<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/penetration-testing" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Penetration-testing ]]></title>
                <link>https://www.itpro.com/tag/penetration-testing</link>
        <description><![CDATA[ All the latest penetration-testing content from the ITPro team ]]></description>
                                    <lastBuildDate>Wed, 22 Oct 2025 11:02:57 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ AI-generated code is now the cause of one-in-five breaches – but developers and security leaders alike are convinced the technology will come good eventually ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/development/ai-generated-code-is-now-the-cause-of-one-in-five-breaches-but-developers-and-security-leaders-alike-are-convinced-the-technology-will-come-good-eventually</link>
                                                                            <description>
                            <![CDATA[ AI coding tools now write 24% of production code globally, but it's risky and causing issues for developers and security practitioners alike. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BJyUaCbykBUPx25vExFApF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pXaDHxpCwz8PrGomizBmrT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Oct 2025 11:02:57 +0000</pubDate>                                                                                                                                <updated>Thu, 23 Oct 2025 09:16:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Development]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pXaDHxpCwz8PrGomizBmrT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Software developer using AI coding tools on a laptop computer with source code pictured on screen and desktop monitor in background.]]></media:description>                                                            <media:text><![CDATA[Software developer using AI coding tools on a laptop computer with source code pictured on screen and desktop monitor in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Software developer using AI coding tools on a laptop computer with source code pictured on screen and desktop monitor in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pXaDHxpCwz8PrGomizBmrT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/development/ai-coding-tools-arent-the-solution-to-the-unfolding-developer-crisis-teams-think-they-can-boost-productivity-and-delivery-times-but-end-up-bogged-down-by-manual-remediation-and-unsafe-code">AI coding tools</a> are creating serious security risks in production, with one-in-five CISOs saying they've suffered major incidents because of <a href="https://www.itpro.com/technology/artificial-intelligence/ai-generated-code-risks-what-cisos-need-to-know">AI-generated code</a>.</p><p>AI coding tools now write 24% of production code – 21% in Europe and 29% in the US – according to a new <a href="https://www.aikido.dev/state-of-ai-security-development-2026" target="_blank"><u>report</u></a> from Aikido. But it's risky, with 69% of security leaders, security engineers, and developers across Europe and the US revealing they'd found serious vulnerabilities in AI-written code.</p><p>US-based respondents were among the worst hit by AI-related flaws, with 43% of organizations reporting serious incidents, compared with just 20% in Europe. </p><p>This, the study noted, appears to be down to better prevention and oversight. For example, EU-based firms reported more “near misses” with AI-generated code than their US counterparts, potentially highlighting more robust testing practices. </p><p>Adding more tools to address the issue isn’t helping, Aikido found. Indeed, <a href="https://www.itpro.com/security/adopting-more-security-tools-doesnt-keep-you-safe-it-just-overloads-your-teams-and-creates-greater-risks">organizations with more security tools report more incidents</a>, with more overhead and slower remediation. </p><p>Nearly two-thirds (64%) of those with just one or two tools had an incident, the figure was 90% for those with between six and nine tools. </p><h2 id="all-in-one-ai-coding-tools-are-helping-bridge-gaps">All-in-one AI coding tools are helping bridge gaps</h2><p>Notably, teams using tools designed for both developers and security teams were more than twice as likely to report zero incidents than those using tools made for only one specific group.</p><p>“Giving developers the right security tool that works with existing tools and workflows allows teams to implement security best practices and improve their posture,” commented Walid Mahmoud, <a href="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important">DevSecOps </a>lead at the UK Cabinet Office.</p><p>Teams using separate AppSec and CloudSec tools were 50% more likely to face incidents, and 93% of those with separate tools reported integration headaches such as duplicate alerts or inconsistent data.</p><h2 id="the-security-blame-game-is-heating-up">The security blame game is heating up</h2><p>The blame for incidents caused by AI code is now becoming a serious point of contention within enterprises, the report noted. For example, 53% of respondents blamed security teams for failing to address issues, while 45% blamed developers who failed to spot issues before pushing to production. </p><p>Meanwhile, 42% pointed toward whoever merged it. This blame game is expected to continue escalating, according to Aikido. Half of developers reckoned they’d be blamed if the AI code they wrote introduced a vulnerability, even more than the security team itself.</p><p>“There's clearly a lack of clarity among respondents over where accountability should sit for good risk management,” commented Andy Boura, CISO at Rothesay.</p><p>Despite concerns across the board, enterprises are expected to continue driving ahead with adoption of AI coding tools, the study noted. Nine-in-ten said they expect <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>to take over <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a> within the next five years, for example</p><p>Meanwhile, 96% believe AI will write secure, reliable, code at some point, with the biggest proportion (44%) thinking it will happen in the next three-to-five years. </p><p>Only 21% think this will be achieved without human oversight, however, underlining the importance of keeping humans in the loop. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/development/think-ai-coding-tools-are-speeding-up-work-think-again-theyre-actually-slowing-developers-down">Think AI coding tools are speeding up work? Think again – they’re actually slowing developers down</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/how-ai-coding-is-transforming-the-it-industry-in-2025">How AI coding is transforming the IT industry in 2025</a></li><li><a href="https://www.itpro.com/software/development/ai-coding-tools-software-development-regional-popularity">AI coding tools are booming – and developers in this one country are by far the most frequent users</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pentesters are now a CISOs best friend as critical vulnerabilities skyrocket ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/pentesters-are-now-a-cisos-best-friend-as-critical-vulnerabilities-skyrocket</link>
                                                                            <description>
                            <![CDATA[ Attack surfaces are expanding rapidly, but pentesters are here to save the day ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rem73Tbz5vDuHLZUD3xWuj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QGJdnzL5ujgBmZvWfYVyk7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Sep 2025 09:44:59 +0000</pubDate>                                                                                                                                <updated>Wed, 24 Sep 2025 09:45:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QGJdnzL5ujgBmZvWfYVyk7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ethical hacker concept image showing hands of a female pentester typing on a laptop keyboard.]]></media:description>                                                            <media:text><![CDATA[Ethical hacker concept image showing hands of a female pentester typing on a laptop keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Ethical hacker concept image showing hands of a female pentester typing on a laptop keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QGJdnzL5ujgBmZvWfYVyk7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Often underestimated by CISOs, hardware and network vulnerabilities are on the rise as IoT proliferates and AI creates increasingly larger attack surfaces.</p><p>That’s according to an analysis by Bugcrowd, which found the last year has seen a massive 88% increase in hardware vulnerabilities and a doubling in network flaws.</p><p>In a new report, <a href="https://www.bugcrowd.com/resources/report/inside-the-mind-ciso-resilience-in-an-ai-accelerated-world/" target="_blank"><u><em>Inside the Mind of a CISO 2025: Resilience in an AI-Accelerated World</em></u></a>, the firm said that 81% of security researchers had encountered new hardware vulnerabilities in the past 12 months.</p><div class="product"><a data-dimension112="79fc052a-60a8-443a-b174-696335c075c0" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="79fc052a-60a8-443a-b174-696335c075c0" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="79fc052a-60a8-443a-b174-696335c075c0" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Bugcrowd pointed to a 40% rise in broken access control vulnerabilities as a key factor behind rising threats. Meanwhile, sensitive data exposure was another problem area, with a 42% increase in critical vulnerabilities tied to personal information like names, addresses, and account details.</p><p>"We are in a high-stakes innovation race, but with every AI advance, the security landscape becomes exponentially more complex," said Nick McKenzie, Bugcrowd CISO. "Attackers are exploiting this complexity, but still targeting foundational layers like hardware and APIs."</p><p>The good news is that the number of critical vulnerabilities has gone down slightly year-over-year. The number of <a href="https://www.itpro.com/development/application-programming-interface-api/358546/nearly-every-company-surveyed-experienced">critical flaws in API</a> targets fell by about 25%, for example, while vulnerabilities in website targets decreased by 30%. </p><p>There was a slight rise in critical vulnerabilities for <a href="https://www.itpro.com/software/google/android">Android</a>, hardware, <a href="https://www.itpro.com/mobile/30409/android-vs-ios-which-mobile-os-is-right-for-you">iOS</a>, and network targets. Of these, broken access control is now the top category at 36%. </p><p>However, there's also been a 42% increase in sensitive data exposure and a 10% increase in API vulnerabilities as attack surfaces expand. Network vulnerabilities doubled, according to the report.</p><h2 id="pentesters-are-having-a-field-day">Pentesters are having a field day</h2><p>This increasingly perilous threat landscape has sparked a boom time for <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">ethical hackers</a> and pentesters, the report noted. Across 2024, there was a 32% increase in average <a href="https://www.itpro.com/security/google-spent-dollar10-million-on-bug-bounty-payouts-last-year-heres-what-flaws-researchers-uncovered">bug bounty payouts</a> for critical vulnerabilities. </p><p>Bugcrowd said enterprises are focusing on critical vulnerability payouts, paying more for P1 vulnerabilities and less for P3, P4, and P5 vulnerabilities.</p><p>Despite this helping hand, <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISOs </a>are still contending with heavy workloads and growing challenges. With applications going through multiple <a href="https://www.itpro.com/software/development/367842/the-four-major-software-development-lifecycle-models-and-how-they-work">development cycles</a> and teams under immense pressure to release features quickly, this is creating a frantic environment where mistakes are made. </p><p>New attack vectors and often forgotten targets like APIs and hardware typically among those overlooked. </p><p>With this in mind, Bugcrowd said organizations should consider adding APIs and hardware to the scope of their offensive security testing programs. </p><p>They should also adopt an integrated approach to attack surface intelligence - which, the firm noted, would help to secure budgets by showing measurable improvements in security efficiency.</p><p>Naturally, the company urged enterprises to make better use of ethical hackers, pentesters, and <a href="https://www.itpro.com/security/cisa-breached-a-federal-agency-as-part-of-its-red-team-program-and-nobody-noticed-for-five-months">red teamers</a> for offensive security training.   </p><p>“By using adversarial testing and objective measurement, security leaders can shift from reactive firefighting to building true resilience, " said Trey Ford, chief strategy and trust officer at Bugcrowd.</p><p>"Ultimately, this enables CISOs to confidently articulate their security story and secure resources necessary to protect their organizations.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/this-deepseek-powered-pen-testing-tool-could-be-a-cobalt-strike-successor-and-hackers-have-downloaded-it-10-000-times-since-july">This DeepSeek-powered pen testing tool could be a Cobalt Strike successor</a></li><li><a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">Everything you need to know about penetration testing</a></li><li><a href="https://www.itpro.com/security/vulnerability-patching-ai-application-security">Businesses are taking their eye off the ball with vulnerability patching</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This DeepSeek-powered pen testing tool could be a Cobalt Strike successor – and hackers have downloaded it 10,000 times since July ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/this-deepseek-powered-pen-testing-tool-could-be-a-cobalt-strike-successor-and-hackers-have-downloaded-it-10-000-times-since-july</link>
                                                                            <description>
                            <![CDATA[ ‘Villager’, a tool developed by a China-based red team project known as Cyberspike, is being used to automate attacks under the guise of penetration testing. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SCHYLK4j7td9YGgWYc4pVe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/THFKPNNcPVcHpAPCmMkcEK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Sep 2025 11:11:24 +0000</pubDate>                                                                                                                                <updated>Tue, 16 Sep 2025 11:11:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LFPWMoCGDVHowHbMpHJZkU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google. &lt;/p&gt;&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/THFKPNNcPVcHpAPCmMkcEK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker working on a desktop computer with dual monitors in a room with red lights.]]></media:description>                                                            <media:text><![CDATA[Hacker working on a desktop computer with dual monitors in a room with red lights.]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker working on a desktop computer with dual monitors in a room with red lights.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/THFKPNNcPVcHpAPCmMkcEK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are deploying a new AI-native penetration testing tool for sophisticated attacks in an industry first, according to new research.</p><p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity </a>firm Straiker has warned that ‘Villager’, a tool developed by a China-based red team project known as Cyberspike, is already being used to automate attacks under the guise of penetration testing.</p><p>Villager leverages the <a href="https://www.itpro.com/software/linux/kali-linux-review-a-swiss-army-knife-for-cyber-security-pros"><u>Kali Linux</u></a> toolsets and <a href="https://www.itpro.com/technology/artificial-intelligence/deepseek-r1-model-jailbreak-security-flaws"><u>DeepSeek v3</u></a> to automate attacks, and is easily accessible via the official Python Package Index (PyPI). </p><div class="product"><a data-dimension112="e67cb378-fa61-4e1c-a539-c9d93c022f5c" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="e67cb378-fa61-4e1c-a539-c9d93c022f5c" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="e67cb378-fa61-4e1c-a539-c9d93c022f5c" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Based on user prompts it can exploit vulnerabilities in a given domain, launch attacks using multiple tools to ensure a victim is breached, and establish persistence for attackers in compromised systems.</p><p>“The framework's most dangerous innovation lies not in any single capability, but in how it seamlessly integrates multiple attack vectors through intelligent task orchestration,” wrote Dan Regalado, principal <a href="https://www.itpro.com/security/ai-security-blunders-have-cyber-professionals-scrambling">AI security</a> researcher at Straiker, and Amanda Rousseau, member of technical staff at Straiker.</p><p>“By combining containerized Kali environments, browser automation, direct code execution, and a 4,201-prompts vulnerability database, all coordinated by AI decision-making, the framework dramatically lowers the technical barrier for conducting complex attacks.”</p><p>Researchers at Straiker compared Villager to Cobalt Strike, a legitimate penetration testing tool that has been <a href="https://www.itpro.com/security/cyber-crime/hundreds-of-cobalt-strike-servers-have-been-taken-offline-in-a-major-law-enforcement-sting"><u>widely used by hackers for illegitimate purposes</u></a>.</p><p>In March, <a href="https://www.itpro.com/security/cyber-crime/cobalt-strike-takedown-fortra-microsoft"><u>Fortra and Microsoft announced an “aggressive campaign”</u></a> against hackers using Cobalt Strike across over 200 malicious domains. Malicious use of the tool on a daily basis dropped 80% as a result.</p><h2 id="villager-pen-testing-tool-is-a-step-above-cobalt-strike">Villager pen testing tool is a step above Cobalt Strike</h2><p>Unlike the scripted attacks possible via Cobalt Strike, the AI-powered Villager is capable of complex attacks based on natural language prompts.</p><p>For example, researchers noted that when Villager detects a victim’s domain using WordPress, it will launch an attack using the WordPress vulnerability scanner WPScan, for which it creates a custom Kali container. </p><p>If an API endpoint is detected, on the other hand, Villager may use browser automation to attempt a breach through a victim’s authentication workflow.</p><p>Each successful step is verified by the tool, which can dynamically adapt its vector depending on the context of the attack. Similarly, each Kali Linux container Villager creates, which can contain a range of <a href="https://www.itpro.com/security/despite-the-hype-cybersecurity-teams-are-still-taking-a-cautious-approach-to-using-ai-tools">cybersecurity tools</a>, has built-in mechanisms to wipe themselves after 24 hours to prevent detection.</p><p>The tools’s command and control (C2) system, accessed via its Python-based FastAPI connection, ensures each attack is broken into manageable subtasks that are handled by its AI model. </p><p>Outputs are standardized using the data validation library Pydantic, researchers added. This ensures each decision Villager makes is reliable and follows on from its previous steps.</p><p>All of this points to an organic, sophisticated methodology that opens the door to more attacks from inexperienced attackers, researchers warned. Since it was published on <a href="https://www.itpro.com/security/cyber-attacks/pypi-attack-targeting-of-repository-shows-no-sign-of-stopping">PyPI </a>in July 2025, Villager has been downloaded more than 10,000 times.</p><p>The authors at Straiker warned the tool could lead to more automated attacks by hackers using off the shelf tools. They also cautioned that attacks of this kind could speed up the rate at which attackers can discover new vulnerabilities and exploit them, shrinking the detection and response window for cybersecurity teams.</p><p>Straiker tracked Cyberspike as having first appeared on a domain established in November 2023, by the supposed AI firm Changchun Anshanyuan Technology Co. </p><p>The authors wrote that no evidence of such a company exists on Chinese social media, though archived pages show it sold Cyberspike as a remote administration tool (RAT) in 2023.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/hackers-are-duping-developers-with-malware-laden-coding-challenges">Hackers are duping developers with malware-laden coding challenges</a></li><li><a href="https://www.itpro.com/security/cyber-crime/anthropic-admits-hackers-have-weaponized-its-tools-and-cyber-experts-warn-its-a-terrifying-glimpse-into-how-quickly-ai-is-changing-the-threat-landscape">Anthropic admits hackers have 'weaponized' its tools</a></li><li><a href="https://www.itpro.com/security/hackers-are-using-ai-to-dissect-threat-intelligence-reports-and-vibe-code-malware">Hackers are using AI to dissect threat intelligence reports and ‘vibe code’ malware</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber professionals call for a 'strategic pause' on AI adoption as teams left scrambling to secure tools ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-professionals-call-for-a-strategic-pause-on-ai-adoption-as-teams-left-scrambling-to-secure-tools</link>
                                                                            <description>
                            <![CDATA[ Security professionals are scrambling to secure generative AI tools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cgh9UxCVnhcsKHUFY8f3sV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aqzJdthdqwShUTpHpZUBqL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Jun 2025 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aqzJdthdqwShUTpHpZUBqL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female cybersecurity analyst pressing fingers to her temple in despair while working at a desktop computer in a dimly lit room.]]></media:description>                                                            <media:text><![CDATA[Female cybersecurity analyst pressing fingers to her temple in despair while working at a desktop computer in a dimly lit room.]]></media:text>
                                <media:title type="plain"><![CDATA[Female cybersecurity analyst pressing fingers to her temple in despair while working at a desktop computer in a dimly lit room.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aqzJdthdqwShUTpHpZUBqL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>More than a third of security leaders and practitioners admit that generative AI is moving faster than their teams can manage.</p><p>Almost half (48%) <a href="https://resource.cobalt.io/state-of-llm-app-security" target="_blank"><u>told</u></a> penetration testing firm Cobalt that they'd like to have a 'strategic pause' to recalibrate their defenses against generative AI-driven threats - something they know they're not likely to get.</p><p>More than seven-in-ten (72%) cited generative AI-related attacks as their top IT risk, but a third still aren't conducting regular security assessments, including penetration testing, for their LLM deployments.</p><p>“Threat actors aren’t waiting around, and neither can security teams,” said Gunter Ollmann, CTO at Cobalt. </p><p>“Our research shows that while genAI is reshaping how we work, it’s also rewriting the rules of risk. The foundations of security must evolve in parallel, or we risk building tomorrow’s innovation on today’s outdated safeguards.” </p><p>Security leaders at C-suite and VP level are more concerned than practitioners about long-term <a href="https://www.itpro.com/technology/artificial-intelligence/six-generative-ai-cyber-security-threats-and-how-to-mitigate-them">generative AI threats</a> such as adversarial attacks - an issue for 76%, compared with just 68% of security practitioners. </p><p>However, 45% of practitioners expressed concern about near-term operational risks such as inaccurate outputs, compared with only 36% of security leaders.</p><p>Security leaders are also more likely to consider changing how their team approaches <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> defense strategies in light of the potential of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a>-driven attacks, at 52% compared with 43% for practitioners.</p><p>Top concerns among all survey respondents included sensitive information disclosure, cited by 46%, model poisoning or theft, a worry for 42%, inaccurate data, an issue for 40%, and training data leakage, cited by 37%.</p><p>Similarly, half said they wanted more transparency from software suppliers about how they detect and prevent vulnerabilities, signaling a growing trust gap in the AI supply chain, the researchers said.</p><p>Many organizations lack the in-house expertise to adequately assess, prioritize, and remediate complex LLM-specific vulnerabilities. </p><p>This can lead to an over-reliance for fixes on third-party model providers or tool vendors - some of which may not prioritize these security issues as quickly or effectively as they should, particularly if the vulnerability lies within the foundational model itself.</p><h2 id="llm-analysis-uncovers-worrying-flaws">LLM analysis uncovers worrying flaws</h2><p>Analysis based on data collected during Cobalt <a href="https://www.itpro.com/tag/penetration-testing">pentests </a>showed that while 69% of serious findings across all categories are resolved, this drops to just 21% of the high-severity vulnerabilities found in LLM pentests. </p><p>This is a concern, researchers said, given that 32% of LLM pentest findings are serious and is the lowest resolution rate across all test types the company conducts.</p><p>While the mean time to resolve (MTTR) for those serious LLM findings that are fixed is a rapid 19 days — the shortest MTTR across all pentest types - this is probably partly because organizations tend to prioritize quicker, and often simpler fixes.</p><p>"Much like the rush to cloud adoption, genAI has exposed a fundamental gap between innovation and security readiness,” said Ollmann.</p><p>“Mature controls were not built for a world of LLMs. Security teams must shift from reactive audits to programmatic, proactive AI testing — and fast.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ai-security-blunders-have-cyber-professionals-scrambling">AI security blunders have cyber professionals sweating</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/enterprises-are-worried-about-agentic-ai-security-risks-gartner-says-the-answer-is-just-adding-more-ai-agents">Enterprises are worried about agentic AI security risks – Gartner says the answer is just adding more AI agents</a></li><li><a href="https://www.itpro.com/security/cyber-crime/agentic-ai-cybersecurity-risks">Agentic AI could be a blessing and a curse for cybersecurity</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bugcrowd’s new MSP program looks to transform pen testing for small businesses ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugcrowds-new-msp-program-looks-to-transform-pen-testing-for-small-businesses</link>
                                                                            <description>
                            <![CDATA[ Cybersecurity provider Bugcrowd has launched a new service aimed at helping MSP’s drive pen testing capabilities - with a particular focus on small businesses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zRvXPxQjKzyxvUBJMMkJ2S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Apr 2025 11:12:46 +0000</pubDate>                                                                                                                                <updated>Thu, 01 May 2025 09:05:38 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity</a> provider <a href="https://www.itpro.com/security/bugcrowd-eyes-global-expansion-after-securing-dollar102-million-in-strategic-growth-funding">Bugcrowd </a>has launched a new service aimed at helping MSP’s drive pen testing capabilities - with a particular focus on supporting small businesses. </p><p>The company said the program will address a growing backlog of compliance-related pen tests among SMBs, enabling them to meet requirements and streamline capabilities. </p><p>Drawing on the expertise of ethical hackers, Bugcrowd said the launch of the scheme marks a “significant step forward” in its mission to expand support for MSPs and customers. </p><p>"Bugcrowd's new MSP offering is a game-changer for our partners and an important step for our program," said Jacques Lopez, VP for global channel & alliances at Bugcrowd. </p><p>"By leveraging our crowdsourced streamlined-scope pen testing capabilities, MSPs can offer their clients fast, reliable, and cost-effective compliance testing. This enables those clients to stay ahead of regulatory requirements and security threats, while their systems are secure and compliant. </p><p>“This offering can augment the capabilities of those partners who already provide pen testing, enabling them to reserve their in-house pen testers for projects they are best suited for while Bugcrowd handles more routine projects.” </p><p>The new <a href="https://www.itpro.com/business/have-we-seen-the-end-of-the-true-msp">MSP </a>program is available immediately, albeit to a limited number of partners, Bugcrowd revealed. Service pricing is also based on a flat rate model, and will offer a raft of options based on the scope of the pen testing required. </p><h2 id="what-to-expect-with-the-new-bugcrowd-service">What to expect with the new Bugcrowd service</h2><p>The new pen testing service will cover a range of key areas, according to Bugcrowd. </p><p>This includes pen testing for networking, APIs, mobile apps, and cloud configurations. Speed and efficiency are also key target for the company, and the scheme will enable partners to launch engagements in around three business days. </p><p>This, the firm noted, will streamline customer security capabilities. </p><p>For MSPs specifically, Bugcrowd said the new program will allow partners to benefit from “faster revenue recognition” by speeding up the initiation of engagements. </p><p>As part of the move, a raft of crowdsourced offerings from the firm, including the <a href="https://www.itpro.com/security/should-your-business-start-a-bug-bounty-program">Bug Bounty</a>, Vulnerability Disclosure Programs, and Attack Surface Management schemes will be made available for resale. </p><p>Mitch Evans, director of cybersecurity consulting at BARR Advisory, said the new program will play a vital role in helping bolster security among small businesses, which has been a long-standing area of concern. </p><p>"SMBs often struggle to employ the services they need to meet compliance requirements. Bugcrowd’s service not only enhances our ability to deliver high-quality compliance testing to our clients but also helps us scale our operations and meet the growing demand for pentesting services," Evans said. </p><p>"We are thrilled to work with Bugcrowd on deploying this service and look forward to new and existing clients benefiting from these trusted capabilities."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/hardware/storage/netapp-eyes-san-market-gains-amid-tighter-partner-collaboration">NetApp eyes SAN market gains amid tighter partner collaboration</a></li><li><a href="https://www.itpro.com/cloud/cloud-computing/it-channel-cloud-capabilities">UK channel partners are ramping up their cloud capabilities</a></li><li><a href="https://www.itpro.com/security/eset-looks-to-empower-partners-with-cybersecurity-portfolio-updates">ESET looks to ‘empower’ partners with cybersecurity portfolio updates</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kubernetes on AWS targeted by hackers abusing legitimate pentesting tools ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/kubernetes-on-aws-targeted-by-hackers-abusing-legitimate-pentesting-tools</link>
                                                                            <description>
                            <![CDATA[ Experts believe the campaign is going to develop further, expanding attacks to other cloud providers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hfW6pudEYjZF4eHsJeYk6Q</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9D2da86awC8eMrg53j5PN7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Jul 2023 11:36:18 +0000</pubDate>                                                                                                                                <updated>Tue, 11 Jul 2023 13:55:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9D2da86awC8eMrg53j5PN7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kubernetes on AWS hack: a picture of a cloud on a 3D rendering of computer chip in balck and neon blue colouring]]></media:description>                                                            <media:text><![CDATA[Kubernetes on AWS hack: a picture of a cloud on a 3D rendering of computer chip in balck and neon blue colouring]]></media:text>
                                <media:title type="plain"><![CDATA[Kubernetes on AWS hack: a picture of a cloud on a 3D rendering of computer chip in balck and neon blue colouring]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9D2da86awC8eMrg53j5PN7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals have been found abusing legitimate open-source penetration testing tools to launch attacks on AWS-hosted Kubernetes environments.</p><p>The campaign, dubbed SCARLETEEL, started in February 2023 and is known for targeting cloud environments.  </p><p>The latest discoveries revealed new tools and techniques to bypass security measures and execute novel intrusions. </p><p>A typical SCARLETEEL attack sees attackers exploiting misconfigured <a href="https://www.itpro.com/amazon-web-services-aws/34126/amazon-web-services-review-aws-packs-in-more-features-than-any-other">AWS</a> policies to escalate their privileges and gain account control.  </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UHcZNnXqYMrrqYNDz9hpHN" name="Automating application-driven container elasticity_listing.jpg" caption="" alt="Image of warehouse with multiple shelves of containers and pick truck" src="https://cdn.mos.cms.futurecdn.net/UHcZNnXqYMrrqYNDz9hpHN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Automating application-driven container elasticity</strong></p><p class="fancy-box__body-text"><em>Learn how to operationalize speed to market while assuring application performance</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/containers/370420/automating-application-driven-container-elasticity"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Once in, the attackers target Kubernetes in order to significantly scale up the attack and deploy malware, such as <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptomining</a> tools.  </p><p>A combination of penetration testing tools was used in the attack. Once the victim’s AWS credentials had been stolen and the AWS CLI binary installed on the exploited containers, the attackers installed Pacu, an AWS exploitation framework, to reveal further vulnerabilities in the victim’s account. </p><p>The attackers also leveraged Peirates, a Kubernetes-specific <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a> tool, to exploit the Kubernetes environment. </p><p>While cryptomining remains one of the operation’s objectives, according to researchers from the Sysdig Threat Research Team, other goals include gaining persistence and the theft of proprietary data. </p><h2 id="what-has-changed-in-the-attack-pattern-xa0">What has changed in the attack pattern? </h2><p>SCARLETEEL was first noted by the team in February 2023 and the techniques in use have changed in the time since.  </p><p>Michael Clark, director of threat research at Sysdig, said: “They kind of evolved their toolsets to understand modern approaches”. </p><p>The attacker’s scripts now account for the differences. </p><p>Although the ability to detect the presence of a Fargate-hosted container is novel, the use of the AWS CLI and Pacu on exploited containers and Peirates to further exploit Kubernetes is a significant development. </p><p>“They use these tools to keep hopping into new environments,” Clark said. </p><p>“So, they may end up in a Fargate [environment] because they look for all the credentials they can.” </p><h2 id="how-were-the-attackers-detected-xa0">How were the attackers detected? </h2><p>In Sysdig’s research, Clark noted that the tools the attackers used are “noisy”, meaning when they run, their processes are often detectable by system and <a href="https://www.itpro.com/business/business-operations/367876/best-network-monitoring-tools">network monitoring tools</a>. </p><p>Understanding what the tools’ reconnaissance looks like is key to detecting what they’re doing and when they’re running. </p><p>“That is really the only way to do it,” Clark said. “You obviously can’t just say ‘don’t let them in’ - that’s the answer to everything.” </p><p>Clark also said the use of Peirates was particularly interesting. The previous attack did not use this tool, but the SCARLETEEL campaign has now expanded to look for <a href="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes">Kubernetes</a> and, if found, take advantage of it. </p><h2 id="moving-beyond-aws-xa0">Moving beyond AWS </h2><p>Alessandro Brucato, threat research engineer at Sysdig, said he believes that the attackers behind the campaign will continue to develop it to target other cloud providers. </p><p>“They will try to focus on how they can make a lot less noise, because actually they can look even more like a legitimate service provider. They may try to find some edge services on some cloud providers.” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI to pay up to $20k in rewards through new bug bounty program ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/openai-to-pay-up-to-dollar20k-in-rewards-through-new-bug-bounty-program</link>
                                                                            <description>
                            <![CDATA[ The move follows a period of unrest over data security concerns ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZzZXTsDY4Nzg33Gh3Do3kK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zwqDDCyttCAQQ9fnt5F8rX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Apr 2023 12:06:44 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Apr 2023 09:03:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zwqDDCyttCAQQ9fnt5F8rX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[lots of lime-coloured padlocks set against a green background, with one orange padlock in the middle that&#039;s unlocked]]></media:description>                                                            <media:text><![CDATA[lots of lime-coloured padlocks set against a green background, with one orange padlock in the middle that&#039;s unlocked]]></media:text>
                                <media:title type="plain"><![CDATA[lots of lime-coloured padlocks set against a green background, with one orange padlock in the middle that&#039;s unlocked]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zwqDDCyttCAQQ9fnt5F8rX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has unveiled a new bug bounty program offering rewards for security researchers if they can uncover vulnerabilities in its products. </p><p>In an announcement on Tuesday, the California-based AI firm said the bug bounty scheme is “essential to our commitment to develop safe and advanced AI” and deliver services that are secure, reliable, and trustworthy. </p><p>As part of the initiative, OpenAI said it will offer a tiered reward system based on the severity of bugs uncovered by researchers. </p><p>Rewards can range from as little as $200 for low-severity flaws with a maximum reward of $20,000 for “exceptional discoveries”. </p><p>“The OpenAI Bug Bounty Program is a way for us to recognize and reward the valuable insights of security researchers who contribute to keeping our technology and company secure,” the firm said in a statement. </p><p>“We invite you to report vulnerabilities, bugs, or security flaws you discover in our systems. By sharing your findings, you will play a crucial role in making our technology safer for everyone.”</p><p>Researchers participating in the new initiative will be able to disclose vulnerabilities or flaws through a partner organisation, Bugcrowd.</p><p>Bugcrowd will manage the submission and reward process, which OpenAI said is designed to “ensure a streamlined experience for all participants”. </p><h2 id="chatgpt-vulnerability-concerns">ChatGPT vulnerability concerns</h2><p>The move from OpenAI follows a period of unrest over security-related issues at the generative AI firm, which has close ties with Microsoft. </p><p>Last month, the company revealed that a bug in <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses"><u>ChatGPT</u></a> led to a <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370315/chatgpt-privacy-flaw-exposes-users-chatbot-interactions"><u>leak of users&apos; data</u></a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aWdFz5f4uyXMEphjuW8u2e" name="SOC modernisation and and the role of XDR_thumb.png" caption="" alt="Whitepaper cover with image of male colleague at workstation" src="https://cdn.mos.cms.futurecdn.net/aWdFz5f4uyXMEphjuW8u2e.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TrendMicro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>SOC modernisation and the role of XDR</strong></p><p class="fancy-box__body-text"><em>How to cope with increasing threats and IT sprawl</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/370276/soc-modernisation-and-and-the-role-of-xdr"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>This flaw meant that <a href="https://www.itpro.com/business/business-strategy/369989/openai-launches-chatgpt-plus-greater-revenue"><u>ChatGPT Plus</u></a> users began seeing user email addresses, subscriber names, payment addresses, and limited credit card information. </p><p>The issue prompted the company to temporarily take the <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369979/chatgpt-vs-chatbots-whats-the-difference"><u>chatbot</u></a> offline to work on a fix. </p><p>“The bug was discovered in the Redis client open-source library, redis-py,” OpenAI explained in a post at the time. </p><p>“As soon as we identified the bug, we reached out to the Redis maintainers with a patch to resolve the issue.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kali Linux releases first-ever defensive distro with score of new tools ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/enterprise-security/370257/kali-linux-releases-first-ever-defensive-distro-score-new-tools</link>
                                                                            <description>
                            <![CDATA[ Kali Purple marks the next step for the red-teaming platform on the project's tenth anniversary ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">unrADLURAspNaGwLVwKfnV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DXyATm7k6CbbwJC5rPAeCK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Mar 2023 12:00:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DXyATm7k6CbbwJC5rPAeCK-1280-80.jpg">
                                                            <media:credit><![CDATA[Kali / Offensive Security]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of a Linux operating system with Kali Purple windows open on the desktop and a stylised dragon in the background next to the text &amp;#039;KALI&amp;#039;]]></media:description>                                                            <media:text><![CDATA[A screenshot of a Linux operating system with Kali Purple windows open on the desktop and a stylised dragon in the background next to the text &amp;#039;KALI&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of a Linux operating system with Kali Purple windows open on the desktop and a stylised dragon in the background next to the text &amp;#039;KALI&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DXyATm7k6CbbwJC5rPAeCK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The team behind the Kali Linux project has released a brand-new version called Kali Purple, designed specifically for defensive security practitioners - a first for the project.</p><p>Kali Purple was released as a technical preview this week and marks the first time the platform has catered to defenders, previously being used as a tool for <a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">red teamers</a> and penetration testers.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nx6u3z9cbusK7Hm4Z2UHgJ" name="nx6u3z9cbusK7Hm4Z2UHgJ.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/nx6u3z9cbusK7Hm4Z2UHgJ.png" mos="https://cdn.mos.cms.futurecdn.net/nx6u3z9cbusK7Hm4Z2UHgJ.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Datto SMB cyber security for MSPs report</strong></p><p class="fancy-box__body-text">A world of opportunity for MSPs</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/smb/370209/datto-smb-cyber-security-for-msps-report" data-original-url="/business-strategy/smb/370209/datto-smb-cyber-security-for-msps-report">FREE DOWNLOAD</a></p></div></div><p>As of now, Kali Purple is a proof of concept distro for security testing, described by Kali as a “reference architecture for the ultimate SOC In-A-Box”.</p><p>It will allow teams to engage in internal wargames, learn how to protect small-to-medium-sized IT environments, and practice <a href="https://www.itpro.com/security/cyber-security/368481/what-is-threat-hunting" data-original-url="https://www.itpro.com/security/cyber-security/368481/what-is-threat-hunting">threat hunting</a>, among other activities.</p><p>The name references the addition of blue and purple team capabilities to Kali Linux’s existing suite of red team testing tools, expanding the distro from its offensive testing pedigree to encompass the entire security testing spectrum.</p><p>More than 100 defensive tools are included within Kali Purple. These include CyberChef, which can <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypt or decrypt data</a> as well as compression and data analysis, Elastic’s security information and event management (SIEM), and the <a href="https://www.itpro.com/software/28109/what-is-open-source" data-original-url="https://www.itpro.com/software/28109/what-is-open-source">open source</a> network intrusion detection system Zeek.</p><p>Kali Autopilot, a script builder for automated attacks is also included in Kali Purple. Through a community hub developers will be able to share scripts for blue teams to go up against, as well as practice packet captures to train in network analysis.</p><p>The developers outlined their goal of making Kali the <a href="https://www.itpro.com/operating-systems/28025/best-linux-distros" data-original-url="https://www.itpro.com/operating-systems/28025/best-linux-distros">best Linux distro</a> for security tests, and expanding enterprise-grade security to all.</p><p>“Remember what we did a decade ago with Kali Linux? Or with BackTrack before that? We made offensive security accessible to everyone,” Kali wrote in its <a href="https://www.kali.org/blog/kali-linux-2023-1-release/#new-tools-in-kali">blog post</a>.</p><p>“No expensive licenses required, no need for commercial grade infrastructure, no writing code or compiling tools to make it all work… just download Kali Linux and do your thing. We are excited to start a new journey with the mission to do exactly the same for defensive security: Just download Kali Purple and do your thing.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/28025/best-linux-distros" data-original-url="/operating-systems/28025/best-linux-distros">Best Linux distros 2023: The finest open source operating systems around</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system" data-original-url="/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system">Windows vs Linux: What's the best operating system?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/operating-systems/370109/linux-edges-closer-full-apple-silicon-with-version-62" data-original-url="/software/operating-systems/370109/linux-edges-closer-full-apple-silicon-with-version-62">Linux edges closer to full Apple silicon support with version 6.2</a></p></div></div><p>Kali Purple has been structured around the National Institute of Standards and Technology’s <a href="https://www.nist.gov/cyberframework/online-learning/five-functions">(NIST’s) five functions</a> as outlined in the Cybersecurity Framework: “identify, protect, detect, respond, and recover”.</p><p>In addition to the announcement of Kali Purple, the firm highlighted eight new tools included in Kali Linux 2023.1.</p><p>These include the aforementioned Cyberchef, as well as packet capture system Arkime, <a href="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important" data-original-url="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important">DevSecOps</a> and vulnerability management tool DefectDojo, network scanner Dscan, <a href="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes" data-original-url="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes">Kubernetes</a> package manager Kubernetes-Helm, password analysis and cracking kit 2 (PACK2), <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">pen test</a> data management tool RedEye, and cryptographic <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm" data-original-url="https://www.itpro.com/data-insights/30212/what-is-an-algorithm">algorithm</a> interface Unicrypto.</p><p>The update also brings a visual refresh to the distro, with new wallpapers and Kali Purple themes, as well as a new tiling and widget system with the introduction of the graphical workspace environment KDE Plasma 5.27.</p><p>Kali Purple is available as a pre-launch technical preview now, with a dedicated Discord server and <a href="https://gitlab.com/kalilinux/kali-purple/documentation/-/wikis/home">wiki</a>. Further details on its full launch are expected in the future.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Podcast transcript: Meet the cyborg hacker ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/369133/podcast-transcript-meet-the-cyborg-hacker</link>
                                                                            <description>
                            <![CDATA[ Read the full transcript for this episode of the IT Pro Podcast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4ekpSreZcLL2go22W64RcW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/e68dF8GWJKnWi2HERUMHr6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Sep 2022 06:30:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/e68dF8GWJKnWi2HERUMHr6-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Podcast transcript: Meet the cyborg hacker]]></media:description>                                                            <media:text><![CDATA[Podcast transcript: Meet the cyborg hacker]]></media:text>
                                <media:title type="plain"><![CDATA[Podcast transcript: Meet the cyborg hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/e68dF8GWJKnWi2HERUMHr6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>This automatically-generated transcript is taken from the IT Pro Podcast episode ‘</em><a href="https://www.itpro.com/security/hacking/369132/the-it-pro-podcast-meet-the-cyborg-hacker" data-original-url="https://www.itpro.com/security/hacking/369132/the-it-pro-podcast-meet-the-cyborg-hacker">Meet the cyborg hacker</a>’<em>. We apologise for any errors.</em></p><h3 class="article-body__section" id="section-adam-shepherd"><span>Adam Shepherd </span></h3><p>Hi, I'm Adam Shepherd,</p><h3 class="article-body__section" id="section-connor-jones"><span>Connor Jones </span></h3><p>And I'm Connor Jones.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>And you're listening to the IT Pro Podcast, where this week we're taking a look at the emerging world of biohacking.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Now it's probably worth making the distinction between the two types of biohacking there are in the world right now. You know, there is of course, the kind of biohacking reserved for scientists, professional and homebrew, that involves the CRISPR gene editing technology. But this of course, is is an IT podcast and we're most concerned with a form of bio hacking of the cyber kind; you know, the one involving tech baked into the human body.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Now, since the invention of computer systems, people have been finding ways to break into them and customise their operation to best suit their own needs. In recent years, however, adventurous experimenters have begun exploring how the same principles can be applied to the human body.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>The so called biohackers have explored a number of ways to combine digital technology with flesh and blood, including implantable chips, digitally enhanced prosthetic limbs and much, much more. But what potential advantages does human augmentation hold? And are there any security risks that might be associated with this emerging practice? We're joined today by Len Noe, a technical evangelist, white hat hacker at CyberArk, and self described transhumanist, who's been immersed in this world for a number of years. Len, thanks for joining us.</p><h3 class="article-body__section" id="section-len-noe"><span>Len Noe </span></h3><p>Thank you guys for having me. It's a pleasure to be here.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So Len, first of all, you've got a number of, shall we say aftermarket extras? Can you talk about some of the biohacking modifications that you've made yourself?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, to be fair, I didn't make them myself. I, the first thing I'm going to say is everything I have, I've done it as safely as humanly possible. I'm not one of those. Do It Yourself guys to do this in your garage.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Don't try this at home, kids. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Yeah. I mean, there was a time that that was the way it was, but we passed that time, we can actually get some some some safe implants. Yeah, currently, I have eight different microchips with varying degrees of functionality, but predominantly, they revolve around RFID and NFC. I can do redirection tags via NFC, I can also have chips that will handle a lot of physical access cards like MIFARE classics, HID procs one and two, pyramid and dala, I actually have a credit card payment chip in my the top of my left hand, so I can actually do tap to pay with my hand, I have a biosensing magnets so that that one's a lot of fun. It's not really a lifting magnet. But due to the way that the magnet was constructed, it actually gives me the ability to feel electromagnetic currents and electromagnetic fields, kind of like a spidey sense. So yeah, and we can get into it a little later. I'm actually in the working on the second round of my prototypes for my pegleg. Those won't be the standard microchip style things. But that's actually a Raspberry Pi Zero W2 that's been actually loaded with Kali encased in bio encapsulation, and then I'm going to be implanting that in my leg, so that way I can actually take systems into places where you can't, or shouldn't be allowed to take technology. So having it set up to run low energy Bluetooth sweeps along with auto pwns while I'm sitting here talking, so yeah, I kind of have a little bit of a fascination with human upgrades.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>This is already my favourite podcast I've ever done. This is great. Can I just ask what is what is the upside of being able to detect and sense electro magnetic fields?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, I'm also very, very passionate about physical pen testing. I'm an avid lock picker. I'm a member of multiple different lock picking clubs. And when you look at physical security, especially around warehouses, how are most of them secured? Magnetic locks, magnetic locks require electricity. So depending on the wiring and the amount of shielding in your your Romex cabling for your electromagnet, I can sit on the outside of your building, run my hands over the wall, and I can actually trace your electrical lines. So at that point, I actually have an idea of where to shim or make, you know, especially if it's a destructive pen test, I can make a small hole and basically clip the electrical wire. And if you know anything about mag locks, especially if you're dealing in like an emergency situation like a fire or a power outage, magnetic locks are automatically designed to actually go into an open state due to an emergency to allow people to get out. So basically the that's one great thing for the magnet. The other thing is it makes a really cool trick at a bar, you can pick up bottle caps and things, you know. And it's, if nothing else, it's a really cool way to get, it's a cool magic trick around young kids too.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>In the immortal words of the Insane Clown Posse: magnets, how do they work?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Why do you have to go there, man? I mean, I'm from Detroit, but I mean, in St. Cloud, we had better musicians, man, let's go with the MC5 or, or the Bay City Rollers. Ted Nugent.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>This is Shaggy 2 Dope erasure, and I will not stand for it. So in terms of some of the other practical use cases that this technology has, aside from the magnets, you mentioned some of the chips that you've been using, particularly the RFID and NFC devices, the contactless payment devices; what other kinds of use cases are there for this technology, either currently, or that you can kind of see emerging in the near future?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, I mean, at this point, it's anything around the contactless technology, we see a lot of NFC used in IoT. You know, when it comes to personal devices, almost every mobile device or tablet that's been released within the last three to five years has NFC capability. And the truth is not a lot of people understand what it is. And the fact that it by its design is an unsecured protocol. You know, the problem when it comes to NFC is we're using application level security to try and lock down an insecure protocol. You know, so anything from, you know, compromising a mobile device through the use of the implants, I mean, one of my favourites is the physical access side of things, you know, and, you know, let me, let me go into this for just a second, if I may, you know, when it comes to our physical access, a lot of places, especially in my tenure, you know, and I've been doing this kind of work for pushing 30 years, only two companies I've ever worked for had any type of multifactor for physical access locations of high, high privilege, you know, data centres, things like that. Most companies will have a single point of access, and it's usually just a bar or a card read, and then the door unlocks. So if we take a look at my implants, and the fact that I have the ability to basically emulate multiple different physical card protocols, here's where it gets funny. If I don't have a copy of a cloned badge, if I don't have a Proxmark, or some type of replay device, if I'm found in a restricted area, the worst you're going to be able to do is trespass me. You're not going to be able to get me arrested, because all I have to do is say, hey, you know the door was open, I'm here looking at the building, I thought this was part of the tour. You know, unlike the days of old, you know, where if I did have that physical piece of evidence that shows how I got in there, then I can be actually looked at as a criminal. So I'm playing a lot in the grey areas. You know, the whole point is the obfuscation. I'm not doing anything that anybody else hasn't done before in a different method, I'm just doing it in a way that would be very, very difficult from a digital forensics or incident response perspective, to be able to actually find that true root cause, on top of the fact that even if they saw some of the bulges in my my skin where I have some of my implants, when it comes to most of the privacy laws in most, you know, first world countries, they're not allowed to actually delve too deeply because it involves my personal medical, the minute it went inside my skin.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>And also, I'd imagine they're not the kind of thing that one would typically notice, unless you knew exactly what you were looking for and where, right?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Exactly. I mean, I've gotten asked a lot of questions in turn over the since I started doing this, like, you know, are these the same chips that I that, you know, are in my dog, are these chips that are in my cat, you know, and in some way the answer's yes. I mean, they all run on the same NFC style protocol. You know, and just like when it comes to a pet, you know, they have those very large wands. So they're gonna they would have to actually try and find the implant, energise the chip, to be able to get a read. Therein lies the same problem when it comes to all augmented humans, in order to be able to detect me and my chips, you would actually have to energise those chips to be able to get a read. So you would need multiple different spectrum analyzers on both high frequency and low frequency. And they would have to be strong enough to energise my entire body in order to for the detection. So from a management or you know, an actual implementation perspective, there is currently no way to actually detect an augmented human with this type of technology inside the body. And that becomes a very large problem for security professionals. And the only way that I can really give as a way to try and combat this is a true defence in depth, and a layered security approach. You know, I've said it a million times, you know, we have no problem putting multifactor authentication in front of all of our privileged data. But we don't do the same thing for our physical locations. And when if there's one person out here, like me, that has the ability to do this, I think that's fact enough that we should be looking at this as a potential threat on a larger scale, and we need to address it accordingly.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So you can clearly see that there's a real benefit to having sort of, like you said, multi layer security with a biological air to it. And you obviously yourself also, what maybe like 5% technology, both by the amount of things that you've got in you by the sounds of it.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>I'm working on it; I'll take 5% is a compliment.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So what what what attracted you to the world of biohacking in the first place?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Why do you climb a mountain? Because it's there. If anybody wants to take a Google, just google me and you can find a picture; I am, I consider the fact that I have one tattoo, it just starts at my neck and goes all the way to my my, the top of my feet. I do flesh hook suspensions for fun. So when I saw that people were actually implanting technology, it just seemed kind of like the next natural evolution to somebody like me, I considered myself to be a modern primitive for a very, very long time. So as far as I know, I was the first person that had brung the, the idea that these can be used for an offensive purpose to the security community. I know I am not the first guy to ever do this. I'm just the first guy that opened his mouth about it. And I think that goes into just the way that I see the world. I was a black hat for a very, very long time. So when I look, walk into a room, the first thing I see is okay, there are cameras, where's the the exit strategies? You know, if you tell me that this is an NFC chip that can interact with a mobile device, maybe you're going to use it for your digital business card, I'm going to look at that same device and see how can I use this in a way that would suit my purposes?</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So let's talk about some of those methods, then some of those ways in which this technology could potentially be used to target businesses. You've spoken already about some of the offensive applications of the magnets you have, for example, but what about some of the, for example, the NFC and RFID chips?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Sure. NFC, you know, like I said, it's pretty much a standard protocol on most modern mobile devices and tablets. The abilities through NFC can be anything from transferring, beaming a file, it could you can use it to set up a Wi-Fi network, you can use it to redirect. I mean, we've seen all kinds of different possibilities. So the way that I've redirected those, I released three different attacks at RSA two years ago. The first one was called Flesh Hook. Flesh Hook is a redirect. Yeah, I made the exploits. I got to name them. That's one of the benefits. So essentially, what that one was, is I would I've set up a BeEF server. And you know, for any of the newbies out there that don't remember the good old days of BeEF, BeEF is the browser extension exploit framework. This is the website that, you know, we've all heard the rumours of the minute you log into this website, the bad guys are in your system. Yeah, that's BeEF. So it's a little bit of a social engineering play. You know, I'd walk up Hey, Adam, man, check this out, dude. Let me see your phone. I found this amazing new video on YouTube. I want to show you. As soon as I can get the device in my hand, if you have NFC turned on, the large flexNExT implant that's in the top of my right hand will actually have enough distance on the antenna that it'll actually read through the actual meat of my hand. I can hold the phone in the correct orientation. It will pop up a redirector where I'm going to just send you to a video, but the minute your browser hits that website, the Java code in the HTML page is actually going to hook the browser and then I have access to the entire BeEF suite. So I can do on device spear phishing attacks, I can geolocate your device, access the cameras, I can use DNS enumeration if you're on a local network or a corporate network, I can do domain identity, subdomain identification and enumeration. Anything that I could even think of. The other one was called leprosy. Again, my attack, I named it. Leprosy doesn't really work as well against iOS devices. But when it comes to Android, once again, you know, this one is a little bit easier. Adam, oh my god, man. You know, I'm over here in the UK with you, you know, my phone died. My wife, I was just on the phone with my wife. She told me something happened to my grandson, man, can I borrow your phone for just a second? You know, of course, you know, you know, yeah, here, dude, call your wife. And again, the URL that's been programmed into the NFC chip, points to a web location where I've got an infected APK that was created with MSF Venom or, you know, a Cobalt Strike beacon. At this point, you know, it's Oh, my God, you know, let's be honest, who remembers my who remembers phone numbers anymore? What's my wife's phone? What's the country code for the United States? Plus one. Okay. So I can go through this big rigmarole of trying to remember a phone number, when actually what I'm doing is installing that APK. And as soon as I'm done, it's like, oh, shit, I can't remember the phone number man here, I'm gonna just go plug my phone in. But at this point, I have a reverse TCP connection back to the device, I can set up persistence, I can get a shell. I mean, at that point, it's whatever I want. And the third one was called handshake. You know, they're all you know, biologically related names. What can I say? And, you know, at that one, you know, I can use a Proxmark, any type of card skimmer I want, get your badge information, write it down onto one of my chips. And if we're in one of those single point access situations, I'm in your privileged locations on prem. And once again, the problem is there's zero indications of compromised to any one of these different attacks.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>I think judging by mine and Adam's reactions after the first question we came in with, and we're just like grinning like Cheshire cats, right? I think we can speak for the both of us saying we're so excited just to hear about this kind of thing, because it's not something we hear about a lot. So with that in mind, then, how many black hats like your former self, are using this in the wild or starting to think about using it in terms of real world attacks?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Okay, this is one of the hardest questions to answer in regards to doing conversations like this. I can tell you this with 100. There, there are some facts that I can give you with 100% certainty. Within the United States, one of the biggest distributors for microchip implants is a company called DangerousThings.com. Within Europe, there is a company called KSEC, K-S-E-C. So I am, I spoke with the CEO of Dangerous Things, a gentleman by the name of Amal. And from him, I was able to gain the fact that Dangerous Things has sold close to about 300,000 implants. I was actually back in y'all's neck of the woods last weekend up in Newcastle, where I actually got to meet Kai from KSEC. And between the two of us we basically came up with an estimation of between four hundred and six hundred thousand implants have been shipped. How many of those implants were actually, have actually made their way inside of a human body? We don't know, but I can tell you this much. I know that I'm using it. I know of quite a few people who are on red teams that are using this technology. We have not found any indications from any type of incidents that have actually happened in the wild where implants were shown to be the root cause, but at the same time, how would you be able to determine that, you know, and therein lies the problem. We may have, I mean, we've seen, you know, breach reports where NFC or RFID were included in the evaluation in terms of cause of breach, but without actually getting access to an individual to find out if they were actually augmented, it could have been a card, it could have been an implant, we don't know. Because, as I said before, there's really no way to determine any type of augmented human with current technology.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>And if yourself and, you know, a significant amount of other red teamers are using this technology and are interested in this technology, it's a fairly safe bet that black and grey hat actors are also interested in it and are deploying it in the wild, you know, it's not, it's not that much of a logical leap.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>No, and that's the way I see it. If once I actually brought this to the out at RSA, I knew this was going to open the door and somebody who is going to read this and there's going to be some black or grey hat somewhere that goes, Hey, this is a new vector. And due to the you know, the privacy laws and everything else, this becomes a much safer road to try and travel if you're going to try and do offensive type activities.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So let's talk about some of the practicalities of this, then, cause this is a very kind of new, very emerging field. Have you experienced any challenges with biohacking and with your implants, you know, other than getting through airport security, which I can imagine is just a barrel of laughs.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Okay, well, you brought it up - the airport is the number one question that I get. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>I'm not surprised. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>You want, would you like me to tell you how I walk, how I get through an airport? </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Absolutely. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>I put one, the left foot in front of the right and then I repeat. That's it.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>No. Does it, do none of them come up on the scanners?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>All right, let's talk about the two different types of metal detectors for two seconds. We have the magnetometer which is just kind of the archway you walk through. There is not enough combined metal in all of my implants to actually trigger a magnetometer. I'm going to carbon date myself here; before my my career in IT, you know, almost 30 years ago, I used to do the job of the TSA before there was a TSA and airport, airport security was still privatised. And don't quote me on this, but I if I remember correctly, the magnetometers would not trigger unless you had a combined metallic weight of at least a .22 calibre bullet. So I mean, if you think about it, when you walk through a metal detector, if you have like a necklace on with a gold charm, it doesn't go off, if you have earrings in, it won't go off. Now, I'm not saying that they couldn't change the sensitivity of the magnetometers to where they would detect it. But they would get so many false positives, trying to check people into an airport that it would be an unusable control. Same with the metal detectors. When you think about my implants, most of them are actually silicone, you know, with the exception of the copper antennas on the larger flexible main membrane implants or the bio magnet, which is a iron core wrapped in titanium, but that's less smaller than the size of a pea. So even if I'm doing you know, the X ray metal detector, doesn't show up, I can walk straight through, the magnetometer will not trigger. So that to me kind of says something about what we're dealing with in terms of airport security. But, you know, we can do a different talk on that one another day.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>That's quite a scary prospects in some ways, particularly if you're trying to defend against these types of attacks.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Yeah, I mean, thankfully, at least at this point, there's not a lot in aeroplanes that are relying on RFID or NFC, you know, but if I can get that pegleg you know, where I actually have a full Linux system, then yeah, that is something that could potentially interact with the Wi-Fi entertainment system on the plane, I mean, it opens a whole lot of different vectors at that point.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>But even beyond air travel, if airport security - which is, I would argue, among the most stringent kind of security, you know, scanning in terms of concealed objects and devices - If it can get past airport gate security, then security in and out of a building or or complex doesn't really stand a chance for detecting this kind of stuff, does it?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Not even, not even a little bit. You know, one one thing that I, just cause you guys are are a lot of fun, and I think you guys will get a kick out of this. I think everybody is familiar with the drug smelling dogs that are used by the authorities. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yes. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, one of the, they actually have a new type of canine that is being released to help military and law enforcement. And they're actually technology sniffing dogs. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>No. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Yes, you can look them up. So these are not used in the same way that narcotic sniffing canines are in terms of they don't use them to be able to get an arrest. They don't bring them up and smell somebody and go, okay, yeah, we've got you, we're going to take you away. They're used more in the post arrest investigation point. They're used a lot with human trafficking, child predators, things like that; people that would actually store illegal data on hard drives, in technology. So if someone gets arrested, they'll get a search warrant, they run the dog around the house looking for hard drives, thumb drives, you know, anywhere that they may have, you know, tried to store illegal and illegal things. I found out that one of the law enforcement agencies that is close to me here in Texas, actually recently got one of these drugs, these key technology smelling dogs. So after, you know, sending an email to the police department going, No, I am not crazy. Yes, I have implants. And here's here's my CV. So you can see I'm a real person, and I'm not messing with you. I'm interested in information about this dog. And after they researched me, they're like, okay, apparently cyborgs are a real thing. They became really open to, you know, having conversations, and I've actually been invited to go up to the Dallas Police Department. And we're going to see if Remi, the technology dog, is able to sniff any of the implants that I have. Because that would actually be probably one of the first ways to try and detect somebody of augmented nature. And the one point that I wanted to point out, and since you guys are definitely geeks, and take that as a hardcore compliment, if you think back to the Terminator movies, where, you know, wherever the resistance was right at the entrances, they always had the guys with the dogs, because they could smell the technology. And I just start to wonder is this going to be a situation where life imitates art or art imitates life? I don't know which, but I'm really excited to get up there. Due to my travel schedule, it's been a little difficult, but I'm hoping to be up there sometime towards the middle of November. And you know, maybe I'll drop you a line and let you guys know how it turns out.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yeah, absolutely. I'm going to ask the obvious question, how can dogs smell technology? How can anyone smell technology?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Okay. Just like the they've taught the dogs to be able to detect specific narcotics, you know, heroin, cocaine, marijuana, things like that. They actually have taught them to key in on specific components that are used in the creation of technology. The name is triphenylphosphine oxide. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Oh, wow. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>So they found one very, very specific element that is used in the creation and manufacture of technology circuit boards, hard drives, and they basically train these dogs to hit on that one specific compound. I don't know if they'd be able to smell it through the skin. I don't know. But I still think it's going to be one hell of an interesting experiment.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Hmm. Yeah, definitely. And you get to hang out with more dogs as well. So that's a win win, really, and especially in my eyes. So in terms of getting this tech into the mainstream then, because obviously, I'm just from hearing you for the past half hour, I'm super excited about it, and I'm probably not going to be alone. So say further down the line that this kind of stuff does reach consumers, the everyday consumer that is, what are the limitations you can imagine a potential regulator seeing, you know, for example, can can realistically we actually have Internet facing machine augmentations of the kind like your like your peg leg, or is that is that a hacking risk waiting to happen?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Um, well, I mean, let's be honest, you know, we can talk about QR codes and they are hacking risks waiting, just waiting to happen, and we see those on buses and trains, and taxi cabs. I don't think honestly, the imposed threat of any technology is going to stop someone from using it if there is the potential for a monetary gain. So to answer your original question, there is a lot of implants going out right now that I see is going to probably help break that stigma barrier. One of them, like I said, is the Walletmor chip that I have in my right hand, it's an actual credit card. So I can do tap to pay. I think, right now, the idea of implants is still, like you said, it's very, very fringe. And you everybody looks at me like I'm some kind of a terminator half the time. I mean, my friends shut their Bluetooth and their Wi-Fi off, the minute I walk into a room. All I want to do is just look at him when I leave and go, I'd be back. But another one that I see that's really made an impact is there's the ability, if you drive a specific model Tesla, you can get an implant and you can programme your valet key onto an implant. And you can basically just jump in your Tesla and you can drive. I think as we see a lot more of these types of implants and technologies that people can actually find a legitimate day to day use for is going to help with the concept of adoption and understanding and acceptance. Right now, there's like I said, 400,000 to 600,000 potential augmented humans out there. I see it moving beyond just the microchip concept, especially with a lot of the advancements we're seeing around graphene batteries. The big issue when it comes to any type of implant is outside of anything that's considered biomedical, there's no internal power for anything yet. And even when it comes to the pegleg, that I'm planning on putting in myself, it uses an indirect power receiver to actually power the device, but there's no battery in it. Because to charge something generates heat. So I think we're right at the precipice of you know, a whole new set of things that could be potentially coming out. I did a keynote in Newcastle over the weekend, and the title was Resistance is futile, we're already Borg. And in that talk, I just brought up some of the stuff that's actually already out there that people may not even be aware of. We've got spinal implants that are, you know, returning motility, to paralysed people, we have ocular implants that are working on giving sight to the blind, we're able to use DNA as a storage medium, and one gramme of DNA could potentially hold over seven terabytes worth of data with a retention period of over 100 years. So we are right on the cusp of so many different technological breakthroughs that cross that human technology barrier, that I think that you know, in terms of what we're going to see in the relatively near future is going to really be up to the order in which these discoveries are made.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So speaking of future technology, and just going back to the kind of Tesla use case you mentioned a little earlier, just as a brief digression. What do you think is the kind of feasibility of projects like Neuralink and other brain computer interfaces?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Oh, you brought up Neuralink, if everybody's familiar with Neuralink, but nobody's familiar with the other company. I'm very, very interested in BCI. Brain computer interfaces, especially for disabled and locked in individuals, I think it's going to be crucial. I just watched an amazing documentary on my way back from Newcastle. Dr. Phil Kennedy, the name of the documentary was called Father of the cyborgs. Dr. Phil Kennedy was actually one of the he's a neurosurgeon. And he actually was the first individual to implant brain computer interfaces into paralysed people. You know, so everybody wants to talk about Neuralink, but they don't want to talk about all the other ones. Another really big player in the BCI field is Synchron. And they're already in human trials. So I think that the idea of BCI is definitely something that's going to happen. But at the same time, all of these new technologies they do will have, you know, an underlying firmware. You know, and one of the things that I'm trying to look at in regards to this, the melding of technology and humanity is as security professionals, we already know there are going to be attack vectors there and we need to be talking about those now. You know, the attacks we see today, the vectors may have changed, but at the core, every single attack today is the same attack that it's been for the last 20 years. I mean, they're looking for credentials, I'm looking for data, I'm trying to exfiltrate things, or I'm going to ransom you, you know, the end game is going to be the same; how we get there may be different. And if we think about all this new advancements in technology, and just that crossover, what happens when ransomware starts affecting Bluetooth or internet enabled bio implants, you know, what happens if I'm, my pacemaker gets a ransomware, then it's an a real ransom at that point. You know, and, you know, we keep running towards the technology and trying to, you know, make ourselves more than human, which is absolutely the core of, you know, the trans human movement. But one thing that I've said all along, and I even started the conversation with you guys today is, it needs to be done safely. And when we look at everything that's coming up, honestly, in my opinion, the end game is still identity, you know, and being able to maintain our individual identity as we become something potentially more than human. And as such, I think our identities, our personal information, you know, identity is going to become the new security. Because once the lines between an individual and the tech stacks that they're interfacing with, you know, gets either faded or removed completely, the only thing left is the individual and the individual identity of the person that's making those interactions.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So just to round things off, then looking at the long term, what kind of potential benefits might be out there for technologists or IT professionals, you know, outside of red teams and perhaps even security, who want to explore biohacking as the practice itself matures?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, again, you know, that's like, in my opinion, that's like asking someone how, how do you want to utilise a laptop or a mobile device? I mean, these microchips were never designed to be used necessarily as offensive tools. But if you look at things like Mimikatz, which is every hacker's favourite LDAP tool, it was, it's originally designed as a an LDAP auditing tool. Any tool this, regardless of what its intended purpose was, can be reused and misconfigured and used as a weapon. So I guess I, you know, not to try and blow off your question. But I guess it depends on really, what are they trying to do? You know, it could be something, I mean, I have no doubt that maybe we're going to start seeing the ability to do OTP. If you're not familiar with it, there's an amazing ecosystem out there. It's called the VivoKey. And this is an implant, the VivoKey architecture will actually allow for one time, you know, MFA OTP, where you're actually going to validate via an implant with an app on your phone, you know, so that's a potential security advancement moving forward, it could be something as simple as using your, your chip, almost kind of like a Fido chip, where you're going to scan your implant to access your computer, again, I would still want to password in there, don't like single points of failure as from a security perspective, you know, maybe you're gonna put your, your badge for work on your chip, and you're just not going to, you know, that way you can badge in. Not everything around implants, or implanted technology is a black art, for the lack of a better term, you know, they can be used just to make people's lives a little simpler. But one of the quotes that I love to use in pretty much every single time I talk is in from my personal experience, things that make life easier, rarely make them safer. So we have to, we are the security professionals, we're the ones that you know, have to warn the masses, we're the ones that have to take care of our employees. So it's up to us to understand what these kinds of threats are, and build that layered security approach and that defence in depth, so that these types of people, people such as myself, are left sitting at the door going well, I managed to hit the badge reader, but I still don't know the key, you know, our data, our physical locations, privilege is privilege, I don't care if it's physical, I don't care if it's digital, you know, and we are the ones that have been empowered by our companies to be the gatekeepers in the security for these types of things. And we need to do our job and be aware that people like me exist and build a strategy around that knowledge to be able to stop people like me.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Well, while we could spend all day digging into the intricacies of biohacking, sadly I'm afraid that's all we've got time for this week. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Aww.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>I know, I could spend the rest of the afternoon talking about this. But our thanks once again to cyberArk's Len Noe for joining us.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>It was absolutely my pleasure, guys. I really enjoyed talking to you. Maybe we can do it again sometime. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yeah, absolutely.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Sounds great. You can find links to all of the topics we've spoken about today in the show notes and even more on our website at ITpro.co.uk.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>You can also follow us on social media as well as subscribe to our daily newsletter.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Don't forget to subscribe to the IT Pro Podcast wherever you find your podcasts. And if you're enjoying the show, leave us a rating and a review.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>We'll be back next week with more insight for the world of IT. And until then, goodbye.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Bye.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: Meet the cyborg hacker ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/369132/the-it-pro-podcast-meet-the-cyborg-hacker</link>
                                                                            <description>
                            <![CDATA[ Resistance is futile - offensive biotech implants are already here ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sHqqiJKcvTj48dfZkrwUvF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/F9XLqHX4GgHqvgUS3jYT3C-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Sep 2022 06:30:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/F9XLqHX4GgHqvgUS3jYT3C-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast: Meet the cyborg hacker]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast: Meet the cyborg hacker]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast: Meet the cyborg hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/F9XLqHX4GgHqvgUS3jYT3C-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The technological arsenal available to cyber criminals is already enough to give any security professional nightmares, but there’s another emerging threat on the horizon that may keep them up at night: bio-augmented hackers. Implantable chips and other modifications are growing in capability and sophistication, and there are a variety of creative ways that attackers can use them to carry out both physical and device-based attacks - </p><p>This is made all the more concerning by the fact that these implants are all but impossible to detect. This week, we’re joined by CyberArk technical evangelist, white hat hacker and self-described transhumanist Len Noe to find out what kind of augmentations cyber criminals currently have access to, how can they be used in intrusions, and why the industry needs to start preparing for their implementation now - as well as some of the positive uses that this technology can be put to.</p><iframe frameborder="0" height="350px" width="100%" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=51343108&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><h2 id="highlights">Highlights</h2><p>“Would you like me to tell you how I get through an airport? I put the left foot in front of the right and then I repeat. That's it… There is not enough combined metal in all of my implants to actually trigger a magnetometer… even if I'm doing the X-ray metal detector, [it] doesn't show up, I can walk straight through, the magnetometer will not trigger.” </p><p>“I know that I'm using it. I know of quite a few people who are on red teams that are using this technology. We have not found any indications from any type of incidents that have actually happened in the wild where implants were shown to be the root cause, but at the same time, how would you be able to determine that - and therein lies the problem.” </p><p>“From… an actual implementation perspective, there is currently no way to actually detect an augmented human with this type of technology inside the body. And that becomes a very large problem for security professionals. And the only way that I can really give as a way to try and combat this is a true defence in depth, and a layered security approach.” </p><p><a href="https://www.itpro.com/security/hacking/369133/podcast-transcript-meet-the-cyborg-hacker" data-original-url="https://www.itpro.com/security/hacking/369133/podcast-transcript-meet-the-cyborg-hacker"><em>Read the full transcript here.</em></a></p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/hacking/356480/the-it-pro-podcast-the-secret-life-of-hackers" data-original-url="https://www.itpro.com/security/hacking/356480/the-it-pro-podcast-the-secret-life-of-hackers">The IT Pro Podcast: The secret life of hackers </a></li><li><a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">Stories from the front line: The secrets of the Red Team revealed </a></li><li><a href="https://www.itpro.com/technology/32336/trade-unions-congress-fearful-of-implanting-workers-with-tracking-chips" data-original-url="https://www.itpro.com/technology/32336/trade-unions-congress-fearful-of-implanting-workers-with-tracking-chips">Trade Unions Congress fearful of implanting workers with tracking chips </a></li><li><a href="https://www.itpro.com/enterprise-security/32641/should-employees-be-microchipped" data-original-url="https://www.itpro.com/enterprise-security/32641/should-employees-be-microchipped">Should employees be microchipped? </a></li><li><a href="https://www.itpro.com/technology/357528/what-is-neuralink" data-original-url="https://www.itpro.com/technology/357528/what-is-neuralink">What is Neuralink? </a></li><li><a href="https://www.itpro.com/business/business-strategy" data-original-url="https://www.itpro.com/strategy/28678/arm-fights-paralysis-with-brain-implant-chips">ARM fights paralysis with brain implant chips </a></li><li><a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">What is penetration testing? </a></li><li><a href="https://www.itpro.com/technology/357241/should-human-augmentation-technology-be-regulated" data-original-url="https://www.itpro.com/technology/357241/should-human-augmentation-technology-be-regulated">Should human augmentation technology be regulated? </a></li><li><a href="https://www.itpro.com/technology/augmented-reality-ar/357294/it-pro-2020-augmenting-the-future" data-original-url="https://www.itpro.com/technology/augmented-reality-ar/357294/it-pro-2020-augmenting-the-future">IT Pro 20/20: The future of augmentation </a></li><li><a href="https://www.itpro.com/technology/358869/the-it-pro-podcast-can-technology-make-us-more-than-human" data-original-url="https://www.itpro.com/technology/358869/the-it-pro-podcast-can-technology-make-us-more-than-human">The IT Pro Podcast: Can technology make us more than human? </a></li><li><a href="https://www.itpro.com/security/privacy/359444/the-it-pro-podcast-should-companies-spy-on-their-employees" data-original-url="https://www.itpro.com/security/privacy/359444/the-it-pro-podcast-should-companies-spy-on-their-employees">The IT Pro Podcast: Should companies spy on their employees? </a></li><li><a href="https://www.youtube.com/watch?v=MrqeaJAVeCI&ab_channel=SecurityBSidesSanFrancisco">BSidesSF 2022 - Biohacker: The Invisible Threat (Len Noe) - YouTube</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1227190226694104600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russia-linked state-sponsored hackers launch fresh attacks by abusing latest red team tool ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/368447/russia-linked-state-sponsored-hackers-launch-fresh-attacks-by-abusing-tool</link>
                                                                            <description>
                            <![CDATA[ Researchers said the new tool has evaded the detection of many leading security products and is quickly growing in popularity ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jmXgFcSTq9jbZtmpxiLS1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Mis3RCBYFmaSRh2Xa8utyW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Jul 2022 09:36:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Mis3RCBYFmaSRh2Xa8utyW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Flag of Russia on a computer binary codes falling from the top and fading away]]></media:description>                                                            <media:text><![CDATA[Flag of Russia on a computer binary codes falling from the top and fading away]]></media:text>
                                <media:title type="plain"><![CDATA[Flag of Russia on a computer binary codes falling from the top and fading away]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Mis3RCBYFmaSRh2Xa8utyW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have discovered hackers abusing the latest penetration testing tool in active attacks on global targets.</p><p>Unit 42 experts said that a malicious payload associated with the Brute Ratel C4 (BRc4) red teaming tool goes undetected by many major security products and has been sued against organisations in North and South America.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368430/ncsc-concerned-for-uk-cyber-experts-burning-out-over-russia-ukraine-cyber-war" data-original-url="/security/cyber-security/368430/ncsc-concerned-for-uk-cyber-experts-burning-out-over-russia-ukraine-cyber-war">NCSC concerned for UK cyber experts burning out over Russia-Ukraine cyber war</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/367461/five-eyes-nations-warn-against-impending-russian-cyber-attacks" data-original-url="/security/cyber-warfare/367461/five-eyes-nations-warn-against-impending-russian-cyber-attacks">Five Eyes nations warn against impending Russian cyber attacks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/360142/russian-cozy-bear-hackers-reportedly-attacked-the-republican-party" data-original-url="/security/hacking/360142/russian-cozy-bear-hackers-reportedly-attacked-the-republican-party">Russian Cozy Bear hackers reportedly attacked the Republican party</a></p></div></div><p>The packaging of the malicious payload is consistent with the tactics deployed by advanced persistent threat group 29 (APT29) - otherwise known as ‘Cozy Bear’ - a Russian-linked state-sponsored hacking group known for the notorious <a href="https://www.itpro.com/security/cyber-attacks/359238/us-and-uk-in-agreement-over-russian-involvement-in-solarwinds-hack" data-original-url="https://www.itpro.com/security/cyber-attacks/359238/us-and-uk-in-agreement-over-russian-involvement-in-solarwinds-hack">SolarWinds attack in 2020</a>. </p><p>The BRc4 tool has been around since 2020 with India-based security engineer Chetan Nayak, who previously worked for <a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">red teams</a> at leading western security vendors, recently commercialising the product. </p><p>Nayak has said the <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">pentesting</a> tool was built after reverse-engineering several major security products, while Unit 42 said BRc4 is newer but no less capable than the more commonly abused <a href="https://www.itpro.com/security/360871/hackers-develop-linux-port-of-cobalt-strike-for-new-attacks" data-original-url="https://www.itpro.com/security/360871/hackers-develop-linux-port-of-cobalt-strike-for-new-attacks">Cobalt Strike</a>.</p><p>“Overall, we believe this research is significant in that it identifies not only a new red team capability that is largely undetectable by most cyber security vendors, but more importantly, a capability with a growing user base that we assess is now leveraging nation-state deployment techniques,” Unit 42 said.</p><p>“We encourage all security vendors to create protections to detect activity from this tool and all organisations to be on alert for activity from this tool.”</p><p>After first being uploaded to VirusTotal in May 2022, the malicious payload slipped under the detection of 56 different security vendors that evaluated it, assigning it ‘benign’ status, Unit 42 said, showing how effective Nayak’s reverse engineering efforts have been.</p><h2 id="method-of-delivery">Method of delivery</h2><p>The malicious file is packaged up as a self-contained, benign ISO file and included in the ISO is the lure file - a Windows shortcut (LNK) file masquerading as a Word document, complete with a fake word doc file icon, and seemingly being a CV for a Roshan Bandara.</p><p>This is the actual malicious file, hidden inside the ISO which slipped through security vendors’ detections. It appears on a user’s hard drive after the ISO is double-clicked and mounted as a Windows drive. When the lure file is opened-clicked, BRc4 would be installed.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zN9yq6wvv8oBhbPFBWeEAd" name="zN9yq6wvv8oBhbPFBWeEAd.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/zN9yq6wvv8oBhbPFBWeEAd.jpg" mos="https://cdn.mos.cms.futurecdn.net/zN9yq6wvv8oBhbPFBWeEAd.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Unified endpoint management solutions 2021-22</strong></p><p class="fancy-box__body-text">Analysing the UEM landscape</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/367050/unified-endpoint-management-solutions-2021-22" data-original-url="/security/endpoint-security/367050/unified-endpoint-management-solutions-2021-22">FREE DOWNLOAD</a></p></div></div><p>This file is typically sent to victims through <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">spear-phishing</a> campaigns or downloaded to the victim by a second-stage downloader, Unit 42 said.</p><p>“While we lack insight into how this particular payload was delivered to a target environment, we observed connection attempts to the C2 server originating from three Sri Lankan IP addresses between May 19-20,” said the researchers.</p><p>In the same folder where the lure file is stored, other archived .exe and .dll files are present but hidden to most Windows users thanks to the operating system’s (OS) default configuration.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YTzVeN3yc8anhG6ia8vrig" name="" alt="Flowchart showing the infection chain of BRc4" src="https://cdn.mos.cms.futurecdn.net/YTzVeN3yc8anhG6ia8vrig.jpg" mos="https://cdn.mos.cms.futurecdn.net/YTzVeN3yc8anhG6ia8vrig.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Unit 42)</span></figcaption></figure><h2 id="brc4-s-capabilities">BRc4’s capabilities</h2><p>Once installed, BRc4 advertises itself as having a broad range of capabilities. These were designed for legitimate use in red team-blue team exercises, but like Cobalt Strike, the powerful tools are often abused by black hat hackers in malicious cyber attacks.</p><p>Some of the tool’s capabilities include:</p><ul><li>SMB and TCP payloads provide the functionality to write custom external C2 channels over legitimate websites such as Slack, Discord, Microsoft Teams, and more</li><li>Ability to keep memory artefacts hidden from EDRs and AV</li><li>Take screenshots</li><li>x64 shellcode loader</li><li>Reflective and object file loader</li><li>Patching Anti Malware Scan Interface (AMSI)</li><li>Create Windows system services</li><li>Upload and download files</li></ul><p>Unit 42 also said the C2 infrastructure used by the threat actors abusing BRc4 is consistent with the methods used by APT29, using popular cloud storage and collaboration platforms.</p><p>The sample analysed by the researchers found the payload ‘calling home’ to an AWS-registered IP address located in the US over port 443. The X.509 certificate on the listening port was also self-signed and set up to impersonate a Microsoft security team.</p><p>A Ukrainian IP address was also used to administer the C2 infrastructure, and researchers believed that the attackers harnessed a residential network for this.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kali Linux creators announce free cyber security sessions delivered live on Twitch ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/penetration-testing/368217/kali-linux-team-free-cyber-security-training-twitch</link>
                                                                            <description>
                            <![CDATA[ The brand-new initiative is aimed at reaching more aspiring certified pen-testers through twice-weekly livestreamed lessons ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tw4ZYdZA2sDrNZku8jecsp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zHEy2JDVnVhn79TBmpvyGJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jun 2022 10:07:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zHEy2JDVnVhn79TBmpvyGJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Code appearing on a screen while running pentesting processes to analyse a server]]></media:description>                                                            <media:text><![CDATA[Code appearing on a screen while running pentesting processes to analyse a server]]></media:text>
                                <media:title type="plain"><![CDATA[Code appearing on a screen while running pentesting processes to analyse a server]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zHEy2JDVnVhn79TBmpvyGJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The company behind digital forensics and penetration testing Kali Linux platform has announced that it will be livestreaming free security training sessions, for 25-weeks, for those looking to build offensive cyber security skills.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="/penetration-testing/33981/what-is-penetration-testing">What is penetration testing?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/28025/best-linux-distros" data-original-url="/operating-systems/28025/best-linux-distros">Best Linux distros 2023: The finest open source operating systems around</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/358117/the-top-online-cyber-security-courses" data-original-url="/business-strategy/careers-training/358117/the-top-online-cyber-security-courses">Top online cyber security courses for 2023</a></p></div></div><p>Offensive Security, which created the Debian-based Kali <a href="https://www.itpro.com/operating-systems/28025/best-linux-distros" data-original-url="https://www.itpro.com/operating-systems/28025/best-linux-distros">Linux distro</a>, launched its remote learning course, OffSec Academy, during the pandemic when live training became unworkable.</p><p>The new livestreamed programme, known as OffSec Live: PEN-200, an independent offshoot of its paid-for OffSec Academy, will deliver two 60-minute sessions every week for 25 weeks, starting on 22 June 2022. All sessions will be available on public streaming platform Twitch.</p><p>The sessions will be broadcast every Wednesday and Friday between 17:00 and 18:00 (BST) and will continue until 30 November.</p><p>OffSec Live will cover the main topics of the PEN-200 curriculum - the content required to prepare budding <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">pen-testers</a> for the Offensive Security Certified Professional (OSCP) <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" data-original-url="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training">certification</a> - but the company said it does not replace the PEN-200 course.</p><p>Those who tune in to the livestreams will also have access to Offensive Security’s mentors via a Discord server, though it’s unlikely the same level of one-to-one support will be available as it is to those who pay to enrol on the PEN-200 course.</p><p>Students paying for expert guidance on the PEN-200 course, not the Twitch-broadcasted OffSec Live: PEN-200 version, have access to the full range of course materials, additional exercises, and demos to cement their learning.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ebWTwtZnKEPD3hvMervZkk" name="ebWTwtZnKEPD3hvMervZkk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" mos="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The truth about cyber security training</strong></p><p class="fancy-box__body-text">Stop ticking boxes. Start delivering real change.</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361094/the-truth-about-cyber-security-training" data-original-url="/security/cyber-security/361094/the-truth-about-cyber-security-training">FREE DOWNLOAD</a></p></div></div><p>“When the pandemic started we were provided a very unique opportunity to experiment with <a href="https://www.itpro.com/business-strategy/careers-training/358117/the-top-online-cyber-security-courses" data-original-url="https://www.itpro.com/business-strategy/careers-training/358117/the-top-online-cyber-security-courses">remote training</a> options,” <a href="https://www.offensive-security.com/offsec/offsec-live">said</a> Offensive Security. “With live training no longer an option, the entire industry was forced to try their version of streaming-based training. For us, the last thing we wanted to do was to take a five-day live class and just make it online. We felt like that would be a really poor experience, and instead we wanted to take advantage of the streaming format and make something special and unique.</p><p>“OffSec Live is our attempt to take what is great about OffSec Academy, and our learnings about successful student learning journeys, and make it available to all students.”</p><p>The OffSec Live initiative is brand-new for the company and in its first iteration. It encourages as many aspiring pentesters to join and engage in the livestreamed sessions, and provide as much feedback as possible.</p><p>Offensive Security said this feedback will inform future evolutions of the course, whether it will continue beyond this first run, and if it will become part of its standard offering.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ethical hackers handed lifeline in controversial US cyber crime review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime</link>
                                                                            <description>
                            <![CDATA[ The DoJ's latest ruling is a boon to "good-faith security research" but some argue that white hats are still not protected ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6vM2oAtd4Fb2pTaXDSuvKJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N22ik5y6rm5mskzYejFrF7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 May 2022 11:49:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N22ik5y6rm5mskzYejFrF7-1280-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphical mockup of a piece of software being tested for vulnerabilities]]></media:description>                                                            <media:text><![CDATA[Graphical mockup of a piece of software being tested for vulnerabilities]]></media:text>
                                <media:title type="plain"><![CDATA[Graphical mockup of a piece of software being tested for vulnerabilities]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N22ik5y6rm5mskzYejFrF7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Department of Justice (DoJ) has announced that it will no longer prosecute ethical hackers under its anti-cyber crime law, the Computer Fraud and Abuse Act (CFAA).</p><p>The landmark change comes after a policy revision, stipulating that cyber security research conducted in “good faith” should not be prosecutable, came into force on Thursday.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" data-original-url="/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">80% of cyber professionals say the Computer Misuse Act is working against them</a></p></div></div><p>There is no concrete guidance on what type of activity falling under the umbrella of ‘cyber security research’ is protected or unprotected under the new policy revision, but security researchers acting in a way that intentionally avoids harm will not be charged under the CFAA.</p><p>Cyber security researchers have previously been fearful of reporting <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">security vulnerabilities</a> in the past out of fear of being charged under the Act, but the US is now adopting a fresh perspective, saying vulnerabilities that are discovered responsibly benefit “the common good”.</p><p>“Computer security research is a key driver of improved cybersecurity,” said Lisa O. Monaco, deputy attorney general. “The department has never been interested in prosecuting good-faith computer security research as a crime, and today’s announcement promotes cyber security by providing clarity for good-faith security researchers who root out vulnerabilities for the common good.”</p><p>The majority of security researchers (60%) <a href="https://www.bugcrowd.com/resources/webinars/hackers-dont-wear-black-hoodies-they-wear-capes">speaking to Bugcrowd in 2020</a> said they had not reported security vulnerabilities they found in the past due to fear of being prosecuted under the CFAA. </p><p>The law has also threatened other areas of cyber security such as legitimate <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a>. Security professionals working for Coalfire in 2019, for example, were handed criminal charges for breaking into Iowa’s Dallas County courthouse after being contracted by the state of Iowa.</p><p>The charges were ultimately dropped but the CFAA, which was drafted in 1986, well before the <a href="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3" data-original-url="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3">modern internet</a>, has always threatened ethical security research.</p><p>The UK’s equivalent legislation, the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act</a> (CMA), has been criticised in the past for also not legally accepting <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hacking</a> as a benefit to society and industry.</p><p>Drafted in 1990 but currently under review, the CMA has been labelled an outdated piece of legislation and like the CFAA up until this week, it too outlaws good-faith ethical hacking.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7aXsyZevCE4BJaQcNzp4zm" name="7aXsyZevCE4BJaQcNzp4zm.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/7aXsyZevCE4BJaQcNzp4zm.png" mos="https://cdn.mos.cms.futurecdn.net/7aXsyZevCE4BJaQcNzp4zm.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The state of email security 2022</strong></p><p class="fancy-box__body-text">Confronting the new wave of cyber attacks</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/367501/the-state-of-email-security-2022" data-original-url="/security/cyber-security/367501/the-state-of-email-security-2022">FREE DOWNLOAD</a></p></div></div><p>A recent <a href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" data-original-url="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">report</a> from the CyberUp campaign, in partnership with techUK, showed that 80% of legitimate cyber security researchers have worried about being punished under the CMA while defending cyber attacks.</p><p>Ethical hacking’s protection from the CFAA received a boost last year in a significant ruling in the Van Buren vs United States case.</p><p>In it, the US Supreme Court ruled that a law enforcement officer, bribed by an outside individual, did not break any laws under the CFAA in accessing information from a computer for unsanctioned reasons.</p><p>Although Van Buren was authorised to access a police database, he was not authorised to hand over confidential information to an outside party in exchange for money, but the ruling meant he could not be prosecuted under the CFAA, leading onlookers to believe this could lead to positive implications for ethical hackers.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/6GrNyc1WAgk" allowfullscreen></iframe></div></div><p>The latest policy revision to the CFAA has been greeted warmly by the cyber security community. Brian Higgins, security specialist at Comparitech, told <em>IT Pro</em> that “this is definitely a step in the right direction by the US authorities”.</p><p>“It’s unreasonable to place such disproportionate restrictions on a vital community of professionals, the majority of whom operate to high standards of ethics and integrity,” he said.</p><p>“Taking the gloves off, even to this extent, will allow a better understanding of the threats we face and the best way to defend against them. This proactive development in the United States will undoubtedly attract a lot of scrutiny from the international community, the majority of whom will be seeking to follow suit in some fashion.”</p><p>The DoJ <a href="https://www.justice.gov/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act">said</a> that individuals claiming to be conducting security research “is not a free pass for those acting in bad faith”. It used an example of <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware" data-original-url="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">extorting other people</a> after discovering a vulnerability, all in the name of research, which would not be protected under the policy revision.</p><p>“Hacking itself, using its current common definition rather than the original, isn't inherently good or evil. Using it for profit and abuse is evil,” said Sam Curry, chief security officer at Cybereason to <em>IT Pro</em>. “Breaking the law is evil. But using it to improve security is a vital function without which we really can't resist the darker kind. In the world of cyber, this is great news for white hats and gives a ray of hope to some grey hats too.”</p><p>Although greeted warmly by many, other corners of the industry have criticised the DoJ for not making more allowances in its policy review.</p><p>Not setting a clear line as to what constitutes an offence in the process of ethical hacking, and what doesn’t, is the main point of contention for the Electronic Frontier Foundation (EFF), which said that it would be better if there was a technological restriction defendants would have to defeat in order to be charged under the CFAA.</p><p>“Instead of this clear line, the new policy explicitly names scenarios in which written policies may give rise to a criminal CFAA charge, such as when an employee violates a contract that puts certain files off limits in all situations, or when an outsider receives a cease-and-desist letter informing them that their access is now unauthorised,” it <a href="https://www.eff.org/deeplinks/2022/05/dojs-new-cfaa-policy-good-start-does-not-go-far-enough-protect-security">said</a>.</p><p>The EFF also criticised the DoJ for saying that security research should be conducted “solely” in good faith, and it excludes “a lot of how research happens in the real world”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Darktrace acquires attack surface management startup Cybersprint ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/mergers-and-acquisitions/362974/darktrace-buys-cybersprint</link>
                                                                            <description>
                            <![CDATA[ The €47.5 million deal marks Darktrace’s first acquisition in its nine-year history ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eAiRpppJH5MiTPhFm7vgGu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/duX6vEHfbNHfCJNWPotSXf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Feb 2022 12:10:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/duX6vEHfbNHfCJNWPotSXf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital generated image of electronic circuit security padlock made out of numbers on black background.]]></media:description>                                                            <media:text><![CDATA[Digital generated image of electronic circuit security padlock made out of numbers on black background.]]></media:text>
                                <media:title type="plain"><![CDATA[Digital generated image of electronic circuit security padlock made out of numbers on black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/duX6vEHfbNHfCJNWPotSXf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK cyber security <a href="https://www.itpro.com/business-strategy/startups/359929/uk-first-in-europe-to-reach-100-tech-unicorns" target="_blank" data-original-url="https://www.itpro.com/business-strategy/startups/359929/uk-first-in-europe-to-reach-100-tech-unicorns">unicorn</a> Darktrace has acquired Dutch attack surface management startup Cybersprint in a deal worth €47.5 million (£39.6 million).</p><p>The acquisition is a mix of 75% cash and 25% equity and represents the first takeover <a href="https://www.itpro.com/security/29150/what-is-darktrace" target="_blank" data-original-url="https://www.itpro.com/security/29150/what-is-darktrace">Darktrace</a> has made in its nine-year history.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/startups/359179/darktrace-ipo-official" data-original-url="/business-strategy/startups/359179/darktrace-ipo-official">Darktrace confirms IPO as revenues soar amid pandemic</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29150/what-is-darktrace" data-original-url="/security/29150/what-is-darktrace">What is Darktrace?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/359473/microsoft-partners-with-darktrace-on-ai-enhanced" data-original-url="/technology/artificial-intelligence-ai/359473/microsoft-partners-with-darktrace-on-ai-enhanced">Microsoft and Darktrace partner on AI-enhanced cloud security</a></p></div></div><p>Cybersprint describes itself as an "attack surface management company" that offers <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" target="_blank" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a> services and continuous, real-time insights from an outside-in perspective. One of its services is an automated tool that maps an organisation's assets so they can continuously monitor areas that might go unnoticed by in house checks, such as older IP addresses. </p><p>Darktrace said the two companies shared an "aligned vision" of delivering a "continuous cyber AI loop", adding that Cybersprint's employees bring an understanding of how to continuously model real-time internet data as well as ethical hacking expertise. </p><p>With the deal, Darktrace will also gain a second Research and Development centre, Cybersprint's Hague facility in the Netherlands, which will be integrated into the Darktrace network.</p><p>The UK cyber firm will aim to use Cybersprints' seven years' worth of R&D to accelerate its own AI-based 'Prevent' product suite, according to CEO Poppy Gustafsson.</p><p>"We are very excited to welcome the Cybersprint team to Darktrace. Bringing inside-out and outside-in visibility together is critical and having access to the robust, rich, real-time external dataset combined with Darktrace's Self-Learning AI means that customers get a holistic view of prioritised cyber risks to harden the parts of their organisation that are most vulnerable," Gustafsson said. </p><p>Cybersprint CEO Pieter Jansen said he felt an "instant" connection on vision, culture and technology with Darktrace. He added that both firms were "passionate" about automating manual tasks in <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security">cyber security</a> from an outside perspective and that "attackers never sleep".</p><p>"We are looking forward to joining Darktrace and working together to accelerate state-of-the-art innovations to make organisations more cyber secure," Jansen said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Train firm slammed over 'bonus' phishing test  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/359490/train-line-comes-under-fire-for-bonus-phishing-test</link>
                                                                            <description>
                            <![CDATA[ Security experts suggest businesses use other 'lures' to avoid upsetting workers in the current climate ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZenR7NqEAj7fNAPsrYXQJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iDnby2TqpeetLrJRdU53pn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 May 2021 12:03:27 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iDnby2TqpeetLrJRdU53pn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A train operated by the West Midlands Trainline parked in a station ]]></media:description>                                                            <media:text><![CDATA[A train operated by the West Midlands Trainline parked in a station ]]></media:text>
                                <media:title type="plain"><![CDATA[A train operated by the West Midlands Trainline parked in a station ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iDnby2TqpeetLrJRdU53pn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Bosses at West Midlands Trainline are facing a backlash after they used the promise of a company-wide bonus as a lure in a <a href="https://www.itpro.com/security/phishing/357231/tribune-staff-tricked-phishing-test" target="_blank" data-original-url="https://www.itpro.com/security/phishing/357231/tribune-staff-tricked-phishing-test">phishing simulation test</a>. </p><p>Julian Edwards, the managing director of the train operator, emailed the company's 2,500 employees with a message saying it wanted to thank them for their hard work during the pandemic, according to <a href="https://www.theguardian.com/uk-news/2021/may/10/train-firms-worker-bonus-email-is-actually-cyber-security-test" target="_blank"><em>the Guardian</em></a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/359465/covid-phishing-fuels-a-15-fold-increase-in-scam-takedowns" data-original-url="/security/phishing/359465/covid-phishing-fuels-a-15-fold-increase-in-scam-takedowns">COVID-related phishing fuels a 15-fold increase in NCSC takedowns</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/355296/it-pros-air-their-opinions-on-phishing-employees" data-original-url="/security/phishing/355296/it-pros-air-their-opinions-on-phishing-employees">IT pros air their opinions on phishing employees</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/357231/tribune-staff-tricked-phishing-test" data-original-url="/security/phishing/357231/tribune-staff-tricked-phishing-test">Tribune Publishing staff enraged after phishing test promises $10k bonuses</a></p></div></div><p>The email promised a one-off payment, but those who clicked the link for the bonus received a message telling them it was a "<a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing simulation test</a>" designed by the firm's IT team to entice employees.</p><p>The leader of the Transport Salaried Staffs Association, Manuel Cortes, called the email "crass and reprehensible", according to <em>the Guardian</em>, especially considering many of the people who work for West Midlands Trainline have had to do so on the front line throughout the pandemic.</p><p>However, while the initiative isn't ideal in the current climate, there's often a <a href="https://www.itpro.com/security/phishing/355296/it-pros-air-their-opinions-on-phishing-employees" target="_blank" data-original-url="https://www.itpro.com/security/phishing/355296/it-pros-air-their-opinions-on-phishing-employees">balance between upsetting the business vs what a malicious attacker would consider</a>, according to Scott Nicholson, the co-CEO of cyber security firm Bridewell Consulting</p><p>"In reality, malicious phishing campaigns will devise the content that is most likely to achieve success," Nicholson told <em>IT Pro</em>. "However, on the other hand, there are many other topics that can be used and techniques to improve user behaviour and phishing defence, detection and response.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TgYwXSHV6efgCB2UrGXGXc" name="TgYwXSHV6efgCB2UrGXGXc.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TgYwXSHV6efgCB2UrGXGXc.png" mos="https://cdn.mos.cms.futurecdn.net/TgYwXSHV6efgCB2UrGXGXc.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Prevent fraud and phishing attacks with DMARC</strong></p><p class="fancy-box__body-text">How to use domain-based message authentication, reporting, and conformance for email security</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359475/prevent-fraud-and-phishing-attacks-with-dmarc" data-original-url="/security/cyber-security/359475/prevent-fraud-and-phishing-attacks-with-dmarc">FREE DOWNLOAD</a></p></div></div><p>"In this instance, employees will understandably feel frustrated and I wonder whether key business stakeholders were aware of the content and topic beforehand. Often, when developing internal phishing awareness campaigns, it is useful to have a small group of key stakeholders agree on phishing content so that an organisation can reduce the risk of phishing attacks but without demotivating or upsetting the workforce." </p><p>Nicholson added that phishing simulations are an essential awareness tool but he also warned that they should not be solely relied upon. The content of the attack requires careful consideration, he said, as businesses can achieve the same outcomes without upsetting their employees.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Taking a proactive approach to cyber security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/penetration-testing/359005/taking-a-proactive-approach-to-cyber-security</link>
                                                                            <description>
                            <![CDATA[ A complete guide to penetration testing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gFBixPVncSZKSnsiUaNteZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZcgPdbYTv5SgnYwcLheDTL-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Mar 2021 11:44:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/ZcgPdbYTv5SgnYwcLheDTL-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A complete guide to penetration testing - whitepaper from CyberCx]]></media:description>                                                            <media:text><![CDATA[A complete guide to penetration testing - whitepaper from CyberCx]]></media:text>
                                <media:title type="plain"><![CDATA[A complete guide to penetration testing - whitepaper from CyberCx]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZcgPdbYTv5SgnYwcLheDTL-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yJi9bKTgeY6ajCQPYRiGJg" name="" alt="CyberCx Logo" src="https://cdn.mos.cms.futurecdn.net/yJi9bKTgeY6ajCQPYRiGJg.jpg" mos="https://cdn.mos.cms.futurecdn.net/yJi9bKTgeY6ajCQPYRiGJg.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>This free guide answers the questions commonly asked by penetration testing buyers and provide guidance to help you maximise the benefits of your penetration testing experience. </p><p>Whether you’re planning a development project, are mindful of a potential upcoming compliance requirement, are concerned of the brand damage a breach could cause, or you’re looking to improve your organisation’s cyber security capabilities, a penetration test, performed by a proven, certified provider, is one of the most powerful and effective ways to understand and improve your organisation’s security posture.</p><p>Download this resource to start taking a proactive approach to cyber security. </p><p>Fill out the form below to access the free resource.</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/cybercx-li-279534?locale=1&p=false&wp=6098"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 80% of cyber professionals say the Computer Misuse Act is working against them ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act</link>
                                                                            <description>
                            <![CDATA[ techUK report calls for "rapid modernisation" of the 30-year-old law that's "stifling" penetration testing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bPfvddXULyJizMmc5oCM9C</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oQu4SjakrwoKz8VXQfWVJG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Nov 2020 12:13:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oQu4SjakrwoKz8VXQfWVJG-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A young professional showing signs of stress at work]]></media:description>                                                            <media:text><![CDATA[A young professional showing signs of stress at work]]></media:text>
                                <media:title type="plain"><![CDATA[A young professional showing signs of stress at work]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oQu4SjakrwoKz8VXQfWVJG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Four in five UK cyber security professionals are worried about breaking the law due to confusion caused by the ageing <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act#:~:text=The%20Computer%20Misuse%20Act%20(CMA,without%20appropriate%20consent%20or%20permission.">Computer Misuse Act</a> (CMA).</p><p>The 30-year-old legislation is restricting <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" target="_blank" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">pen-testers</a> and white hat hackers with strict and often out-dated definitions, according to a survey commissioned by teckUK and the CyberUp Campaign.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act" data-original-url="/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act">UK gov urged to overhaul "unfit for purpose" Computer Misuse Act</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act" data-original-url="/data-loss-prevention/26673/36-of-ex-employees-are-breaking-the-computer-misuse-act">36% of ex-employees are breaking the computer misuse act</a></p></div></div><p>The survey, which was circulated between 46 respondents representing 11 organisations and some 25,120 employees, found that the legislation was stifling security teams in the UK, with 80% of respondents saying they have been <a href="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act" data-original-url="https://www.itpro.com/policy-legislation/computer-misuse-act/356280/calls-to-reform-the-computer-misuse-act">worried about breaking the law</a> when researching vulnerabilities or investigating cyber threat actors.</p><p>Around 40% of those surveyed said the CMA has acted as a barrier to them or their colleagues and had even prevented employees from proactively safeguarding against security breaches. Furthermore, 91% of businesses believed that the law puts UK consultancies at a competitive disadvantage with other countries.</p><p>Some of the answers also suggested confusion about what counts as a criminal offence under the CMA. In fact, in only three cyber incident examples - 'web scraping' (74%), 'open source internet scanning' (68%), and 'default credentials in login panels exposed to the internet' (74%) - did respondents reach a reasonable level of consensus.</p><p>The Computer Misuse Act was enshrined in 1990, long before the internet became the essential tool for businesses it is today. Although it has been updated a number of times, both techUK and the CyberUp Campaign are calling for the government to open a consultation within the industry to put the law through "rapid modernisation".</p><p>"I know from my time in this industry that there are now real concerns among the cyber security community that this law is impeding professionals ability to protect the nation from the ever-evolving range of <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber threats</a> we face, and preventing the sector from establishing its leadership position on the international stage," Conservative MP Ruth Edwards wrote in the report.</p><p>"If ever there was going to be a time to prioritise the rapid modernisation of our cyber legislation, it is now, when our reliance on safe, reliable and resilient digital technologies has been brought into stark relief by the coronavirus pandemic."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How cyber attack simulations differ from penetration tests and vulnerability scanning ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/penetration-testing/357806/how-cyber-attack-simulations-differ-from-penetration-tests-and</link>
                                                                            <description>
                            <![CDATA[ Exploring the Cymulate Edge ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hYLAdaDvCpRH9bX5nNmUy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ToDVdgntGNNDuLhNm3tnG3-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Nov 2020 13:04:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/ToDVdgntGNNDuLhNm3tnG3-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ToDVdgntGNNDuLhNm3tnG3-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bV9aqGqGZWgBH6fkccbu7Q" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/bV9aqGqGZWgBH6fkccbu7Q.png" mos="https://cdn.mos.cms.futurecdn.net/bV9aqGqGZWgBH6fkccbu7Q.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Penetration tests and vulnerability scans are useful for getting insight into the security posture of an organisation at a specific moment. Although useful, they do not present the full picture, especially when it comes to sophisticated, multi-vector attacks.</p><p>Download this whitepaper to learn:</p><p>✓ The pros and cons of each method</p><p>✓ The new and effective approach to cybersecurity validation</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/cymulate-q4?locale=1&p=false&wp=5465"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ethics of red team security testing questioned in new report ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/penetration-testing/354693/ethics-of-red-team-security-testing-questioned-in-new-report</link>
                                                                            <description>
                            <![CDATA[ Research finds employees are far more likely to put up with red team testing if it's not conducted on themselves ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oidYhcHoLkzJ7yysq4SJki</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dBqckCAfsZL4kbNfPmBSmX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Feb 2020 12:26:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dBqckCAfsZL4kbNfPmBSmX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dBqckCAfsZL4kbNfPmBSmX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Workers in areas like HR and finance are more likely than IT or <a href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs" data-original-url="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs">security professionals</a> to object to internal security testing, a report has found, raising serious ethical questions around how far security teams should go in their work.</p><p><a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">The process of red team security testing</a> on colleagues and fellow workers may lead an organisation to identify gaps or lapses in its cyber security hygiene, but such actions could have an adverse effect on staff morale, research has suggested.</p><p>There are wide differences in the moral interpretation of social engineering attacks between IT and non-IT employees, according to findings by researchers Tarah Wheeler and Roy Iverson. For example, non-tech workers, in areas such as HR and legal, are nine times more likely to object to <a href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" data-original-url="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">receiving a phishing email</a> than staff in security-related jobs.</p><p>These employees are also three times more likely to object to <a href="https://www.itpro.com/social-engineering/34308/fraudsters-use-ai-voice-manipulation-to-steal-200000" data-original-url="https://www.itpro.com/social-engineering/34308/fraudsters-use-ai-voice-manipulation-to-steal-200000">security workers impersonating VIPs</a>, and four times more likely to object to the red team targeting receptionists to gain entry into an organisation.</p><p>The team surveyed more than 500 workers about their stance on the moral acceptability of conducting internal security tests and presented their findings at the Washington-based tech conference ShmooCon 2020.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">Stories from the front line: The secrets of the Red Team revealed</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-breaches/34355/an-inside-job-the-human-factor-of-cybersecurity" data-original-url="/data-breaches/34355/an-inside-job-the-human-factor-of-cybersecurity">An inside job: The human factor of cybersecurity</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="/penetration-testing/33981/what-is-penetration-testing">What is penetration testing?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a></p></div></div><p>The type of testing that respondents were questioned on ranged from sending threatening emails to inciting bribery, and even planting files on employees’ devices.</p><p>These measures may or may not comprise offensive red team testing routinely conducted by teams within or external to organisations. One prominent case of penetration testing, for example, arose last September when <a href="https://www.itpro.com/penetration-testing/34392/pen-testers-arrested-after-breaking-into-courthouse-that-hired-them" data-original-url="https://www.itpro.com/penetration-testing/34392/pen-testers-arrested-after-breaking-into-courthouse-that-hired-them">two individuals hired by a US-based courthouse were caught trying to physically break into its premises</a>.</p><p>Despite many workers holding moral objections to elements of red team testing, the research also found that employees were generally more comfortable being on the orchestration side than on the receiving end.</p><p>In some cases, those on the receiving side of red team testing are approximately four-and-a-half times more likely to morally object to certain tests being conducted than if they were organising these tests.</p><p>“What we found was surprising and counterintuitive,” Wheeler and Iverson said in their research paper.</p><p>“Respondents (even professional security experts) were reportedly 450% more likely to be morally fine with conducting certain often-used tests on other people than they are with having tests run against themselves.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3GmXf5RKGBRxqycJoBDAZQ" name="3GmXf5RKGBRxqycJoBDAZQ.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/3GmXf5RKGBRxqycJoBDAZQ.jpg" mos="https://cdn.mos.cms.futurecdn.net/3GmXf5RKGBRxqycJoBDAZQ.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Testing for compliance just became easier</strong></p><p class="fancy-box__body-text">How you can use technology to ensure compliance in your organisation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/compliance/354495/testing-for-compliance-just-became-easier" data-original-url="/policy-legislation/compliance/354495/testing-for-compliance-just-became-easier">FREE DOWNLOAD</a></p></div></div><p>The researchers added that the data collected allows them to start a discussion about the best practices with engaging in internal penetration testing within an organisation, and the impact of deceptive social engineering attacks on company morale.</p><p>Moreover, <a href="https://www.itpro.com/strategy/29101/six-ways-boards-can-step-up-support-for-cyber-security" data-original-url="https://www.itpro.com/strategy/29101/six-ways-boards-can-step-up-support-for-cyber-security">company boards should adopt a measured approach to overseeing cyber security policy</a> in order to raise the overall level of hygiene among senior employees as well as across the wider workforce.</p><p>These measures include hearing a presentation about information security at least twice a year, demanding high-value targets like executives are within scope of testing and understanding the incentives for succeeding in compromising targets inside the company.</p><p>“Anecdotally, we have heard internal red teamers describing scoping for engagements that disinclude [sic] the most likely targets - executives,” Wheeler and Iverson added. “Because those same executives did not wish to have the potential interruption to their services that the discovery of poor security awareness would entail.</p><p>“This is unfortunate, as rapid, constant testing that perpetually integrates small changes leads to the strongest defence of any company.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is Breach and Attack Simulation (BAS)? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/penetration-testing/354645/what-is-breach-and-attack-simulation-bas</link>
                                                                            <description>
                            <![CDATA[ Explaining the latest security tool helping organisations identify and rectify vulnerabilities in their cyber defences ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fkBxvkVE5A7yMZNwPb7gtL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fMbMro3SjAzTb5vKxrzNfc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Jan 2020 11:41:46 +0000</pubDate>                                                                                                                                <updated>Wed, 29 Jan 2020 14:30:46 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Esther Kezia Thorpe ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPPgWan5PqHyFNtSS9gnbR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fMbMro3SjAzTb5vKxrzNfc-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data Breach overlaying a circuitboard]]></media:description>                                                            <media:text><![CDATA[Data Breach overlaying a circuitboard]]></media:text>
                                <media:title type="plain"><![CDATA[Data Breach overlaying a circuitboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fMbMro3SjAzTb5vKxrzNfc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As organisations try and stay one step ahead of cyber criminals, Breach and Attack Simulations (BAS) are growing in popularity as a way of testing cyber resilience. The technology is used to automatically spot weaknesses in an organisation’s <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a>, a little like automated, ongoing <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" target="_blank" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a>.</p><p>The global BAS market is expected to reach <a href="https://www.businesswire.com/news/home/20191004005232/en/1.68-Billion-Automated-Breach-Attack-Simulation-Markets">$1.68 billion by 2027</a> - a 37.8% growth from 2018’s figures - primarily driven by demand for prioritising security investments as <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" target="_blank" data-original-url="itpro.co.uk/security/27713/the-importance-and-benefits-of-effective-patch-management">vulnerability management</a> grows ever more complicated.</p><p>Furthermore, Breach and Attack Simulation technologies were highlighted as one of the top solutions for <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do" target="_blank" data-original-url="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISOs</a> to consider in a recent <a href="https://secrutiny.com/2019/09/gartner-reveals-breach-and-attack-simulation-technologies-as-one-of-the-top-cyber-security-solutions">report</a> from Gartner, because of its effectiveness at testing against known threats.</p><p>But just what are Breach and Attack Simulations, and how are they being used by businesses?</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qZwCbfgifg63ta2zNJgRFh" name="qZwCbfgifg63ta2zNJgRFh.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/qZwCbfgifg63ta2zNJgRFh.jpg" mos="https://cdn.mos.cms.futurecdn.net/qZwCbfgifg63ta2zNJgRFh.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The 3 approaches of Breach and Attack Simulation technologies</strong></p><p class="fancy-box__body-text">A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/354494/the-3-approaches-of-breach-and-attack-simulation-technologies" data-original-url="/security/cyber-attacks/354494/the-3-approaches-of-breach-and-attack-simulation-technologies">FREE DOWNLOAD</a></p></div></div><h2 id="the-different-types-of-breach-and-attack-simulations">The different types of Breach and Attack Simulations</h2><p>BAS is an emerging technology that runs simulated automated attacks, mimicking the attacks likely to be deployed by cyber criminals. These ‘pretend’ attacks can help a company identify potential vulnerabilities in security systems, as well as test out the detection and prevention capabilities.</p><p><a href="https://www.itpro.com/security/cyber-attacks/354494/the-3-approaches-of-breach-and-attack-simulation-technologies" data-original-url="https://www.itpro.com/security/cyber-attacks/354494/the-3-approaches-of-breach-and-attack-simulation-technologies">According to Cymulate</a>, BAS technologies fall into three main categories, depending on the approach needed.</p><p>The first is agent-based vulnerability scanners. As opposed to using protocols like SSH to remotely access network devices, this method involves running agents directly on target devices themselves to test them for known vulnerabilities. These agents are deployed inside an organisation’s LAN and distributed across a number of machines, with the goal being to map out the potential routes an attacker could take to move through the network.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/30837/four-strategies-organisations-are-using-to-combat-cyber-attacks" data-original-url="/endpoint-security/30837/four-strategies-organisations-are-using-to-combat-cyber-attacks">Four strategies organisations are using to combat cyber attacks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/29101/six-ways-boards-can-step-up-support-for-cyber-security" data-original-url="/strategy/29101/six-ways-boards-can-step-up-support-for-cyber-security">Six ways boards can step up support for cyber security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34257/it-pro-panel-why-is-patch-management-so-difficult" data-original-url="/security/34257/it-pro-panel-why-is-patch-management-so-difficult">IT Pro Panel: Why is patch management so difficult?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/34735/the-it-pro-podcast-how-do-we-fix-security" data-original-url="/business-strategy/34735/the-it-pro-podcast-how-do-we-fix-security">The IT Pro Podcast: How do we fix security?</a></p></div></div><p>The second type of BAS tests the organisation’s security by generating ‘malicious’ traffic inside the internal network. Virtual machines are set up inside the network which act as targets for the test, using a database of attack scenarios. The BAS sends attacks between these machines, then checks that the organisation’s security solutions are able to detect and block the traffic.</p><p>The third category consists of multi-vector simulated attacks, and are the most advanced and true-to-life type of simulation that can be deployed. This ‘black box’ approach puts a lightweight agent on a workstation within the network. Usually cloud-based, the assessments utilise distinct types of attack tactics to try and bypass the security in place, both internally and externally to the organisation’s LAN.</p><h2 id="pros-and-cons-of-breach-and-attack-simulations">Pros and cons of Breach and Attack Simulations</h2><p>One major benefit of BAS is the <a href="https://www.itpro.com/strategy/29594/what-is-workload-automation" target="_blank" data-original-url="https://www.itpro.com/strategy/29594/what-is-workload-automation">automation</a> aspect. Having tests scheduled and frequently carried out automatically by a tool means that potential weaknesses can be spotted and dealt with quickly, compared to one-off tests where staff may be more alert to issues.</p><p>Automated tests can be particularly useful in larger organisations where networks are constantly changing, especially if new tools are being deployed, software is updated, or operations expand into new locations. Regular tests can identify issues with complex networks quickly and efficiently, and some BAS technologies can be set up to run constantly, meaning that vulnerabilities can be spotted almost instantly.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qZwCbfgifg63ta2zNJgRFh" name="qZwCbfgifg63ta2zNJgRFh.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/qZwCbfgifg63ta2zNJgRFh.jpg" mos="https://cdn.mos.cms.futurecdn.net/qZwCbfgifg63ta2zNJgRFh.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The 3 approaches of Breach and Attack Simulation technologies</strong></p><p class="fancy-box__body-text">A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/354494/the-3-approaches-of-breach-and-attack-simulation-technologies" data-original-url="/security/cyber-attacks/354494/the-3-approaches-of-breach-and-attack-simulation-technologies">FREE DOWNLOAD</a></p></div></div><p>However, human cyber experts are usually much more creative in how they deploy attacks. BAS is limited in what it can test, and can only run known attack simulations. This is why <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a> - a simulated attack run by <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">highly trained security professionals</a> to probe business systems for vulnerabilities - may uncover different problems compared to BAS.</p><p>There is also a danger that IT teams can end up overloaded with notifications on an ongoing basis with BAS, especially if there is no easy way to differentiate routine issues from important alerts.</p><p>As with many security tools, Breach and Attack Simulation is not a <a href="https://www.itpro.com/endpoint-security/30837/four-strategies-organisations-are-using-to-combat-cyber-attacks" target="_blank" data-original-url="https://www.itpro.com/endpoint-security/30837/four-strategies-organisations-are-using-to-combat-cyber-attacks">comprehensive solution</a>, and different tools have different purposes depending on how they are deployed. However, as part of a comprehensive cyber security strategy, BAS can play a valuable role, particularly as the technology matures and BAS providers continue to evolve their offerings.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How targeted simulations differ from penetration tests and vulnerability scanning ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/penetration-testing/354497/how-targeted-simulations-differ-from-penetration-tests-and</link>
                                                                            <description>
                            <![CDATA[ Stay one step ahead of cyber attackers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wbFcxt6cCbbXTptssjz6hd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sPocofyEzGwydhaf2UKvbk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jan 2020 10:47:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sPocofyEzGwydhaf2UKvbk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sPocofyEzGwydhaf2UKvbk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="N3uGqYEBCCJAy4GtzrFdT9" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/N3uGqYEBCCJAy4GtzrFdT9.png" mos="https://cdn.mos.cms.futurecdn.net/N3uGqYEBCCJAy4GtzrFdT9.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>As cyberattacks become more sophisticated, they become harder to detect and mitigate. Current methods that organisations use to verify that their systems and data are protected are vulnerability scans and penetration tests, neither of which present the full picture of an organisation’s security posture.</p><p>The most effective way for an organisation to test its resilience against the growing wave of cybercrime is to opt for targeted attack simulations that use multi-vector simulated attacks. These kinds of simulations are known as Breach and Attack Simulations (BAS).</p><p>This whitepaper evaluates the effectiveness of a holistic BAS strategy compared to traditional methods of gaining insight into the security posture of an organisation. </p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/cymulate-q1?locale=1&p=false&wp=4004"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The 3 approaches of Breach and Attack Simulation technologies ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/354494/the-3-approaches-of-breach-and-attack-simulation-technologies</link>
                                                                            <description>
                            <![CDATA[ A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5XuToeT6FARj9kpxtfpw5h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qZwCbfgifg63ta2zNJgRFh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jan 2020 09:54:27 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qZwCbfgifg63ta2zNJgRFh-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qZwCbfgifg63ta2zNJgRFh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="N3uGqYEBCCJAy4GtzrFdT9" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/N3uGqYEBCCJAy4GtzrFdT9.png" mos="https://cdn.mos.cms.futurecdn.net/N3uGqYEBCCJAy4GtzrFdT9.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Until recently, the cybersecurity professional’s arsenal of testing tools has mainly consisted of vulnerability scanners and manual penetration testing. But that has changed since Breach and Attack Simulation (BAS) technology has become available. </p><p>All BAS solutions are able to simulate threat actor’s hostile activities with some level of automation, yet different BAS vendors offer different approaches, each with its own set of capabilities, benefits and drawbacks.</p><p>This whitepaper takes a closer look at the different categories of BAS solutions, to make it easier for CISOs, CIOs and other cybersecurity professionals to select the most appropriate BAS solution for their organisation. </p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/cymulate-q1?locale=1&p=false&wp=3968"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers 'are no longer winning', says KPMG cyber chief ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34660/hackers-are-no-longer-winning-says-kpmg-cyber-chief</link>
                                                                            <description>
                            <![CDATA[ Despite progress over the past two years, a wealth of threats still plague both the public and private sectors ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eZdXqbjkf8fXuJN4wrJTCo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GCsxrL26j7Pj4pEgKsjRjm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Oct 2019 11:03:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GCsxrL26j7Pj4pEgKsjRjm-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker in the shadows]]></media:description>                                                            <media:text><![CDATA[Hacker in the shadows]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker in the shadows]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GCsxrL26j7Pj4pEgKsjRjm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are 'no longer winning the cyber crime war' following years of public and private investment and cross-industry collaboration, according to KPMG's global head of cyber futures David Ferbrache.</p><p>The nation's cyber resilience against hackers has improved over the past two years, with joint operations between law enforcement and the private sector frustrating opportunities for criminals to profit from cyber crime.</p><p>Speaking at a London technology forum on Thursday, Ferbrache said: "I'm not sure they quite are [winning the war], curiously... I would have given you a different answer two years ago."</p><p>"The takedown operations by law enforcement in conjunction with tech firms, telecoms, financial services are getting better, faster and more disruptive in terms of some of the things that the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web" target="_blank" data-original-url="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web sites</a> use for trading information," he said.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/machine-learning/30588/hackers-could-weaponise-ai-with-devastating-consequences" data-original-url="/machine-learning/30588/hackers-could-weaponise-ai-with-devastating-consequences">Hackers could 'weaponise AI', with devastating consequences</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32902/student-loans-company-hit-by-a-million-cyber-attacks-last-year" data-original-url="/security/32902/student-loans-company-hit-by-a-million-cyber-attacks-last-year">Student Loans Company hit by a million cyber attacks last year</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32117/what-is-the-dark-web" data-original-url="/security/32117/what-is-the-dark-web">What is the dark web?</a></p></div></div><p>He also said that active defence measures taken by the National Cyber Security Centre, that are being used to protect the wider population who cannot be expected to implement advanced <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> protocols, are also very effective at keeping the bad guys at bay.</p><p>It's also becoming increasingly difficult to hack modern systems, something he observed during his time as red team exercise leader at the professional services firm, he explained.</p><p>"It's actually getting harder to break into well-configured systems than it used to be. I used to run the red team penetration testing for KPMG as well and our job was getting harder."</p><p>He added it's the systems that aren't well-configured that worry him the most, such as easily discoverable routers left with their default passwords unchanged.</p><p>Echoing the tone of the Westminster eForum discussion around the UK's cyber security capabilities, Fiona Boyd, head of cyber security operations at Fujitsu EMEIA, described the fight against hackers as "a constant war of attrition".</p><p>Boyd cited figures from the Student Loans Company, which in 2015 reported three cyber attacks on the business. A year later, that rose to 95, and in the fiscal year 17/18 that rose to <a href="https://www.itpro.com/security/32902/student-loans-company-hit-by-a-million-cyber-attacks-last-year" target="_blank" data-original-url="https://www.itpro.com/security/32902/student-loans-company-hit-by-a-million-cyber-attacks-last-year">965,000</a>.</p><p>Although Ferbrache said things are getting better, there was agreement on the panel that pervasive threats still threaten the cyber security of both the public and private sectors in the UK.</p><h3 class="article-body__section" id="section-smart-malware"><span>Smart malware</span></h3><p>Jeremy Watson, professor of engineering systems at University College London (UCL), said that he was "excited" at the prospect of smarter, AI-powered cyber defence tools becoming available, but added <a href="https://www.itpro.com/machine-learning/30588/hackers-could-weaponise-ai-with-devastating-consequences" target="_blank" data-original-url="https://www.itpro.com/machine-learning/30588/hackers-could-weaponise-ai-with-devastating-consequences">AI-driven malware</a> is already a threat.</p><p>"At UCL we've been looking at how AI can shape an attack system for industrial control systems and been able to show that it is possible to do that as well as to defend," said Watson. "So, if we can do that from an academic point of view then clearly people with malintent and the resources can do it in other ways."</p><p>Speakers added that <a href="https://www.itpro.com/security/34656/arm-partners-with-government-to-create-hack-resistant-chips" target="_blank" data-original-url="https://www.itpro.com/security/34656/arm-partners-with-government-to-create-hack-resistant-chips">'secure by design'</a> protocols should be implemented as soon as possible to help secure the growing internet of things (IoT) industry, which is set to explode as manufacturers capitalise on the demand for smarter devices.</p><p>This would include the creation of new business models to make securing IoT devices more attractive for manufacturers, according to Watson.</p><p>However, the panel warned that without legislation compelling manufacturers to bake security measures into the device as standard, it becomes a difficult task.</p><p>"If you look at the darker side of some security, it's like selling the absence of the negative - it isn't necessarily an easy sell," said Watson.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is penetration testing? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing</link>
                                                                            <description>
                            <![CDATA[ Going beyond tooling and tech solutions with penetration testing is an effective way of achieving assurance in the security of your IT assets ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">moAMaQwc7q9qi8kF4dpcGW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KBQPyK3YkYoZ3uK9vhw5mg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Oct 2019 09:00:00 +0000</pubDate>                                                                                                                                <updated>Sat, 07 Sep 2024 16:57:15 +0000</updated>
                                                                                                                                            <category><![CDATA[Development]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Fleur Doidge ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Dale Walker ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KBQPyK3YkYoZ3uK9vhw5mg-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A graphic depiction of an ethical hacker certificate]]></media:description>                                                            <media:text><![CDATA[A graphic depiction of an ethical hacker certificate]]></media:text>
                                <media:title type="plain"><![CDATA[A graphic depiction of an ethical hacker certificate]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KBQPyK3YkYoZ3uK9vhw5mg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Penetration testing, or "pen testing", is the practice of performing simulated attacks on a network, in order to evaluate the various cyber security controls and processes an organization may deploy to protect IT assets.</p><p>Typically performed by an external agent, a penetration test can be performed in a variety of ways, but they all involve attempts to breach an organization&apos;s defenses using the same tools that threat actors may deploy.</p><p>Despite common wisdom, the main goal of a penetration test is not to simply find vulnerabilities in an organisation&apos;s defenses. Instead, a test should be viewed as the primary way of gaining assurance in an organization&apos;s vulnerability assessment and management process.</p><p>A report from application security vendor Veracode found that automated scans failed to find 62% of Common Weakness Enumeration (CWE) flaws successfully exposed by manual pen testing. It&apos;s for this reason that <a href="https://www.mordorintelligence.com/industry-reports/penetration-testing-market" target="_blank">Mordor Intelligence</a> analysis forecasts the testing market will reach $12.8 billion by 2029.</p><p>"Some bugs require knowledge of underlying business logic or data flows," Veracode chief research officer Chris Eng points out. "For example, with a page that should only be accessible by certain users, an automated scan generally wouldn’t be able to tell if the appropriate access control check was in place because it doesn’t know the business rules unique to that application."</p><p>A penetration tester uses contextual clues to evaluate vulnerability impacts. It can be worse to allow a user to manipulate a price, versus letting them manipulate some other variable - but code-wise these look identical, Eng says.</p><h2 id="how-penetration-tests-are-deployed">How penetration tests are deployed</h2><p><a href="https://www.itpro.com/security/penetration-testing/357806/how-cyber-attack-simulations-differ-from-penetration-tests-and">External pen tests</a> may target servers and hardware that any hacker might see, with internal tests typically simulating what happens if hackers cross the network perimeter or an insider threat wants to cause trouble. Either way, a test should never disrupt or put systems at risk.</p><p>Tactics strictly reflect organizational context. Conversely, &apos;straight&apos; <strong>vulnerability scanning</strong>, while useful, merely inspects points of potential exploitation on the network. Pen testing is more probing and wide-ranging as well as active, rigorous and tailored.</p><p>Don&apos;t ask testers to simply see what they can find - what comes back may be too costly or overlook business-critical issues. Define structure and goals for testing from the start; know what success looks like so you can judge the results. Is it just about keeping hackers out, or more about vulnerability exploitation and data exposure?</p><p>Eng says balance speed against depth. Pen testing can "absolutely" drive a deep dig to unravel issues, but "seeing how far you can get" depends on budget. If 80% of issues are likely identified in week one, is a second testing week worthwhile?</p><p>Different organizations will have different thresholds, part-dependent on application criticality and data sensitivities. A good test team will understand how deep they can go within agreed timeframes without sacrificing necessary breadth of coverage, he says.</p><p>One evolving approach is a move toward smaller, more frequent penetration tests, with a pool of hours or days used at shorter notice. Instead of testing massively once a year, test new functionality as it’s developed - mirroring faster development timeframes and agile practices.</p><h2 id="what-should-be-tested">What should be tested?</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2121px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CNNLM7Zn8bJD74Rnxw6etF" name="E7092140-12D2-4751-A587-763690169FE0_1_201_a.jpeg" alt="Number of dialogue windows and verficiation portals representing a security stack managed by CISOs" src="https://cdn.mos.cms.futurecdn.net/CNNLM7Zn8bJD74Rnxw6etF.jpg" mos="" align="middle" fullscreen="" width="2121" height="1193" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>"Consider your overall attack surface. If you have a bunch of public-facing applications that are easily exploitable via a bug in some open source library, probably address that before finding and fixing bugs deeper within the system," Eng says.</p><p>"I would want to run software composition analysis and possibly an attack surface management (ASM) tool for a big-picture view of lowest hanging fruit before drilling too deeply into any single penetration test."</p><p>Certain applications will want pen testing regardless, he adds.</p><p>"Even a small &apos;shop&apos; can be one ransomware attack from being shuttered," agrees Charles Henderson, enterprise vice-president (EVP) of cyber security services at cyber security and compliance services provider Coalfire.</p><p>Approaches might include "adversary emulation" - or red teaming. This simulated attack is like a fire drill that might need to be as realistic as possible. It might also be important that internal IT staffers aren&apos;t notified of tests prior to completion and reporting, enabling comparisons that highlight the gap between attempted attack and successful defense.</p><p>Conversely, the focus may be on how the internal &apos;blue&apos; team moves from a posture of assumed breach to detect and respond, or a &apos;purple&apos; mix of teams and approaches, Henderson says.</p><p>The critical factor can be how the &apos;home&apos; team detects and responds to breaches, because that&apos;s always possible, he points out.</p><h2 id="how-to-pick-a-penetration-testing-company">How to pick a penetration testing company</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="m8LD3ENwxn3C9qP6jjPzb3" name="Software_developer_GettyImages-1387361769.jpg" alt="Software developer using AI coding tools on a desktop computer in an open plan office space." src="https://cdn.mos.cms.futurecdn.net/m8LD3ENwxn3C9qP6jjPzb3.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>It&apos;s key to analyse teams and skillsets on offer in detail. Security consultants capable of pen testing typically hail from providers who can offer someone with a relevant research background and who can speak authoritatively on the topic.</p><p>"If they&apos;re relying on the the skills of others on how to test, they&apos;re very reactionary," Henderson notes. "You&apos;re looking for a firm with really good testers, because no matter how good their methodology is, it comes down to who&apos;s on the keyboard."</p><p>Even with suitable skillsets, good methodology and enough time and resource are essential. And as usual - if you get pricing that&apos;s too good to to be true, it probably is, he says.</p><p>Some may be doing mostly tool based testing - although there&apos;s absolutely a place for that, he adds, whether in a self-service capacity or as a managed service with oversight.</p><p>"We offer it too - but if you&apos;re doing penetration testing, you&apos;re really looking for that manual use of human beings to connect issues they find and fully understand the gravity of it, rather than just delivering a list of defects across the environment," Henderson explains.</p><p>Decide which players you can trust and with what. You might also look at strong recommendations from previous customers and focus on accredited testers, for instance with the global Council of Registered Ethical Security Testers (<a href="https://www.crest-approved.org/"><u>CREST</u></a>) certification, which requires examination and adherence to enforceable codes of conduct.</p><h2 id="what-happens-in-a-penetration-test">What happens in a penetration test?</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:6500px;"><p class="vanilla-image-block" style="padding-top:53.85%;"><img id="BByVuGVeFJCJKekuHdacrY" name="ransomware_GettyImages-1420039900.jpg" alt="Cyber Security Ransomware Email Phishing Encrypted Technology" src="https://cdn.mos.cms.futurecdn.net/BByVuGVeFJCJKekuHdacrY.jpg" mos="" align="middle" fullscreen="" width="6500" height="3500" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>As we&apos;ve noted, the nature of the test depends entirely on what objectives an organization hopes to achieve. </p><p>Typically, though, pen testers perform both external tests, which target the servers and hardware that any hacker would be able to see, and internal tests, which simulate what would happen if those hackers made it past the perimeter and got inside your network, or if an employee wanted to cause trouble. </p><p>Both approaches can be revealing and combined they can provide a good indication of your real-world security position.</p><p>An external test may be almost invisible, although, if you have a good security infrastructure, it will hopefully flag up any suspicious connection attempts. An internal test needn&apos;t be much more invasive: the tester simply requires access to your network so they can mimic the actions of a hacker.</p><p>If that makes you nervous, remember that the testers are looking to expose vulnerabilities, not to exploit them. No data will be compromised, no systems will be interrupted and no damage will be done. Still, it&apos;s worth making sure any senior stakeholders have been notified that a pen test is taking place so that they&apos;re aware of what&apos;s happening.</p><p>Tests can take as little as a few hours or last as long as a few weeks, depending on the scope. Just remember that the pen testers&apos; work isn&apos;t over when they log out or discontinue their <a href="https://www.itpro.com/security/ransomware/357175/nyotron-lets-you-test-your-security-with-simulated-ransomware">simulated attacks</a>; further time is needed to produce a vulnerability report, after which your business will need time to digest its findings and respond as needed. Indeed, there&apos;s a good chance that you will want to involve the testing agency in remedying any issues discovered, so it&apos;s worth thinking about keeping them involved for the long-term.</p><p>With all tests, you should focus on what needs fixing urgently and be realistic about what&apos;s a long-term goal, or what might not be worth fixing at all given the risk appetite of your business. The value of pen testing is that it gives you the information you need to make these decisions.</p><h2 id="how-to-prepare-your-business-for-a-penetration-test">How to prepare your business for a penetration test</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:5000px;"><p class="vanilla-image-block" style="padding-top:66.66%;"><img id="w5JYQ7WJEQXwsceXnkL5J3" name="w5JYQ7WJEQXwsceXnkL5J3.jpg" alt="cartoon graphic woman holding a large pencil next to a large clipboard with a checklist" src="https://cdn.mos.cms.futurecdn.net/w5JYQ7WJEQXwsceXnkL5J3.jpg" mos="" align="middle" fullscreen="" width="5000" height="3333" attribution="" endorsement="" class=""></p></div></div></figure><p>In the interest of simulating an &apos;attack&apos; that&apos;s as realistic as possible, internal IT teams would ideally not be notified of an incoming test before it has been completed and an external report has been compiled. Typically, only a small number of key stakeholders will be aware a test is even happening.</p><p>This way, defences will be tested organically, with internal IT teams able to devise their own report accordingly, mirroring the process of an actual attack like a mock fire drill. The two reports can then be compared to highlight the differences between what was actioned in the attack, and what was picked up by the IT team.</p><p>Before the test team arrives, it can also pay to undergo a security pulse check, including <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">basic patch management</a> and applying hardware and software updates. Of course, patch management and general updating should be regularly undertaken regardless, but ensuring everything is completely up-to-date as a preliminary for penetration testing will mean that security measures are tested in their entirety.</p><p>Prepare also to work collaboratively with the test team. Sharing knowledge beforehand can save them time, and you money. Conversely, you should take the time to understand the methods and tools they will use to analyse your network. The more you understand, the more valuable the test.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What's the difference between active and passive reconnaissance? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/penetration-testing/34465/whats-the-difference-between-active-and-passive-reconnaissance</link>
                                                                            <description>
                            <![CDATA[ Exploring essential tools of both ethical and malicious hackers alike ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iuAKacJhCTrm5gYUHgsz9L</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jEcgjwrxDgkjXfaDBqsrBL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 27 Sep 2019 11:50:00 +0000</pubDate>                                                                                                                                <updated>Thu, 19 Nov 2020 12:53:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Cooper ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jEcgjwrxDgkjXfaDBqsrBL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A shield with a keyhole on a radar system denoting cyber security]]></media:description>                                                            <media:text><![CDATA[A shield with a keyhole on a radar system denoting cyber security]]></media:text>
                                <media:title type="plain"><![CDATA[A shield with a keyhole on a radar system denoting cyber security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jEcgjwrxDgkjXfaDBqsrBL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hacking is a profession that requires lots of preparation. It isn't a case of selecting a target and hitting them with whatever malware you've got - it's far more nuanced. Pentesters and malicious attackers need to know how best to hit an <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">organisation</a>, including how to gain access to their networks without being caught, and when the right time to strike is. This information will only be gleaned from thorough reconnaissance.</p><p>With the sheer volume of systems and cloud environments on offer to businesses, a blueprint of the target helps to strengthen the attack. Does the target use an on-premise infrastructure, or does it use a cloud service from a third-party provider? How many employees does it have, and which ones are authorised to access the systems you want to hit? Do employees have their own <a href="https://www.itpro.com/security/28086/iot-privacy-security-concerns" data-original-url="https://www.itpro.com/security/28086/iot-privacy-security-concerns">devices</a> at work? - this can all be critical information.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="/penetration-testing/33981/what-is-penetration-testing">What is penetration testing?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a></p></div></div><p>Regardless of your route in, the key to successful reconnaissance is stealth. Going undetected will keep your eventual attack a surprise (<a href="https://www.itpro.com/security/357821/weekly-threat-roundup-cisco-bluekeep-apache-unomi" target="_blank" data-original-url="https://www.itpro.com/security/357821/weekly-threat-roundup-cisco-bluekeep-apache-unomi">though most businesses should expect to be regularly attacked these days</a>).</p><h3 class="article-body__section" id="section-active-vs-passive-reconnaissance"><span>Active vs passive reconnaissance</span></h3><p>"Reconnaissance', which is often shortened to 'recon' is a military term for observing a region to locate the enemy or find information to design an attack strategy. Within IT, the term is normally classified as either 'active' or 'passive' with each referring to different methods. </p><p><strong>Active reconnaissance</strong></p><p>Active reconnaissance is a more direct approach. Hackers will use this method to probe a system for weaknesses, often risking early detection. Of the two, this is the fastest method of recon, actively searching for vulnerabilities or entre points. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qG8vMhfHtBczgFT5DicnnL" name="qG8vMhfHtBczgFT5DicnnL.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/qG8vMhfHtBczgFT5DicnnL.png" mos="https://cdn.mos.cms.futurecdn.net/qG8vMhfHtBczgFT5DicnnL.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Best practices for protecting remote work</strong></p><p class="fancy-box__body-text">Staying safe and secure while working from home</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/357754/best-practices-for-protecting-remote-work" data-original-url="/security/357754/best-practices-for-protecting-remote-work">FREE DOWNLOAD</a></p></div></div><p>System information is used to gain unauthorised access to protected materials, infiltrating any firewalls or routers. The hacker then actively maps the <a href="https://www.itpro.com/network-internet/33399/five-things-to-get-off-your-it-network" data-original-url="https://www.itpro.com/network-internet/33399/five-things-to-get-off-your-it-network">network infrastructure</a>, using tools such as NSLookup to identify hosts. Once they have been found, a port scan is conducted to reveal any potential vulnerabilities. </p><p>The Nmap open source tool is perhaps the most well-known exploit kit used for active reconnaissance, which uses a range of different scan types to find hosts and services connected to a network.</p><p>Given this approach requires interaction with a system, it’s far more likely that a scan will be caught by a system’s firewall or an attached security suite.</p><p><strong>Passive reconnaissance</strong></p><p>Passive reconnaissance does not rely on direct interactions with a target system, and is therefore far easier to hide. This technique involves simply eavesdropping on a network in order to gain intelligence, with hackers being able to analyse the target company for partner and employee details, technology in use, and <a href="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address" data-original-url="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address">IP information</a>.</p><p>If the attack is conducted successfully, the only evidence of a hacker's presence would be in analytical data, and with no red flags raised, they shouldn't appear in security logs.</p><p>Using tools such as Wget, hackers can browse a website offline, analysing content to reveal hardware, operating systems and contact information. Other common methods of passive reconnaissance include advanced Google searches, sifting through information stored on discarded devices, and <a href="https://www.itpro.com/social-engineering/34308/fraudsters-use-ai-voice-manipulation-to-steal-200000" data-original-url="https://www.itpro.com/social-engineering/34308/fraudsters-use-ai-voice-manipulation-to-steal-200000">impersonating users</a>.</p><h3 class="article-body__section" id="section-use-cases-for-active-and-passive-reconnaissance"><span>Use cases for active and passive reconnaissance</span></h3><p>Differences in method, unsurprisingly, yield different results. Active reconnaissance is riskier (from the hacker's perspective) but generally more useful information is gathered. Passive reconnaissance carries less risk, but is slightly more unreliable, can be time-consuming, and is usually far less revealing.</p><p>Despite these drawbacks, passive reconnaissance is the preferred tactic for many hackers, chiefly because of the reduced risk of detection. It also allows hackers to avoid the risk of incrimination, and the information gathered is still incredibly useful for supporting future cyber attacks. Conversely, active reconnaissance normally requires scrupulous preparation in order to avoid detection, and hackers always run the risk that a trace of their attack may be left behind.</p><p>All organisations are susceptible to these types of attacks, not just high profile networks. Small and medium-sized businesses should be particularly wary of reconnaissance, <a href="https://www.itpro.com/digital-transformation/33137/how-data-can-help-smbs-with-digital-transformation" data-original-url="https://www.itpro.com/digital-transformation/33137/how-data-can-help-smbs-with-digital-transformation">especially if they have digital transformation projects underway</a>. Ventures that <a href="https://www.itpro.com/security/32966/majority-of-firms-have-been-breached-in-the-last-year-fuelling-threat-detection" data-original-url="https://www.itpro.com/security/32966/majority-of-firms-have-been-breached-in-the-last-year-fuelling-threat-detection">haven’t been properly checked for potential security breaches</a>, or that have misconfigured security tools, can be especially helpful to hackers trying to infiltrate your network.</p><p>Other risks worth considering include unfortified applications containing data which could be <a href="https://www.itpro.com/security/data-breaches/354532/huge-data-leak-exposes-british-consultancy-firms-and-thousands-of" data-original-url="https://www.itpro.com/security/data-breaches/354532/huge-data-leak-exposes-british-consultancy-firms-and-thousands-of">vulnerable to being accessed by third-parties</a>. Every organisation should be one step ahead of potential hackers and consider all the processes that a criminal could deploy in order to gain access to confidential information.</p><p>It’s also important to remember that reconnaissance is equally useful for <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hacking</a>. This process usually involves professional penetration tests deploying the methods hackers normally adopt in order to locate the holes in an organisation's defences. This would allow the business to resolve any of these weaknesses as and when they're found before they're exploited by hackers in a live setting. The method isn't always free from fuss, however, and <a href="https://www.itpro.com/penetration-testing/34392/pen-testers-arrested-after-breaking-into-courthouse-that-hired-them" data-original-url="https://www.itpro.com/penetration-testing/34392/pen-testers-arrested-after-breaking-into-courthouse-that-hired-them">pen-testers have occasionally been mistaken for actual criminals</a>.</p><p>Penetration testers would likely cover both methods in order to provide a comprehensive overview of an organisation's cyber defences. Vulnerabilities are reported, and the organisation will then set out to remedy them. Taking into account information gathered, organisations can augment a <a href="https://www.itpro.com/private-cloud/29637/how-to-keep-applications-secure-in-a-private-cloud" data-original-url="https://www.itpro.com/private-cloud/29637/how-to-keep-applications-secure-in-a-private-cloud">web application firewall (WAF)</a>, the most holistic defence against cyber attacks. A strong WAF should be flexible to adapt to an organisation's needs, and secure to protect applications both in the cloud and on-premise.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Modern cyber security bears great resemblance to the Titanic disaster, says Stena CISO ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34443/modern-cyber-security-bears-great-resemblance-to-the-titanic-disaster-says-stena-ciso</link>
                                                                            <description>
                            <![CDATA[ The security head likens the maritime disaster to cyber security blunders and gives his thoughts on how to move forward ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tRg4Fk5YmjmsQvyk9Mr1Tj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KLkC38xCVXUUeck5xakUL5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Sep 2019 10:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KLkC38xCVXUUeck5xakUL5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Magnus Carling]]></media:description>                                                            <media:text><![CDATA[Magnus Carling]]></media:text>
                                <media:title type="plain"><![CDATA[Magnus Carling]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KLkC38xCVXUUeck5xakUL5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Magnus Carling, CISO of worldwide conglomerate Stena AB, likened modern cyber security practices to the oversights which led to the Titanic disaster in 1912.</p><p>Speaking at Cloudsec 2019, Carling told attendees "the iceberg was innocent. It wasn't the iceberg that made Titanic sink", before drawing some obvious comparisons between the famous sinking and modern cyber attacks.</p><p>Carling said the Titanic's captain ignored warnings from other ships about the oncoming iceberg, just like how system administrators sometimes either ignore or misread warning signs that a business may be under attack.</p><p>In addition, the captain demonstrated unsafe practices by travelling at around 22 knots - much higher than what was considered to be safe. This can be considered equal to ignoring other security best practices such as securing endpoints or not managing patches adequately.</p><p>The crew tasked with keeping the smooth running of the ship was also not given any sort of disaster training, said Carling which akin to not having a <a href="https://www.itpro.com/disaster-recovery-dr/30650/why-cloud-should-be-part-of-your-disaster-recovery-strategy" target="_blank" data-original-url="https://www.itpro.com/disaster-recovery-dr/30650/why-cloud-should-be-part-of-your-disaster-recovery-strategy">disaster recovery strategy</a> in place if a business comes under a cyber attack.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you" data-original-url="/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you">IBM’s cyber security crash course brings out the very worst in you</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/disaster-recovery-dr/30650/why-cloud-should-be-part-of-your-disaster-recovery-strategy" data-original-url="/disaster-recovery-dr/30650/why-cloud-should-be-part-of-your-disaster-recovery-strategy">Why cloud should be part of your disaster recovery strategy</a> General Data Protection Regulation (GDPR)</p></div></div><p>The last similarity was that before leaving for her maiden voyage, the Titanic was equipped with too few lifeboats and the crew knew this and departed anyway. In doing so, the crew "silenced the security voice", Carling said.</p><p>"I can bet my dog that someone somewhere told someone in charge [that] it's not a good idea to run in that high speed, it's not a good idea to not have lifeboats and not train the crew how to use the lifeboats - and I think we're seeing this today, in many cases," he added.</p><p>Carling said cyber security practitioners need to ask themselves whether their security voice is strong enough but to permanently avoid this possibility, we must embrace regulations.</p><p>"But there's one thing that can help us which is a good thing and that's regulations because a lot of people think that regulations are like this heavy weighted blanket [and that] it's a lot of work being compliant. But they do help you because they give you arguments that you should improve your cyber security stature."</p><p>One such regulation that Carling heralded was the network and information systems (NIS) directive adopted by EU member states in 2016 - it was the first EU-wide cyber security regulation. Carling said the NIS directive is the cyber security equivalent of the safety of life at sea (SOLAS) convention adopted in the maritime industry.</p><p>The <a href="https://www.itpro.com/security/33294/ncsc-targets-business-leaders-with-cyber-security-toolkit" target="_blank" data-original-url="https://www.itpro.com/security/33294/ncsc-targets-business-leaders-with-cyber-security-toolkit">NIS directive</a> aimed to unify the standards of cyber security within the EU to help protect member states from being attacked through vulnerabilities in other nations. It was implemented in UK domestic law at the same time as <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>.</p><p>But regulations alone won't keep out the numerous intruders trying to steal data from businesses, a well-trained team running a tight security operations centre (SOC) that can react quickly and effectively to cyber threats is the best defence against attackers.</p><p>That's why at Stena AB, the company runs red team versus blue team exercises roughly three times every year so its cyber security practitioners are ready to respond to the latest threats that could strike their business.</p><p>A red team drill is like <a href="https://www.itpro.com/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you" target="_blank" data-original-url="https://www.itpro.com/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you">a cyber attack training day</a>, security practitioners assemble and are divided into two teams: red team attacks and blue defends. The red team will try to simulate a cyber attack by attempting to breach Stena's systems and the blue team will try and stop it from happening. It's a common industry exercise that keeps security teams sharp.</p><p>When <em>IT Pro</em> asked for details of anything that came up in recent exercises, Carling told us that asset management was something that Stena and all other companies in the world will face issues with.</p><p>"[The red team] will find devices that are not supposed to be there and utilise them, they will breach them and get in. If you have a good red team, you can't stop them, they will get in one way or another," said Carling. "The only difference is how long it takes for them to get in. The improvement that we want to see is whether the blue team is getting better at detecting them." </p><p>In addition to regular exercise, Stena also has a global SOC which gives their security experts a holistic, business-wide view of their facilities' security.</p><p>"No captain would ever navigate without radar," he said, so there's no reason why security professionals should operate without an extensive view of oncoming threats.</p><p>"If you don't know what's in your network, you don't have security - you need to know exactly what's out there," said Carling.</p><p>The latest technique used by the company is deploying cyber security ambassadors where individuals from different Stena facilities who have shown an interest in cyber security can congregate and receive extensive training and then head back to their base and spread that knowledge to their team.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pen testers arrested after breaking into courthouse that hired them ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/penetration-testing/34392/pen-testers-arrested-after-breaking-into-courthouse-that-hired-them</link>
                                                                            <description>
                            <![CDATA[ Specialists claim they were testing ‘physical’ vulnerability points as part of a cyber assessment ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">agne4nKTsXABZ1fnfcuRbP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NNHp7vEZAUj3QneQfcrDyE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Sep 2019 11:14:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NNHp7vEZAUj3QneQfcrDyE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A thief cutting a lock to break into a building]]></media:description>                                                            <media:text><![CDATA[A thief cutting a lock to break into a building]]></media:text>
                                <media:title type="plain"><![CDATA[A thief cutting a lock to break into a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NNHp7vEZAUj3QneQfcrDyE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two security specialists have been arrested after physically breaking into a US courthouse, something they claim was part of the <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> penetration assessment they were hired to complete.</p><p>Dallas' State Court Administration (SCA) hired the two specialists through a third-party to conduct a <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" target="_blank" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration test</a> of the electronic records held by the Dallas County Courthouse. However, authorities were alerted when the two men were found attempting to breaking into the site using an assortment of burglary tools.</p><p>The two men later claimed they were hired to test the courthouse alarm system, and how responsive the police were, according to the <a href="https://eu.desmoinesregister.com/story/news/crime-and-courts/2019/09/11/men-arrested-burglary-dallas-county-iowa-courthouse-hired-judicial-branch-test-security-ia-crime/2292295001" target="_blank"><em>Des Moines Register</em></a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/enterprise-security/31054/under-the-prevailing-threat-of-ransomware-physical-security-is-being" data-original-url="/enterprise-security/31054/under-the-prevailing-threat-of-ransomware-physical-security-is-being">Under the prevailing threat of ransomware, physical security is being forgotten</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/32717/what-can-an-ethical-hacker-do-for-my-business" data-original-url="/hacking/32717/what-can-an-ethical-hacker-do-for-my-business">What can an ethical hacker do for my business?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31384/how-to-protect-your-business-from-endpoint-attacks" data-original-url="/security/31384/how-to-protect-your-business-from-endpoint-attacks">How to protect your business from endpoint attacks</a></p></div></div><p>The SCA, which governs courthouses in the state, confirmed they had hired the pen-testers from security firm Coalfire to "attempt unauthorised access to court records through various means" and ascertain vulnerabilities.</p><p>"SCA did not intent, or anticipate, those efforts to include forced entry into a building," the organisation added in a statement.</p><p>"SCA apologizes to the Dallas County Board of Supervisors and law enforcement and will fully cooperate with the Dallas County Sheriff's Office and the Dallas County Attorney as they pursue this investigation."</p><p>It's currently unclear what the agreement stipulated, however, the two specialists remain adamant that by physically breaking into the site they were operating under the boundaries of the contract.</p><p>The <a href="https://www.itpro.com/enterprise-security/31054/under-the-prevailing-threat-of-ransomware-physical-security-is-being" target="_blank" data-original-url="https://www.itpro.com/enterprise-security/31054/under-the-prevailing-threat-of-ransomware-physical-security-is-being">testing of physical defences</a> forms an integral part of many cyber security strategies, particularly in locations housing highly sensitive data, as there are often security vulnerabilities that can only be exploited by being in close proximity to target devices.</p><p>Nvidia, for example, last month disclosed <a href="https://www.itpro.com/security/34156/businesses-urged-to-patch-against-highly-severe-nvidia-flaws" target="_blank" data-original-url="https://www.itpro.com/security/34156/businesses-urged-to-patch-against-highly-severe-nvidia-flaws">five dangerous vulnerabilities in its GeForce, Quadro and Tesla graphics processing units (GPUs)</a>, with the most severe flaw allowing an attacker to install malware on a victim's machine.</p><p>These flaws, however, required hackers to be physically close to target devices, meaning an organisation hoping to protect themselves from attacks would need to invest in physical defences just as much as cyber defences.</p><p>"Coalfire is a global cybersecurity firm that has conducted over 10,000 security assessments since 2001," a spokesperson told <em>IT Pro</em>.</p><p>"We have performed hundreds of assessments for similar government agencies, and our employees work diligently to ensure our engagements are conducted with the utmost integrity and in alignment with the objectives of our client.</p><p>"However, we cannot comment on this situation or any specific client engagements due to the confidential nature of our work and various security and privacy laws. Additionally, we cannot comment on this specific case as it is an active legal matter."</p><p>The two pen-testers, Justin Wynn and Gary Demercurio, have been charged with third-degree burglary and possession of burglary tools. They are set to return to the Dallas County Courthouse for a preliminary hearing on 23 September.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers may start 'Warshipping' businesses to steal data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/penetration-testing/34171/hackers-may-start-warshipping-businesses-to-steal-data</link>
                                                                            <description>
                            <![CDATA[ IBM's latest imagined attack vector could soon be a reality ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sofeUwNC91WhbVXonjhGMQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GmZxA5G78b3kRSeEARZPgm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Aug 2019 10:28:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GmZxA5G78b3kRSeEARZPgm-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber attack]]></media:description>                                                            <media:text><![CDATA[Cyber attack]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GmZxA5G78b3kRSeEARZPgm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IBM has revealed what it thinks could be a future attack vector for cyber criminals to harness when attempting to hijack a victim's wireless network and steal sensitive data without detection.</p><p>The technique explained by the company at Black Hat 2019 is being coined "Warshipping" and involves concealing a tiny homebrew device, which it said costs less than $100 to build, inside of a regular-looking parcel and sending it to a victim - perhaps a business or CEO.</p><p>With the number of packages getting delivered to businesses and stored in mailrooms increasing every day, attackers can use this to their advantage by deploying this device to sniff a company's network for access points and other data worth harvesting.</p><p>"Think of the volume of boxes moving through a corporate mailroom daily. Or, consider the packages dropped off on the porch of a CEO's home, sitting within range of their home Wi-Fi," said Charles Henderson, global head of <a href="https://www.itpro.com/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you" target="_blank" data-original-url="https://www.itpro.com/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you">IBM X-Force Red</a>. "Using warshipping, X-Force Red was able to infiltrate corporate networks undetected.</p><p>"Our aim in doing so was to help educate our customers about security blind spots and modern ways adversaries can disrupt their business operations or steal sensitive data." </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YsepmLbtwHQmAgGziQLaWK" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/YsepmLbtwHQmAgGziQLaWK.png" mos="https://cdn.mos.cms.futurecdn.net/YsepmLbtwHQmAgGziQLaWK.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>Image by IBM</em></p><p>The makeshift device (pictured above) is fitted with a wireless 3G modem which allowed IBM researchers to remotely control the device from back in their lab. The device itself is a single board computer (SBC) which are cheap and cheerful networked PCs powered by a mobile phone battery.</p><p>The design's main limitation is its power consumption, but IBM managed to tweak it to become a low-power device, capable of being turned off when it's not needed.</p><p>Once concealed in the parcel and in transit, the device periodically scans for wireless networks which lets the controllers monitor the location of the parcel and ultimately verify that it has been delivered to the intended target.</p><p>"Once we see that a warship device has arrived at the target's front door, mailroom or loading dock, we are able to remotely control the system and run tools to either passively or actively attempt to attack the target's wireless access," said Henderson. "The goal of these attacks is to obtain data that can be cracked by more powerful systems in the lab, such as a hash."</p><p>IBM said it could gain a foothold on the network by listening for a handshake (a packet signalling an established connection) and capturing the hash to crack a preshared key which can be used to gain network access, and collect data that can be siphoned back to a more powerful system for cracking. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/32540/european-banks-bleed-millions-from-physical-cyber-attacks-through-devices-like-the" data-original-url="/security/32540/european-banks-bleed-millions-from-physical-cyber-attacks-through-devices-like-the">European banks bleed millions from physical cyber attacks through devices like the Raspberry Pi</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you" data-original-url="/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you">IBM’s cyber security crash course brings out the very worst in you</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34163/swapgs-attack-is-the-latest-windows-exploit-to-worry-about" data-original-url="/security/34163/swapgs-attack-is-the-latest-windows-exploit-to-worry-about">SWAPGS Attack is the latest Windows exploit to worry about</a></p></div></div><p>The warship can also be set up as an 'evil twin' network whereby attacks could be performed by setting up a spoof network to which employees could be enticed to connect devices to, revealing their true credentials which can then be used to move deeper throughout a legitimate network.</p><p>Henderson noted the researchers were then able to exploit vulnerabilities in things like employee devices to establish a persistent foothold on the network, giving them the ability to "steal employee data, exfiltrate corporate data or harvest user credentials".</p><p>The name 'Warshipping" was inspired by and named after a combination of Wardialing and Wardriving.</p><p>The former was a network-cracking approach in the 1980s and 1990s dial-up era which involved attackers spamming phone numbers until they landed on a weak system.</p><p>The latter was used more recently in the 2005 TJX data breach which cost the company close to $2 billion. In this case, attackers drove around Miami and sat in TJX store car parks and sniffing the store's networks locally from a vehicle, using cheap wireless equipment.</p><p>"Attacks like these are particularly concerning as they are so difficult to detect and can prove to be detrimental if executed successfully," said Stuart Sharp, VP of solution engineering at OneLogin. "These attacks are certainly viable as they require low powered devices that can be activated remotely, meaning they can withstand transit for many days without losing power.</p><p>"Organisations should be extra vigilant when accepting packages and refrain from leaving empty boxes within the confines of the business," he added.</p><p>Henderson said we could expect to see the attack method being exploited more heavily during times of the year which see high volume deliveries such as Christmas or Black Friday.</p><p>No examples of Warshipping have been seen in the wild yet. However, in late 2018 a string of European banks were targeted by attackers posing as job seekers, couriers and inspectors who then installed Raspberry Pi devices in places like meeting rooms and <a href="https://www.itpro.com/security/32540/european-banks-bleed-millions-from-physical-cyber-attacks-through-devices-like-the" target="_blank" data-original-url="https://www.itpro.com/security/32540/european-banks-bleed-millions-from-physical-cyber-attacks-through-devices-like-the">stole tens of millions of dollars by doing so</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How do you become an ethical hacker? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker</link>
                                                                            <description>
                            <![CDATA[ We examine what certifications do you need, what jobs are available and how much you can expect to be paid ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8sfKBHrggppFm6qjTAe767</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZzdJSZhjvG3kZFpodAqtjF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Jul 2019 12:10:00 +0000</pubDate>                                                                                                                                <updated>Fri, 29 Apr 2022 15:27:50 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ connor.jones@futurenet.com (Connor Jones) ]]></author>                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Connor Jones is the News and Analysis Editor at ITPro, CloudPro, and ChannelPro. As the brands’ leader for news, he welcomes pitches on all topics, and he personally still reports breaking news on the topics of cyber security, software, and Big Tech firms.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;He has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs.&lt;/p&gt;
&lt;p&gt;Connor is currently in his third year at ITPro, but has been a journalist for much longer, having written for the likes of Red Bull Esports and UNILAD. He has a master’s degree in Magazine Journalism from one of the UK’s leading journalism departments at the University of Sheffield, as well as an undergraduate degree in English Language from Sheffield Hallam University.&lt;/p&gt;
&lt;p&gt;When he’s not hitting the phones trying to squeeze stories out of sources and press offices, in his free time Connor studies software development, is a keen cook, and enjoys leading an active life through cycling, hiking, racket sports, and weightlifting.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZzdJSZhjvG3kZFpodAqtjF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ethical hacker silhouette walking through a keyhole, symbolising physical security and penetration testing]]></media:description>                                                            <media:text><![CDATA[Ethical hacker silhouette walking through a keyhole, symbolising physical security and penetration testing]]></media:text>
                                <media:title type="plain"><![CDATA[Ethical hacker silhouette walking through a keyhole, symbolising physical security and penetration testing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZzdJSZhjvG3kZFpodAqtjF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Often depicted as hooded basement-dwellers, faces lit only by blue light, hackers come in all shapes and sizes - and notably wear different coloured hats. The annoying, destruction-wielding hackers are known as black hats whereas those who use their hacking abilities for ethical, productive purposes are known as <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hats</a>.</p><p>Ethical hackers are in short supply in the industry and they serve an important purpose in the overall protection of modern businesses and other organisations. The old saying ‘attack is the best form of defence’ certainly rings true in the cyber security industry, and it’s why ethical hackers are paid handsomely for their services. Their role is to use their hacking abilities and knowledge of systems to find security vulnerabilities in software and infrastructure so they can be patched before criminals can exploit them. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/635041/getting-inside-the-minds-of-ethical-hackers" data-original-url="/635041/getting-inside-the-minds-of-ethical-hackers">Getting inside the minds of ethical hackers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a></p></div></div><p>Their work is invaluable to businesses that handle large quantities of sensitive or personally identifiable information, or those that are subject to tight regulations such as banking and financial services firms. </p><p>White hats can most commonly be found working in-house at businesses or independently, either as contractors or as modern-day bounty hunters - hackers who look for security vulnerabilities in companies that offer bug bounty programmes. There are a number of large companies such as Apple and Microsoft that offer lucrative bug bounties that increase in monetary reward based on how severe the vulnerability is.</p><p>There are a multitude of routes one can take to become an ethical hacker and, as previously mentioned, a number of different ways these hackers can monetise their skill set. The cyber security industry has been intent on attracting new talent to the scene and there is an abundance of resources to get you on your way to becoming a fully-fledged white hat. </p><h2 id="what-is-an-ethical-hacker">What is an ethical hacker?</h2><p>Before delving any deeper, it's important to clear up any misconceptions of what an ethical hacker is, rather than making judgements on what's morally right and wrong.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ebWTwtZnKEPD3hvMervZkk" name="ebWTwtZnKEPD3hvMervZkk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" mos="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The truth about cyber security training</strong></p><p class="fancy-box__body-text">Stop ticking boxes. Start delivering real change.</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361094/the-truth-about-cyber-security-training" data-original-url="/security/cyber-security/361094/the-truth-about-cyber-security-training">FREE DOWNLOAD</a></p></div></div><p>Jeff Schmidt, global head of business continuity, security and governance at BT, describes an ethical hacker as a computer security expert. They must specialise in penetration testing (i.e. working out how easy it is to break into computer systems) and other testing methods to ensure infrastructure is sufficiently secured against potential hacks.</p><p>However, another expert in the field of cyber security, Conrad Constantine, a research team engineer at AlienVault, thinks the description of any role as a "hacker," whether ethical or not, is irrelevant.</p><p>"Nobody says they are going to go see an ethical locksmith or an ethical lawyer do they?" he told <em>IT Pro</em>.</p><p>But what the role is called is simply semantics. It could be we decide to refer to them as a white hat hacker or penetration tester. The important differentiator between an ethical hacker and a criminal hacker is that the former carries out <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> testing with the full consent of the company they are working on behalf of.</p><p>If they did not have permission, the offence would be punishable under the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act</a>.</p><p>Ian Glover, chairman of CREST, prefers the <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration tester</a> label and his definition goes a little further in that it recognises you need to be more than just a techie in order to truly fulfil the role. He believes you need to have consultancy skills as well.</p><p>A penetration tester, he says, has to be able to "communicate the results of the tests at a level tailored to the audience", Glover says, and "provide technical consultancy and recommendations to customers as to how any reported vulnerabilities could be mitigated".</p><h2 id="what-certifications-and-training-do-ethical-hackers-need">What certifications and training do ethical hackers need?</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FuCpWYsutYheGJP5YKKdSU" name="" alt="A group of people seated at desks during a training session" src="https://cdn.mos.cms.futurecdn.net/FuCpWYsutYheGJP5YKKdSU.jpg" mos="https://cdn.mos.cms.futurecdn.net/FuCpWYsutYheGJP5YKKdSU.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>OK, so talking of the necessary skills for the job, what <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" target="_blank" data-original-url="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training">qualifications</a> do you need? Peter Chadha, <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do" data-original-url="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">chief executive</a> and founder of DrPete, reckons that all you need is "a vast amount of technical knowledge of IT systems and <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> and, in particular, how to exploit their vulnerabilities", but acknowledges that there are formal qualifications available.</p><p>"Most commonly the EC-Council Certified Ethical Hacker certification, a self-study or classroom course with a 200 multiple choice question exam at the end," Chadha says, adding: "<a href="https://www.itpro.com/security/20685/gchq-extends-skills-cyber-security-certification-scheme-private-sector" data-original-url="https://www.itpro.com/security/20685/gchq-extends-skills-cyber-security-certification-scheme-private-sector">Communications-Electronics Security Group (CESG)</a> [now part of the National Cyber Security Centre] approval is also required for any penetration test on a company, and this is appointed by a government department."</p><p>This involves the CHECK scheme, where penetration testers prove themselves through practical examination under lab conditions. "There are two levels of approval," Chadha explains. "A penetration test member and a penetration test team lead, and government departments will require at least one team lead working on any project."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HzoyL9nmubvMyv9xsnSFZ5" name="HzoyL9nmubvMyv9xsnSFZ5.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/HzoyL9nmubvMyv9xsnSFZ5.png" mos="https://cdn.mos.cms.futurecdn.net/HzoyL9nmubvMyv9xsnSFZ5.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Security awareness training strategies for account takeover protection</strong></p><p class="fancy-box__body-text">Why you need an inside-the-perimeter strategy for internal threats</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/internet-security/359469/security-awareness-training-strategies-for-account-takeover" data-original-url="/security/internet-security/359469/security-awareness-training-strategies-for-account-takeover">FREE DOWNLOAD</a></p></div></div><p>Phil Robinson, director of Digital Assurance and a Founder Associate Member of the Institute of Information Security Professionals points towards the Tiger Scheme and CREST certifications. "There are entry level testing certifications, for those wishing to be part of a testing team and working under the management of a team leader, and senior testing <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" data-original-url="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training">certifications</a> for more experienced individuals to either work on their own or to lead a team," Robinson told <em>IT Pro</em>.</p><p>"It also helps to have a reasonable general background and experience alongside certifications such as <a href="https://www.itpro.com/business-strategy/careers-training/356572/best-it-degrees-for-landing-the-hottest-tech-jobs" data-original-url="https://www.itpro.com/business-strategy/careers-training/356572/best-it-degrees-for-landing-the-hottest-tech-jobs">a Masters in Information Security</a>," he added.</p><p>As far as the CREST certification is concerned, Ian Glover points out that in order to pass at the lower level a candidate will need "knowledge and skills on a wide range of relevant subjects, and in addition they would normally require two to three years regular and frequent practical experience, equating to about 6,000 hours experience and research." When it comes to the higher level that increases to five years or 10,000 hours.</p><h2 id="can-cyber-criminals-become-ethical-hackers">Can cyber criminals become ethical hackers?</h2><p>But what about if that 'experience and research' was largely garnered on, for want of a better phrase, the dark side? Can, and do, black hat hackers cross the divide and <a href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" data-original-url="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">enter the legit world of the penetration tester</a>?</p><p>Dominique Karg, is the co-founder and brilliantly titled chief hacking officer at AlienVault. He has no problem with poachers turned gamekeeper.</p><p>"I think they're the only ones that can do the job well," he says, adding "I got my ethical hacking job that way. I had to choose between being taught something I already knew at the <a href="https://www.itpro.com/security/hacking/358001/20-universities-targeted-by-shadow-academy-hackers" data-original-url="https://www.itpro.com/security/hacking/358001/20-universities-targeted-by-shadow-academy-hackers">university</a> or getting paid for what I liked to do anyway. The decision was easy."</p><p>Ian Glover agrees that we have to recognise where the industry has come from. "There are individuals within the industry that have crossed from the dark to the light," he says, but warns that the situation is changing very quickly.</p><p>"There is no reason now to have worked on the dark side to enter or progress in the industry," Glover argues, concluding "in fact the high ethical standards that CREST member companies sign up to would make it difficult for them to employ such individuals."</p><p>Marcus Ranum, chief security officer at <a href="https://www.itpro.com/security/34773/tenable-declares-there-are-far-worse-security-threats-to-fear-than-zero-day-exploits" data-original-url="https://www.itpro.com/security/34773/tenable-declares-there-are-far-worse-security-threats-to-fear-than-zero-day-exploits">Tenable Network Security</a>, thinks that a track record as a recreational hacker simply shows errors in judgement and a willingness to put self-interest first. "That's not something that should impress a prospective client," he insists. "After all, if you were acting like a sociopath last month, why should I believe you're not one today?"</p><h2 id="what-kinds-of-ethical-hacker-job-roles-are-available">What kinds of ethical hacker job roles are available?</h2><p>Much like how cyber security as an industry is somewhat of a catch-all term for different sub-fields, the term ‘ethical hacker’ also encompasses many different types of <a href="https://www.itpro.com/business-strategy/careers-training/355028/5-best-entry-level-tech-jobs" data-original-url="https://www.itpro.com/business-strategy/careers-training/355028/5-best-entry-level-tech-jobs">jobs</a>, the most common and perhaps most glamorised being a <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration tester</a>.</p><p>Penetration testers, or pen testers, are hired to probe a business for cyber security weaknesses through both digital and kinetic means. Some penetration testers are hired to assess the physical security of a company’s office building, for example, since this can be an entry point through which hackers could conduct local attacks. Other common job roles are security analysts, information security consultants, and network security specialists.</p><p>There are also opportunities to get involved in corporate <a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">red team</a>-blue team exercises, which involve cyber security staff taking part in <a href="https://www.itpro.com/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you" data-original-url="https://www.itpro.com/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you">virtual war games</a> to hone skills and ensure everyone is prepared to face a real cyber attack when the time comes. Ethical hackers will typically get drafted in to participate on the red team - the offensive team the company’s staff try to keep out of their systems - and these kinds of roles can often pay well too, especially on a contract or consultancy basis.</p><h2 id="what-39-s-the-average-salary-for-an-ethical-hacker">What's the average salary for an ethical hacker?</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WFFZJ9EoCo3pMpB9QwbAXZ" name="" alt="A pile of British pound sterling banknotes" src="https://cdn.mos.cms.futurecdn.net/WFFZJ9EoCo3pMpB9QwbAXZ.jpg" mos="https://cdn.mos.cms.futurecdn.net/WFFZJ9EoCo3pMpB9QwbAXZ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Experts speaking to <em>IT Pro</em> all said that there is <a href="https://www.itpro.com/business-strategy/careers-training/359789/best-paying-tech-jobs" data-original-url="https://www.itpro.com/business-strategy/careers-training/359789/best-paying-tech-jobs">plenty of money to be made</a> as an ethical hacker, with the demand for such talents far outweighing the supply. Newcomers to the job market can expect to make around £25,000, according to Ian Glover, while a registered professional with some experience could be looking at a salary in the region of £55,000. A team leader should be expecting even more; a sum north of £90,000 would be about right in the current market.</p><p>Peter Chadha adds that a penetration tester working as a contractor can easily earn between £400-£500 a day. As for <a href="https://www.itpro.com/business-strategy/careers-training/34591/how-to-make-yourself-irreplaceable-in-tomorrow-s-job-market" data-original-url="https://www.itpro.com/business-strategy/careers-training/34591/how-to-make-yourself-irreplaceable-in-tomorrow-s-job-market">market buoyancy</a>, Glover told <em>IT Pro</em> that "the demand for high-quality individuals working for professional companies far outstrips supply."</p><p>"The UK is seen as one of the leaders in this area and the opportunity to work on international projects is increasing every day."</p><p>John Yeo, director at Trustwave SpiderLabs, put it in a nutshell when he told us that given the recent uptick in mainstream media awareness of the types of malicious compromises that take place on a regular basis, and the reality that now cyber security is much higher on every organisation's executive agenda "in many respects it has never been better".</p><p>Another way to ethically make money from hacking is to take part in bug bounty programmes, which are used by companies like <a href="https://www.itpro.com/security/23979/google-offers-security-flaw-hunters-3000-bounty" data-original-url="https://www.itpro.com/security/23979/google-offers-security-flaw-hunters-3000-bounty">Google</a>, <a href="https://www.itpro.com/security/26694/microsoft-targets-net-core-with-new-bug-bounty-rewards" data-original-url="https://www.itpro.com/security/26694/microsoft-targets-net-core-with-new-bug-bounty-rewards">Microsoft</a>, <a href="https://www.itpro.com/security/26256/uber-launches-bug-bounty-programme-with-10k-prize" data-original-url="https://www.itpro.com/security/26256/uber-launches-bug-bounty-programme-with-10k-prize">Uber</a>, and <a href="https://www.itpro.com/security/26532/white-hat-hackers-access-full-database-of-pornhub-members" data-original-url="https://www.itpro.com/security/26532/white-hat-hackers-access-full-database-of-pornhub-members">even PornHub</a> to encourage hackers to discreetly report flaws instead of exploiting them. However, bug bounty programmes aren’t only reserved for major tech companies. The UK’s Ministry of Defence (MoD) recently introduced <a href="https://www.itpro.com/security/358083/mod-launches-bug-bounty-programme" data-original-url="https://www.itpro.com/security/358083/mod-launches-bug-bounty-programme">its own programme</a> through which white hat hackers can disclose vulnerabilities to the UK government department without fear of prosecution.</p><p>Apple is especially well-known for handsomely rewarding its ethical hackers, having <a href="https://www.itpro.com/security/27056/apple-finally-introduces-bug-bounty-programme" data-original-url="https://www.itpro.com/security/27056/apple-finally-introduces-bug-bounty-programme">launched a bug bounty programme in 2016</a> which pays security experts between $25,000 (£18,000) and $1 million (£720,000) for a disclosed security issue. What's more, the company <a href="https://developer.apple.com/security-bounty/payouts">states</a> that vulnerabilities which “were previously unknown to Apple” could potentially “result in a 50% additional bonus” added to the payout.</p><p>In October 2020, the tech giant paid a team of penetration testers <a href="https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities" data-original-url="https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities">at least $288,500</a> (£222,813) for finding and disclosing critical vulnerabilities in its network. Out of the 55 bugs reported by the team, the 11 most critical ones made it possible to access Apple’s <a href="https://www.itpro.com/infrastructure" data-original-url="https://www.itpro.com/infrastructure">infrastructure</a> and use it to potentially steal confidential information such as private emails and <a href="https://www.itpro.com/tag/icloud" data-original-url="https://www.itpro.com/search/icloud">iCloud</a> data.</p><p>Only a few months prior, <a href="https://www.itpro.com/security/ethical-hacking/355860/developer-scores-100000-bounty-from-apple-for-exposing-a-critical" data-original-url="https://www.itpro.com/security/ethical-hacking/355860/developer-scores-100000-bounty-from-apple-for-exposing-a-critical">developer Bhavuk Jain</a> managed to identify a security vulnerability in the <a href="https://www.itpro.com/mobile/33765/sign-in-with-apple-launched-at-wwdc-2019" data-original-url="https://www.itpro.com/mobile/33765/sign-in-with-apple-launched-at-wwdc-2019">"Sign in with Apple"</a> feature which could have been used to enable hackers to take control of a user's account. For this discovery, the tech giant chose to award Jain with a $100,000 (£72,280) payout.</p><p>So what are you waiting for?</p><h2 id="how-to-apply-for-a-job-as-an-ethical-hacker">How to apply for a job as an ethical hacker </h2><p>Who should you approach if you actually want to get started in the penetration testing field? We ask the experts...</p><ul><li><strong>Ian Glover:</strong> "Anyone interested in a career in the industry should contact CREST who will provide advice and guidance on the <a href="https://www.itpro.com/business-strategy/careers-training/356531/tech-leaders-share-how-to-break-into-the-tech-industry" data-original-url="https://www.itpro.com/business-strategy/careers-training/356531/tech-leaders-share-how-to-break-into-the-tech-industry">best way to enter</a> and then progress in the industry. We are also working with a number of universities to provide internship and work placement opportunities for individuals, with a great deal of success."</li><li><strong>Marcus Ranum:</strong> "Get a job working as an auditor. Penetration testing can be thought of as a 'more aggressive audit' and there's a lot of intellectual overlap in the field."</li><li><strong>Jeff Schmidt:</strong> "The <a href="https://www.itpro.com/625504/cyber-security-challenge-uk-launched" data-original-url="https://www.itpro.com/625504/cyber-security-challenge-uk-launched">Cyber Security Challenge UK</a> is a good starting point to get an understanding of the cyber learning opportunities and careers within the industry."</li><li><strong>Peter Chadha:</strong> "Search for the equivalent of CESG team members and network with them to build connections and knowledge in this area."</li><li><strong>John Yeo:</strong> "Invest the time and effort in going to conferences and get to know the various characters within the industries for which this isn't just a day a job, but enjoy it so much that they're regulars on the conference circuit."</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Our 5-minute guide to security awareness training ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training</link>
                                                                            <description>
                            <![CDATA[ How security awareness training can build resilience in your business and reduce the likelihood of a successful cyber attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">h7ANZCnAVJhEFAbPTAoucm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3BBjRB7TFv8wtojSeTwKWJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Jul 2019 12:31:00 +0000</pubDate>                                                                                                                                <updated>Fri, 24 Jan 2020 09:43:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Cooper ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3BBjRB7TFv8wtojSeTwKWJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Business classroom with a woman talking about cyber security, blue padlock image on whiteboard]]></media:description>                                                            <media:text><![CDATA[Business classroom with a woman talking about cyber security, blue padlock image on whiteboard]]></media:text>
                                <media:title type="plain"><![CDATA[Business classroom with a woman talking about cyber security, blue padlock image on whiteboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3BBjRB7TFv8wtojSeTwKWJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The speed at which the security landscape is evolving can make it challenging to keep up to date with the latest threats for those on the front line of a business' cyber defences. It is even more difficult for employees who aren't involved in cyber security to know what to look out for when it comes to ransomware, phishing and data breaches.</p><p>The four major cyber security concerns expressed by IT professionals in a recent survey are a breach of confidential data, with 68% highlighting it as a major concern, followed by <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing attacks</a> (68%), <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">CEO fraud attacks</a> (68%) and <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware attacks</a> (62%). </p><p>All of these methods of attack can involve exploiting employees at a company, and therefore training is one way to reduce the risk of staff accidentally opening a <a href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" data-original-url="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">malicious email attachment</a>, or falling prey to a <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">social engineering attempt</a>.</p><h2 id="what-is-security-awareness-training">What is security awareness training?</h2><p>As the name suggests, security awareness training is educating staff about what potential cyber threats look like, so that they are able to avoid attacks. </p><p>It doesn't guarantee that an employee will never make a mistake, but by raising awareness of common and emerging ways that hackers can try and get information, it keeps cyber security at the forefront of their minds.</p><p>Security awareness training should focus on three primary strands: firstly, how IT and devices should be used in the business; secondly, what security threats look like; and thirdly, how to respond both to suspicious activity, and an actual cyber attack.</p><p>Most organisations should have corporate policies about how to use devices, whether those are business-issued or personal. <a href="https://www.itpro.com/security/33537/what-is-shadow-it" data-original-url="https://www.itpro.com/security/33537/what-is-shadow-it">Shadow IT</a> - or unauthorised business devices and apps - is a security issue that can leave businesses vulnerable, so it is important to set out and regularly reinforce expectations for what devices staff can use, and any limitations on that, particularly when they're connected to a corporate network.</p><p>Keeping employees up-to-date with what security threats look like is another important aspect of security awareness training. This can be everything from the basics of <a href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" data-original-url="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">what to look out for with a phishing email</a>, to <a href="https://www.itpro.com/security/33946/50-of-cyber-attacks-now-use-island-hopping" data-original-url="https://www.itpro.com/security/33946/50-of-cyber-attacks-now-use-island-hopping">trends right at the cutting edge</a> of the cyber security landscape. </p><p>Finally, it is crucial not to leave out what to do in the event of receiving a suspicious email, such as reporting procedures and who to turn to, as well as what to do in the event of a cyber attack. This can also be a good place to highlight the organisation's disaster recovery plan, to improve how the business will respond and ensure all employees are on board.</p><h2 id="pros-and-cons-of-security-awareness-training">Pros and cons of security awareness training</h2><p>With 56% of security professionals <a href="https://www.redteamsecure.com/danger-ranks-7-times-employees-caused-data-breaches">saying that</a> employees are the number one cause of data breaches, there are numerous benefits to improving staff awareness of cyber threats.</p><p>Frequent security awareness training will help bake cyber security into an organisation's culture. Collective awareness is a powerful tool, and is particularly important for businesses with a high staff turnover.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" data-original-url="/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">Five giveaways that show an email is a phishing attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs" data-original-url="/security/28196/the-cybersecurity-skills-your-business-needs">The cyber security skills your business needs</a></p></div></div><p>If staff are being vigilant about the emails they receive, what passwords they set, and how they share information internally and externally, the risk of a silly mistake having devastating consequences for the business is greatly reduced.</p><p>One clear benefit of having regular training is increased compliance. Should a data breach happen, showing that you had <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/30107/get-gdpr-ready" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/30107/get-gdpr-ready">adequate training in place</a> and that it was enforced will be a key part of determining how much fault lies with the business.</p><p>However, there is always a risk that, as with too-frequent fire alarms, too much of an emphasis on security awareness training can make employees blas about potential threats. </p><p>Some forms of security awareness training can also be quite costly, especially hands-on and classroom-based training, which is often more effective than an online course or internal briefings. But the costs of implementing security awareness training should be balanced against the long-term financial and reputational cost of a successful cyber attack. </p><p>Security awareness training will also not help if an employee is intent on acting maliciously. It does, however, mean that they can't plead ignorance about policies and procedures if these are regularly highlighted in training.</p><h2 id="how-to-implement-security-awareness-training">How to implement security awareness training</h2><p>A large part of security awareness training is highlighting bad habits that staff may be getting into, and raising awareness of the consequences. There are four main ways that security awareness training can be implemented to improve some of these simple vulnerabilities:</p><p><strong>A classroom-style approach</strong>, where employees gather in an external or internal room for a dedicated training session. This can be delivered by a member of the IT or security team, or an external training company can be hired.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YELhdLvsMXZEMNLFaaH9m6" name="YELhdLvsMXZEMNLFaaH9m6.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/YELhdLvsMXZEMNLFaaH9m6.png" mos="https://cdn.mos.cms.futurecdn.net/YELhdLvsMXZEMNLFaaH9m6.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Best practices for implementing security awareness training</strong></p><p class="fancy-box__body-text">How to develop a security awareness programme that will actually change behaviour</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354100/best-practices-for-implementing-security-awareness-training" data-original-url="/security/cyber-security/354100/best-practices-for-implementing-security-awareness-training">FREE DOWNLOAD</a></p></div></div><p><strong>An online course</strong>, which can be delivered to both new and existing employees on a regular basis. Online courses or training videos are often used for compliance training, fire safety and more, and can easily be used for security awareness as well. Although there is no guarantee of how engaged an employee is when doing online courses, they can be completed by new starters almost straight away, and quizzes can be used at the end to test understanding.</p><p><strong>Internal tests</strong> are a method growing in popularity, where companies send simulated phishing attacks to their own employees. Security staff can then determine who falls prey to a phishing attack, and use that for further training if necessary. Bristol City Council recently <a href="https://www.itpro.com/security/33211/bristol-city-council-launches-phishing-attacks-against-own-staff" data-original-url="https://www.itpro.com/security/33211/bristol-city-council-launches-phishing-attacks-against-own-staff">sent a wave of spoof phishing attacks to their own colleagues</a>, sending those who clicked on the link to a targeted training site.</p><p><strong>Frequent reminders</strong> like posters which can be displayed prominently in an office alongside health and safety notices, or specific company emails, both of which can be used to cover subjects like what a suspicious email looks like, how to verify links, and the importance of a secure password.</p><p>The key with any form of awareness training is to keep it frequent. At the moment, just 11% of organisations continuously train employees on how to spot cyber attacks, according to global research from Vanson Bourne. 52% perform training just quarterly, or once a year.</p><p>But annual training means that a new member of staff could go for over 11 months without any form of security training, hugely increasing the risk of them accidentally clicking a malicious email, or worse.</p><p>The speed at which attacks evolve means that continuous training is the best way to keep employees up-to-date with what to look out for, as well as embedding cyber awareness into the company culture.</p><h2 id="who-takes-the-initiative">Who takes the initiative?</h2><p>Security awareness training reduces the likelihood of employees falling victim to a cyberattack, yet which employee is responsible for organising the training? Such initiatives have been known to fall between the scope of several roles, with CIOs, IT managers, and even human resources known to pick up the mantle.</p><p>IT managers are understandably most enthusiastic about security awareness training, as they are well versed in cyber threats. They are burdened with at least a portion of responsibility in the event of a breach, and so typically are the people pushing for training to be deployed. But in most organisations they are overshadowed by a CIO who has one eye on a stretched IT budget.</p><p>Senior business managers may be resistant to training, since their employees' schedules would be disrupted. Though training does initially hamper productivity, in the long run eliminating security threats ensures a higher level of productivity. Needless to say, business managers usually play no more than a side-role in introducing training. </p><p>For security to be given the attention it deserves at employee-level, it must be managed by the board. In the present day, CIOs are frequently given a chair at the top table in order to keep C-suite members aware of security issues and compliance risks. By acting as a bridge between IT managers and those at the top, the CIO can ensure the board of directors takes security seriously, going a long way to bolstering the security training programme within an organisation.</p><p>In all, the CIO would typically be responsible for bringing a security awareness program to the board, but for it to be successful, all within the organisation must buy-in to the initiative.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft launches $20,000 Azure DevOps bug bounty programme ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/32781/microsoft-launches-20000-azure-devops-bug-bounty-programme</link>
                                                                            <description>
                            <![CDATA[ Critical remote code execution flaws are the highest-paid, while denial-of-service attacks earn nothing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mSL9Yem8yHxPUarR7qi3Fh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/g43JRgnEoDRbAmLZhJXgeV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Jan 2019 09:56:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/g43JRgnEoDRbAmLZhJXgeV-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft Azure]]></media:description>                                                            <media:text><![CDATA[Microsoft Azure]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft Azure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/g43JRgnEoDRbAmLZhJXgeV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers who discover flaws in Microsoft's Azure DevOps platform could earn themselves up to $20,000, after the company announced its latest bug bounty programme.</p><p>The Microsoft Azure DevOps Services Bounty is the company's tenth concurrent bug bounty programme and covers Redmond's suite of cloud-based DevOps tools. Previously known as Visual Studio Team Services, these include continuous integration and continuous delivery (CI/CD) tools, Git repos, kanban boards, testing tools and more.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/desktop-software/23180/microsoft-opens-up-bug-bounty-programme-for-online-services" data-original-url="/desktop-software/23180/microsoft-opens-up-bug-bounty-programme-for-online-services">Microsoft opens up bug bounty programme for online services</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a></p></div></div><p>"Security has always been a passion of mine," said Microsoft's director of engineering for Azure DevOps, Buck Hodges, "and I see this program as a natural complement to our existing security framework. We'll continue to employ careful code reviews and examine the security of our infrastructure. We'll still run our security scanning and monitoring tools. And we'll keep assembling a red team on a regular basis to attack our own systems to identify weaknesses."</p><p>Rewards range from $500 all the way up to $20,000 at the top end, with payouts affected by a number of different factors. The quality of the report itself (meaning how easy the report makes it for Microsoft's engineers to understand, reproduce and fix the problem) is graded as either high, medium or low, with different bounties for each.</p><p>Different levels of compensation are also awarded based on the severity of the bug, but only 'critical' or 'important' bugs will qualify for a reward - disclosures of any other category of bug will merely earn a public acknowledgement from Microsoft, should the report lead to a fix.</p><p>Finally, the impact of the bug itself will be taken into consideration too. Remote code execution flaws are, understandably, the most valuable, followed by privilege escalation and information leaking, while tampering flaws are eligible only for a limited payout, and denial of service vulnerabilities are not rewarded at all.</p><p>Bug bounties are becoming an increasingly common security measure among large companies, with the idea being to make it more valuable to responsibly disclose the flaw to the victim than to exploit it for personal gain.</p><p>Major organisations like Facebook, Apple, and Google all offer their own bug bounty programmes, and the practice is touted as a good way to ensure that fewer flaws and exploits appear in the wild.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What can an ethical hacker do for my business? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hacking/32717/what-can-an-ethical-hacker-do-for-my-business</link>
                                                                            <description>
                            <![CDATA[ 'Ethical' and 'hacking' aren't usual bedfellows, but when paired they can be excellent penetration testers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mXkmxpZQr8FP2GRz4kwey5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ab6kcmEH5dwCesoTYeh2qW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Jan 2019 06:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nik Rawlinson ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ab6kcmEH5dwCesoTYeh2qW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ab6kcmEH5dwCesoTYeh2qW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>"We think like hackers do," explained Tim Holman, CEO of 2|SEC. "Criminals don't just stop at the first exploit they find. They will chain exploits and pivot off exposed systems to gain further leverage."</p><p>2|SEC is a London-based cyber security service provider that provides penetration testing services - among others - for a wide variety of clients. Otherwise known as "<a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" target="_blank" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hackers</a>" or "pen testers", such specialists are contracted by organisations that want to know if they need to up their security game.</p><p>And, if they do, where.</p><p>"The obvious benefit is that your systems will be protected against the latest criminal exploits and techniques that are being used against you," Holman explained. "Unless you have [a] full time, dedicated resource that can stay on top of the latest threats and vulnerabilities, your company will find it very difficult to match the experience and expertise that a professional penetration tester will bring."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs" data-original-url="/security/28196/the-cybersecurity-skills-your-business-needs">The cyber security skills your business needs</a></p></div></div><p>There's nothing shady about contracting with an ethical hacker. The companies we approached for this feature were happy to talk about what they do and how they do it, pointing out that they remain within the law by only accessing the systems they've been authorised to target, and only doing so within a defined time frame.</p><p>"Our approach is always to use the very latest research, exploits and techniques to see if we can gain a foothold in your company; and to do that, we have to be very careful not to bring systems crashing down or inadvertently expose sensitive data."</p><h3 class="article-body__section" id="section-growing-importance"><span>Growing importance</span></h3><p>As organisations handle and process larger amounts of data, the need for pen testing is increasing. Not long ago, they were routinely advised to run tests every couple of years, but that no longer satisfies many of their clients.</p><p>"Some of the compliance requirements are mandating that organisations who accept payment card data should be doing this at least annually and moving towards a model where they do it every six months," said Oliver Pinson-Roxburgh, MD of Bulletproof. "If your application undergoes a significant change since your last pen test, advice would be to retest then, too."</p><p>In part, this is being driven by the strictures of GDPR. "We have more customers asking about what they should be doing," Pinson-Roxburgh said. "Often, they don't have an incident response plan and want to know that if they get caught out, they can at least do something."</p><p>Having such a plan in place, and being able to prove you've been diligent with your testing, helps to demonstrate you're taking some responsibility. "It shows that you've taken reasonable efforts to do all that you can," said Mark Nicholls, director of cyber security at Redscan.</p><p>"We have often helped companies assess their readiness for a breach and, defensively, asked what a security and network team have done in response when an attack has taken place. Have they been able to acquire the necessary information within the first 72 hours following an attack to report to authorities?"</p><p>Making such reasonable efforts will often be enough to avoid the breach in the first place, as it will help identify where patches and fixes either haven't been applied, or are only partially effective.</p><p>"My experience has been that those organisations that were fined under the Data Protection Act could largely have solved their problems by doing a pen test or implementing some form of initial security scanning or testing," said Pinson-Roxburgh. "Where the ICO has published rulings, they [often] show that if the organisation had done the right things about security it would have identified the problems.</p><p>Often, it's a well-known, three-month-old vulnerability that they should have known about and fixed."</p><h3 class="article-body__section" id="section-your-first-approach"><span>Your first approach</span></h3><p>Ethical hackers are used to hand-holding new customers - particularly any that aren't sure what they need or what's on offer.</p><p>As Nicholls explains, outlining what the client does as a business, the systems it's running and what the ethical hacker can do is usually the start for any conversation. "We'll then assign a number of days [for the test during which] they can stand up appropriate resources, whether it be project managers or developers, to make sure we don't take anything down - or so they can address critical issues as we find them."</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eXGSkUreKM864h2x4bLzR8" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/eXGSkUreKM864h2x4bLzR8.jpg" mos="https://cdn.mos.cms.futurecdn.net/eXGSkUreKM864h2x4bLzR8.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em><strong>Pen testers are often told to social engineer their way into systems - even offering fake bribes to staff</strong></em></p><p>But pen testing often goes further than sitting at a keyboard and mouse and searching for vulnerabilities.</p><p>"We have red team exercises where the customer gives us an objective that we have to achieve by any means," said Pinson-Roxburgh. "That could be physically going to the building and finding our way in, or social engineering our way in. We've done a few big data centre tests, supposedly the most secure data centres in the world, and found our way in through a combination of social/physical access to the buildings, and hacking portals. For some customers we've even done bribes to see how their staff react to security [threats]."</p><p>Pinson-Roxburgh's preference would be to work with live systems wherever possible because, "if they're going to give us a system that's half finished because it's in pre-production, they're not going to get a realistic test. [That's not good when] most of the organisations are saying they want you to simulate things from the hacker's perspective."</p><p>But Nicholls also sees value in working with parallel infrastructure and data sets. With live systems, he says, "there's always an inherent risk when you're testing an application or server where issues may arise from being scanned.</p><p>Although rare with applications nowadays being more resilient, it can lead to downtime. So, we advise testing against a representative system that closely mirrors what's live. It gives you a good idea of what vulnerabilities there are, and we don't need to hold back. We can assess every parameter."</p><h3 class="article-body__section" id="section-confidentiality-and-confidence"><span>Confidentiality and confidence</span></h3><p>Should a tester gain access to your system, they could have access to confidential data. It's essential to ensure your pen tester signs and complies with a non-disclosure agreement, and that its staff have the necessary security accreditation.</p><p>Ultimately, you need to feel comfortable working with them, but that doesn't necessarily mean avoiding someone with a shady background - so long as they've since gone good.</p><p>"Many of the most celebrated security people started on the wrong side," Nicholls said. "Curiosity, early on, can be an issue but if that has changed and they're now progressing in a security career where they're offering their capabilities, there's no reason why a person such as that wouldn't meet the various standards and certifications."</p><p>Responding to an unsolicited approach, though, is a different matter entirely, and Pinson- Roxburgh advises caution.</p><p>"What I've seen more recently is organisations being solicited directly by people looking for bug bounties. I'd recommend an organisation be very cautious in such a situation because we've seen scenarios where the person making the approach is demanding certain amounts of money, only for the organisation to discover that the thing that's been found doesn't warrant the amount of money they've paid...</p><p>"When you're approached by someone asking about bug bounties, mention the Computer Misuse Act and the fact that nobody should be testing your systems without your authorisation."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FOI reveals NHS Trusts spend as little as £250 on cyber security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/wannacry/32547/foi-reveals-nhs-trusts-spend-as-little-as-250-on-cyber-security</link>
                                                                            <description>
                            <![CDATA[ 'Alarming' spend and expertise discrepancies exposed as DHSC threatens enforcement action ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oJ3p2Mu2MpX9NPdkPyPBCK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mds3gPMjrWMfM9saHMdukW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Dec 2018 10:43:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mds3gPMjrWMfM9saHMdukW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mds3gPMjrWMfM9saHMdukW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The NHS is struggling to retain critical cyber security expertise and expenditure is being allocated erratically, with some Trusts spending as little as 250 in the last year, it has emerged.</p><p>Despite the Department for Health and Social Care (DHSC) having committed an additional 150 million on NHS cyber security a year after the WannaCry attack, <a href="https://www.redscan.com/news/nhs-cybersecurity-skills-survey" target="_blank">research by Redscan</a> has exposed a prominent gap in both funding and staffing.</p><p>The average spend on data security training across 159 Trusts surveyed was 5,356 in the last 12 months, but this ranged widely from between 238 and 78,000 with no correlation to the size of Trust, or its location.</p><p>For a mid-sized Trust of between 3,000 and 4,000 employees, for example, training spend ranged from 500 to 33,000. But the research also notes a significant amount of training was conducted in-house using NHS Digital resources.</p><p>GDPR training was the most common programme taken up, with other prominent courses including BCS Practioner Certificate in Data Protection, and Senior Information Risk Owner.</p><p>However, it was found that NHS Trusts have only employed an average of one qualified security professional per 2,582 staff.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/31423/nhs-asks-ibm-to-boost-its-cyber-security-defences-after-wannacry" data-original-url="/cyber-security/31423/nhs-asks-ibm-to-boost-its-cyber-security-defences-after-wannacry">NHS asks IBM to boost its cyber security defences after WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/31554/uk-government-lacks-urgency-in-tackling-cyber-security-skills-gap" data-original-url="/cyber-security/31554/uk-government-lacks-urgency-in-tackling-cyber-security-skills-gap">UK government 'lacks urgency' in tackling cyber security skills gap</a></p></div></div><p>Alarmingly, almost a quarter of Trusts, 24 out of 108, retain no staff with security qualifications despite some employing around 16,000 full-time and part-time workers. A handful of Trusts also reported having employees in the process of obtaining security qualifications.</p><p>"These findings shine a light on the cyber security failings of the NHS, which is struggling to implement a cohesive security strategy under difficult circumstances," said Redscan's director of cyber security Mark Nicholls.</p><p>"Individual trusts lack in-house cybersecurity talent and many are falling short of training targets; while investment in security and data protection training is patchy at best. The extent of discrepancies is alarming, as some NHS organisations are far better resourced, funded and trained than others."</p><p>The findings, released following a Freedom of Information (FOI) campaign which saw responses from 159 NHS Trusts, have been released a year-and-a-half after the devastating <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">WannaCry attack that DHSC estimated to cost 92 million</a>.</p><p>Several parliamentary reports have since savaged the NHS' record on cyber security resilience, with among the latest in April showing <a href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" target="_blank" data-original-url="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">zero Trusts passed the government's cyber security assessments</a>.</p><p>A separate FOI request Redscan sent to NHS Digital revealed signs of improvement, as 139 Trusts had now undertaken a Data Security Onsite Assessment, compared to just 60 Trusts last year.</p><p>Beyond announcing an additional 150 million over the next three years, the DHSC also committed to <a href="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline" target="_blank" data-original-url="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline">upgrading all Windows XP devices to Windows 10 by 2020</a> in a deal struck with Microsoft earlier this year.</p><p>"Cyber security is a priority for this government and funding is provided to NHS Trusts based on their specific needs and capabilities," a DHSC spokesperson told <em>IT Pro</em>.</p><p>"Over 60m was invested last year for critical infrastructure, and there will be a further 150m over the next three to improve resilience across the health and care system.</p><p>"Where Trusts do not take sufficient action to secure their networks and systems, we will use strong enforcement powers to ensure they improve."</p><p>Redscan's Nicholls added that as the skills gap continues to grow, it'll become harder for organisations across all sectors to find the people with the right knowledge and expertise.</p><p>"It's even tougher for the NHS, which must compete with the private sector's bumper wages," he continued, "not to mention the fact that trusts outside of traditional tech hubs like London and Cambridge have a smaller talent pool from which to choose from."</p><p>Kaspersky's principal security researcher David Emm told <em>IT Pro</em> that given how very attractive health data is to criminals, it is vital the NHS invests money in robust protections.</p><p>"Healthcare providers must also work closely with their IT security teams to implement sophisticated, high-quality protection that will allow them to manage and protect customer data," he said.</p><p>"Not just for the sake of tick-box' compliance, or to avoid hefty fines and embarrassing, often irreparable reputational damage, but to enable them and their patients to reap the many rewards of advanced digital healthcare, confident in the knowledge that data, devices and networks are secure."</p><p><em>IT Pro</em> also approached NHS Digital, NHS England and NHS Improvement for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ It's now "impossible" to protect critical UK infrastructure from cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cyber-attacks/32391/its-now-impossible-to-protect-critical-uk-infrastructure-from-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ Parliamentary committee warns that mitigating the effects of successful attacks is becoming a 'new normal' ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">erGv7mELTofG61f7Uf33g3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nTJvtqYKvzWnsYGW5W7rTW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 19 Nov 2018 10:39:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nTJvtqYKvzWnsYGW5W7rTW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of construction workers representing UK infrastructure]]></media:description>                                                            <media:text><![CDATA[Image of construction workers representing UK infrastructure]]></media:text>
                                <media:title type="plain"><![CDATA[Image of construction workers representing UK infrastructure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nTJvtqYKvzWnsYGW5W7rTW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>MPs and Lords have warned it's "impossible" to completely protect the UK's infrastructure from a WannaCry-scale cyber attack, with mitigation quickly-becoming a new normal'.</p><p>Several factors stand in the way of fully securing the UK's critical national infrastructure (CNI), including an increasingly complex security landscape, and the government's failure to define what it considers to be critical, according to the Joint Committee on the National Security Strategy (JCNSS).</p><p>In a report assessing the scale of threat the UK faces, the Parliamentary committee also said laws stemming from EU-wide regulations have been useful, but do not go far enough.</p><p>"'Critical' national infrastructure is, by definition, a priority for the Government and industry. However, as the economy becomes more interconnected, it is increasingly difficult to determine which elements are truly critical," the <a href="https://publications.parliament.uk/pa/jt201719/jtselect/jtnatsec/1708/170809.htm#_idTextAnchor063" target="_blank">JCNSS report said</a>.</p><p>"Fast-changing threats and the rapid emergence of new vulnerabilities make it impossible to secure CNI networks and systems completely.</p><p>"Continually updated plans for improving CNI defences and reducing the potential impact of attacks must therefore be the 'new normal' if the Government and operators are to be agile in responding to this changing environment and in taking advantage of constant technological innovation."</p><p>The committee raised concerns that the expectations for the National Cyber Security Centre (NCSC), formed to provide cyber training and leadership for UK organisations, is outrstripping its resources.</p><p>NHS Digital deputy chief executive Rob Shaw revealed in evidence that he had expected an "army" of experts to support the NHS through 2017's WannaCry attack, but soon learned the NCSC lacked staffing to help out on the ground.</p><p>JCNSS said it had concerns about the NCSC's capacity to meet growing demand for services and expertise, and that its effectiveness will be limited in future unless it can recruit at the appropriate scale.</p><p>The government must also publish a ten-year plan for the institutional development of the NCSC, setting out the resources and staffing levels it expects the organisation to need.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/national-cyber-security-centre-ncsc/31903/ncsc-challenges-business-leaders-to-learn-the-basics-of" data-original-url="/national-cyber-security-centre-ncsc/31903/ncsc-challenges-business-leaders-to-learn-the-basics-of">NCSC challenges business leaders to learn the 'basics' of cyber security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/31554/uk-government-lacks-urgency-in-tackling-cyber-security-skills-gap" data-original-url="/cyber-security/31554/uk-government-lacks-urgency-in-tackling-cyber-security-skills-gap">UK government 'lacks urgency' in tackling cyber security skills gap</a></p></div></div><p>The committee made several further recommendations for the government and for businesses, including instigating a cultural change among CNI-linked organisations, and for politicians and ministers to take initiative in making cyber resilience a priority.</p><p>Private sector companies overseeing CNI, as well as firms comprising the supply chain, should consider cyber security as another business risk, and proactively manage threats. This is especially true where "commercial interests may not always align with the demands of national security".</p><p>Moreover, the government needs to appoint a cabinet office minister charged with overseeing the resilience of CNI, instead of patchwork of multi-ministerial oversight that exists currently.</p><p>Under the current structure, each department would have a different approach to overseeing cyber security in its constituent sectors, with occasional overlap.</p><p>A more focused and proactive leadership from central government is needed to ensure cyber security is handled in a more consistent way, the report continued, and blasted the status quo of ministers only occasionally checking-in as "wholly inadequate".</p><p>"It's vital that that short-term memories and political distractions such as Brexit do not derail focus from these important initiatives," said Mimecast's cyber resilience expert Pete Banham</p><p>"Private sector businesses today need a risk and security champion in the boardroom; likewise, it's time Government had a cyber tsar in the Cabinet.</p><p>"Minimising the impact of attacks should be top priority as a defence-only strategy is doomed to fail. This should include regular fire drills' for all employees to respond to and recover to cyber-attacks.</p><p>"We've seen a growing number of CNI organisations, including the NHS, make determined moves to adopt more resilient postures in the last two years. WannaCry helped focus attention and budget allocation but still more needs to be done."</p><p>Stuart McKenzie, FireEye's vice president for EMEA, meanwhile warned much of the technology used within CNI remains fragile and relies on outdated standards of security.</p><p>"The threats facing CNI have constantly evolved, meaning that today's threat is something that wasn't imaginable when many of the systems were originally designed, leaving them increasingly vulnerable," he said.</p><p>"These are not quick problems to solve, but they are not insolvable. We would recommend that CNI organisations conduct a mapping exercise to understand their exposure and risk and put in place some controls to protect the most critical threats.</p><p>"With breaches becoming inevitable, organisations need to not only to set defences and identify attacks, but crucially to have a really clear understanding of what to do in the event of a breach - every organisation needs to have a really clear incident response plan that's well tested and regularly rehearsed."</p><p>Mandatory policy decisions should also be implemented, the report recommended, including a plan to roll-out penetration-testing for CNI-linked organisations, and continued membership in key EU groups and information-sharing schemes following Brexit.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Vulnerabilities in web applications at the heart of 73% of breaches, Kaspersky finds ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/penetration-testing/31721/vulnerabilities-in-web-applications-at-the-heart-of-73-of-breaches</link>
                                                                            <description>
                            <![CDATA[ Pen test analysis finds 43% of companies have low or extremely low levels of security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8PAGjyD4BMxoV1JLCbvALd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jpMiuQLHHoxgan6q6eJeDg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Aug 2018 10:58:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jpMiuQLHHoxgan6q6eJeDg-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A padlock on a motherboard surrounded by keys]]></media:description>                                                            <media:text><![CDATA[A padlock on a motherboard surrounded by keys]]></media:text>
                                <media:title type="plain"><![CDATA[A padlock on a motherboard surrounded by keys]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jpMiuQLHHoxgan6q6eJeDg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The vast majority of successful breaches into corporate networks last year were caused by vulnerable web applications, according to a Kaspersky Lab analysis of penetration tests.</p><p>Against a backdrop of increasingly-common remote and cloud-based working habits, experts found that 73% of successful beaches exploited weaknesses in web applications, with 43% of organisations assessed having 'low or extremely low' protection against external threats.</p><p>Kaspersky's latest '<a href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/08/16093216/Security_assessment_of_corporate_information_systems_2017_ENG_web.pdf" target="_blank">Security Assessment of Corporate Information Systems</a>' comprised an examination of the security configurations of organisations across various industries, and in the public sector, finding that only 14% had above 'average levels' of security.</p><p>Using its own metrics and methodology, the cyber security firm said 29% of companies examined had 'extremely low' levels of security, with a further 29% scoring 'average' levels. No organisation assessed achieved 'high' levels of security.</p><p>The information security landscape, meanwhile, is even worse, with a 'low or extremely low' level of protection identified for 93% of all organisations. In 86% of cases Kaspersky's experts were able to gain the highest internal network privileges in an organisation, and for 42% of companies only two attack steps were needed to achieve this.</p><p>"Our research has shown that vulnerable web applications can provide gateways into corporate networks," said Kaspersky Lab's principal security researcher David Emm.</p><p>"There are many security measures that can be implemented to guard against this nature of attack - half of these breaches could have been prevented by restricting access to management interfaces.</p><p>"We encourage IT security specialists to identify the vulnerabilities their organisations have and focus on strengthening them."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/28452/ransomware-attacks-on-businesses-are-spiking-says-kaspersky" data-original-url="/security/ransomware/28452/ransomware-attacks-on-businesses-are-spiking-says-kaspersky">Ransomware attacks on businesses are spiking, says Kaspersky</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/exploits/31676/vulnerabilities-in-fax-machines-could-let-hackers-infiltrate-a-network" data-original-url="/exploits/31676/vulnerabilities-in-fax-machines-could-let-hackers-infiltrate-a-network">Vulnerabilities in fax machines could let hackers infiltrate a network</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31639/ai-considered-silver-bullet-for-cyber-security-challenges" data-original-url="/security/31639/ai-considered-silver-bullet-for-cyber-security-challenges">AI considered 'silver bullet' for cyber security challenges</a></p></div></div><p>Kaspersky's analysis showed "unambiguously" that sufficient attention is not being paid to the security of web applications.</p><p>Damningly, all web applications used by government organisations had high-risk vulnerabilities, with an average of 2.6 high-risk vulnerabilities per application. E-commerce web applications, on the other hand, contained the fewest high-risk weaknesses.</p><p>Arbitrary file upload proved the most widespread vulnerability exploited to gain access to a network, while other vulnerabilities, such as SQL injection, arbitrary file reading, and XML external entity, were used to steal sensitive information such as passwords.</p><p>"To improve their security stances, companies are recommended to pay special attention to web application security, timely updates of vulnerable software, password protection and firewalling rules," the research paper concluded.</p><p>"The task of completely preventing compromising of information resources becomes extremely difficult in large networks, or even impossible when attacks are launched using 0-day vulnerabilities.</p><p>"Therefore, it is important to ensure that information security incidents are detected as early as possible."</p><p>The need for organisations to bolster their cyber security infrastructure and guard against both external and internal breaches has arguably never been greater.</p><p>Companies must be especially vigilant in light of the newly-introduced General Data Protection Regulation (GDPR), which carries a fine of up to 20 million or 4% of global annual turnover for the most serious breaches.</p><p>In light of the growing threat of cyber attack and malicious infiltration organisations of all sizes and in all industries now face, Gartner recently revealed that <a href="https://www.itpro.com/security/31710/worldwide-security-spending-to-exceed-124-billion-by-next-year" target="_blank" data-original-url="https://www.itpro.com/security/31710/worldwide-security-spending-to-exceed-124-billion-by-next-year">global security spending is expected to exceed $124 billion</a> by the end of 2019.</p><p>Whether this level of expenditure is high enough or is being committed into the right areas, remains to be seen - but Kaspersky's analysis certainly painted a bleak picture for the global cyber security landscape in 2017, at the very least.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New ‘facial recognition’ tool could help white hat hackers harvest social media profiles ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/31662/new-facial-recognition-tool-could-help-white-hat-hackers-harvest-social-media</link>
                                                                            <description>
                            <![CDATA[ Security company claims software creates a level playing field for white hats and pen testers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iKYkP3A3q4V9Yy9NyignFm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HZAGiXiZE4YQr4aspB87CQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Aug 2018 08:52:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HZAGiXiZE4YQr4aspB87CQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Surveillance, machine learning, facial recognition]]></media:description>                                                            <media:text><![CDATA[Surveillance, machine learning, facial recognition]]></media:text>
                                <media:title type="plain"><![CDATA[Surveillance, machine learning, facial recognition]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HZAGiXiZE4YQr4aspB87CQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new facial recognition tool has been released that could help automatically identify and harvest the social media profiles of thousands of targets with very little effort. The tool is primarily aimed at white hat hackers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" data-original-url="/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">Social engineering: The biggest security risk to your business</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a></p></div></div><p>The tool - dubbed <a href="https://github.com/SpiderLabs/social_mapper" target="_blank">Social Mapper</a> - was developed by security company Trustwave, who has released it on Github under an open source license. The company, which specialises in ethical hacking services, says that Social Mapper is intended for use by white-hat hackers, penetration testers and 'red teams' - internal security staff who are tasked with simulating cyber attacks on the organisation.</p><p>Social Mapper only needs a list of targets with the individuals' names and photographs. Users can also input the LinkedIn ID of a specific company, and it will automatically create a list of targets based on all the people who are registered as employees of said company on LinkedIn.</p><p>From there, Social Mapper logs into a range of social media sites - including Facebook, Twitter, LinkedIn, Google+ and Instagram, as well as regional platforms like VKontakte and Weibo - and searches the targets' names, using facial recognition to match their profile picture to the given photo.</p><p>The software will then output a report containing all of the available social media profiles for each target, available in a variety of formats. It can also generate the target's work email, if you tell the software what format to use.</p><p>Any security expert worth their salt will tell you that a complete list of a target's social media profiles is an incredibly useful tool when conducting a cyber attack, and gathering such data is often the first step when conducting reconnaissance before an attack.</p><p>"Once social mapper has finished running and you've collected the reports, what you do then is only limited by your imagination, but here are a few ideas:</p><ul><li>Create fake social media profiles to 'friend' the targets and send them links to credential capturing landing pages or downloadable malware. Recent statistics show social media users are more than twice as likely to click on links and open documents compared to those delivered via email.</li><li>Trick users into disclosing their emails and phone numbers with vouchers and offers to make the pivot into phishing, vishing or smishing.</li><li>Create custom phishing campaigns for each social media site, knowing that the target has an account. Make these more realistic by including their profile picture in the email. Capture the passwords for password reuse.</li><li>View target photos looking for employee access card badges and familiarise yourself with building interiors."</li></ul><p>However, Trustwave's Jacob Wilkin (<a href="https://www.trustwave.com/Resources/SpiderLabs-Blog/Mapping-Social-Media-with-Facial-Recognition--A-New-Tool-for-Penetration-Testers-and-Red-Teamers/?page=1&year=0&month=0&LangType=1033" target="_blank">who created the tool</a>) noted that "While this is an easy task for a few, it can become incredibly tedious when done at scale". This, he said, is the primary idea behind Social Mapper: to speed up intelligence gathering that pen testers previously had to do manually.</p><p>"Its primary benefit comes from the automation of matching profiles and the report generation capabilities. As the security industry continues to struggle with talent shortages and rapidly evolving adversaries, it is imperative that a penetration tester's time is utilized in the most efficient means possible."</p><p>While Trustwave has stated that Social Mapper is intended to be used by ethical white hat hackers, concerns have been raised that because the tool can be freely downloaded and used by anyone, it could easily be deployed by criminals.</p><p>Tim Helming, director of product management at DomainTools said that threat actors using open source components for phishing attacks show that available tools on the internet have "enormous potential to be used for both helpful and nefarious purposes".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Large businesses are the most vulnerable to cyber attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cyber-security/31513/large-businesses-are-the-most-vulnerable-to-cyber-attacks</link>
                                                                            <description>
                            <![CDATA[ Password flaws, unsecured protocols and out-of-date software - enterprises have them all ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">heHmXsSSQBq2s15NhZxikh</guid>
                                                                                                                            <pubDate>Mon, 16 Jul 2018 10:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                                        <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Large enterprises are the least prepared of all companies against cyber crime, despite having greater budgets and resources, according to new research.</p><p>Contrary to received wisdom, larger companies performed the worst when assessed by cyber security consultancy firm Coalfire, in part due to their complex organisational structure and large attack surface built from multiple acquisitions.</p><p>Researchers' assumptions that SMBs would be the most at risk due to a lack of firm process and procedure, as well as staffing and budget weaknesses, were defied in Coalfire's first annual <a href="https://issuu.com/coalfire/docs/coal0071_rr2018_labs_8-hr?e=29648651/62412278" target="_blank">Penetration Risk Report</a>, with midsized businesses hitting what the report dubbed a "cyber security sweet spot".</p><p>The report's findings, based on 310 penetrations tests across 148 organisations of various sizes, showed that while large enterprises are too diverse and complex to uniformly protect their entire architecture, midsized businesses provide the best configuration to best secure their environments.</p><p>Among all types of penetration tests conducted on large organisations, 49% of vulnerabilities found were deemed high risk, versus 38% for small businesses and 34% for medium businesses.</p><p>"Large organizations do not become large organizations entirely on their good looks and charm," the report said. "For many companies, growth is largely 'inorganic', achieved through mergers and acquisitions. As the asset collection grows, the attack surface grows.</p><p>"An acquiring company with its own asset management challenges often integrates other companies that come with their unique asset management challenges. When you mix poor asset management into a growing attack surface, you find the security posture will erode quickly, as it is inversely proportional to the growth of the attack surface."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/31250/large-businesses-overlook-supplier-cybersecurity-risks" data-original-url="/cyber-security/31250/large-businesses-overlook-supplier-cybersecurity-risks">Large businesses 'overlook' supplier cybersecurity risks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs" data-original-url="/security/28196/the-cybersecurity-skills-your-business-needs">The cyber security skills your business needs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29543/insider-threats-make-up-74-of-business-cyber-security-incidents" data-original-url="/security/29543/insider-threats-make-up-74-of-business-cyber-security-incidents">Insider threats make up 74% of business cyber security incidents</a></p></div></div><p>Rapid change, shadow IT and employee turnover were all highlighted as factors that contributed to a "cyber-dynamic" environment within enterprises that is harder to control and get full visibility into, with internal networks considered the biggest vulnerability.</p><p>But while large organisations proved best at defending against phishing and other social engineering attacks, midsized businesses performed best at protecting their assets and mitigating their overall security risks.</p><p>"Our extensive penetration tests flip the thinking that large enterprises are the most secure, even with significant cyber security budgets and investments in staffing and other resources," said Andy Barratt, Coalfire's UK managing director.</p><p>"However, this doesn't apply to social engineering where large corporates are more secure. Despite bigger companies outperforming their smaller rivals in this area, it's clear that human error poses the greatest risk to businesses of all sizes. Whether you're a FTSE 100 company or an SMB, the chances are that staff are your cyber security Achilles' heel."</p><p>The researchers also found that internal networks showed higher risk factors than external networks - despite their presumption that internet-based attacks represented a greater threat - while human error was the weakest security link in an organisation, given the prevalence of phishing attacks.</p><p>Unsecured protocols, password flaws, missing system patches, out-of-date software and cross-site scripting, meanwhile, comprised the top five most common enterprise vulnerabilities in both external and internal networks. But phishing attacks were identified as the gateway for attackers to infiltrate an organisation on a deeper level.</p><p>Coalfire's researchers issued recommendations for organisations of all sizes to follow, including implementing two-factor authentication, expanding patch management beyond Windows Update, as well as maintaining an accurate inventory of systems and their dependencies.</p><p>Beyond general advice, small businesses were encouraged to integrate security checkpoints in engineering and development processes, while midsized business were urged to focus investment on mitigating human error, particularly in developing programmes to boost cyber security awareness, and engaging employees in social engineering testing.</p><p>The report recommended that large companies prioritise asset management, and focus on raising the level of visibility across the entire organisation, given the greater tendency for these companies to suffer from "technology sprawl and complex, decentralised operations".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to install Kali Linux on Raspberry Pi ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/31455/how-to-install-kali-linux-on-raspberry-pi</link>
                                                                            <description>
                            <![CDATA[ Follow these simple steps to install the penetration testing software on the compact computer for mobile hacking ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8LDg74vkAobQ49RUjDEj6Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BiT8DhKfTchdZ6kAHcZikB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Jul 2018 14:32:00 +0000</pubDate>                                                                                                                                <updated>Tue, 22 Sep 2020 13:29:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BiT8DhKfTchdZ6kAHcZikB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[List of Kali images to download for the Raspberry Pi]]></media:description>                                                            <media:text><![CDATA[List of Kali images to download for the Raspberry Pi]]></media:text>
                                <media:title type="plain"><![CDATA[List of Kali images to download for the Raspberry Pi]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BiT8DhKfTchdZ6kAHcZikB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Despite what a million stock images might tell you, hacking isn't just for hooded teenagers in darkened rooms. It can also be used for good in the great outdoors, such as by enabling people to pentest from outside their building, for instance. </p><p>To be able to hack from 'anywhere' you need the right tools and downloading the Kali Linux on the Raspberry Pi should be your first port of call. The Raspberry Pi is a small, credit card-sized computer that doesn't require a lot of power to use. When combined with Kali Linux it becomes a super-portable network testing machine that you can take anywhere.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/linux/31023/kali-linux-installation-on-windows-10" data-original-url="/linux/31023/kali-linux-installation-on-windows-10">Kali Linux installation on Windows 10</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/31187/how-to-put-alexa-on-raspberry-pi" data-original-url="/hardware/31187/how-to-put-alexa-on-raspberry-pi">How to put Alexa on Raspberry Pi</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/desktop-hardware/28790/the-best-raspberry-pi-alternatives" data-original-url="/desktop-hardware/28790/the-best-raspberry-pi-alternatives">Best alternatives to the Raspberry Pi mini-PC</a></p></div></div><p>This can be run on your laptop and used to test your Wi-Fi password strength - or your neighbours. You can also spoof networks, test for Bluetooth vulnerabilities and much more. If you don't want Kali installed directly on to your computer, you can even add a touchscreen device. </p><p>All you need to get started is either a Raspberry Pi 2 or 3, a supply of power, a HDMI cable, a minimum 8GB SD-Card and a keyboard and a mouse for control.</p><h3 class="article-body__section" id="section-downloading-the-kali-image-for-raspberry-pi"><span>Downloading the Kali image for Raspberry Pi</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mp8MduL7sCiSwCuV4aDC4o" name="" alt="List of Kali images to download for the Raspberry Pi" src="https://cdn.mos.cms.futurecdn.net/mp8MduL7sCiSwCuV4aDC4o.png" mos="https://cdn.mos.cms.futurecdn.net/mp8MduL7sCiSwCuV4aDC4o.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>To start, you need a Kali Linux 2.0 image file, which you can download from the <a href="https://www.offensive-security.com/kali-linux-arm-images" target="_blank">Offensive Security downloads area</a>. You'll have to scroll down to find the Raspberry Pi2/3 download as there are a number of different variants. </p><p>It is vital that you properly verify what you're installing and that it is a genuine version of kali, rather than a fraudulent lookalike, especially if you plan to use it for security testing. Detailed instructions on how to do so can be found on <a href="https://docs.kali.org/introduction/download-official-kali-linux-images" target="_blank">the Kali website</a>.</p><p>After you have the file downloaded it will need to be extracted. Most computers will not have the right software to extract it, but WinRAR can be downloaded and installed to extract the image file if you don't already have software for that purpose.</p><p>When you have extracted the image, you're ready to write it to an SD-Card. The minimum size is 8GB, although using something bigger like 16GB or even 32GB is considerably better as it will give you more space to download and run tools and apps.</p><p>From there, load the image file into Win32Disk Imager (a Windows program for saving and restoring images from removable drives) and write it to the correct drive, making sure you have picked the correct one as it will overwrite any drive that is selected. It will take a few minutes to write the package, and will state 'Write Successful' when it has completed.</p><h3 class="article-body__section" id="section-installing-kali-on-raspberry-pi"><span>Installing Kali on Raspberry Pi</span></h3><p>Once the image is written to the SD-Card, it is ready to install into the Pi. Everything can now be plugged into a monitor or TV with a HDMI cable and you can even add an old keyboard and mouse for control.</p><p>After powering up the Pi it will go through a boot up process where the screen will go blank a few times before you can finish. For the final step, a login prompt will appear asking for a username and a password. The default should be 'root' and 'toor' respectively.</p><p>Naturally, it goes without saying that you'll want to change the access credentials to something more secure as soon as possible, but you should also change the SSH host keys, as the Kali image for Raspberry Pi comes with a set of default keys pre-configured. From the command line, use the following commands to change your SSH host keys:</p><p>root@kali:~ rm /etc/ssh/ssh_host_*</p><p>root@kali:~ dpkg-reconfigure openssh-server</p><p>root@kali:~ service ssh restart</p><h3 class="article-body__section" id="section-installing-hacking-tools"><span>Installing hacking tools</span></h3><p>Once that's done, enter the command startx from the command line to boot into the graphical desktop environment. By default, ARM-based Kali images come with the bare minimum of tools pre-installed, but you can use Kali metapackages to install new ones. Various metapackages are available containing different groups of tools for specific purposes such as password cracking or Wi-Fi analysis.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Kha7hPozenDNQTFy5JZyn" name="" alt="List of Kali Metapackages to add testing tools to a Raspberry Pi" src="https://cdn.mos.cms.futurecdn.net/Kha7hPozenDNQTFy5JZyn.png" mos="https://cdn.mos.cms.futurecdn.net/Kha7hPozenDNQTFy5JZyn.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The full list of available metapackages can be found <a href="https://tools.kali.org/kali-metapackages" target="_blank">here</a>. You can install the 'kali-linux-full' metapackage to get all the tools that are included with the default desktop image of Kali, or you can get every single available tool with the 'kali-linux-all' metapackage. Alternatively, you can also pick specific metapackages to install based on your needs. All metapackages are installed using the standard Linux apt-get method - for example, to get the complete toolset, you'd use the command apt-get install kali-linux-all.</p><p>Once you've installed your desired tools and made sure you've changed the default passwords, you're all set to start using Kali. Happy hacking!</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ For digital transformation to work, developers need to take security seriously ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/digital-transformation/31251/for-digital-transformation-to-work-developers-need-to-take-security</link>
                                                                            <description>
                            <![CDATA[ Security heads at GSK, M&S and Williams believe software engineers need a guiding hand ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">k29C2ec2uyqiCPqrRcBsqp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6RktghQ98dMzmGtESRQA3Q-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 Jun 2018 05:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6RktghQ98dMzmGtESRQA3Q-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[security]]></media:description>                                                            <media:text><![CDATA[security]]></media:text>
                                <media:title type="plain"><![CDATA[security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6RktghQ98dMzmGtESRQA3Q-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When it comes to innovation, many IT leaders are fond of the mantra 'move fast and break things'. However, if you're responsible for the integrity and availability of your organisation's IT systems, breaking things can have some pretty disastrous consequences.</p><p>So how do some of the tech industry's top security chiefs handle the problem of ensuring their companies can move at the necessary speed required to maintain a viable digital transformation initiative whilst also keeping everything as protected as possible?</p><p>For Marks & Spencer's head of information security, Lee Barney, the answer is in making sure that you're properly implementing <a href="https://www.itpro.com/devops/28097/what-is-devops" target="_blank" data-original-url="https://www.itpro.com/devops/28097/what-is-devops">DevOps practices</a> and <a href="https://www.itpro.com/strategy/28239/getting-buy-in-on-agile" target="_blank" data-original-url="https://www.itpro.com/strategy/28239/getting-buy-in-on-agile">agile methodologies</a>. The rest, he says, will follow naturally.</p><p>"We bake the responsibility for cybersecurity into the first line of defence," he explains. "Making sure the software engineers know exactly what they need to do to code securely, so they are as good as the red team [penetration testers probing the infrastructure for vulnerabilities], for example, in identifying unsecure code and avoiding that... that is the way to do it.</p><p>"If you've gone the whole hog with DevOps, that should be fine, because the people who are actually making the changes - not just the software engineers but the people who are responsible for making sure that particular product is up and running - they also know about security. They know enough security to know when they don't know enough, and they then come to you and ask for assistance."</p><p>John Meakin, CISO of GlaxoSmithKline, agrees that the key is in enabling developers and giving them a good toolkit for securing and testing their code. After all, he points out - they're the ones that are going to be responsible for actually delivering security, rather than the CISO.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud-computing/29944/devops-in-the-cloud-everything-you-need-to-know" data-original-url="/cloud-computing/29944/devops-in-the-cloud-everything-you-need-to-know">DevOps in the cloud: everything you need to know</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/collaboration-software/28797/the-role-of-collaboration-in-digital-transformation" data-original-url="/collaboration-software/28797/the-role-of-collaboration-in-digital-transformation">The role of collaboration in digital transformation</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-intelligence/25264/how-analytics-helped-williams-deliver-a-podium-finish-at-italian-grand" data-original-url="/business-intelligence/25264/how-analytics-helped-williams-deliver-a-podium-finish-at-italian-grand">How analytics helped Williams deliver a podium finish at Italian Grand Prix</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/digital-transformation/31168/four-ways-cios-can-drive-digital-transformation" data-original-url="/digital-transformation/31168/four-ways-cios-can-drive-digital-transformation">Four ways CIOs can drive digital transformation</a></p></div></div><p>"You basically let go and allow them to do the security - so long as you're there," he says. "You've got to be there and you've got to be confident in telling them when they're doing it wrong. Because you're there, you're [telling them] early enough that it makes a difference.</p><p>"If the design is fundamentally wrong, then you need to point that out; you need to point out the risk. Not say to them 'the design is wrong, this is how you design it'. You point out the risk, which leads them to the decision 'oh, the design was wrong, I need to design it a different way'."</p><p>For Graeme Hackland, <a href="https://www.itpro.com/business-intelligence/25264/how-analytics-helped-williams-deliver-a-podium-finish-at-italian-grand" target="_blank" data-original-url="https://www.itpro.com/business-intelligence/25264/how-analytics-helped-williams-deliver-a-podium-finish-at-italian-grand">CIO of Formula One team Williams</a>, achieving 'security by design' in a DevOps environment is tricky if your development team hasn't specifically trained for it. If integrating security as a core part of the development process isn't a natural thing for them, developers will often see the addition of security as something which slows them down when they're on a tight deadline.</p><p>"We're getting to the point where you have to get to your developers a lot earlier and get them into that mindset and thinking fairly early in their career," he states. "So it's focusing on the human aspect from my point of view, and making sure that your coders and the testers who are sitting right next to them are in that mindset just without even having to think about it - it's just part of who they are."</p><p>However, Meakin also warns that developers need to meet security personnel halfway. While he noted that the culture of a developer community isn't going to change overnight, he stressed the importance of developers evolving and engaging with security on a deeper level.</p><p>Thankfully, he sees a new breed of developers and development managers entering the industry who do truly understand the value of security and are happy to work with security teams as a core part of the development process.</p><p>"One of the great things within GSK is that there's been a recognition that not only does security need to adapt its approach but the developer community themselves need to adapt their mindset," Meakin says.</p><p>"What we're finding is that as we look out at the developer community as part of a natural refresh, we're finding a generation of developers - including development managers - who really get security. They don't know all the techie details we do... but they get security and they're prepared to give security almost equal weighting with business function points."</p><p><em>Picture: Shutterstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ “It’s the legacy that gets you”, warns ex-TalkTalk boss  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-breaches/31245/it-s-the-legacy-that-gets-you-warns-ex-talktalk-boss</link>
                                                                            <description>
                            <![CDATA[ Dido Harding urges companies to decommission unsecured legacy systems to avoid a costly data breach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2t6Vf9XAhk12wTFhvGynpu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qEcx36CEunvfEHU8NxuM58-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 05 Jun 2018 14:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/qEcx36CEunvfEHU8NxuM58-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[TalkTalk logo]]></media:description>                                                            <media:text><![CDATA[TalkTalk logo]]></media:text>
                                <media:title type="plain"><![CDATA[TalkTalk logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qEcx36CEunvfEHU8NxuM58-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The former CEO of TalkTalk, who witnessed the fallout from the telecom provider's 2015 hack, has issued a stark warning to companies, advising them to invest in decommissioning their legacy technology systems before it's too late.</p><p>Speaking at the annual InfoSecurity Europe conference in London, Dido Harding told attendees that if they did not take the time to audit their legacy technology, it may have dire consequences further down the line.</p><p>Harding speaks from experience; it was a flaw in a legacy system that caused the catastrophic data breach of TalkTalk's systems in 2015 and led to the theft of 157,000 customers' bank details and personal information, as well as <a href="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack" target="_blank" data-original-url="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack">a then-record breaking fine from the ICO of 400,000</a>.</p><p>"We were a business that had grown through a lot of acquisitions, and a business that we had bought had bought a business, that had bought a business, that had a legacy website that had an extremely simple SQL injection vulnerability in a legacy website that had not been used in two of those three acquisitions."</p><p>TalkTalk failed to properly scan the infrastructure of Tiscali when it bought the company's UK business in 2009, and was unaware that three vulnerable webpages enabled hackers to gain access to a database holding customer information, or that the database version was outdated and out of support. </p><p>According to Harding, the flaw went undiscovered despite penetration testing, security audits and other forms of cyber due diligence being carried out at the time Tiscali was acquired by TalkTalk. "None of us found it. We should have done, but none of us did."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack" data-original-url="/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack">TalkTalk hack: Two men plead guilty to TalkTalk hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach" data-original-url="/security/28810/how-to-react-to-a-data-breach">Data breach response: How to react when your business gets hit</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/25490/talktalk-hack-should-the-company-have-encrypted-customer-data" data-original-url="/security/25490/talktalk-hack-should-the-company-have-encrypted-customer-data">TalkTalk hack: should the company have encrypted customer data?</a></p></div></div><p>"It is the legacy that gets you," she added. "It's acquisitions and legacy within acquisitions that gets you. And it's business leaders not really hearing from their security experts that they need to spend money in decommissioning the legacy - whether they acquired it or built it themselves. And that's pretty much what happened to us."</p><p>Harding also talked in more detail about the infamous hack, including laying out TalkTalk's immediate response to it in more detail. She said that her biggest regret was not informing customers earlier, and reminded attendees that three months after the hack, TalkTalk's customer base reported higher satisfaction and lower churn than it did before.</p><p>One of the former CEO's most important takeaways from the hack was that security is a board-level issue, but also that boards are looking at security in the wrong way. Rather than looking at security as a black-and-white, pass-fail metric, boards need to see security as a spectrum of risk.</p><p>"The vast majority of boards want to be able to abdicate responsibility by asking their security professionals 'are we ok?'," she said, "and you mustn't let them ask that question."</p><p>"If you're running an oil rig, as the chief exec, you wouldn't go 'are we physically OK?'. You'd ask a different question; you'd say 'what are the risks? What are the risks I'm happy to accept, and what are the risks that I'm really worried about that we need to be pushing to mitigate?'"</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kali Linux comes to Windows 10, handing hacking tools to pen testers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/penetration-testing/30697/kali-linux-comes-to-windows-10-handing-hacking-tools-to-pen-testers</link>
                                                                            <description>
                            <![CDATA[ Hacker-friendly distro arrives on Windows Subsystem for Linux ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">piFi89nnaUweVJib1zNwcm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dF5KwnXo7RGbYHjT7MtqHQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 Mar 2018 10:59:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dF5KwnXo7RGbYHjT7MtqHQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dF5KwnXo7RGbYHjT7MtqHQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kali Linux is now officially available on the Microsoft Store, marking another milestone in Microsoft's recent bid to support open source software.</p><p>Running on <a href="https://blogs.msdn.microsoft.com/commandline/2017/05/11/new-distros-coming-to-bashwsl-via-windows-store" target="_blank">Windows Subsystem for Linux (WSL)</a>, a feature introduced as part of last year's Fall Creators Update that allows users to run various Linux distros on top of existing Windows 10 installations, Kali Linux joins other popular distros such as openSUSE, Fedora and Ubuntu.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29630/the-future-of-cyber-security" data-original-url="/security/29630/the-future-of-cyber-security">The future of cyber security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29224/the-cyber-security-threat-in-charts" data-original-url="/security/29224/the-cyber-security-threat-in-charts">The cyber security threat in six charts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28959/the-human-security-risk" data-original-url="/security/28959/the-human-security-risk">The human security risk</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a></p></div></div><p>"Our community expressed great interest in bringing Kali Linux to WSL in response to a blog post on Kali Linux on WSL. We are happy to officially introduce Kali Linux on WSL," said Microsoft's WSL programme manager, Tara Raj, as part of a <a href="https://blogs.msdn.microsoft.com/commandline/2018/03/05/kali-linux-for-wsl" target="_blank">blog post</a> announcing the distro's availability.</p><p>"We would like to extend our sincerest thanks to the Kali Linux team and especially [Kali lead developer] Mati Aharoni for all their patience, hard work and support to plan, build, and publish their distro packages in the Windows Store. Thank you!"</p><p>Kali Linux, a security-focused Linux distro based on Debian, is designed primarily for 'offensive security' - a branch of cyber security that involves <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">ethical hackers</a>attacking businesses in order to expose flaws in their networks that can then be fixed, a process known as penetration testing.</p><p>As well as <a href="https://www.itpro.com/security/20288/penetration-testing-enterprise-guide" target="_blank" data-original-url="https://www.itpro.com/security/20288/penetration-testing-enterprise-guide">penetration testers</a> and red teams, the distro is also used by actual cyber criminals, due to its effectiveness. The software comes pre-packaged with a variety of different hacking tools, including password crackers, packet sniffers and exploit tools.</p><p>Ian Thornton-Trump, cyber vulnerability and threat hunting lead at Ladbrokes Coral, told<em>IT Pro</em> that such tools could be dangerous in the wrong hands, but equally warned that using these tools on Windows 10 could expose hackers, due to the type of data Microsoft collects from the OS.</p><p>"Windows 10 collects a ton of user telemetry. If you're going to get your hack on, you're going to get caught," he said,"and in the US, you may go to jail for a very long time - especially if you are a jerk and go after infrastructure you don't own. So, it's like a bear trap for script kiddies and entrepreneurial cyber criminals."</p><p>However, he also pointed out that making Kali more accessible could lead to improvements in overall security, such as security teams using it to illustrate network vulnerabilities to board members.</p><p>"Kali is pure red, like the blood of your cyber enemies. But I do think it may do some good if used to improve security, and the key word is responsibly," he said. "Learning is always cool - getting busted under the CFAA because OPSEC training is not included in Kali is un-cool. Bottom line: hack what you own. If you don't own, it don't hack it - unless you have written permission."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ De Montfort University launches a week of cyber security events ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cyber-security/30609/de-montfort-university-launches-a-week-of-cyber-security-events</link>
                                                                            <description>
                            <![CDATA[ DMU students will be able to gain practical experience from industry experts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dzMRZZZbpEAWZNfY451hZf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iqWWZW3hUsJ8mBtfKMsbJF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Feb 2018 09:46:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iqWWZW3hUsJ8mBtfKMsbJF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iqWWZW3hUsJ8mBtfKMsbJF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>De Montfort University in Leicester is launching a week-long programme of hands-on events designed to give students a chance to get to grips with the practical aspects of cyber security.</p><p>Beginning this Saturday, #DMUCyberWeek will include challenges, workshops and talks lead by some of the security industry's top minds, such as researchers from Check Point, BT, Deloitte and Airbus.</p><p>"We are fortunate in the Cyber Technology Institute to have such excellent relationships with industry," said the head of DMU's school of computer science and informatics, Professor Helge Janicke.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" data-original-url="/careers/28212/a-guide-to-cyber-security-certification-and-training">A guide to cyber security certification and training</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/625504/cyber-security-challenge-uk-launched" data-original-url="/625504/cyber-security-challenge-uk-launched">Cyber Security Challenge UK launched</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29224/the-cyber-security-threat-in-charts" data-original-url="/security/29224/the-cyber-security-threat-in-charts">The cyber security threat in six charts</a></p></div></div><p>"#DMUCyberWeek represents an important knowledge exchange opportunity - our students have the chance to meet potential employers and our partners get to meet the future talent of their industry."</p><p>One of the sessions involves a digital forensics challenge that has been featured at Las Vegas' infamous Defcon security show and is co-hosted by former DMU alumnus Molly Betts, who is now part of Airbus' cyber forensics division, following a placement with the company as part of her studies.</p><p>The programme will also play host to the official start of Cyber Security Challenge UK's 2018 schedule. The government-endorsed initiative hosts an annual series of competitions designed to encourage engagement with and participation in the security community among students.</p><p>#DMUCyberWeek will host the initiative's first Capture the Flag event, which is part of the qualifying rounds to earn a place in the final Masterclass round. Teams of students must work together to solve a variety of security problems and earn points.</p><p>"I love taking part in anything run by Cyber Security Challenge UK," said Chris Hatton, second-year DMU computer security student and secretary of the university's cyber security society, DMU Hackers. "It's a great way to get experience and I'm keen to encourage other DMU Hackers to join in."</p><p>"Competitions like these are great for three reasons - they're really fun, they're the best way to learn and they're perfect for networking and getting your name out there if you want to get into cyber security. #DMUCyberWeek is definitely one of the best weeks at DMU. You just don't get another chance like it to hear from and speak to so many industry experts."</p><p>Getting more students and young people into the world of cyber security is one of the industry's top priorities, as reports have indicated that a looming skills gap could be set to leave organisations <a href="https://www.itpro.com/strategy/27923/cyber-skills-gap-cybersecurity-skills-gap-leaves-one-in-four-organisations-exposed" target="_blank" data-original-url="https://www.itpro.com/strategy/27923/cyber-skills-gap-cybersecurity-skills-gap-leaves-one-in-four-organisations-exposed">dangerously lacking in talented security personnel</a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC blocks millions of cyber attacks launched against UK ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/national-cyber-security-centre-ncsc/30462/ncsc-blocks-millions-of-cyber-attacks-launched-against-uk</link>
                                                                            <description>
                            <![CDATA[ But hackers will respond with fresh ways to target businesses and citizens, body warns ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">d1eAqXmum2SL95Hn8gmj6q</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YDDFz2U2cRjpiRXpDNTtsR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 05 Feb 2018 12:54:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Lee Bell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YDDFz2U2cRjpiRXpDNTtsR-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YDDFz2U2cRjpiRXpDNTtsR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals will change their tactics in response to the National Cyber Security Centre's (NCSC's) success in blocking millions of attacks against UK businesses over the last year, the organisation's director warned today.</p><p>In a report entitled <a href="https://www.ncsc.gov.uk/information/active-cyber-defence-one-year">Active Cyber Defence - One Year On</a>', the GCHQ-led agency today detailed the success it has had in reducing cybercrime against businesses and citizens since it introduced its four Active Cyber Defence (ACD) programmes a year ago, under the government's National Cyber Security Strategy.</p><p>These four programmes are aimed at improving UK security by checking public body websites' security, blocking fake emails, thwarting phishing attacks and stopping public sector bodies' IT systems from landing on malicious websites.</p><p>As a result, the UK's share of visible global phishing attacks has almost halved since the measures began a year ago, dropping from 5.3% in June 2016 to 3.1% November 2017, according to the report. The organisation also blocked an average 4.5 million malicious emails per month from reaching users, and carried out more than one million security scans and seven million security tests on public sector websites.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29726/what-is-cyber-terrorism" data-original-url="/security/29726/what-is-cyber-terrorism">What is cyber terrorism?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/27497/philip-hammond-outlines-19-billion-cybersecurity-counter-attack" data-original-url="/hacking/27497/philip-hammond-outlines-19-billion-cybersecurity-counter-attack">Philip Hammond outlines £1.9 billion cybersecurity counter-attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs" data-original-url="/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs">Kaspersky offers hackers $100,000 for spotting bugs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/national-cyber-security-centre-ncsc/30355/russian-cyber-attack-would-cripple-uk-infrastructure-warns" data-original-url="/national-cyber-security-centre-ncsc/30355/russian-cyber-attack-would-cripple-uk-infrastructure-warns">Russian cyber attack would cripple UK infrastructure, warns defence secretary</a></p></div></div><p>Additionally, the NCSC removed 121,479 UK-hosted phishing sites, 18,067 of which were spoofing UK government services. As a result, the average time it took to take down sites spoofing government services dropped from 42 hours to 10 hours, it said.</p><p>ACD has also accommodated for a dramatic drop of scam emails from bogus @gov.uk' accounts, the report said, with a total of 515,658 rejected over the year.</p><p>NCSC technical director Ian Levy said: "The ACD programme intends to increase our cyber adversaries' risk and reduces their return on investment to protect the majority of people in the UK from cyber attacks. The results are positive, but there is a lot more work to be done."</p><p>However, he warned that the programmes' success will see attackers alter their tactics.</p><p>"The successes we have had in our first year will cause attackers to change their behaviour and we will need to adapt," he said. "Our measures seem to already be having a great security benefit - we now need to incentivise others to do similar things to scale up the benefits to best protect the UK from commodity cyberattacks in a measurable way."</p><p>The NCSC's report also listed the 10 most-spoofed government departments, revealing that HMRC is the most targeted, with 16,064 fake websites taken down. Also on the list are the DVLA, the Student Loans Company and the Crown Prosecution Service.</p><p>The report comes after UK defence secretary Gavin Williamson <a href="https://www.itpro.com/national-cyber-security-centre-ncsc/30355/russian-cyber-attack-would-cripple-uk-infrastructure-warns" data-original-url="https://www.itpro.com/national-cyber-security-centre-ncsc/30355/russian-cyber-attack-would-cripple-uk-infrastructure-warns">warned that a cyber attack</a> by Russia could cripple Britain's infrastructure and cause "thousands and thousands and thousands of deaths". The NCSC's head, Ciaran Martin, had earlier claimed that an attack on the UK's energy infrastructure or election process "is a matter of when, not if".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 3 reasons why Nadine Dorries is totally wrong about password sharing ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/30089/3-reasons-why-nadine-dorries-is-totally-wrong-about-password-sharing</link>
                                                                            <description>
                            <![CDATA[ Frustration abounds as MPs expose their backwards security practises ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uiCsMdYaUAaaM2z13NyyhB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/T5otn7g3g38REfj2ZVHKvY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Dec 2017 17:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T5otn7g3g38REfj2ZVHKvY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[facepalm sad social media]]></media:description>                                                            <media:text><![CDATA[facepalm sad social media]]></media:text>
                                <media:title type="plain"><![CDATA[facepalm sad social media]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/T5otn7g3g38REfj2ZVHKvY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Shh - what's that? If you listen very, very carefully, you'll hear it; it's the sound of countless security experts smashing their heads against their keyboards in frustration. The cause, <a href="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption" target="_blank" data-original-url="https://www.itpro.com/security/28380/deeply-misguided-tech-industry-rejects-rudd-s-attack-on-encryption">as so often before</a>, is the government's laughable attitude to data privacy and cyber security.</p><p>Where to begin with this latest shambles? You may recall that First Secretary of State Damian Green was allegedly found to have rude and naughty pictures of the pornographic variety on his government-issued computer, which Green denies.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29705/what-are-biometrics" data-original-url="/security/29705/what-are-biometrics">What are biometrics?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28576/dreaming-of-a-world-without-passwords" data-original-url="/security/28576/dreaming-of-a-world-without-passwords">Dreaming of a world without passwords</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="/security/29093/what-is-phishing">What is phishing?</a></p></div></div><p>Nadine Dorries, Conservative MP for Mid Beds, leapt to Green's defence over the weekend, pointing out that if porn was found on Green's computer, it may not have been him who was downloading and/or viewing it on taxpayer time. After all, she said, her staff use her login to access her official computer all the time. Even interns on exchange programmes!</p><p>Er, sorry... What?</p><p>Yes folks, you read that correctly - Dorries is so free and easy with her access credentials that she even hands them out to visiting exchange students. To make matters worse, several of her fellow MPs admitted they also share their login details with staff, including Nick Boles, Will Quince and Robert Syms.</p><p>Of course, Dorries was quick to downplay the seriousness of her actions, stating that all she has on her computer is a shared email account, with no access to government documents. Boles, similarly, said that only the four people he employs to deal with correspondence from constituents have access to the passwords, which are regularly changed.</p><p>For the avoidance of doubt, let's be crystal clear: this is a dangerous, insecure and irresponsible practice. Under no circumstances should anyone be sharing one login between multiple staff members. There are numerous ways to ensure staff members can access a shared computer, mailbox or file storage system without having one login that simply gets passed around, and the fact that government MPs are apparently not using any of them is extremely alarming.</p><p>Dorries and co claim that sharing their login with staff isn't an issue, but let's take the time to unpick some of the many, many problems with these arguments.</p><p>Firstly, there's the issue of lateral movement. Dorries says that the only thing on the computer is a shared email account. Even if that's true, the computer itself is 'Westminster-based', and is likely to be connected to some kind of internal network. This opens up the possibility for lateral movement, using Dorries' machine as a way to gain access to a more important target within the network.</p><p>Then there's the issue of data protection. The shared mailbox used by the staff of Dorries and Boles presumably contains at least a partial list of constituents' names and email addresses, along with who knows what additional information shared as part of their correspondence. Behaviour like this puts all of that information at risk.</p><p>Last but not least, accountability is the biggest problem with using a shared login - and one that is best illustrated, ironically, by the very issue that prompted Dorries' admission in the first place. She is quite right in stating that if Green's access credentials were shared by his staff, there's no way of proving that it was him that was allegedly looking at porn, but that's a huge problem.</p><p>Let's imagine that, instead of perusing some nudes, the First Secretary of State was instead accused of using his computer to <a href="https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs" target="_blank" data-original-url="https://www.itpro.com/antivirus/30085/kaspersky-offers-hackers-100000-for-spotting-bugs">leak classified intelligence data to Russian agents</a>. With a single shared login, it's virtually impossible to trace the source of the leak back to the mole. If everyone has their own credentials, it's instantly obvious.</p><p>The concept of not sharing your username and password with anyone is a basic, fundamental tenet of cyber security best practice, and the tools to ensure that you shouldn't need to share your credentials have existed for years. Considering that the Tories are supposed to be the party of business, its own staff seem to be <a href="https://www.itpro.com/public-sector/29288/whatsapp-amber-not-getting-the-message" target="_blank" data-original-url="https://www.itpro.com/public-sector/29288/whatsapp-amber-not-getting-the-message">trailing laughably far behind the curve</a> when it comes to keeping up with industry security standards - which would be funny if it wasn't so alarming.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>