGoHAmboAJq59jFDFm.png" mos="https://cdn.mos.cms.futurecdn.net/F3FfKGoHAmboAJq59jFDFm.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Gemalto described the attacks as as "serious and sophisticated", but said no signs of malicious activity were observed anywhere else in its networks.</p><p>"No breaches were found in the infrastructure running our SIM activity or in other parts of the secure network which manage our other products such as banking cards, ID cards or electronic passports," the statement continued. </p><p>"We are conscious that the most eminent state agencies, especially when they work together, have resources and legal support that go far beyond that of typical hackers and criminal organisations.</p><p>"And, we are concerned that they could be involved in such indiscriminate operations against private companies with no grounds for suspicion," the statement concluded. </p><p>When the allegations first came to light last week, Gelmato said in a statement that the security services appear to have tried to reach as many mobile phones as possible.</p><p>"We cannot at this early stage verify the findings of the publication and had no prior knowledge that these agencies were conducting this operation," the firm said.</p><p>"We take this publication very seriously and will devote all resources necessary to fully investigate and understand the scope of such sophisticated techniques."</p><p><strong><em>This article was originally published on 25/2/15 and updated on the same day to include details of Gemalto's investigation.</em></strong></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK tribunal rules GCHQ's NSA data-sharing deal "unlawful" ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/24005/uk-tribunal-rules-gchqs-nsa-data-sharing-deal-unlawful</link>
                                                                            <description>
                            <![CDATA[ Civil liberty groups cheer court ruling, but claim there is more work to do ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2x4oWP8kCmFdzXmHJ2RmUz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Feb 2015 16:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Surveillance]]></media:description>                                                            <media:text><![CDATA[Surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[Surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Investigatory Powers Tribunal (IPT) has declared British intelligence services acted unlawfully by accessing the personal communications data gathered by the US National Security Agency (NSA).</p><p>The IPT, set up 15 years ago to oversee the activities of GCHQ, MI5 and MI6, ruling follows a complaint made by several civil liberties organisations, including Amnesty International, Privacy International, Bytes for All and Liberty.</p><p>The Tribunal said the way intelligence was shared between GCHQ and the NSA's Prism surveillance programme was unlawful up until December 2014, because the rules governing the practice were kept secret.</p><p>Post-December 2014, this was no longer the case, as the details of it were made public through the work of the Tribunal.</p><p>The existence of Prism came to light in a series of disclosures by NSA whistleblower Edward Snowden during the summer of 2013.</p><p>Through the programme, it's alleged the NSA was able to access data used by the a wide range of tech giants, including Microsoft, Yahoo, Google and Facebook, and share it with GCHQ if needed.</p><p>As a result of today's outcome, Privacy International and Bytes for All have asked for further clarification from the court regarding the interception and collection of their communications data.</p><p>If it transpires that their data was unlawfully collected before December 2014, the parties are set to demand its immediate deletion.</p><p>They also want to challenge the assertion that GCHQ's activities after December 2014 were lawful, and have vowed to lodge an application with the European Court of Human Rights on this point.</p><p>Eric King, deputy director of Privacy International, said the ruling should put an end to security agencies acting like they can operate outside of the law.</p><p>"We must not allow agencies to continue justifying mass surveillance programs using secret interpretations of secret laws. The world owes Edward Snowden a great debt for blowing the whistle, and today's decision is a vindication of his actions," he said.</p><p>"But more work needs to be done. The only reason why the NSA-GCHQ sharing relationship is still legal today is because of a last-minute clean-up effort by Government to release previously secret arrangements'.</p><p>"That is plainly not enough to fix what remains a massive loophole in the law, and we hope that the European Court decides to rule in favour of privacy rather than unchecked State power."</p><p>James Welch, legal director for Liberty, added: "The Intelligence Services retain a largely unfettered power to rifle through millions of people's private communications and the Tribunal believes the limited safeguards revealed during last year's legal proceedings are an adequate protection of our privacy. We disagree, and will be taking our fight to the European Court of Human Rights."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Governments accused of using hacked data to spy on people ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/23998/governments-accused-of-using-hacked-data-to-spy-on-people</link>
                                                                            <description>
                            <![CDATA[ According to leaked documents, governmental organisations in the UK, US and Canada are making use of hacked intel ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nWpGZUHXYPhzHxoHihUytR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dpWWQo2P3DuoSFbihnmfPc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Feb 2015 09:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dpWWQo2P3DuoSFbihnmfPc-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hand casting a shadow over a keyboard]]></media:description>                                                            <media:text><![CDATA[Hand casting a shadow over a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Hand casting a shadow over a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dpWWQo2P3DuoSFbihnmfPc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK, US and Canadian governments are using data gleaned from hackers to spy on people, a report has revealed.</p><p>Documents leaked to <em><a href="https://firstlook.org/theintercept/2015/02/04/demonize-prosecute-hackers-nsa-gchq-rely-intel-expertise">The Intercept</a></em> suggest the National Security Agency (NSA) is using data mined by hackers in their own snooping schemes in an initiative called Intolerant.</p><p>One leaked document explained the thinking behind the campaign, stating: "INTOLERANT traffic is very organised. Each event is labeled to identify and categorise victims. Cyber attacks commonly apply descriptors to each victim it helps herd victims and track which attacks succeed and which fail."</p><p>The documents went on to explain that hackers are stealing the emails of some of its targets and collecting their stolen data, meaning the investigating government agencies can get access to their targets' emails and gain other insights into who's being hacked.</p><p>They continued: "People who open attachments from unknown senders (gasp) or respond to 'Nigerian' money laundering emails aren't the only individuals on the internet being hacked.</p><p>"Some of our targets are also being targeted by outside forces, by state-sponsored and freelance hackers. Could your target's communications be the target of other countries or groups?"</p><p>The documents list a number of groups that have been spied upon using the techniques, including the Indian navy, Tibetan pro-democracy personalities and the Tibetan Government in Exile.</p><p>Other documents referred to a scheme named Lovely Horse that monitored security analyst and hacker Twitter accounts to gain insights into how to more effectively monitor targets.</p><p>"Analysts are potentially missing out on valuable open source information relating to cyber defence because of an inability to easily keep up to date with specific blogs and Twitter sources," the documents said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ex-NSA director: Support for insecure cryptography tool "regrettable" ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/23870/ex-nsa-director-support-for-insecure-cryptography-tool-regrettable</link>
                                                                            <description>
                            <![CDATA[ The solution was riddled with backdoors but was pushed to businesses regardless ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cGmNjc95abzWnbgLeFTPXy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Jan 2015 09:44:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The NSA's former research director has apologised for the body's endorsement of an insecure cryptography solution that was adopted by American businesses.</p><p>The NSA's support for the Dual Elliptic Curve Deterministic Random Bit Generator (Dual EC DRBG) was a key factor in the US National Institute of Standards and Technology (NIST) approving the tool as a trustworthy solution throughout the 2000s, encouraging businesses to use the system.</p><p>It was integrated into RSA Security's BSAFE toolkits, alongside others'.</p><p>However, researchers have since found plenty of backdoors allowing hackers to siphon off and decrypt data, rendering the tool useless.</p><p>The NSA's former research director, Michael Wertheimer, wrote in a <a href="http://www.ams.org/notices/201502/rnoti-p165.pdf" target="_blank" data-original-url="http://www.ams.org//notices/201502/rnoti-p165.pdf">letter published by the American Mathematical Society</a>: "With hindsight, the NSA should have ceased supporting the Dual EC DRBG algorithm immediately after security researchers discovered the potential for a trapdoor.</p><p>"In truth, I can think of no better way to describe our failure to drop support for the Dual EC DRBG algorithm as anything other than regrettable."</p><p>The flaw was exposed by former government contractor Edward Snowden in 2013 in leaked documents and as a result, NIST removed the tool from its approved list in 2014.</p><p>"The costs to the Defense Department to deploy a new algorithm were not an adequate reason to sustain our support for a questionable algorithm," Wertheimer continued.</p><p>"Indeed, we support NIST's April 2014 decision to remove the algorithm. Furthermore, we realise that our advocacy for the Dual EC DRBG casts suspicion on the broader body of work the NSA has done to promote secure standards."</p><p>To add more fuel to the fire, it later came to light that the NSA may have paid RSA $10m to integrate its security solution into the software, although neither the NSA nor RSA have officially confirmed this.</p><p>Wertheimer was the NSA's research director from May 2010 until September 2014, according to his LinkedIn profile.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the security industry must stop the Edward Snowden scaremongering ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-loss-prevention/23123/why-the-security-industry-must-stop-the-edward-snowden-scaremongering</link>
                                                                            <description>
                            <![CDATA[ Davey Winder argues that it's time for the security industry to stop fixating on the Edward Snowden's revelations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9n9MJc6HCN4LscXKRUhYs1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Sep 2014 07:37:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Edward Snowden picture]]></media:description>                                                            <media:text><![CDATA[Edward Snowden picture]]></media:text>
                                <media:title type="plain"><![CDATA[Edward Snowden picture]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An email arrived in my inbox this week with the 'revelation' that Dropbox had complied with 268 law enforcement and government agency requests since January 2014.</p><p>Of those, only 91 of the customers concerned were informed regarding the legal process leading to this examination of their data. So far, so interesting, although not particularly surprising, as this kind of data privacy issue has been big news ever since the first trickle of Edward Snowden leaks began last summer.</p><div><blockquote><p>Hanging the key management argument on the spy scandal hook is becoming increasingly dangerous. The more people read this reasoning, the less impact it has and the less likely they are to take it seriously.</p></blockquote></div><p>It was also no surprise the email then went on to warn me that "many other cloud and data storage providers are receiving these kinds of requests every day," and - here comes the PR payload - there is "a way for cloud providers to extricate themselves from being in bed with the Feds."</p><p>That route involves customer-managed encryption keys.</p><p>While I happen to think that retaining control over encryption keys is a very good idea indeed, and have explained why very recently over at our sister publication <em><a href="http://www.cloudpro.co.uk/cloud-essentials/cloud-security/4456/encryption-key-management-how-to-keep-your-company-safe">Cloud Pro</a></em>, I don't think it's all about Edward Snowden, Big Brother or the FBI knocking on your data storage door with a feather either.</p><p>Hanging the key management argument just on the spy scandal hook is, in my opinion, becoming increasingly dangerous. Mainly because the more people read this reasoning, the less impact it has and the less likely they are to take the matter seriously.</p><p>The real argument has more to do with due diligence, regulatory compliance, accidental data leakage and organised crime than anything else. Focusing on those arguments are far more likely to lead to change within the enterprise cloud security mindset.</p><p>I've been as guilty as anyone of suffering from OSS, AKA Obsessive Snowden Syndrome. However, it's time to stop.</p><p>There are far too many vested interests for it to continue, and I include myself and the rest of the technology media here, along with the primary defendant in the shape of the security vendors.</p><p>What Snowden did deserves our collective praise, and the increase of insecurity awareness as a result is important. Now, I would argue is the time to get back to basics and start remembering that it's all about the data. Secure that data effectively, and that includes having control and possession of your encryption keys, and you can ignore the hyperbole.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Yahoo reveals fine threats of up to $250,000 by US government ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/23109/yahoo-reveals-fine-threats-of-up-to-250000-by-us-government</link>
                                                                            <description>
                            <![CDATA[ Secret court documents reveal court case dated back to 2007 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mhkYoFsUkYFiMg9nNJAm1Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QRUvq2gjMZMwSLiNrVbo3D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 15 Sep 2014 10:39:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QRUvq2gjMZMwSLiNrVbo3D-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spy]]></media:description>                                                            <media:text><![CDATA[Spy]]></media:text>
                                <media:title type="plain"><![CDATA[Spy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QRUvq2gjMZMwSLiNrVbo3D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US government threatened to fine Yahoo $250,000 every day if it didn't hand over user data to the NSA, according to recently unsealed court documents.</p><p>In a <a href="http://yahoopolicy.tumblr.com/post/97238899258/shedding-light-on-the-foreign-intelligence-surveillance">blog post</a>, Ron Bell, general counsel of Yahoo, said the release of over 1,500 documents shed light on the firm's previously undisclosed fight with the NSA over user data access.</p><p>He said that the company "refused to comply with what we viewed as unconstitutional and overbroad surveillance and challenged the US Government's authority."</p><p>"Our challenge, and a later appeal in the case, did not succeed said Ron Bell. He added that court material showed "how we had to fight every step of the way to challenge the US government's surveillance efforts."</p><p>According to Bell, the court upheld laws preceding Section 702 of the FISA Amendments Act. This is more commonly known as Prism, which was revealed by former NSA contractor Edward Snowden.</p><p>"Despite the declassification and release, portions of the documents remain sealed and classified to this day, unknown even to our team," said Bell.</p><p>One document from May 2008 showed that the US government not only threatened to impose a $250,000 fine on Yahoo each day it didn't hand over data but would then double this fine each week the internet giant failed to turn over data. Unsurprisingly, Yahoo complied with the legal action.</p><p>Bell said that Yahoo's fight against the US government would continue.</p><p>"We are still pushing for the FISC to release materials from the 2007-2008 case in the lower court. The FISC indicated previously that it was waiting on the FISC-R ruling in relation to the 2008 appeal before moving forward. Now that the FISC-R matter is resolved, we will work hard to make the materials from the FISC case public, as well," he said.</p><p>He added that Yahoo would continue to "contest requests and laws that we consider unlawful, unclear, or overbroad". </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google "worse than NSA" claims Rupert Murdoch ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22914/google-worse-than-nsa-claims-rupert-murdoch</link>
                                                                            <description>
                            <![CDATA[ Rupert Murdoch has spoken on Twitter about Google's “privacy invasion,” sparking online debate ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ukuijJdabDDHqTrmRC7maj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mTJMVwSBz7LuuFX2SeF65f-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Aug 2014 12:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Preece ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/MfwwRmvRe3qucjt85cMgeg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/mTJMVwSBz7LuuFX2SeF65f-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mTJMVwSBz7LuuFX2SeF65f-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Media mogul Rupert Murdoch has sparked a backlash after taking to Twitter over the weekend to criticise Google's privacy policies, comparing them unfavourably to the NSA.</p><p>The tweet, posted on 17 August, reads "NSA privacy invasion bad, but nothing compared to Google."</p><div><blockquote><p>NSA privacy invasion bad, but nothing compared to Google.Rupert Murdoch (@rupertmurdoch) August 17, 2014</p></blockquote></div><p>Predictably, Twitter users were quick to respond to the claim, bringing up Murdoch's own invasions of privacy with phone hacking at <em>The News of the World</em> newspaper, which led to its closure. Many pointed out the comments were hypocritical after his part in the paper's wrongdoing.</p><p>One respondent, @davidbadash, tweeted:</p><div><blockquote><p>So @rupertmurdoch, who had to shutter a century-old paper for cell phone tapping hypocritically attacks Google, NSA: https://t.co/yOsuDVOA3sDavid Badash (@davidbadash) August 17, 2014</p></blockquote></div><p>This is not the first time Murdoch has targeted the search engine, tweeting back in April: "Google attack on NSA extreme nerve. Google has more data on all of us and uses it. No evidence of NSA doing this. Ethical company?"</p><p>Also, in January 2012, he also blasted the company's role in movie piracy by tweeting: "Piracy leader is Google who streams movies free, sells advts around them. No wonder pouring millions into lobbying."</p><div><blockquote><p>Piracy leader is Google who streams movies free, sells advts around them. No wonder pouring millions into lobbying.Rupert Murdoch (@rupertmurdoch) January 14, 2012</p></blockquote></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Edward Snowden awarded three-year Russian permit ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22857/edward-snowden-awarded-three-year-russian-permit</link>
                                                                            <description>
                            <![CDATA[ The former US intelligence contractor is working in an IT-related job, although he has a modest living ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2jH3fhf7Kpp8M61WFMBrNW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 Aug 2014 08:14:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Edward Snowden picture]]></media:description>                                                            <media:text><![CDATA[Edward Snowden picture]]></media:text>
                                <media:title type="plain"><![CDATA[Edward Snowden picture]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Edward Snowden has been awarded a three-year residency permit in Russia according to his lawyers.Former US Intelligence contractor Snowden is wanted in the US for leaking sensitive secrets to many high-profile newspapers in the UK and abroad, but sought asylum in Russia as it's one of the only countries that promised not to hand him in.Snowden fled to Hong Kong and then went on to Russia last year, when he was accused of leaking security secrets including controversial surveillance programmes run by the US National Security Agency (NSA) - <a href="https://www.itpro.com/security/22650/snowden-just-10-of-nsa-data-is-terrorism-related" data-original-url="https://www.itpro.com/security/22650/snowden-just-10-of-nsa-data-is-terrorism-related">such as PRISM</a> - that gathered personal information from US citizens, including their email, phone and internet use.The former intelligence contractor lived in Moscow's Sheremetyevo airport before the country offered him asylum exactly a year before his residency permit began.Snowden's lawyer Anatoly Kucherena said: "The decision on the application has been taken and therefore, with effect from August 1, 2014, Edward Snowden has received a three-year residential permit. In the future, Edward himself will take a decision on whether to stay on (in Russia) on and get Russian citizenship or leave for the United States."Snowden is eligible to apply for citizenship in the country after he has been living there for five years. He will decide if he wants to stay and apply in 2018.The lawyer revealed that Snowden is being protected by private security guards to safeguard him from threats posed by the US, adding: "He leads a rather modest lifestyle, but nevertheless we proceed from the tone of statements that come from the US State Department and other political figures. The security issue should not be treated as a secondary one."It is thought that Snowden currently holds access to 1.7 million digital documents revealing information about the US' security schemes. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple denies NSA data-grabbing backdoors exist in iOS ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/22763/apple-denies-nsa-data-grabbing-backdoors-exist-in-ios</link>
                                                                            <description>
                            <![CDATA[ Claims made by forensic data scientist at hacking conference about iOS access flaws denied by Apple ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7M3eRvejs2LUpwnBoJHtcS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rspMKVvJ8Fgeo5q2ek64oa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Jul 2014 11:28:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[iOS]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Apple]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rspMKVvJ8Fgeo5q2ek64oa-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rspMKVvJ8Fgeo5q2ek64oa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple's iOS mobile operating system contains numerous backdoors that allow hackers to bypass its PIN and password controls to steal users' personal data, a data forensics scientist has claimed.</p><p>Speaking at the Hackers of Planet Earth (HOPE) conferences last week, Jonathan Zdziarski shared with delegates details about various backdoors he claims to have found in iOS-running devices that could potentially be exploited by government agencies, such as the NSA.</p><p>During his presentation he flagged several mobile OS features that could make the OS vulnerable to government snooping, although <a href="http://www.zdziarski.com/blog/?p=3441">he has since gone to great lengths to reiterate</a> that he has not accused Apple of working with the NSA.</p><div><blockquote><p>We have designed iOS so that its diagnostic functions do not compromise user privacy and security, but still provides needed information to enterprise IT departments.</p></blockquote></div><p>These include the "lockdownd", "Pcapd" and "mobile.file_relay", which it is claimed can side-step encrypted backups to plunder data on the behalf of third parties.</p><p>In a blog post, <a href="http://www.zdziarski.com/blog/?p=3441">published in the wake of his appearance at the conference</a>, he said Apple needs to explain to the 600 million people using iOS devices why this capability is included in the mobile operating system.</p><p>"At the same time, this is NOT a zero day and NOT some widespread security emergency. My paranoia level is tweaked, but not going crazy," he added.</p><p>"My hope is that Apple will correct the problem. Nothing less, nothing more. I want these services off my phone. They don't belong there."</p><p>The claims have been strenuously denied by Apple in <a href="http://www.imore.com/apple-reaffirms-never-worked-any-government-agency-backdoor-product-service">a statement to <em>iMore</em></a>, where it was also quick to stress that it has never worked with any government agency to install a backdoor in one of its products.</p><p>"We have designed iOS so that its diagnostic functions do not compromise user privacy and security, but still provides needed information to enterprise IT departments, developers and Apple for troubleshooting technical issues," the statement reads.</p><p>"A user must have unlocked their device and agreed to trust another computer before that computer is able to access this limited diagnostic data.</p><p>"The user must agree to share this information, and data is never transferred without consent," it added.</p><p>NSA whistleblower <a href="https://www.itpro.com/security/22734/snowden-calls-on-peers-to-develop-anti-surveillance-tech" data-original-url="https://www.itpro.com/security/22734/snowden-calls-on-peers-to-develop-anti-surveillance-tech">Edward Snowden also spoke</a>, via video link, at the conference this week, and urged attendees to use their skills and expertise to build anti-surveillance products. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Snowden calls on peers to develop anti-surveillance tech ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22734/snowden-calls-on-peers-to-develop-anti-surveillance-tech</link>
                                                                            <description>
                            <![CDATA[ NSA whistleblower to focus on promoting anti-snooping tools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eBagTVo7s4gMZqUsVXQ6SV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Jul 2014 09:08:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Edward Snowden picture]]></media:description>                                                            <media:text><![CDATA[Edward Snowden picture]]></media:text>
                                <media:title type="plain"><![CDATA[Edward Snowden picture]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Edward Snowden wants the cybersecurity industry to channel its expertise into creating technologies that prevent governments from snooping on their citizens' online activities.</p><p>Snowden, who has become a torchbearer for the anti-surveillance movement after systematically leaking details about US efforts to keep tabs on its residents, was speaking at the Hackers On Planet Earth (HOPE) conference in New York over the weekend.</p><p>During his presentation, he called on the audience to pool their resources to create anti-tracking technologies that will encrypt messages and allow people to communicate anonymously online.</p><p>"You in this room, right now have both the means and the capability to improve the future by encoding our rights into programmes and protocols by which we rely every day," he said.</p><p>"This is what a lot of my future work is going to be involved in."</p><p>His conference presentation was broadcast via video link from Russia, where Snowden was granted asylum in June 2013 in the wake of revelations he made about the activities of the US National Security Agency (NSA).</p><p>It is understood he has since found work in the country as an IT contractor, but according to a report on <a href="http://www.reuters.com/article/2014/07/19/us-usa-snowden-hackers-idUSKBN0FO0ZB20140719">Reuters</a> his Russian visa is due to expire at the end of this month.</p><p>If the Russian authorities decide not to extend his rights to say in the country, he faces being sent back to the US where he faces criminal charges over his decision to leak classified information about the NSA's activities.</p><p>In his most recent round of revelations, published last week, Snowden claimed nude photos accrued by the NSA during its surveillance activities were "routinely" passed around by some members of staff.</p><p>The claim was made during a seven hour interview with <a href="http://www.theguardian.com/world/2014/jul/17/edward-snowden-professionals-encrypt-client-communications-nsa-spy">The Guardian newspaper</a>, where he also shed some considerable light on his life in Russia.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft confesses to 14% global device market share ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/strategy/22699/microsoft-confesses-to-14-global-device-market-share</link>
                                                                            <description>
                            <![CDATA[ Firm to tackle Chromebooks with $199 HP Stream laptop ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i8Jo5GW1YoDip9gaCFDm4L</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Kiv8XnbTVoGPA7LKkNGo4H-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Jul 2014 10:44:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Microsoft]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Khidr Suleman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Kiv8XnbTVoGPA7LKkNGo4H-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Kiv8XnbTVoGPA7LKkNGo4H-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft COO Kevin Turner has admitted the firm is in the midst of re-inventing itself as it looks to catch up to its competitors.</p><p>In a wide-ranging keynote at the firm's annual Worldwide Partner Conference, Turner talked about market share, how it plans on targetting the low-end space and what it's doing to combat snooping. He also revealed brief details about Windows Threshold.</p><p><strong>Global device market share</strong></p><p>Turner claimed Microsoft has changed the way it measures success in the device space as it now looks at the market as a whole. He conceded the firm has just 14 per cent of global device market share when PCs, smartphones and tablets are tallied.</p><p>"The reality is the world's shifted, the world's evolved," <em><a href="http://www.winbeta.org/news/microsoft-admits-14-device-share-we-have-rethink-how-we-look-our-business" target="_blank">WinBeta</a></em> reported Turner as saying.</p><p>"We now measure ourselves by total device space. We have a much bigger opportunity than we've ever had in the past to grow our business, but we have to rethink how we look at our business."</p><p><strong>Windows vs Chromebooks</strong></p><p>As part of Microsoft's strategy to increase market share, Turner announced that a $199 HP Stream Windows laptop will go on sale at the end of the year. However, he stopped short of sharing the device's specifications on-stage.</p><p>He also revealed an 11.6in Toshiba laptop, with a 32GB SSD, will retail at $249, and 7/8in Windows tablets will be launched with a price-point of $99.</p><p>"We are going to participate at the low-end," <a href="http://www.theverge.com/2014/7/14/5897641/microsoft-launches-a-price-assault-on-chromebooks" target="_blank"><em>The Verge</em></a> reported Turner as saying.</p><p>"We've got a great value proposition against Chromebooks, we are not ceding the market to anyone."</p><p><strong>Protecting data against government snooping</strong></p><p>Turner reaffirmed Microsoft's commitment to protecting user data, noting it will take government authorities to court if necessary to protect information.</p><p>"We will not provide any government with encryption keys or assist their efforts to break our encryption. We will not engineer backdoors in the products," he was quoted as saying by <a href="http://redmondmag.com/blogs/the-schwartz-report/2014/07/unfettered-access-to-data.aspx" target="_blank"><em>Redmond magazine</em></a><em>.</em></p><p>"We have never provided a business government data in response to a national security order. Never. And we will contest any attempt by the US government or any government to disclose customer content stored exclusively in another place. That's our commitment."</p><p><strong>Windows Threshold</strong></p><p>Little information was revealed about the next major edition of Windows, which is codenamed Threshold and is expected to be launched in Spring 2015.</p><p>Turner did claim the firm was listening to feedback from consumers and businesses and that the operating system will be a "great world-class enterprise OS."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Snowden: Just 10% of NSA data is terrorism-related ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22650/snowden-just-10-of-nsa-data-is-terrorism-related</link>
                                                                            <description>
                            <![CDATA[ New documents released by Edward Snowden reveal that only 10 per cent of the NSA’s collected data pertains to possible illegal activity ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">exgJR7U3Qo3mhjBtx3t7zu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Jul 2014 10:57:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alex Hamilton ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Edward Snowden picture]]></media:description>                                                            <media:text><![CDATA[Edward Snowden picture]]></media:text>
                                <media:title type="plain"><![CDATA[Edward Snowden picture]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ULyMsNDRUY4EdibcUdr8KJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>New releases from whistleblower Edward Snowden have revealed that only 10 per cent of all communications data collected by the NSA came from the agency's targets.</p><p>The documents released by Snowden included 160,000 email and instant messaging conversations, as well as 7,900 files ripped from more than 11,000 online accounts. All of the info was collected during the NSA's highly controversial PRISM and Upstream projects.</p><p>According to analysis conducted by <em>The <a href="http://www.washingtonpost.com/world/national-security/in-nsa-intercepted-data-those-not-targeted-far-outnumber-the-foreigners-who-are/2014/07/05/8139adf8-045a-11e4-8572-4b1b969b6322_story.html">Washington Post</a></em>, nearly half of all the files contained details belonging to US citizens which had been "minimised" due to lack of a security threat.</p><p>A significant majority of the remaining 50 per cent were foreigners with no links to terrorist or criminal activities, such as tourists and visitors on business.</p><p>Among the documents that it pinched, the NSA found revelations about an overseas nuclear project, the military secrets of a foreign power and the identities of aggressive intruders into US computer networks, according to <em>The Post</em>.</p><p>Despite this, a far larger number of discoveries included the details of ordinary people's lives. Among them were divorce proceedings, tax documents, political and religious conversations and other private communications.</p><p>There are rules in place for most government agencies in the US when they intend to hack into someone's private life. Taps that are installed into phones by the FBI, for example, are switched off when a wife or child uses it.</p><p>The NSA, however, dredged up the names and details of every person in a chatroom their target entered. This included those who were logged into the room by default for just visiting the website.</p><p>According to a former agency analyst that spoke to the publication, the NSA taught their staff that only "reasonable belief" a target was foreign would be enough to justify spying on them.</p><p>Often people would be targeted for writing their emails or communications in a foreign language, despite millions of Americans not having English as their primary dialect, the documents detail.</p><p>The NSA would then push the boundaries outwards, so that every friend of a "foreigner" was guilty by association and warranted surveillance.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EFF sues NSA over hoarding details of zero day flaws ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22643/eff-sues-nsa-over-hoarding-details-of-zero-day-flaws</link>
                                                                            <description>
                            <![CDATA[ Alleges spy agency knew about Heartbleed and other flaws but kept quiet ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8uDcSx2dkqwTRAx7AxS7Lb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VRhW2RQHz4iBwWRtfLF34J-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Jul 2014 14:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VRhW2RQHz4iBwWRtfLF34J-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security exploits]]></media:description>                                                            <media:text><![CDATA[Security exploits]]></media:text>
                                <media:title type="plain"><![CDATA[Security exploits]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VRhW2RQHz4iBwWRtfLF34J-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Electronic Frontier Foundation has filed a complaint against the NSA, alleging it knew about the Heartbleed bug for years before the public learned of its existence.</p><p>The internet freedom campaign organisation <a href="https://www.eff.org/document/eff-v-nsa-odni-complaint">claimed</a> that the NSA chooses where and when it informs the security community about zero-day flaws and is aiming to get the spy agency to be more transparent.</p><p>In April, it was revealed by Bloomberg News that the NSA had secretly exploited the Heartbleed bug in the OpenSSL for at least two years before the public knew of its existence. The US government denied the report and said it had developed a Vulnerability Equities Process for deciding when to share knowledge of exploits with firms and the public.</p><p>The White House explained in a <a href="http://www.whitehouse.gov/blog/2014/04/28/heartbleed-understanding-when-we-disclose-cyber-vulnerabilities">blog</a> at the time this process was to disclose flaws and said it had "established a disciplined, rigorous and high-level decision-making process for vulnerability disclosure".</p><p>But in the same post said that the process had "no hard and fast rules".</p><p>The EFF said it had lodged a Freedom of Information request for records related to zero day flaws with both the NSA and the US Office of the Director of National Intelligence. It made the FOIA request on 6 May but has yet to have received any documentation. The privacy campaigners also want more detail on how intelligence agencies choose whether to disclose exploits.</p><p>"This FOIA suit seeks transparency on one of the least understood elements of the US intelligence community's toolset: security vulnerabilities," said EFF Legal Fellow Andrew Crocker. "These documents are important to the kind of informed debate that the public and the administration agree needs to happen in our country."</p><p>EFF Global Policy Analyst Eva Galperin said that while spy agencies held onto zero day exploits, the wider community was left defenceless against hackers and cybercriminals as well as unfriendly foreign governments.</p><p>"Since these vulnerabilities potentially affect the security of users all over the world, the public has a strong interest in knowing how these agencies are weighing the risks and benefits of using zero days instead of disclosing them to vendors," she said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Angry Birds, Squeaky Dolphin, NoseySmurf: The NSA programs you never knew about ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22640/angry-birds-squeaky-dolphin-noseysmurf-the-nsa-programs-you-never-knew-about</link>
                                                                            <description>
                            <![CDATA[ IT Pro takes you on a run down of some of the major NSA projects that may have passed you by over the last 12 months ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">k6wA47KBez4T4otymWJony</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Jul 2014 14:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alex Hamilton ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Angry Birds in space]]></media:description>                                                            <media:text><![CDATA[Angry Birds in space]]></media:text>
                                <media:title type="plain"><![CDATA[Angry Birds in space]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Security Agency (NSA), set up to combat foreign and domestic intelligence threats to the US, has had its reputation turned upside down since whistleblower Edward Snowden began to leak details of its clandestine activities.</p><p>In the past year, Snowden's leaks have revealed more than 40 separate intelligence campaigns undertaken by the NSA or its UK allies at GCHQ.</p><p>Among the most infamous was the news the NSA had been infiltrating the data centres of US technology companies - including Facebook, Microsoft and Google - and snatching user data from the traffic.</p><p>Upstream and PRISM, the names of the surveillance operations that conducted those clandestine acts, caused outrage throughout the technology industry and the world. People began to wonder if their data was truly safe in the hands of the big companies and on the internet.</p><p>The ripples of that discovery can still be felt today, as companies attempt to <a href="http://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=4&cad=rja&uact=8&ved=0CEAQFjAD&url=http%3A%2F%2Fwww.itpro.com%2Fsecurity%2F20476%2Fnsa-paid-google-yahoo-and-microsoft-cover-prism-compliance-costs&ei=p5a2U5nEJeKR0QXYtoF4&usg=AFQjCNGzaX0iYIZ">side-step their involvement</a> or relocate their services to assuage worried customers.</p><p>Yet those two operations were only part of myriad of projects the NSA and GCHQ have undertaken. The details of many more have been released by Snowden over the past year, some of which you might never even have heard of.</p><h3 class="article-body__section" id="section-angry-birds"><span>Angry Birds</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KVDQadPyDpdDqyKYiVoDmC" name="" alt="Angry Birds in space" src="https://cdn.mos.cms.futurecdn.net/KVDQadPyDpdDqyKYiVoDmC.jpg" mos="https://cdn.mos.cms.futurecdn.net/KVDQadPyDpdDqyKYiVoDmC.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Nowhere is safe from the prying eyes of government agencies, it seems, not even much-loved mobile game Angry Birds.</p><p>As soon as a player opened up the game and began their bird-slinging adventures, algorithms within the game's code relayed their age, sex and other information to intelligence agents.</p><p>This is according to documents leaked from GCHQ, which revealed how it and the NSA had been working on ways to tap into mobiles and collect data through apps. Not just Angry Birds fell foul of the surveillance program: Google Maps, Facebook, Twitter and LinkedIn were also targeted.</p><p>"It effectively means that anyone using a smartphone is working in support of a GCHQ system," a secret 2008 report by the British agency said.</p><h3 class="article-body__section" id="section-noseysmurf"><span>NoseySmurf</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HT86y5RYWJyUcSbQZs6aK5" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/HT86y5RYWJyUcSbQZs6aK5.jpg" mos="https://cdn.mos.cms.futurecdn.net/HT86y5RYWJyUcSbQZs6aK5.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Also known by the names "TrackerSmurf" and "DreamySmurf", the NoseySmurf project tied into the Angry Birds scheme by tapping into mobile phones to scrape data from users.</p><p>The NSA spent over $1 billion (580 million) in its search to find more efficient tracking and piggybacking methods for infiltrating targeted devices. In one top-secret presentation, the agency describes a victim uploading an image to Facebook from their phone as a "Golden Nugget!!"</p><p>From the simple act of someone uploading a picture to a social media site, later slides say, agents could glean a victim's contacts, location, gender, age, income, ethnicity, education level and even number of children.</p><h3 class="article-body__section" id="section-happyfoot"><span>HappyFoot</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7sStEf86W6dUrez2CpsErb" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/7sStEf86W6dUrez2CpsErb.jpg" mos="https://cdn.mos.cms.futurecdn.net/7sStEf86W6dUrez2CpsErb.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>HappyFoot was the codename for an operation designed to track internet users' movements by piggybacking onto their cookies and location data.</p><p>When a consumer visits a site cookies are enabled on their computer, allowing the site's company to tailor advertisements to them, something government snoops were keen to exploit.</p><p>Slides released by Snowden and published by the <a href="http://www.washingtonpost.com/blogs/the-switch/wp/2013/12/10/nsa-uses-google-cookies-to-pinpoint-targets-for-hacking"><em>Washington Pos</em>t</a> revealed the NSA had been latching onto these cookies in order to identify possible targets for further hacking operations.</p><p>Using a <a href="http://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=1&cad=rja&uact=8&ved=0CCUQFjAA&url=http%3A%2F%2Fwww.itpro.com%2Fsecurity%2F21218%2Fnsa-and-gchq-tracked-google-cookies&ei=gJe2U6j6KoyY0AXhqIDwDA&usg=AFQjCNG4k16kB_vQZV576ZQaiF8N4duJEA&sig2=NB">unique cookie from Google</a> called PREF, intelligence agents could pick out one person from a sea of internet data in order to focus on them specifically. The NSA slides indicated that Google complied with this action entirely after being compelled to by the US government.</p><h3 class="article-body__section" id="section-squeaky-dolphin"><span>Squeaky Dolphin</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mYfA6XJ83wCzVQv9iuVdMS" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/mYfA6XJ83wCzVQv9iuVdMS.jpg" mos="https://cdn.mos.cms.futurecdn.net/mYfA6XJ83wCzVQv9iuVdMS.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>There's a prize for anyone who can understand the reasoning behind this codename. Squeaky Dolphin was an initiative thought up by the UK's GCHQ. It involved tapping into the cables carrying the world's web traffic in order to monitor what people are up to on social media.</p><p>Documents leaked to <a href="http://investigations.nbcnews.com/_news/2014/01/27/22469304-snowden-docs-reveal-british-spies-snooped-on-youtube-and-facebook?lite">NBC news</a> by Snowden revealed how British spies showed off their new invention to their US counterparts. GCHQ demonstrated how it could monitor YouTube in real time and collect addresses from the billions of videos watched every day.</p><p>Analysts demonstrated how, through a central information hub, they could determine which videos were popular in which cities and at what times, as well as what each demographic preferred to click on.</p><p>The UK spooks did mention to their allies that this program was for general trends only and not for spying on individuals, but there are as yet unconfirmed rumours GCHQ used the tech to target Twitter users with propaganda.</p><h3 class="article-body__section" id="section-gilgamesh"><span>Gilgamesh</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uUVoc2pXzySqc54GT8JR2Q" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/uUVoc2pXzySqc54GT8JR2Q.jpg" mos="https://cdn.mos.cms.futurecdn.net/uUVoc2pXzySqc54GT8JR2Q.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Unfortunately, this operation has nothing to do with the fifth king of Uruk Mesopotamia.</p><p>According both to documents released by Snowden and the testimony of a former drone operator, the NSA used telecommunications devices as targets for drone strikes.</p><p>Rather than confirming with operatives on the ground, said the whistleblower, the NSA would identify a target based on the geolocation of their phone and order an assassination.</p><p>The drone operator was adamant the technology was aiding the War on Terror but that civilians were "absolutely" being killed en masse by the strikes.</p><p>Terrorists cottoned on to the NSA's idea, though, and began to mix up their SIM cards to avoid being tracked. Commanders would switch them with footsoldiers and footsoldiers with civilians.</p><p>The NSA often located targets based on their activity levels and not on the content of the calls, resulting in, according to the former pilot "death by unreliable data."</p><h3 class="article-body__section" id="section-egotisticalgoat"><span>EgotisticalGoat</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eLmE65LLf74yLyexi7Wgnh" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/eLmE65LLf74yLyexi7Wgnh.jpg" mos="https://cdn.mos.cms.futurecdn.net/eLmE65LLf74yLyexi7Wgnh.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>EgotisticalGoat and its sister program, EgotisticalGiraffe, were designed to help facilitate attacks on people using the anonymous network Tor.</p><p>Techniques included targeting web browsers like Firefox and giving the NSA full control over a target's computer keystrokes, online activity and files.</p><p>The Tor network is relied upon by journalists, activists and campaigners around the world to maintain the secrecy of their communications and avoid reprisals from their respective governments.</p><p>The network, oddly enough, is provided with 60 per cent of its funding by the US government.</p><p>Agents operating EgotisticalGoat admitted the Tor network was too large for them to completely crack. In one top-secret presentation named "Tor Stinks" it stated "We will never be able to de-anonymize all Tor users all the time ... with manual analysis we can de-anonymize only a very small fraction of Tor users."</p><p>With more information to come from Snowden, who claims his leaks to date are just the tip of the iceberg, do we have more cause for concern over our data than ever before? Are all of these operations a gross misconduct or a necessary evil? Let us know what you think by emailing us at <a href="mailto://comments@itpro.co.uk" data-original-url="mailto:comments@itpro.co.uk?Subject=Snowden%leaks">comments@itpro.co.uk</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco berates US government over router tampering ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22263/cisco-berates-us-government-over-router-tampering</link>
                                                                            <description>
                            <![CDATA[ US undermining goals of free communication ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dJKFayYfGD8yqiesZog991</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CafQrf23bp4hEf3WfndzgY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 May 2014 13:22:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CafQrf23bp4hEf3WfndzgY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacking]]></media:description>                                                            <media:text><![CDATA[Hacking]]></media:text>
                                <media:title type="plain"><![CDATA[Hacking]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CafQrf23bp4hEf3WfndzgY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cisco's legal counsel has blasted the US government over accusations the NSA has been tampering with communications equipment.</p><p>The spy agency has reportedly been <a href="https://www.itpro.com/public-sector/22233/nsa-intercepted-international-shipments-of-computer-hardware" target="_blank" data-original-url="https://www.itpro.com/public-sector/22233/nsa-intercepted-international-shipments-of-computer-hardware">intercepting shipments of routers, switches and servers</a> in order to hide their surveillance equipment.</p><p>Writing in a <a href="http://blogs.cisco.com/news/internet-security-necessary-for-global-technology-economy">blog post</a>, Cisco's legal counsel Mark Chandler said that the actions of the US government have overreached, "undermining the goals of free communication".</p><div><blockquote><p>We expect our government to value and respect this trust.</p></blockquote></div><p>"Confidence in the open, global internet has brought enormous economic benefits to the United States and to billions around the world," said Chandler.</p><p>"This confidence has been eroded by revelations of government surveillance, by efforts of the US government to force US companies to provide access to communications of non-US citizens even when that violates the privacy laws of countries where US companies do business, and allegations that governments exploit rather than report security vulnerabilities in products."</p><p>Chandler said that it was Cisco's policy and practice not to work with any government, the US included, to weaken its products.</p><p>"When we learn of a security vulnerability, we respond by validating it, informing our customers, and fixing it.</p><p>"We react the same when we find that a customer's security has been impacted by external forces, regardless of what country or form of government or how that security breach occurred. We offer customers robust tools to defend their environments against attack, and detect attacks when they are happening. By doing these things, we have built and maintained our customers' trust.</p><p>"We expect our government to value and respect this trust."</p><p>Last December, <a href="https://www.reformgovernmentsurveillance.com">eight technology companies expressed concern</a> to US President Barack Obama and Congress that the US government's surveillance efforts as revealed by Snowden were harmful.</p><p>Chandler said that the revelations over hardware tampering were damaging and his firm should not expect the government to act in this manner.</p><p>"We comply with US laws, like those of many other countries, which limit exports to certain customers and destinations," said Chandler.</p><p>"We ought to be able to count on the government to then not interfere with the lawful delivery of our products in the form in which we have manufactured them. To do otherwise, and to violate legitimate privacy rights of individuals and institutions around the world, undermines confidence in our industry."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA intercepted international shipments of computer hardware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/22233/nsa-intercepted-international-shipments-of-computer-hardware</link>
                                                                            <description>
                            <![CDATA[ Government agency secretly installed surveillance equipment in company routers, switches and servers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hQALbJDKLCXUU7LkBhJk5D</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 13 May 2014 09:14:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Surveillance]]></media:description>                                                            <media:text><![CDATA[Surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[Surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The NSA has been intercepting shipments of routers, switches and servers in order to hide their surveillance equipment, according to the people who exposed the agency's secret Prism spy project.</p><p>Journalist Glenn Greenwald made the revelations to a number of news sources while promoting his new book "No Place to Hide", which details more of the state secrets Edward Snowden revealed to him. </p><p>A June 2010 report from the head of the NSA's Access and Target Development department explains how the NSA would intercept packages, he alleges. The agency would then install surveillance equipment before resealing the packages so the changes were undetectable. The shipments would then be sent abroad.</p><p>When the equipment was finally received and installed it would then connect back to the NSA. The report states: "In one recent case, after several months, a beacon implanted through supply-chain interdiction called back to the NSA covert infrastructure. This call back provided us access to further exploit the device and survey the network."</p><p><a href="http://www.theguardian.com/books/2014/may/12/glenn-greenwald-nsa-tampers-us-internet-routers-snowden">The Guardian</a> reports that for years the US government had warned companies not to trust Chinese routers manufactured by companies such as ZTE and Huawei because they "are built with backdoor surveillance functionality that gives the Chinese government the ability to spy on anyone using them."</p><p>The committee behind the claims explained that "private-sector entities in the United States are strongly encouraged to consider the long-term security risks associated with doing business with either ZTE or Huawei for equipment or services. Based on available classified and unclassified information, Huawei and ZTE cannot be trusted to be free of foreign state influence and thus pose a security threat to the United States and to our systems."</p><p>This led to Huawei eventually abandoning the US market. If Greenwald's claims are true, it now seems the US government was doing exactly the same.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Leaked emails show NSA's close ties with Google ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22198/leaked-emails-show-nsas-close-ties-with-google</link>
                                                                            <description>
                            <![CDATA[ NSA organised meetings with Google execs to discuss security issues, it is claimed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9ryhv696NasrRasEUmEFsL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mTJMVwSBz7LuuFX2SeF65f-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 May 2014 15:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Google]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alex Hamilton ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/mTJMVwSBz7LuuFX2SeF65f-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mTJMVwSBz7LuuFX2SeF65f-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A leaked email exchange between Google and the NSA suggests the two parties were working far more closely than the former has implied.</p><p><a href="http://america.aljazeera.com/articles/2014/5/6/nsa-chief-google.html"><em>Al Jazeera</em></a> has posted two sets of emails between NSA director general Keith Alexander and Google executives Sergey Brin and Eric Schmidt, dated from before the Snowden revelations last year, discussing company cooperation.</p><p>In one email, dated June 2012, Alexander invites Schmidt to a four-hour meeting on classified threats at a secure facility near San Jose. Alexander had already met with other industry executives, but wanted a separate meeting with the Google exec.</p><p>The emails are said to have been related to the NSA's Enduring Security Framework (ESF) program. The ESF project played a major role, according to Alexander, in thwarting BIOS attacks on American computer systems.</p><p>Schmidt, who has been critical of the NSA and declared its surveillance programs illegal, replies in friendly terms to Alexander: "So great to see you!" He writes. "I'm unlikely to be in California ... would love to see you another time."</p><p>Google co-founder Sergey Brin attended other ESF meetings, and was sent an email by Alexander to thank him for his participation in the programme: "Your insights, as a key member of the Defence Industrial Base, are valuable to ensure ESF's efforts have measurable impact."</p><p>When it was alleged the NSA had infiltrated Google's internal datacentres, the company spoke up in outrage. The firm has also reacted by making changes to its privacy policy, allowing it to <a href="https://www.itpro.com/data-protection/22171/apple-google-microsoft-set-to-notify-users-of-government-data-requests" data-original-url="https://www.itpro.com/data-protection/22171/apple-google-microsoft-set-to-notify-users-of-government-data-requests">inform users who are targeted by government data requests</a>.</p><p>The disclosure by Al Jazeera has indicated that perhaps the companies in Silicon Valley know more than they are letting on. Indeed, earlier this year a senior lawyer for the NSA told <a href="http://www.theguardian.com/world/2014/mar/19/us-tech-giants-knew-nsa-data-collection-rajesh-de">The Guardian</a> of how the major tech companies were fully aware of PRISM and its implications.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>