<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/ethical-hacking"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Ethical-hacking ]]></title>
                <link>https://www.itpro.com/uk/tag/ethical-hacking</link>
        <description><![CDATA[ All the latest ethical-hacking content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Wed, 08 Nov 2023 07:00:21 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Why the Space Force wants white hats to attack a satellite ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A US space launch is a very high-security affair. Systems are locked down, many of the staff hold national security clearance, and the rocket and its payload are carefully protected.</p><p>But when SpaceX launched its CRS-28 resupply mission to the International Space Station (ISS) in June, it did so carrying a special satellite that the US military was actively encouraging people to hack.</p><p>Run by the US Space Force, Hack-a-Sat was essentially a game of Capture the Flag. Organizers tasked <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker"><u>ethical hackers</u></a> with flexing their skills to break into a satellite and discover a special code, in a race against four other competing teams. The military hopes that this will also help raise awareness around cyber threats to space hardware.</p><p>The diminutive 34 x 11 x 11cm “cube” satellite is named Moonlighter and was deployed into low Earth orbit after about a month aboard the ISS, and was the target in this year’s Hack-A-Sat competition.</p><p>The event brings skilled cyber enthusiasts together to build enthusiasm for careers in the sector and specifically attract raw talent to the field of cyber security for vital communications satellites.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XwWCccN8DFYGdyRyZj9Eo3" name="GettyImages-1423513491-email-BEC-crop.jpg" caption="" alt="A CGI render of a white envelope being shot at from all directions by arrows with red-tips, to represent business email compromise (BEC)." src="https://cdn.mos.cms.futurecdn.net/XwWCccN8DFYGdyRyZj9Eo3.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec" target="_blank"><strong>What is Business Email Compromise (BEC)?</strong></a></p></div></div><p>The event brings skilled cyber enthusiasts together to build enthusiasm for careers in the sector and specifically attract raw talent to the field of cyber security for vital communications satellites. This could help protect government assets from a new generation of threat actors, and address the <a href="https://www.itpro.com/security/strain-of-cyber-skills-deficit-still-impacting-firms-despite-global-workforce-surge"><u>ongoing cyber skills deficit</u></a>.</p><p>“They started to go and ask all the different organizations within the government and military saying, ‘Hey, can you let these hackers, these top cybersecurity enthusiasts, go and hack into your systems?’, and their first response was, ‘Absolutely not. No way’,” says Captain Kevin Bernert, the Space Force’s Hack-A-Sat program manager.</p><p>But Captain Bernert’s team persisted. In the first few years, the competition was run on <a href="https://www.itpro.com/virtualisation/31628/what-is-server-virtualisation"><u>virtual machines (VMs)</u></a> down on Earth, or actual space hardware planted firmly on the ground. This year, Moonlighter was actually put orbit where it patiently waited to be hacked.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="koNvE9zmQFam7EYpnGTT9m" name="ThreatLabz Report_The state of encrypted attacks_listing.jfif.jpg" caption="" alt="Whitepaper cover with title over image of high rise buildings with red circular digital icons dotted around" src="https://cdn.mos.cms.futurecdn.net/koNvE9zmQFam7EYpnGTT9m.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how the encrypted threat landscape has changed over time<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/threatlabz-report-the-state-of-encrypted-attacks">DOWNLOAD NOW</a></p></div></div><p>It’s a real test for the competitors, as there are specific difficulties that we don’t need to deal with down on Earth. “With space vehicles orbiting the Earth at high speeds, you only have a certain amount of opportunities to make contact with that vehicle,” says Bernert. </p><p>Hackers trying to send a command package, for example, might not know if it was successfully executed until the next time they can make contact. Other challenges include limited <a href="https://www.itpro.com/broadband/30274/what-is-bandwidth"><u>bandwidth</u></a> and tricky power management. Hackers must be careful about how much energy their code uses on a device powered by only a solar panel.</p><p>Would-be attackers also need to take into account complex orbital mechanics to establish a connection with their target. Other aspects of the competition will be more familiar.</p><p>“It&apos;s still essentially a computer,” says Bernert. “You still have to apply all the cyber security principles. Now, it&apos;s just in a more rigorous domain.”</p><h2 id="cyber-attack-innovation">Cyber attack innovation</h2><p>To communicate with the satellite in orbit, teams will use the same ground stations that are used for ordinary satellites. Moonlighter has been sandboxed so that even though the satellite is in space, nothing too dramatic can be compromised. </p><p>“It works just like any other satellite would work in Low Earth Orbit,” says Bernert. “We don&apos;t have a propulsion system on it, so they won&apos;t be able to just send it off into deep space or into the Earth&apos;s atmosphere.” The satellite also has a built-in “reset” button that the military can use to restore the sandbox to a blank slate.</p><p>The competition is as realistic as possible and the organizers urge teams to pick members who have skills in the different disciplines such a complex hacking task requires, including radio communications, exploit development, satellite operations. and astrophysics.</p><p>Bernert is confident that by tapping into this “untraditional” pool of individuals, the task can be solved in innovative ways. But even with the right people, winning the competition will require an effective strategy.</p><p>“We let the competitors get creative with how they want to go about denying or degrading their competitors&apos; satellites, but we also give them the opportunity to have game theory get involved,” says Bernert, describing how teams will have to choose between playing aggressively, to capture their opponents’ flags, or as in a real cyber-conflict, choosing to play more defensively to protect their own.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jcRn6x39ApowgWbrWX2wmA" name="GettyImages-1210827873-North Korea- Cyber.jpg" caption="" alt="A hooded figre standing in front of a digital version of the North Korean flag" src="https://cdn.mos.cms.futurecdn.net/jcRn6x39ApowgWbrWX2wmA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/should-your-business-worry-about-north-korean-cyber-attacks" target="_blank"><strong>Should your business worry about North Korean cyber attacks?</strong></a></p></div></div><p>Even after the winners have been crowned and the Moonlighter satellite has been successfully compromised, the real-world stakes of the competition remain very much front of mind for those participating. Bernert’s hope, and that of Space Force, is that this can put <a href="https://www.itpro.com/security/cyber-attacks/ncsc-new-class-of-russian-cyber-attackers-seek-to-destroy-critical-infrastructure"><u>threats to critical infrastructure</u></a> in context.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=53232388&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>“People are realising that it&apos;s not just limited to specific nations with large military budgets – it&apos;s becoming a lot more proliferated and more accessible to everybody,” he says. </p><p>“With that, obviously, comes the need to make sure that systems that are now being procured and launched in rapid quantities are cyber secure, because so much of our lives for pretty much everybody across the globe is tied directly to safe satellite vehicle operations.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/why-space-force-wants-white-hats-to-attack-a-satellite</link>
                                                                            <description>
                            <![CDATA[ Authorities hope the first-of-its-kind competition could bring benefits to the cyber sector ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GuKbKtQCqPMgNeEnKmeNqf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YbcC8yDvBUesBTFirmL6G4-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Nov 2023 07:00:21 +0000</pubDate>                                                                                                                                <updated>Wed, 08 Nov 2023 13:34:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ James O&#039;Malley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/YbcC8yDvBUesBTFirmL6G4-1280-80.png">
                                                            <media:credit><![CDATA[Marc DeNofio / The Aerospace Corporation]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ Moonlighter satellite, a small cube-shaped craft with solar panel wings on either side, against a black background.]]></media:description>                                                            <media:text><![CDATA[ Moonlighter satellite, a small cube-shaped craft with solar panel wings on either side, against a black background.]]></media:text>
                                <media:title type="plain"><![CDATA[ Moonlighter satellite, a small cube-shaped craft with solar panel wings on either side, against a black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YbcC8yDvBUesBTFirmL6G4-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A US space launch is a very high-security affair. Systems are locked down, many of the staff hold national security clearance, and the rocket and its payload are carefully protected.</p><p>But when SpaceX launched its CRS-28 resupply mission to the International Space Station (ISS) in June, it did so carrying a special satellite that the US military was actively encouraging people to hack.</p><p>Run by the US Space Force, Hack-a-Sat was essentially a game of Capture the Flag. Organizers tasked <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker"><u>ethical hackers</u></a> with flexing their skills to break into a satellite and discover a special code, in a race against four other competing teams. The military hopes that this will also help raise awareness around cyber threats to space hardware.</p><p>The diminutive 34 x 11 x 11cm “cube” satellite is named Moonlighter and was deployed into low Earth orbit after about a month aboard the ISS, and was the target in this year’s Hack-A-Sat competition.</p><p>The event brings skilled cyber enthusiasts together to build enthusiasm for careers in the sector and specifically attract raw talent to the field of cyber security for vital communications satellites.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XwWCccN8DFYGdyRyZj9Eo3" name="GettyImages-1423513491-email-BEC-crop.jpg" caption="" alt="A CGI render of a white envelope being shot at from all directions by arrows with red-tips, to represent business email compromise (BEC)." src="https://cdn.mos.cms.futurecdn.net/XwWCccN8DFYGdyRyZj9Eo3.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec" target="_blank"><strong>What is Business Email Compromise (BEC)?</strong></a></p></div></div><p>The event brings skilled cyber enthusiasts together to build enthusiasm for careers in the sector and specifically attract raw talent to the field of cyber security for vital communications satellites. This could help protect government assets from a new generation of threat actors, and address the <a href="https://www.itpro.com/security/strain-of-cyber-skills-deficit-still-impacting-firms-despite-global-workforce-surge"><u>ongoing cyber skills deficit</u></a>.</p><p>“They started to go and ask all the different organizations within the government and military saying, ‘Hey, can you let these hackers, these top cybersecurity enthusiasts, go and hack into your systems?’, and their first response was, ‘Absolutely not. No way’,” says Captain Kevin Bernert, the Space Force’s Hack-A-Sat program manager.</p><p>But Captain Bernert’s team persisted. In the first few years, the competition was run on <a href="https://www.itpro.com/virtualisation/31628/what-is-server-virtualisation"><u>virtual machines (VMs)</u></a> down on Earth, or actual space hardware planted firmly on the ground. This year, Moonlighter was actually put orbit where it patiently waited to be hacked.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="koNvE9zmQFam7EYpnGTT9m" name="ThreatLabz Report_The state of encrypted attacks_listing.jfif.jpg" caption="" alt="Whitepaper cover with title over image of high rise buildings with red circular digital icons dotted around" src="https://cdn.mos.cms.futurecdn.net/koNvE9zmQFam7EYpnGTT9m.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how the encrypted threat landscape has changed over time<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/threatlabz-report-the-state-of-encrypted-attacks">DOWNLOAD NOW</a></p></div></div><p>It’s a real test for the competitors, as there are specific difficulties that we don’t need to deal with down on Earth. “With space vehicles orbiting the Earth at high speeds, you only have a certain amount of opportunities to make contact with that vehicle,” says Bernert. </p><p>Hackers trying to send a command package, for example, might not know if it was successfully executed until the next time they can make contact. Other challenges include limited <a href="https://www.itpro.com/broadband/30274/what-is-bandwidth"><u>bandwidth</u></a> and tricky power management. Hackers must be careful about how much energy their code uses on a device powered by only a solar panel.</p><p>Would-be attackers also need to take into account complex orbital mechanics to establish a connection with their target. Other aspects of the competition will be more familiar.</p><p>“It&apos;s still essentially a computer,” says Bernert. “You still have to apply all the cyber security principles. Now, it&apos;s just in a more rigorous domain.”</p><h2 id="cyber-attack-innovation">Cyber attack innovation</h2><p>To communicate with the satellite in orbit, teams will use the same ground stations that are used for ordinary satellites. Moonlighter has been sandboxed so that even though the satellite is in space, nothing too dramatic can be compromised. </p><p>“It works just like any other satellite would work in Low Earth Orbit,” says Bernert. “We don&apos;t have a propulsion system on it, so they won&apos;t be able to just send it off into deep space or into the Earth&apos;s atmosphere.” The satellite also has a built-in “reset” button that the military can use to restore the sandbox to a blank slate.</p><p>The competition is as realistic as possible and the organizers urge teams to pick members who have skills in the different disciplines such a complex hacking task requires, including radio communications, exploit development, satellite operations. and astrophysics.</p><p>Bernert is confident that by tapping into this “untraditional” pool of individuals, the task can be solved in innovative ways. But even with the right people, winning the competition will require an effective strategy.</p><p>“We let the competitors get creative with how they want to go about denying or degrading their competitors&apos; satellites, but we also give them the opportunity to have game theory get involved,” says Bernert, describing how teams will have to choose between playing aggressively, to capture their opponents’ flags, or as in a real cyber-conflict, choosing to play more defensively to protect their own.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jcRn6x39ApowgWbrWX2wmA" name="GettyImages-1210827873-North Korea- Cyber.jpg" caption="" alt="A hooded figre standing in front of a digital version of the North Korean flag" src="https://cdn.mos.cms.futurecdn.net/jcRn6x39ApowgWbrWX2wmA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/should-your-business-worry-about-north-korean-cyber-attacks" target="_blank"><strong>Should your business worry about North Korean cyber attacks?</strong></a></p></div></div><p>Even after the winners have been crowned and the Moonlighter satellite has been successfully compromised, the real-world stakes of the competition remain very much front of mind for those participating. Bernert’s hope, and that of Space Force, is that this can put <a href="https://www.itpro.com/security/cyber-attacks/ncsc-new-class-of-russian-cyber-attackers-seek-to-destroy-critical-infrastructure"><u>threats to critical infrastructure</u></a> in context.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=53232388&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>“People are realising that it&apos;s not just limited to specific nations with large military budgets – it&apos;s becoming a lot more proliferated and more accessible to everybody,” he says. </p><p>“With that, obviously, comes the need to make sure that systems that are now being procured and launched in rapid quantities are cyber secure, because so much of our lives for pretty much everybody across the globe is tied directly to safe satellite vehicle operations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI to pay up to $20k in rewards through new bug bounty program ]]></title>
                                                                                                <dc:content><![CDATA[ <p>OpenAI has unveiled a new bug bounty program offering rewards for security researchers if they can uncover vulnerabilities in its products. </p><p>In an announcement on Tuesday, the California-based AI firm said the bug bounty scheme is “essential to our commitment to develop safe and advanced AI” and deliver services that are secure, reliable, and trustworthy. </p><p>As part of the initiative, OpenAI said it will offer a tiered reward system based on the severity of bugs uncovered by researchers. </p><p>Rewards can range from as little as $200 for low-severity flaws with a maximum reward of $20,000 for “exceptional discoveries”. </p><p>“The OpenAI Bug Bounty Program is a way for us to recognize and reward the valuable insights of security researchers who contribute to keeping our technology and company secure,” the firm said in a statement. </p><p>“We invite you to report vulnerabilities, bugs, or security flaws you discover in our systems. By sharing your findings, you will play a crucial role in making our technology safer for everyone.”</p><p>Researchers participating in the new initiative will be able to disclose vulnerabilities or flaws through a partner organisation, Bugcrowd.</p><p>Bugcrowd will manage the submission and reward process, which OpenAI said is designed to “ensure a streamlined experience for all participants”. </p><h2 id="chatgpt-vulnerability-concerns">ChatGPT vulnerability concerns</h2><p>The move from OpenAI follows a period of unrest over security-related issues at the generative AI firm, which has close ties with Microsoft. </p><p>Last month, the company revealed that a bug in <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses"><u>ChatGPT</u></a> led to a <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370315/chatgpt-privacy-flaw-exposes-users-chatbot-interactions"><u>leak of users&apos; data</u></a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aWdFz5f4uyXMEphjuW8u2e" name="SOC modernisation and and the role of XDR_thumb.png" caption="" alt="Whitepaper cover with image of male colleague at workstation" src="https://cdn.mos.cms.futurecdn.net/aWdFz5f4uyXMEphjuW8u2e.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TrendMicro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>SOC modernisation and the role of XDR</strong></p><p class="fancy-box__body-text"><em>How to cope with increasing threats and IT sprawl</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/370276/soc-modernisation-and-and-the-role-of-xdr"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>This flaw meant that <a href="https://www.itpro.com/business/business-strategy/369989/openai-launches-chatgpt-plus-greater-revenue"><u>ChatGPT Plus</u></a> users began seeing user email addresses, subscriber names, payment addresses, and limited credit card information. </p><p>The issue prompted the company to temporarily take the <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369979/chatgpt-vs-chatbots-whats-the-difference"><u>chatbot</u></a> offline to work on a fix. </p><p>“The bug was discovered in the Redis client open-source library, redis-py,” OpenAI explained in a post at the time. </p><p>“As soon as we identified the bug, we reached out to the Redis maintainers with a patch to resolve the issue.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/openai-to-pay-up-to-dollar20k-in-rewards-through-new-bug-bounty-program</link>
                                                                            <description>
                            <![CDATA[ The move follows a period of unrest over data security concerns ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZzZXTsDY4Nzg33Gh3Do3kK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zwqDDCyttCAQQ9fnt5F8rX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Apr 2023 12:06:44 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Apr 2023 09:03:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zwqDDCyttCAQQ9fnt5F8rX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[lots of lime-coloured padlocks set against a green background, with one orange padlock in the middle that&#039;s unlocked]]></media:description>                                                            <media:text><![CDATA[lots of lime-coloured padlocks set against a green background, with one orange padlock in the middle that&#039;s unlocked]]></media:text>
                                <media:title type="plain"><![CDATA[lots of lime-coloured padlocks set against a green background, with one orange padlock in the middle that&#039;s unlocked]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zwqDDCyttCAQQ9fnt5F8rX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has unveiled a new bug bounty program offering rewards for security researchers if they can uncover vulnerabilities in its products. </p><p>In an announcement on Tuesday, the California-based AI firm said the bug bounty scheme is “essential to our commitment to develop safe and advanced AI” and deliver services that are secure, reliable, and trustworthy. </p><p>As part of the initiative, OpenAI said it will offer a tiered reward system based on the severity of bugs uncovered by researchers. </p><p>Rewards can range from as little as $200 for low-severity flaws with a maximum reward of $20,000 for “exceptional discoveries”. </p><p>“The OpenAI Bug Bounty Program is a way for us to recognize and reward the valuable insights of security researchers who contribute to keeping our technology and company secure,” the firm said in a statement. </p><p>“We invite you to report vulnerabilities, bugs, or security flaws you discover in our systems. By sharing your findings, you will play a crucial role in making our technology safer for everyone.”</p><p>Researchers participating in the new initiative will be able to disclose vulnerabilities or flaws through a partner organisation, Bugcrowd.</p><p>Bugcrowd will manage the submission and reward process, which OpenAI said is designed to “ensure a streamlined experience for all participants”. </p><h2 id="chatgpt-vulnerability-concerns">ChatGPT vulnerability concerns</h2><p>The move from OpenAI follows a period of unrest over security-related issues at the generative AI firm, which has close ties with Microsoft. </p><p>Last month, the company revealed that a bug in <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses"><u>ChatGPT</u></a> led to a <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370315/chatgpt-privacy-flaw-exposes-users-chatbot-interactions"><u>leak of users&apos; data</u></a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aWdFz5f4uyXMEphjuW8u2e" name="SOC modernisation and and the role of XDR_thumb.png" caption="" alt="Whitepaper cover with image of male colleague at workstation" src="https://cdn.mos.cms.futurecdn.net/aWdFz5f4uyXMEphjuW8u2e.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TrendMicro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>SOC modernisation and the role of XDR</strong></p><p class="fancy-box__body-text"><em>How to cope with increasing threats and IT sprawl</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/370276/soc-modernisation-and-and-the-role-of-xdr"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>This flaw meant that <a href="https://www.itpro.com/business/business-strategy/369989/openai-launches-chatgpt-plus-greater-revenue"><u>ChatGPT Plus</u></a> users began seeing user email addresses, subscriber names, payment addresses, and limited credit card information. </p><p>The issue prompted the company to temporarily take the <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369979/chatgpt-vs-chatbots-whats-the-difference"><u>chatbot</u></a> offline to work on a fix. </p><p>“The bug was discovered in the Redis client open-source library, redis-py,” OpenAI explained in a post at the time. </p><p>“As soon as we identified the bug, we reached out to the Redis maintainers with a patch to resolve the issue.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New ‘DarkBit’ ransomware gang shuts down Technion, demands $1.7 million ransom ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A cyber attack on the Israel Institute of Technology has brought to light the emergence of a potentially aggressive new ransomware gang, DarkBit. </p><p>The institute, known as Technion, was struck by a ransomware attack over the weekend during which hackers demanded an 80-Bitcoin ransom, equivalent to around $1.7 million (£1.4 million).</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">What is ransomware? <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/370041/ryuk-conti-ransomware-members-uk-sanctions-crackdown" data-original-url="/security/cyber-crime/370041/ryuk-conti-ransomware-members-uk-sanctions-crackdown">Ryuk, Conti ransomware members hit with UK sanctions in latest crackdown</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/370034/esxi-ransomware-florida-supreme-court-worldwide-universities" data-original-url="/security/cyber-attacks/370034/esxi-ransomware-florida-supreme-court-worldwide-universities">ESXi ransomware campaign strikes Florida Supreme Court, worldwide universities</a></p></div></div><p>In the ransomware note, the group threatened to raise the ransom sum by 30% if the academic institution failed to pay the ransom in a 48-hour period.</p><p>The <a href="https://www.itpro.com/security/ransomware/369506/ransomware-why-do-businesses-still-pay-up" data-original-url="https://www.itpro.com/security/ransomware/369506/ransomware-why-do-businesses-still-pay-up">ransomware</a> note was also littered with anti-Israeli government rhetoric, suggesting that the attack was politically motivated.</p><p>Believed to be a hacktivist operation, the likelihood of a victim paying DarkBit and then later receiving the decryptor is generally lower since the attack isn't believed to be wholly motivated by money.</p><p>“We’re sorry to inform you that we had to hack Technion network completely and transfer 'all' data to our secure servers,” the note read.</p><p>“So, keep calm, take a breath and think about an apartheid regime that causes troubles here and there.”</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1624814604936249345"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1624814604936249345"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Technion confirmed it was dealing with a security incident in a statement online on Sunday 12 February, adding that it was working to determine the full scale of exposure. </p><p>“The Technion is under cyber attack. The scope and nature of the attack are under investigation,” the statement read, “To carry out the process of collecting the information and handling it, we use the best experts in the field, in the Technion and outside, and coordinate with the authorities.”</p><p>While the exact scale of the attack is yet to be disclosed, the university said in a follow-up statement that campus activity, including exams, would not be affected. </p><h2 id="who-are-darkbit">Who are DarkBit? </h2><p>DarkBit appears to be one of the newest <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> groups to emerge in recent months. </p><p>The identity of the group remains unclear, but given the politically charged language in the ransomware note left over the weekend, the group could be the latest sophisticated ‘<a href="https://www.itpro.com/security/cyber-warfare/365716/hactivism-russia-ukraine-having-opposite-effect" data-original-url="https://www.itpro.com/security/cyber-warfare/365716/hactivism-russia-ukraine-having-opposite-effect">hacktivist</a>’ group to land on the scene.</p><p>In its Twitter bio, the group claims to be against “racism, fascism and apartheid”.</p><p>Hacktivist groups have wrought havoc on organisations globally and the subcommunity within cyber security has received special attention since the <a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far" data-original-url="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far">war in Ukraine</a> broke out. </p><p>Pro-Russian hacktivist group, Killnet, for example, has <a href="https://www.itpro.com/security/cyber-attacks/369592/killnet-hackers-claim-ddos-attack-on-eu-parliament-website" data-original-url="https://www.itpro.com/security/cyber-attacks/369592/killnet-hackers-claim-ddos-attack-on-eu-parliament-website">claimed responsibility</a> for a number of devastating attacks against public services in Ukraine since the onset of the conflict in February last year. </p><p>Earlier this month, the group launched attacks against more than a dozen US hospitals amidst its ongoing reprisal campaign against nations supporting the Ukrainian war effort.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XDpMcyCkWZKyuSYDHyEDuV" name="XDpMcyCkWZKyuSYDHyEDuV.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/XDpMcyCkWZKyuSYDHyEDuV.jpg" mos="https://cdn.mos.cms.futurecdn.net/XDpMcyCkWZKyuSYDHyEDuV.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>IDC MarketScape: Worldwide unified endpoint management services</strong></p><p class="fancy-box__body-text">2022 vendor assessment</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/369801/idc-marketscape-worldwide-unified-endpoint-management-services" data-original-url="/security/endpoint-security/369801/idc-marketscape-worldwide-unified-endpoint-management-services">FREE DOWNLOAD</a></p></div></div><p>Bogdan ‘Bob’ Botezatu, director of threat analytics at Bitdefender, told <em>IT Pro</em> that while hacktivism is far from a new trend, recent geopolitical events have resulted in a surge of hacktivist-related incidents. </p><p>“Hacktivism is known as a type of hacking to support civil, political, or religious causes. It has become chiefly consecrated with the advent of the Anonymous hacking group and has become more and more frequently used in the past few years as hacking groups affiliated with state actors have entered the scene,” he said. </p><p>“In the past year alone, since the start of Russia’s invasion of Ukraine, several hacking groups have openly offered their cyber crime expertise to support Russia’s cause by hacking into companies in countries part of NATO or the EU.” </p><p>Chris Hauk, consumer privacy champion at Pixel Privacy, noted that DarkBit’s ransomware demand message also warned Technion to “be careful when you decide to fire your employees, especially the geek ones”. </p><p>This comment, Hauk noted, could suggest that the attack could have been the result of revenge from a disgruntled former employee. </p><p>Hauk’s suggestion follows similar comments by security researcher, Dominic Alvieri, who <a href="https://twitter.com/AlvieriD/status/1624904631208779784">tweeted yesterday</a> that the group has “gone from hacktivist, to ransomware group, now to a disgruntled former employee all in one day.” </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ransomware/370053/new-darkbit-ransomware-gang-shuts-down-technion-demands-17-million</link>
                                                                            <description>
                            <![CDATA[ A politically charged ransom note suggests DarkBit are one of the newest hacktivist gangs to emerge in recent months ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">j1zgmuKFiMggiY8D5FVvAU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LGuL2WiAc6tibevwqn6nCa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Feb 2023 16:30:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LGuL2WiAc6tibevwqn6nCa-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware on a red screen]]></media:description>                                                            <media:text><![CDATA[Ransomware on a red screen]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware on a red screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LGuL2WiAc6tibevwqn6nCa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A cyber attack on the Israel Institute of Technology has brought to light the emergence of a potentially aggressive new ransomware gang, DarkBit. </p><p>The institute, known as Technion, was struck by a ransomware attack over the weekend during which hackers demanded an 80-Bitcoin ransom, equivalent to around $1.7 million (£1.4 million).</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">What is ransomware? <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/370041/ryuk-conti-ransomware-members-uk-sanctions-crackdown" data-original-url="/security/cyber-crime/370041/ryuk-conti-ransomware-members-uk-sanctions-crackdown">Ryuk, Conti ransomware members hit with UK sanctions in latest crackdown</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/370034/esxi-ransomware-florida-supreme-court-worldwide-universities" data-original-url="/security/cyber-attacks/370034/esxi-ransomware-florida-supreme-court-worldwide-universities">ESXi ransomware campaign strikes Florida Supreme Court, worldwide universities</a></p></div></div><p>In the ransomware note, the group threatened to raise the ransom sum by 30% if the academic institution failed to pay the ransom in a 48-hour period.</p><p>The <a href="https://www.itpro.com/security/ransomware/369506/ransomware-why-do-businesses-still-pay-up" data-original-url="https://www.itpro.com/security/ransomware/369506/ransomware-why-do-businesses-still-pay-up">ransomware</a> note was also littered with anti-Israeli government rhetoric, suggesting that the attack was politically motivated.</p><p>Believed to be a hacktivist operation, the likelihood of a victim paying DarkBit and then later receiving the decryptor is generally lower since the attack isn't believed to be wholly motivated by money.</p><p>“We’re sorry to inform you that we had to hack Technion network completely and transfer 'all' data to our secure servers,” the note read.</p><p>“So, keep calm, take a breath and think about an apartheid regime that causes troubles here and there.”</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1624814604936249345"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1624814604936249345"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Technion confirmed it was dealing with a security incident in a statement online on Sunday 12 February, adding that it was working to determine the full scale of exposure. </p><p>“The Technion is under cyber attack. The scope and nature of the attack are under investigation,” the statement read, “To carry out the process of collecting the information and handling it, we use the best experts in the field, in the Technion and outside, and coordinate with the authorities.”</p><p>While the exact scale of the attack is yet to be disclosed, the university said in a follow-up statement that campus activity, including exams, would not be affected. </p><h2 id="who-are-darkbit">Who are DarkBit? </h2><p>DarkBit appears to be one of the newest <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> groups to emerge in recent months. </p><p>The identity of the group remains unclear, but given the politically charged language in the ransomware note left over the weekend, the group could be the latest sophisticated ‘<a href="https://www.itpro.com/security/cyber-warfare/365716/hactivism-russia-ukraine-having-opposite-effect" data-original-url="https://www.itpro.com/security/cyber-warfare/365716/hactivism-russia-ukraine-having-opposite-effect">hacktivist</a>’ group to land on the scene.</p><p>In its Twitter bio, the group claims to be against “racism, fascism and apartheid”.</p><p>Hacktivist groups have wrought havoc on organisations globally and the subcommunity within cyber security has received special attention since the <a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far" data-original-url="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far">war in Ukraine</a> broke out. </p><p>Pro-Russian hacktivist group, Killnet, for example, has <a href="https://www.itpro.com/security/cyber-attacks/369592/killnet-hackers-claim-ddos-attack-on-eu-parliament-website" data-original-url="https://www.itpro.com/security/cyber-attacks/369592/killnet-hackers-claim-ddos-attack-on-eu-parliament-website">claimed responsibility</a> for a number of devastating attacks against public services in Ukraine since the onset of the conflict in February last year. </p><p>Earlier this month, the group launched attacks against more than a dozen US hospitals amidst its ongoing reprisal campaign against nations supporting the Ukrainian war effort.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XDpMcyCkWZKyuSYDHyEDuV" name="XDpMcyCkWZKyuSYDHyEDuV.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/XDpMcyCkWZKyuSYDHyEDuV.jpg" mos="https://cdn.mos.cms.futurecdn.net/XDpMcyCkWZKyuSYDHyEDuV.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>IDC MarketScape: Worldwide unified endpoint management services</strong></p><p class="fancy-box__body-text">2022 vendor assessment</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/369801/idc-marketscape-worldwide-unified-endpoint-management-services" data-original-url="/security/endpoint-security/369801/idc-marketscape-worldwide-unified-endpoint-management-services">FREE DOWNLOAD</a></p></div></div><p>Bogdan ‘Bob’ Botezatu, director of threat analytics at Bitdefender, told <em>IT Pro</em> that while hacktivism is far from a new trend, recent geopolitical events have resulted in a surge of hacktivist-related incidents. </p><p>“Hacktivism is known as a type of hacking to support civil, political, or religious causes. It has become chiefly consecrated with the advent of the Anonymous hacking group and has become more and more frequently used in the past few years as hacking groups affiliated with state actors have entered the scene,” he said. </p><p>“In the past year alone, since the start of Russia’s invasion of Ukraine, several hacking groups have openly offered their cyber crime expertise to support Russia’s cause by hacking into companies in countries part of NATO or the EU.” </p><p>Chris Hauk, consumer privacy champion at Pixel Privacy, noted that DarkBit’s ransomware demand message also warned Technion to “be careful when you decide to fire your employees, especially the geek ones”. </p><p>This comment, Hauk noted, could suggest that the attack could have been the result of revenge from a disgruntled former employee. </p><p>Hauk’s suggestion follows similar comments by security researcher, Dominic Alvieri, who <a href="https://twitter.com/AlvieriD/status/1624904631208779784">tweeted yesterday</a> that the group has “gone from hacktivist, to ransomware group, now to a disgruntled former employee all in one day.” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Research: Luxury cars and emergency services vehicles vulnerable to remote takeover ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A number of automotive manufacturers use systems containing vulnerabilities that could allow threat actors to hack cars, steal customer data, or complete full account takeovers, research has revealed.</p><p>Brands including Ferrari, BMW, Rolls Royce, Mercedes-Benz, Porsche, and Ford were found critically vulnerable to endpoint attacks, with flaws such as poorly-managed APIs and improper SSO configuration enabling lateral attacks and remote access to vehicles.</p><p>Researchers also found major flaws in the code used by telematics firm Spireon, which provides GPS services for more than 15 million vehicles.</p><p>Using an <a href="https://www.itpro.com/hacking/34441/how-does-a-sql-injection-attack-work" data-original-url="https://www.itpro.com/hacking/34441/how-does-a-sql-injection-attack-work">SQL injection attack</a>, Curry and his team gained remote access to all Spireon devices, used commonly by emergency services vehicles, allowing them to view live locations and remotely execute code to unlock and start the engine of vehicles, for example.</p><p>Further endpoint investigation and manipulation revealed an admin dashboard with access to the system’s 1.2 million user accounts, as well as vehicle identification numbers (VINs) and fleet location data.</p><p>Vulnerabilities in Mercedes-Benz cars allowed for public registration on an associated vehicle repair website, and this account gave the researchers access to the Mercedes-Benz GitHub. </p><p>Attackers could use this as a launch pad for remote code execution, as well as access to internal Mercedes-Benz communications channels and <a href="https://www.itpro.com/network-internet/web-hosting/368156/what-is-aws-hosting-and-how-it-underpins-the-internet-today" data-original-url="https://www.itpro.com/network-internet/web-hosting/368156/what-is-aws-hosting-and-how-it-underpins-the-internet-today">Amazon Web Services (AWS)</a> control panels.</p><p>The findings were the result of months of investigation by web application security researcher Sam Curry and others, as detailed in a full <a href="https://samcurry.net/web-hackers-vs-the-auto-industry">report</a> on his website.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eNyWocwZkU6AFRW4cbpF2B" name="eNyWocwZkU6AFRW4cbpF2B.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/eNyWocwZkU6AFRW4cbpF2B.png" mos="https://cdn.mos.cms.futurecdn.net/eNyWocwZkU6AFRW4cbpF2B.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Getting board-level buy-in for security strategy</strong></p><p class="fancy-box__body-text">Why cyber security needs to be a board-level issue</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy" data-original-url="/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy">FREE DOWNLOAD</a></p></div></div><p>Many attacks could be performed without any interaction with users at all. By searching for domains under “ferrari.com”, the team discovered a number of subdomains such as ‘api.ferrari.com’, ‘cms-dealer.ferrari.com’, ‘cms-new.ferrari.com’ and ‘cms-dealer.test.ferrari.com’.</p><p>Although manufacturers had implemented <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso" data-original-url="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on (SSO)</a> measures for these subdomains, Curry and his team found these were flawed. By extracting the Ferrari SSO JavaScript code, they could identify the specific <a href="https://www.itpro.com/development/application-programming-interface-api/358546/nearly-every-company-surveyed-experienced" data-original-url="https://www.itpro.com/development/application-programming-interface-api/358546/nearly-every-company-surveyed-experienced">API</a> routes that each used. Queries to Ferrari’s production API allowed for information to be returned on any of the company’s customers.</p><p>Through this method, attackers could access, modify, create, or remove user accounts, as well as alter their account’s role to give themselves heightened positions or list themselves as a Ferrari owner. </p><p>"Like many other industries, the automotive industry has incorporated heavy usage of APIs across many of its public services,” said Yaniv Balmas, VP of research at Salt Security.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine" data-original-url="/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine">Hyundai vulnerability allowed remote hacking of locks, engine</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/369147/11-million-tesla-cars-recalled-over-software-glitch" data-original-url="/security/vulnerability/369147/11-million-tesla-cars-recalled-over-software-glitch">1.1 million Tesla cars recalled over software glitch</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/34441/how-does-a-sql-injection-attack-work" data-original-url="/hacking/34441/how-does-a-sql-injection-attack-work">How does a SQL injection attack work?</a></p></div></div><p>“We also encountered similar issues with some of these car manufacturers and others. We can confirm these are not isolated cases and do not cover the entire attack surface and existing vulnerabilities. They do, however, show the depth and magnitude of the API adaptation issues.</p><p>“Rapid API adoption allows car manufacturers to publish more functionality to be used by car owners, dealerships, and others and is meant to provide a better user experience.</p><p>"However, human nature and history teach us that, unfortunately, usability will always be prioritised over security and privacy - and the results are very well shown by the report. We congratulate Sam Curry for publishing this wonderful research and highlighting the global API security issue."</p><p>Household brands such as Kia and Ford were also found lacking in security. Kia’s systems allowed for remote access to vehicles including car cameras through token manipulation, while an endpoint attack on Ford’s APIs granted control over customer accounts and vehicle telematics.</p><p>Curry’s full report follows his November 2022 <a href="https://twitter.com/samwcyo/status/1597695281881296897">Twitter thread</a>, which detailed the vulnerabilities that <a href="https://www.itpro.com/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine" data-original-url="https://www.itpro.com/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine">enabled remote hacking of Hyundai and Genesis cars</a> through API exploitation.</p><p>The researchers have informed all the affected companies of the vulnerabilities, which have since been fixed. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/vulnerability/369800/luxury-cars-emergency-vehicles-vulnerable-remote-takeover</link>
                                                                            <description>
                            <![CDATA[ A "global API issue" has been highlighted through months-long research into brands such as Ferrari and Mercedes-Benz, leaving owners open to hacking, account takeovers, and more ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iJ6V8XdNbR2XUMBbA5ifdk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wfFjV7Fx7GLJ2kXQSmw5FF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Jan 2023 12:38:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wfFjV7Fx7GLJ2kXQSmw5FF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up of a red Ferrari sports car]]></media:description>                                                            <media:text><![CDATA[A close up of a red Ferrari sports car]]></media:text>
                                <media:title type="plain"><![CDATA[A close up of a red Ferrari sports car]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wfFjV7Fx7GLJ2kXQSmw5FF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A number of automotive manufacturers use systems containing vulnerabilities that could allow threat actors to hack cars, steal customer data, or complete full account takeovers, research has revealed.</p><p>Brands including Ferrari, BMW, Rolls Royce, Mercedes-Benz, Porsche, and Ford were found critically vulnerable to endpoint attacks, with flaws such as poorly-managed APIs and improper SSO configuration enabling lateral attacks and remote access to vehicles.</p><p>Researchers also found major flaws in the code used by telematics firm Spireon, which provides GPS services for more than 15 million vehicles.</p><p>Using an <a href="https://www.itpro.com/hacking/34441/how-does-a-sql-injection-attack-work" data-original-url="https://www.itpro.com/hacking/34441/how-does-a-sql-injection-attack-work">SQL injection attack</a>, Curry and his team gained remote access to all Spireon devices, used commonly by emergency services vehicles, allowing them to view live locations and remotely execute code to unlock and start the engine of vehicles, for example.</p><p>Further endpoint investigation and manipulation revealed an admin dashboard with access to the system’s 1.2 million user accounts, as well as vehicle identification numbers (VINs) and fleet location data.</p><p>Vulnerabilities in Mercedes-Benz cars allowed for public registration on an associated vehicle repair website, and this account gave the researchers access to the Mercedes-Benz GitHub. </p><p>Attackers could use this as a launch pad for remote code execution, as well as access to internal Mercedes-Benz communications channels and <a href="https://www.itpro.com/network-internet/web-hosting/368156/what-is-aws-hosting-and-how-it-underpins-the-internet-today" data-original-url="https://www.itpro.com/network-internet/web-hosting/368156/what-is-aws-hosting-and-how-it-underpins-the-internet-today">Amazon Web Services (AWS)</a> control panels.</p><p>The findings were the result of months of investigation by web application security researcher Sam Curry and others, as detailed in a full <a href="https://samcurry.net/web-hackers-vs-the-auto-industry">report</a> on his website.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eNyWocwZkU6AFRW4cbpF2B" name="eNyWocwZkU6AFRW4cbpF2B.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/eNyWocwZkU6AFRW4cbpF2B.png" mos="https://cdn.mos.cms.futurecdn.net/eNyWocwZkU6AFRW4cbpF2B.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Getting board-level buy-in for security strategy</strong></p><p class="fancy-box__body-text">Why cyber security needs to be a board-level issue</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy" data-original-url="/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy">FREE DOWNLOAD</a></p></div></div><p>Many attacks could be performed without any interaction with users at all. By searching for domains under “ferrari.com”, the team discovered a number of subdomains such as ‘api.ferrari.com’, ‘cms-dealer.ferrari.com’, ‘cms-new.ferrari.com’ and ‘cms-dealer.test.ferrari.com’.</p><p>Although manufacturers had implemented <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso" data-original-url="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on (SSO)</a> measures for these subdomains, Curry and his team found these were flawed. By extracting the Ferrari SSO JavaScript code, they could identify the specific <a href="https://www.itpro.com/development/application-programming-interface-api/358546/nearly-every-company-surveyed-experienced" data-original-url="https://www.itpro.com/development/application-programming-interface-api/358546/nearly-every-company-surveyed-experienced">API</a> routes that each used. Queries to Ferrari’s production API allowed for information to be returned on any of the company’s customers.</p><p>Through this method, attackers could access, modify, create, or remove user accounts, as well as alter their account’s role to give themselves heightened positions or list themselves as a Ferrari owner. </p><p>"Like many other industries, the automotive industry has incorporated heavy usage of APIs across many of its public services,” said Yaniv Balmas, VP of research at Salt Security.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine" data-original-url="/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine">Hyundai vulnerability allowed remote hacking of locks, engine</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/369147/11-million-tesla-cars-recalled-over-software-glitch" data-original-url="/security/vulnerability/369147/11-million-tesla-cars-recalled-over-software-glitch">1.1 million Tesla cars recalled over software glitch</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/34441/how-does-a-sql-injection-attack-work" data-original-url="/hacking/34441/how-does-a-sql-injection-attack-work">How does a SQL injection attack work?</a></p></div></div><p>“We also encountered similar issues with some of these car manufacturers and others. We can confirm these are not isolated cases and do not cover the entire attack surface and existing vulnerabilities. They do, however, show the depth and magnitude of the API adaptation issues.</p><p>“Rapid API adoption allows car manufacturers to publish more functionality to be used by car owners, dealerships, and others and is meant to provide a better user experience.</p><p>"However, human nature and history teach us that, unfortunately, usability will always be prioritised over security and privacy - and the results are very well shown by the report. We congratulate Sam Curry for publishing this wonderful research and highlighting the global API security issue."</p><p>Household brands such as Kia and Ford were also found lacking in security. Kia’s systems allowed for remote access to vehicles including car cameras through token manipulation, while an endpoint attack on Ford’s APIs granted control over customer accounts and vehicle telematics.</p><p>Curry’s full report follows his November 2022 <a href="https://twitter.com/samwcyo/status/1597695281881296897">Twitter thread</a>, which detailed the vulnerabilities that <a href="https://www.itpro.com/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine" data-original-url="https://www.itpro.com/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine">enabled remote hacking of Hyundai and Genesis cars</a> through API exploitation.</p><p>The researchers have informed all the affected companies of the vulnerabilities, which have since been fixed. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Offensive Security bans use of ChatGPT in cyber security certification exams ]]></title>
                                                                                                <dc:content><![CDATA[ <p>IT and cyber security organisation Offensive Security has banned ChatGPT in its certification exams.</p><p>The company becomes the second major IT organisation to ban the use of ChatGPT after Stack Overflow did the same, prohibiting chatbot-generated answers back in December.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/369641/stack-overflow-temporarily-bans-chatgpt-from-platform" data-original-url="/technology/artificial-intelligence-ai/369641/stack-overflow-temporarily-bans-chatgpt-from-platform">Stack Overflow temporarily bans ChatGPT from platform</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/369729/chatgpt-write-our-christmas-cards" data-original-url="/technology/artificial-intelligence-ai/369729/chatgpt-write-our-christmas-cards">We asked ChatGPT to write our Christmas cards. It didn't go well</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/369766/google-upends-teams-to-counter-threat-chatgpt" data-original-url="/technology/artificial-intelligence-ai/369766/google-upends-teams-to-counter-threat-chatgpt">Google "upends" internal teams to counter threat posed by ChatGPT</a></p></div></div><p>In its Offensive Security Certified Professional (<a href="https://help.offensive-security.com/hc/en-us/articles/360040165632-OSCP-Exam-Guide" target="_blank">OSCP</a>) exam guide, Offensive Security now lists chatbots such as ChatGPT and YouChat under its exam restrictions list. Other restrictions included on the list are spoofing, commercial tools or services, automatic exploitation tools, and mass vulnerability scanners.</p><p>“Any tools that perform similar functions as those above are also prohibited. You are ultimately responsible for knowing what features or external utilities any chosen tool is using,” the company stated on its website. “The primary objective of the OSCP exam is to evaluate your skills in identifying and exploiting vulnerabilities, not in automating the process.”</p><p>The use of chatbots is also restricted from its other exams, including Offensive Security Web Expert (<a href="https://help.offensive-security.com/hc/en-us/articles/360046869951-OSWE-Exam-Guide" target="_blank">OSWE</a>), Offensive Security Experienced <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" target="_blank" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">Penetration Tester</a> (<a href="https://help.offensive-security.com/hc/en-us/articles/360050293792-OSEP-Exam-Guide" target="_blank">OSEP</a>), and Offensive Security Wireless Professional (<a href="https://help.offensive-security.com/hc/en-us/articles/360046904731-OSWP-Exam-Guide" target="_blank">OSWP</a>). Although it’s unclear when these rules were added to the guides, all of them were updated five days ago.</p><p><em>IT Pro</em> has asked Offensive Security - the team behind Kali Linux - why it has decided to ban the use of <a href="https://www.itpro.com/networking/27171/what-is-a-chatbot" target="_blank" data-original-url="https://www.itpro.com/networking/27171/what-is-a-chatbot">chatbots</a>. However, it stated in its exam guide that it will not comment on allowed or restricted tools, other than what is already included in the guide.</p><p>Developed by OpenAI, <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369729/chatgpt-write-our-christmas-cards" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/369729/chatgpt-write-our-christmas-cards">ChatGPT</a> has impressed IT professionals across the industry with its ability to generate sophisticated answers from text prompts provided by users.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1610027841827266561"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1610027841827266561"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Its power has been particularly evident in software development applications, being able to generate entire functions based on programmer prompts, and cyber security professionals have shown it can also generate basic vulnerability exploit code.</p><p>Despite this, Stack Overflow's <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369641/stack-overflow-temporarily-bans-chatgpt-from-platform" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/369641/stack-overflow-temporarily-bans-chatgpt-from-platform">decision to ban the tool</a> from its platform was made after it concluded that answers generated using it were often too erroneous. Stack Overflow moderators said this could be harmful to users who search for help with their problems.</p><p>“Because such answers are so easy to produce, a large number of people are posting a lot of answers,” said the moderators. “The volume of these answers (thousands) and the fact that the answers often require a detailed read by someone with at least some subject matter expertise in order to determine that the answer is actually bad has effectively swamped our volunteer-based quality curation infrastructure.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence-ai/369785/offensive-security-bans-chatgpt-from-cyber-certification-exams</link>
                                                                            <description>
                            <![CDATA[ It becomes the second major IT organisation to ban the use of the powerful tool that's taken the industry by storm ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3RrdbjmcU5P31cMdG6ZgKb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Nkbty4iP4SETyn4Ja5xtud-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Jan 2023 11:26:49 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Nkbty4iP4SETyn4Ja5xtud-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Programming language as seen on a computer monitor ]]></media:description>                                                            <media:text><![CDATA[Programming language as seen on a computer monitor ]]></media:text>
                                <media:title type="plain"><![CDATA[Programming language as seen on a computer monitor ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Nkbty4iP4SETyn4Ja5xtud-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IT and cyber security organisation Offensive Security has banned ChatGPT in its certification exams.</p><p>The company becomes the second major IT organisation to ban the use of ChatGPT after Stack Overflow did the same, prohibiting chatbot-generated answers back in December.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/369641/stack-overflow-temporarily-bans-chatgpt-from-platform" data-original-url="/technology/artificial-intelligence-ai/369641/stack-overflow-temporarily-bans-chatgpt-from-platform">Stack Overflow temporarily bans ChatGPT from platform</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/369729/chatgpt-write-our-christmas-cards" data-original-url="/technology/artificial-intelligence-ai/369729/chatgpt-write-our-christmas-cards">We asked ChatGPT to write our Christmas cards. It didn't go well</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/369766/google-upends-teams-to-counter-threat-chatgpt" data-original-url="/technology/artificial-intelligence-ai/369766/google-upends-teams-to-counter-threat-chatgpt">Google "upends" internal teams to counter threat posed by ChatGPT</a></p></div></div><p>In its Offensive Security Certified Professional (<a href="https://help.offensive-security.com/hc/en-us/articles/360040165632-OSCP-Exam-Guide" target="_blank">OSCP</a>) exam guide, Offensive Security now lists chatbots such as ChatGPT and YouChat under its exam restrictions list. Other restrictions included on the list are spoofing, commercial tools or services, automatic exploitation tools, and mass vulnerability scanners.</p><p>“Any tools that perform similar functions as those above are also prohibited. You are ultimately responsible for knowing what features or external utilities any chosen tool is using,” the company stated on its website. “The primary objective of the OSCP exam is to evaluate your skills in identifying and exploiting vulnerabilities, not in automating the process.”</p><p>The use of chatbots is also restricted from its other exams, including Offensive Security Web Expert (<a href="https://help.offensive-security.com/hc/en-us/articles/360046869951-OSWE-Exam-Guide" target="_blank">OSWE</a>), Offensive Security Experienced <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" target="_blank" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">Penetration Tester</a> (<a href="https://help.offensive-security.com/hc/en-us/articles/360050293792-OSEP-Exam-Guide" target="_blank">OSEP</a>), and Offensive Security Wireless Professional (<a href="https://help.offensive-security.com/hc/en-us/articles/360046904731-OSWP-Exam-Guide" target="_blank">OSWP</a>). Although it’s unclear when these rules were added to the guides, all of them were updated five days ago.</p><p><em>IT Pro</em> has asked Offensive Security - the team behind Kali Linux - why it has decided to ban the use of <a href="https://www.itpro.com/networking/27171/what-is-a-chatbot" target="_blank" data-original-url="https://www.itpro.com/networking/27171/what-is-a-chatbot">chatbots</a>. However, it stated in its exam guide that it will not comment on allowed or restricted tools, other than what is already included in the guide.</p><p>Developed by OpenAI, <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369729/chatgpt-write-our-christmas-cards" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/369729/chatgpt-write-our-christmas-cards">ChatGPT</a> has impressed IT professionals across the industry with its ability to generate sophisticated answers from text prompts provided by users.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1610027841827266561"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1610027841827266561"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Its power has been particularly evident in software development applications, being able to generate entire functions based on programmer prompts, and cyber security professionals have shown it can also generate basic vulnerability exploit code.</p><p>Despite this, Stack Overflow's <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369641/stack-overflow-temporarily-bans-chatgpt-from-platform" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/369641/stack-overflow-temporarily-bans-chatgpt-from-platform">decision to ban the tool</a> from its platform was made after it concluded that answers generated using it were often too erroneous. Stack Overflow moderators said this could be harmful to users who search for help with their problems.</p><p>“Because such answers are so easy to produce, a large number of people are posting a lot of answers,” said the moderators. “The volume of these answers (thousands) and the fact that the answers often require a detailed read by someone with at least some subject matter expertise in order to determine that the answer is actually bad has effectively swamped our volunteer-based quality curation infrastructure.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Podcast transcript: Meet the cyborg hacker ]]></title>
                                                                                                <dc:content><![CDATA[ <p><em>This automatically-generated transcript is taken from the IT Pro Podcast episode ‘</em><a href="https://www.itpro.com/security/hacking/369132/the-it-pro-podcast-meet-the-cyborg-hacker" data-original-url="https://www.itpro.com/security/hacking/369132/the-it-pro-podcast-meet-the-cyborg-hacker">Meet the cyborg hacker</a>’<em>. We apologise for any errors.</em></p><h3 class="article-body__section" id="section-adam-shepherd"><span>Adam Shepherd </span></h3><p>Hi, I'm Adam Shepherd,</p><h3 class="article-body__section" id="section-connor-jones"><span>Connor Jones </span></h3><p>And I'm Connor Jones.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>And you're listening to the IT Pro Podcast, where this week we're taking a look at the emerging world of biohacking.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Now it's probably worth making the distinction between the two types of biohacking there are in the world right now. You know, there is of course, the kind of biohacking reserved for scientists, professional and homebrew, that involves the CRISPR gene editing technology. But this of course, is is an IT podcast and we're most concerned with a form of bio hacking of the cyber kind; you know, the one involving tech baked into the human body.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Now, since the invention of computer systems, people have been finding ways to break into them and customise their operation to best suit their own needs. In recent years, however, adventurous experimenters have begun exploring how the same principles can be applied to the human body.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>The so called biohackers have explored a number of ways to combine digital technology with flesh and blood, including implantable chips, digitally enhanced prosthetic limbs and much, much more. But what potential advantages does human augmentation hold? And are there any security risks that might be associated with this emerging practice? We're joined today by Len Noe, a technical evangelist, white hat hacker at CyberArk, and self described transhumanist, who's been immersed in this world for a number of years. Len, thanks for joining us.</p><h3 class="article-body__section" id="section-len-noe"><span>Len Noe </span></h3><p>Thank you guys for having me. It's a pleasure to be here.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So Len, first of all, you've got a number of, shall we say aftermarket extras? Can you talk about some of the biohacking modifications that you've made yourself?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, to be fair, I didn't make them myself. I, the first thing I'm going to say is everything I have, I've done it as safely as humanly possible. I'm not one of those. Do It Yourself guys to do this in your garage.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Don't try this at home, kids. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Yeah. I mean, there was a time that that was the way it was, but we passed that time, we can actually get some some some safe implants. Yeah, currently, I have eight different microchips with varying degrees of functionality, but predominantly, they revolve around RFID and NFC. I can do redirection tags via NFC, I can also have chips that will handle a lot of physical access cards like MIFARE classics, HID procs one and two, pyramid and dala, I actually have a credit card payment chip in my the top of my left hand, so I can actually do tap to pay with my hand, I have a biosensing magnets so that that one's a lot of fun. It's not really a lifting magnet. But due to the way that the magnet was constructed, it actually gives me the ability to feel electromagnetic currents and electromagnetic fields, kind of like a spidey sense. So yeah, and we can get into it a little later. I'm actually in the working on the second round of my prototypes for my pegleg. Those won't be the standard microchip style things. But that's actually a Raspberry Pi Zero W2 that's been actually loaded with Kali encased in bio encapsulation, and then I'm going to be implanting that in my leg, so that way I can actually take systems into places where you can't, or shouldn't be allowed to take technology. So having it set up to run low energy Bluetooth sweeps along with auto pwns while I'm sitting here talking, so yeah, I kind of have a little bit of a fascination with human upgrades.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>This is already my favourite podcast I've ever done. This is great. Can I just ask what is what is the upside of being able to detect and sense electro magnetic fields?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, I'm also very, very passionate about physical pen testing. I'm an avid lock picker. I'm a member of multiple different lock picking clubs. And when you look at physical security, especially around warehouses, how are most of them secured? Magnetic locks, magnetic locks require electricity. So depending on the wiring and the amount of shielding in your your Romex cabling for your electromagnet, I can sit on the outside of your building, run my hands over the wall, and I can actually trace your electrical lines. So at that point, I actually have an idea of where to shim or make, you know, especially if it's a destructive pen test, I can make a small hole and basically clip the electrical wire. And if you know anything about mag locks, especially if you're dealing in like an emergency situation like a fire or a power outage, magnetic locks are automatically designed to actually go into an open state due to an emergency to allow people to get out. So basically the that's one great thing for the magnet. The other thing is it makes a really cool trick at a bar, you can pick up bottle caps and things, you know. And it's, if nothing else, it's a really cool way to get, it's a cool magic trick around young kids too.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>In the immortal words of the Insane Clown Posse: magnets, how do they work?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Why do you have to go there, man? I mean, I'm from Detroit, but I mean, in St. Cloud, we had better musicians, man, let's go with the MC5 or, or the Bay City Rollers. Ted Nugent.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>This is Shaggy 2 Dope erasure, and I will not stand for it. So in terms of some of the other practical use cases that this technology has, aside from the magnets, you mentioned some of the chips that you've been using, particularly the RFID and NFC devices, the contactless payment devices; what other kinds of use cases are there for this technology, either currently, or that you can kind of see emerging in the near future?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, I mean, at this point, it's anything around the contactless technology, we see a lot of NFC used in IoT. You know, when it comes to personal devices, almost every mobile device or tablet that's been released within the last three to five years has NFC capability. And the truth is not a lot of people understand what it is. And the fact that it by its design is an unsecured protocol. You know, the problem when it comes to NFC is we're using application level security to try and lock down an insecure protocol. You know, so anything from, you know, compromising a mobile device through the use of the implants, I mean, one of my favourites is the physical access side of things, you know, and, you know, let me, let me go into this for just a second, if I may, you know, when it comes to our physical access, a lot of places, especially in my tenure, you know, and I've been doing this kind of work for pushing 30 years, only two companies I've ever worked for had any type of multifactor for physical access locations of high, high privilege, you know, data centres, things like that. Most companies will have a single point of access, and it's usually just a bar or a card read, and then the door unlocks. So if we take a look at my implants, and the fact that I have the ability to basically emulate multiple different physical card protocols, here's where it gets funny. If I don't have a copy of a cloned badge, if I don't have a Proxmark, or some type of replay device, if I'm found in a restricted area, the worst you're going to be able to do is trespass me. You're not going to be able to get me arrested, because all I have to do is say, hey, you know the door was open, I'm here looking at the building, I thought this was part of the tour. You know, unlike the days of old, you know, where if I did have that physical piece of evidence that shows how I got in there, then I can be actually looked at as a criminal. So I'm playing a lot in the grey areas. You know, the whole point is the obfuscation. I'm not doing anything that anybody else hasn't done before in a different method, I'm just doing it in a way that would be very, very difficult from a digital forensics or incident response perspective, to be able to actually find that true root cause, on top of the fact that even if they saw some of the bulges in my my skin where I have some of my implants, when it comes to most of the privacy laws in most, you know, first world countries, they're not allowed to actually delve too deeply because it involves my personal medical, the minute it went inside my skin.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>And also, I'd imagine they're not the kind of thing that one would typically notice, unless you knew exactly what you were looking for and where, right?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Exactly. I mean, I've gotten asked a lot of questions in turn over the since I started doing this, like, you know, are these the same chips that I that, you know, are in my dog, are these chips that are in my cat, you know, and in some way the answer's yes. I mean, they all run on the same NFC style protocol. You know, and just like when it comes to a pet, you know, they have those very large wands. So they're gonna they would have to actually try and find the implant, energise the chip, to be able to get a read. Therein lies the same problem when it comes to all augmented humans, in order to be able to detect me and my chips, you would actually have to energise those chips to be able to get a read. So you would need multiple different spectrum analyzers on both high frequency and low frequency. And they would have to be strong enough to energise my entire body in order to for the detection. So from a management or you know, an actual implementation perspective, there is currently no way to actually detect an augmented human with this type of technology inside the body. And that becomes a very large problem for security professionals. And the only way that I can really give as a way to try and combat this is a true defence in depth, and a layered security approach. You know, I've said it a million times, you know, we have no problem putting multifactor authentication in front of all of our privileged data. But we don't do the same thing for our physical locations. And when if there's one person out here, like me, that has the ability to do this, I think that's fact enough that we should be looking at this as a potential threat on a larger scale, and we need to address it accordingly.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So you can clearly see that there's a real benefit to having sort of, like you said, multi layer security with a biological air to it. And you obviously yourself also, what maybe like 5% technology, both by the amount of things that you've got in you by the sounds of it.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>I'm working on it; I'll take 5% is a compliment.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So what what what attracted you to the world of biohacking in the first place?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Why do you climb a mountain? Because it's there. If anybody wants to take a Google, just google me and you can find a picture; I am, I consider the fact that I have one tattoo, it just starts at my neck and goes all the way to my my, the top of my feet. I do flesh hook suspensions for fun. So when I saw that people were actually implanting technology, it just seemed kind of like the next natural evolution to somebody like me, I considered myself to be a modern primitive for a very, very long time. So as far as I know, I was the first person that had brung the, the idea that these can be used for an offensive purpose to the security community. I know I am not the first guy to ever do this. I'm just the first guy that opened his mouth about it. And I think that goes into just the way that I see the world. I was a black hat for a very, very long time. So when I look, walk into a room, the first thing I see is okay, there are cameras, where's the the exit strategies? You know, if you tell me that this is an NFC chip that can interact with a mobile device, maybe you're going to use it for your digital business card, I'm going to look at that same device and see how can I use this in a way that would suit my purposes?</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So let's talk about some of those methods, then some of those ways in which this technology could potentially be used to target businesses. You've spoken already about some of the offensive applications of the magnets you have, for example, but what about some of the, for example, the NFC and RFID chips?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Sure. NFC, you know, like I said, it's pretty much a standard protocol on most modern mobile devices and tablets. The abilities through NFC can be anything from transferring, beaming a file, it could you can use it to set up a Wi-Fi network, you can use it to redirect. I mean, we've seen all kinds of different possibilities. So the way that I've redirected those, I released three different attacks at RSA two years ago. The first one was called Flesh Hook. Flesh Hook is a redirect. Yeah, I made the exploits. I got to name them. That's one of the benefits. So essentially, what that one was, is I would I've set up a BeEF server. And you know, for any of the newbies out there that don't remember the good old days of BeEF, BeEF is the browser extension exploit framework. This is the website that, you know, we've all heard the rumours of the minute you log into this website, the bad guys are in your system. Yeah, that's BeEF. So it's a little bit of a social engineering play. You know, I'd walk up Hey, Adam, man, check this out, dude. Let me see your phone. I found this amazing new video on YouTube. I want to show you. As soon as I can get the device in my hand, if you have NFC turned on, the large flexNExT implant that's in the top of my right hand will actually have enough distance on the antenna that it'll actually read through the actual meat of my hand. I can hold the phone in the correct orientation. It will pop up a redirector where I'm going to just send you to a video, but the minute your browser hits that website, the Java code in the HTML page is actually going to hook the browser and then I have access to the entire BeEF suite. So I can do on device spear phishing attacks, I can geolocate your device, access the cameras, I can use DNS enumeration if you're on a local network or a corporate network, I can do domain identity, subdomain identification and enumeration. Anything that I could even think of. The other one was called leprosy. Again, my attack, I named it. Leprosy doesn't really work as well against iOS devices. But when it comes to Android, once again, you know, this one is a little bit easier. Adam, oh my god, man. You know, I'm over here in the UK with you, you know, my phone died. My wife, I was just on the phone with my wife. She told me something happened to my grandson, man, can I borrow your phone for just a second? You know, of course, you know, you know, yeah, here, dude, call your wife. And again, the URL that's been programmed into the NFC chip, points to a web location where I've got an infected APK that was created with MSF Venom or, you know, a Cobalt Strike beacon. At this point, you know, it's Oh, my God, you know, let's be honest, who remembers my who remembers phone numbers anymore? What's my wife's phone? What's the country code for the United States? Plus one. Okay. So I can go through this big rigmarole of trying to remember a phone number, when actually what I'm doing is installing that APK. And as soon as I'm done, it's like, oh, shit, I can't remember the phone number man here, I'm gonna just go plug my phone in. But at this point, I have a reverse TCP connection back to the device, I can set up persistence, I can get a shell. I mean, at that point, it's whatever I want. And the third one was called handshake. You know, they're all you know, biologically related names. What can I say? And, you know, at that one, you know, I can use a Proxmark, any type of card skimmer I want, get your badge information, write it down onto one of my chips. And if we're in one of those single point access situations, I'm in your privileged locations on prem. And once again, the problem is there's zero indications of compromised to any one of these different attacks.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>I think judging by mine and Adam's reactions after the first question we came in with, and we're just like grinning like Cheshire cats, right? I think we can speak for the both of us saying we're so excited just to hear about this kind of thing, because it's not something we hear about a lot. So with that in mind, then, how many black hats like your former self, are using this in the wild or starting to think about using it in terms of real world attacks?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Okay, this is one of the hardest questions to answer in regards to doing conversations like this. I can tell you this with 100. There, there are some facts that I can give you with 100% certainty. Within the United States, one of the biggest distributors for microchip implants is a company called DangerousThings.com. Within Europe, there is a company called KSEC, K-S-E-C. So I am, I spoke with the CEO of Dangerous Things, a gentleman by the name of Amal. And from him, I was able to gain the fact that Dangerous Things has sold close to about 300,000 implants. I was actually back in y'all's neck of the woods last weekend up in Newcastle, where I actually got to meet Kai from KSEC. And between the two of us we basically came up with an estimation of between four hundred and six hundred thousand implants have been shipped. How many of those implants were actually, have actually made their way inside of a human body? We don't know, but I can tell you this much. I know that I'm using it. I know of quite a few people who are on red teams that are using this technology. We have not found any indications from any type of incidents that have actually happened in the wild where implants were shown to be the root cause, but at the same time, how would you be able to determine that, you know, and therein lies the problem. We may have, I mean, we've seen, you know, breach reports where NFC or RFID were included in the evaluation in terms of cause of breach, but without actually getting access to an individual to find out if they were actually augmented, it could have been a card, it could have been an implant, we don't know. Because, as I said before, there's really no way to determine any type of augmented human with current technology.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>And if yourself and, you know, a significant amount of other red teamers are using this technology and are interested in this technology, it's a fairly safe bet that black and grey hat actors are also interested in it and are deploying it in the wild, you know, it's not, it's not that much of a logical leap.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>No, and that's the way I see it. If once I actually brought this to the out at RSA, I knew this was going to open the door and somebody who is going to read this and there's going to be some black or grey hat somewhere that goes, Hey, this is a new vector. And due to the you know, the privacy laws and everything else, this becomes a much safer road to try and travel if you're going to try and do offensive type activities.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So let's talk about some of the practicalities of this, then, cause this is a very kind of new, very emerging field. Have you experienced any challenges with biohacking and with your implants, you know, other than getting through airport security, which I can imagine is just a barrel of laughs.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Okay, well, you brought it up - the airport is the number one question that I get. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>I'm not surprised. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>You want, would you like me to tell you how I walk, how I get through an airport? </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Absolutely. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>I put one, the left foot in front of the right and then I repeat. That's it.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>No. Does it, do none of them come up on the scanners?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>All right, let's talk about the two different types of metal detectors for two seconds. We have the magnetometer which is just kind of the archway you walk through. There is not enough combined metal in all of my implants to actually trigger a magnetometer. I'm going to carbon date myself here; before my my career in IT, you know, almost 30 years ago, I used to do the job of the TSA before there was a TSA and airport, airport security was still privatised. And don't quote me on this, but I if I remember correctly, the magnetometers would not trigger unless you had a combined metallic weight of at least a .22 calibre bullet. So I mean, if you think about it, when you walk through a metal detector, if you have like a necklace on with a gold charm, it doesn't go off, if you have earrings in, it won't go off. Now, I'm not saying that they couldn't change the sensitivity of the magnetometers to where they would detect it. But they would get so many false positives, trying to check people into an airport that it would be an unusable control. Same with the metal detectors. When you think about my implants, most of them are actually silicone, you know, with the exception of the copper antennas on the larger flexible main membrane implants or the bio magnet, which is a iron core wrapped in titanium, but that's less smaller than the size of a pea. So even if I'm doing you know, the X ray metal detector, doesn't show up, I can walk straight through, the magnetometer will not trigger. So that to me kind of says something about what we're dealing with in terms of airport security. But, you know, we can do a different talk on that one another day.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>That's quite a scary prospects in some ways, particularly if you're trying to defend against these types of attacks.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Yeah, I mean, thankfully, at least at this point, there's not a lot in aeroplanes that are relying on RFID or NFC, you know, but if I can get that pegleg you know, where I actually have a full Linux system, then yeah, that is something that could potentially interact with the Wi-Fi entertainment system on the plane, I mean, it opens a whole lot of different vectors at that point.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>But even beyond air travel, if airport security - which is, I would argue, among the most stringent kind of security, you know, scanning in terms of concealed objects and devices - If it can get past airport gate security, then security in and out of a building or or complex doesn't really stand a chance for detecting this kind of stuff, does it?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Not even, not even a little bit. You know, one one thing that I, just cause you guys are are a lot of fun, and I think you guys will get a kick out of this. I think everybody is familiar with the drug smelling dogs that are used by the authorities. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yes. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, one of the, they actually have a new type of canine that is being released to help military and law enforcement. And they're actually technology sniffing dogs. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>No. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Yes, you can look them up. So these are not used in the same way that narcotic sniffing canines are in terms of they don't use them to be able to get an arrest. They don't bring them up and smell somebody and go, okay, yeah, we've got you, we're going to take you away. They're used more in the post arrest investigation point. They're used a lot with human trafficking, child predators, things like that; people that would actually store illegal data on hard drives, in technology. So if someone gets arrested, they'll get a search warrant, they run the dog around the house looking for hard drives, thumb drives, you know, anywhere that they may have, you know, tried to store illegal and illegal things. I found out that one of the law enforcement agencies that is close to me here in Texas, actually recently got one of these drugs, these key technology smelling dogs. So after, you know, sending an email to the police department going, No, I am not crazy. Yes, I have implants. And here's here's my CV. So you can see I'm a real person, and I'm not messing with you. I'm interested in information about this dog. And after they researched me, they're like, okay, apparently cyborgs are a real thing. They became really open to, you know, having conversations, and I've actually been invited to go up to the Dallas Police Department. And we're going to see if Remi, the technology dog, is able to sniff any of the implants that I have. Because that would actually be probably one of the first ways to try and detect somebody of augmented nature. And the one point that I wanted to point out, and since you guys are definitely geeks, and take that as a hardcore compliment, if you think back to the Terminator movies, where, you know, wherever the resistance was right at the entrances, they always had the guys with the dogs, because they could smell the technology. And I just start to wonder is this going to be a situation where life imitates art or art imitates life? I don't know which, but I'm really excited to get up there. Due to my travel schedule, it's been a little difficult, but I'm hoping to be up there sometime towards the middle of November. And you know, maybe I'll drop you a line and let you guys know how it turns out.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yeah, absolutely. I'm going to ask the obvious question, how can dogs smell technology? How can anyone smell technology?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Okay. Just like the they've taught the dogs to be able to detect specific narcotics, you know, heroin, cocaine, marijuana, things like that. They actually have taught them to key in on specific components that are used in the creation of technology. The name is triphenylphosphine oxide. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Oh, wow. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>So they found one very, very specific element that is used in the creation and manufacture of technology circuit boards, hard drives, and they basically train these dogs to hit on that one specific compound. I don't know if they'd be able to smell it through the skin. I don't know. But I still think it's going to be one hell of an interesting experiment.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Hmm. Yeah, definitely. And you get to hang out with more dogs as well. So that's a win win, really, and especially in my eyes. So in terms of getting this tech into the mainstream then, because obviously, I'm just from hearing you for the past half hour, I'm super excited about it, and I'm probably not going to be alone. So say further down the line that this kind of stuff does reach consumers, the everyday consumer that is, what are the limitations you can imagine a potential regulator seeing, you know, for example, can can realistically we actually have Internet facing machine augmentations of the kind like your like your peg leg, or is that is that a hacking risk waiting to happen?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Um, well, I mean, let's be honest, you know, we can talk about QR codes and they are hacking risks waiting, just waiting to happen, and we see those on buses and trains, and taxi cabs. I don't think honestly, the imposed threat of any technology is going to stop someone from using it if there is the potential for a monetary gain. So to answer your original question, there is a lot of implants going out right now that I see is going to probably help break that stigma barrier. One of them, like I said, is the Walletmor chip that I have in my right hand, it's an actual credit card. So I can do tap to pay. I think, right now, the idea of implants is still, like you said, it's very, very fringe. And you everybody looks at me like I'm some kind of a terminator half the time. I mean, my friends shut their Bluetooth and their Wi-Fi off, the minute I walk into a room. All I want to do is just look at him when I leave and go, I'd be back. But another one that I see that's really made an impact is there's the ability, if you drive a specific model Tesla, you can get an implant and you can programme your valet key onto an implant. And you can basically just jump in your Tesla and you can drive. I think as we see a lot more of these types of implants and technologies that people can actually find a legitimate day to day use for is going to help with the concept of adoption and understanding and acceptance. Right now, there's like I said, 400,000 to 600,000 potential augmented humans out there. I see it moving beyond just the microchip concept, especially with a lot of the advancements we're seeing around graphene batteries. The big issue when it comes to any type of implant is outside of anything that's considered biomedical, there's no internal power for anything yet. And even when it comes to the pegleg, that I'm planning on putting in myself, it uses an indirect power receiver to actually power the device, but there's no battery in it. Because to charge something generates heat. So I think we're right at the precipice of you know, a whole new set of things that could be potentially coming out. I did a keynote in Newcastle over the weekend, and the title was Resistance is futile, we're already Borg. And in that talk, I just brought up some of the stuff that's actually already out there that people may not even be aware of. We've got spinal implants that are, you know, returning motility, to paralysed people, we have ocular implants that are working on giving sight to the blind, we're able to use DNA as a storage medium, and one gramme of DNA could potentially hold over seven terabytes worth of data with a retention period of over 100 years. So we are right on the cusp of so many different technological breakthroughs that cross that human technology barrier, that I think that you know, in terms of what we're going to see in the relatively near future is going to really be up to the order in which these discoveries are made.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So speaking of future technology, and just going back to the kind of Tesla use case you mentioned a little earlier, just as a brief digression. What do you think is the kind of feasibility of projects like Neuralink and other brain computer interfaces?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Oh, you brought up Neuralink, if everybody's familiar with Neuralink, but nobody's familiar with the other company. I'm very, very interested in BCI. Brain computer interfaces, especially for disabled and locked in individuals, I think it's going to be crucial. I just watched an amazing documentary on my way back from Newcastle. Dr. Phil Kennedy, the name of the documentary was called Father of the cyborgs. Dr. Phil Kennedy was actually one of the he's a neurosurgeon. And he actually was the first individual to implant brain computer interfaces into paralysed people. You know, so everybody wants to talk about Neuralink, but they don't want to talk about all the other ones. Another really big player in the BCI field is Synchron. And they're already in human trials. So I think that the idea of BCI is definitely something that's going to happen. But at the same time, all of these new technologies they do will have, you know, an underlying firmware. You know, and one of the things that I'm trying to look at in regards to this, the melding of technology and humanity is as security professionals, we already know there are going to be attack vectors there and we need to be talking about those now. You know, the attacks we see today, the vectors may have changed, but at the core, every single attack today is the same attack that it's been for the last 20 years. I mean, they're looking for credentials, I'm looking for data, I'm trying to exfiltrate things, or I'm going to ransom you, you know, the end game is going to be the same; how we get there may be different. And if we think about all this new advancements in technology, and just that crossover, what happens when ransomware starts affecting Bluetooth or internet enabled bio implants, you know, what happens if I'm, my pacemaker gets a ransomware, then it's an a real ransom at that point. You know, and, you know, we keep running towards the technology and trying to, you know, make ourselves more than human, which is absolutely the core of, you know, the trans human movement. But one thing that I've said all along, and I even started the conversation with you guys today is, it needs to be done safely. And when we look at everything that's coming up, honestly, in my opinion, the end game is still identity, you know, and being able to maintain our individual identity as we become something potentially more than human. And as such, I think our identities, our personal information, you know, identity is going to become the new security. Because once the lines between an individual and the tech stacks that they're interfacing with, you know, gets either faded or removed completely, the only thing left is the individual and the individual identity of the person that's making those interactions.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So just to round things off, then looking at the long term, what kind of potential benefits might be out there for technologists or IT professionals, you know, outside of red teams and perhaps even security, who want to explore biohacking as the practice itself matures?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, again, you know, that's like, in my opinion, that's like asking someone how, how do you want to utilise a laptop or a mobile device? I mean, these microchips were never designed to be used necessarily as offensive tools. But if you look at things like Mimikatz, which is every hacker's favourite LDAP tool, it was, it's originally designed as a an LDAP auditing tool. Any tool this, regardless of what its intended purpose was, can be reused and misconfigured and used as a weapon. So I guess I, you know, not to try and blow off your question. But I guess it depends on really, what are they trying to do? You know, it could be something, I mean, I have no doubt that maybe we're going to start seeing the ability to do OTP. If you're not familiar with it, there's an amazing ecosystem out there. It's called the VivoKey. And this is an implant, the VivoKey architecture will actually allow for one time, you know, MFA OTP, where you're actually going to validate via an implant with an app on your phone, you know, so that's a potential security advancement moving forward, it could be something as simple as using your, your chip, almost kind of like a Fido chip, where you're going to scan your implant to access your computer, again, I would still want to password in there, don't like single points of failure as from a security perspective, you know, maybe you're gonna put your, your badge for work on your chip, and you're just not going to, you know, that way you can badge in. Not everything around implants, or implanted technology is a black art, for the lack of a better term, you know, they can be used just to make people's lives a little simpler. But one of the quotes that I love to use in pretty much every single time I talk is in from my personal experience, things that make life easier, rarely make them safer. So we have to, we are the security professionals, we're the ones that you know, have to warn the masses, we're the ones that have to take care of our employees. So it's up to us to understand what these kinds of threats are, and build that layered security approach and that defence in depth, so that these types of people, people such as myself, are left sitting at the door going well, I managed to hit the badge reader, but I still don't know the key, you know, our data, our physical locations, privilege is privilege, I don't care if it's physical, I don't care if it's digital, you know, and we are the ones that have been empowered by our companies to be the gatekeepers in the security for these types of things. And we need to do our job and be aware that people like me exist and build a strategy around that knowledge to be able to stop people like me.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Well, while we could spend all day digging into the intricacies of biohacking, sadly I'm afraid that's all we've got time for this week. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Aww.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>I know, I could spend the rest of the afternoon talking about this. But our thanks once again to cyberArk's Len Noe for joining us.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>It was absolutely my pleasure, guys. I really enjoyed talking to you. Maybe we can do it again sometime. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yeah, absolutely.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Sounds great. You can find links to all of the topics we've spoken about today in the show notes and even more on our website at ITpro.co.uk.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>You can also follow us on social media as well as subscribe to our daily newsletter.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Don't forget to subscribe to the IT Pro Podcast wherever you find your podcasts. And if you're enjoying the show, leave us a rating and a review.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>We'll be back next week with more insight for the world of IT. And until then, goodbye.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Bye.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/369133/podcast-transcript-meet-the-cyborg-hacker</link>
                                                                            <description>
                            <![CDATA[ Read the full transcript for this episode of the IT Pro Podcast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4ekpSreZcLL2go22W64RcW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/e68dF8GWJKnWi2HERUMHr6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Sep 2022 06:30:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/e68dF8GWJKnWi2HERUMHr6-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Podcast transcript: Meet the cyborg hacker]]></media:description>                                                            <media:text><![CDATA[Podcast transcript: Meet the cyborg hacker]]></media:text>
                                <media:title type="plain"><![CDATA[Podcast transcript: Meet the cyborg hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/e68dF8GWJKnWi2HERUMHr6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>This automatically-generated transcript is taken from the IT Pro Podcast episode ‘</em><a href="https://www.itpro.com/security/hacking/369132/the-it-pro-podcast-meet-the-cyborg-hacker" data-original-url="https://www.itpro.com/security/hacking/369132/the-it-pro-podcast-meet-the-cyborg-hacker">Meet the cyborg hacker</a>’<em>. We apologise for any errors.</em></p><h3 class="article-body__section" id="section-adam-shepherd"><span>Adam Shepherd </span></h3><p>Hi, I'm Adam Shepherd,</p><h3 class="article-body__section" id="section-connor-jones"><span>Connor Jones </span></h3><p>And I'm Connor Jones.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>And you're listening to the IT Pro Podcast, where this week we're taking a look at the emerging world of biohacking.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Now it's probably worth making the distinction between the two types of biohacking there are in the world right now. You know, there is of course, the kind of biohacking reserved for scientists, professional and homebrew, that involves the CRISPR gene editing technology. But this of course, is is an IT podcast and we're most concerned with a form of bio hacking of the cyber kind; you know, the one involving tech baked into the human body.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Now, since the invention of computer systems, people have been finding ways to break into them and customise their operation to best suit their own needs. In recent years, however, adventurous experimenters have begun exploring how the same principles can be applied to the human body.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>The so called biohackers have explored a number of ways to combine digital technology with flesh and blood, including implantable chips, digitally enhanced prosthetic limbs and much, much more. But what potential advantages does human augmentation hold? And are there any security risks that might be associated with this emerging practice? We're joined today by Len Noe, a technical evangelist, white hat hacker at CyberArk, and self described transhumanist, who's been immersed in this world for a number of years. Len, thanks for joining us.</p><h3 class="article-body__section" id="section-len-noe"><span>Len Noe </span></h3><p>Thank you guys for having me. It's a pleasure to be here.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So Len, first of all, you've got a number of, shall we say aftermarket extras? Can you talk about some of the biohacking modifications that you've made yourself?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, to be fair, I didn't make them myself. I, the first thing I'm going to say is everything I have, I've done it as safely as humanly possible. I'm not one of those. Do It Yourself guys to do this in your garage.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Don't try this at home, kids. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Yeah. I mean, there was a time that that was the way it was, but we passed that time, we can actually get some some some safe implants. Yeah, currently, I have eight different microchips with varying degrees of functionality, but predominantly, they revolve around RFID and NFC. I can do redirection tags via NFC, I can also have chips that will handle a lot of physical access cards like MIFARE classics, HID procs one and two, pyramid and dala, I actually have a credit card payment chip in my the top of my left hand, so I can actually do tap to pay with my hand, I have a biosensing magnets so that that one's a lot of fun. It's not really a lifting magnet. But due to the way that the magnet was constructed, it actually gives me the ability to feel electromagnetic currents and electromagnetic fields, kind of like a spidey sense. So yeah, and we can get into it a little later. I'm actually in the working on the second round of my prototypes for my pegleg. Those won't be the standard microchip style things. But that's actually a Raspberry Pi Zero W2 that's been actually loaded with Kali encased in bio encapsulation, and then I'm going to be implanting that in my leg, so that way I can actually take systems into places where you can't, or shouldn't be allowed to take technology. So having it set up to run low energy Bluetooth sweeps along with auto pwns while I'm sitting here talking, so yeah, I kind of have a little bit of a fascination with human upgrades.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>This is already my favourite podcast I've ever done. This is great. Can I just ask what is what is the upside of being able to detect and sense electro magnetic fields?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, I'm also very, very passionate about physical pen testing. I'm an avid lock picker. I'm a member of multiple different lock picking clubs. And when you look at physical security, especially around warehouses, how are most of them secured? Magnetic locks, magnetic locks require electricity. So depending on the wiring and the amount of shielding in your your Romex cabling for your electromagnet, I can sit on the outside of your building, run my hands over the wall, and I can actually trace your electrical lines. So at that point, I actually have an idea of where to shim or make, you know, especially if it's a destructive pen test, I can make a small hole and basically clip the electrical wire. And if you know anything about mag locks, especially if you're dealing in like an emergency situation like a fire or a power outage, magnetic locks are automatically designed to actually go into an open state due to an emergency to allow people to get out. So basically the that's one great thing for the magnet. The other thing is it makes a really cool trick at a bar, you can pick up bottle caps and things, you know. And it's, if nothing else, it's a really cool way to get, it's a cool magic trick around young kids too.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>In the immortal words of the Insane Clown Posse: magnets, how do they work?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Why do you have to go there, man? I mean, I'm from Detroit, but I mean, in St. Cloud, we had better musicians, man, let's go with the MC5 or, or the Bay City Rollers. Ted Nugent.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>This is Shaggy 2 Dope erasure, and I will not stand for it. So in terms of some of the other practical use cases that this technology has, aside from the magnets, you mentioned some of the chips that you've been using, particularly the RFID and NFC devices, the contactless payment devices; what other kinds of use cases are there for this technology, either currently, or that you can kind of see emerging in the near future?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, I mean, at this point, it's anything around the contactless technology, we see a lot of NFC used in IoT. You know, when it comes to personal devices, almost every mobile device or tablet that's been released within the last three to five years has NFC capability. And the truth is not a lot of people understand what it is. And the fact that it by its design is an unsecured protocol. You know, the problem when it comes to NFC is we're using application level security to try and lock down an insecure protocol. You know, so anything from, you know, compromising a mobile device through the use of the implants, I mean, one of my favourites is the physical access side of things, you know, and, you know, let me, let me go into this for just a second, if I may, you know, when it comes to our physical access, a lot of places, especially in my tenure, you know, and I've been doing this kind of work for pushing 30 years, only two companies I've ever worked for had any type of multifactor for physical access locations of high, high privilege, you know, data centres, things like that. Most companies will have a single point of access, and it's usually just a bar or a card read, and then the door unlocks. So if we take a look at my implants, and the fact that I have the ability to basically emulate multiple different physical card protocols, here's where it gets funny. If I don't have a copy of a cloned badge, if I don't have a Proxmark, or some type of replay device, if I'm found in a restricted area, the worst you're going to be able to do is trespass me. You're not going to be able to get me arrested, because all I have to do is say, hey, you know the door was open, I'm here looking at the building, I thought this was part of the tour. You know, unlike the days of old, you know, where if I did have that physical piece of evidence that shows how I got in there, then I can be actually looked at as a criminal. So I'm playing a lot in the grey areas. You know, the whole point is the obfuscation. I'm not doing anything that anybody else hasn't done before in a different method, I'm just doing it in a way that would be very, very difficult from a digital forensics or incident response perspective, to be able to actually find that true root cause, on top of the fact that even if they saw some of the bulges in my my skin where I have some of my implants, when it comes to most of the privacy laws in most, you know, first world countries, they're not allowed to actually delve too deeply because it involves my personal medical, the minute it went inside my skin.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>And also, I'd imagine they're not the kind of thing that one would typically notice, unless you knew exactly what you were looking for and where, right?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Exactly. I mean, I've gotten asked a lot of questions in turn over the since I started doing this, like, you know, are these the same chips that I that, you know, are in my dog, are these chips that are in my cat, you know, and in some way the answer's yes. I mean, they all run on the same NFC style protocol. You know, and just like when it comes to a pet, you know, they have those very large wands. So they're gonna they would have to actually try and find the implant, energise the chip, to be able to get a read. Therein lies the same problem when it comes to all augmented humans, in order to be able to detect me and my chips, you would actually have to energise those chips to be able to get a read. So you would need multiple different spectrum analyzers on both high frequency and low frequency. And they would have to be strong enough to energise my entire body in order to for the detection. So from a management or you know, an actual implementation perspective, there is currently no way to actually detect an augmented human with this type of technology inside the body. And that becomes a very large problem for security professionals. And the only way that I can really give as a way to try and combat this is a true defence in depth, and a layered security approach. You know, I've said it a million times, you know, we have no problem putting multifactor authentication in front of all of our privileged data. But we don't do the same thing for our physical locations. And when if there's one person out here, like me, that has the ability to do this, I think that's fact enough that we should be looking at this as a potential threat on a larger scale, and we need to address it accordingly.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So you can clearly see that there's a real benefit to having sort of, like you said, multi layer security with a biological air to it. And you obviously yourself also, what maybe like 5% technology, both by the amount of things that you've got in you by the sounds of it.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>I'm working on it; I'll take 5% is a compliment.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So what what what attracted you to the world of biohacking in the first place?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Why do you climb a mountain? Because it's there. If anybody wants to take a Google, just google me and you can find a picture; I am, I consider the fact that I have one tattoo, it just starts at my neck and goes all the way to my my, the top of my feet. I do flesh hook suspensions for fun. So when I saw that people were actually implanting technology, it just seemed kind of like the next natural evolution to somebody like me, I considered myself to be a modern primitive for a very, very long time. So as far as I know, I was the first person that had brung the, the idea that these can be used for an offensive purpose to the security community. I know I am not the first guy to ever do this. I'm just the first guy that opened his mouth about it. And I think that goes into just the way that I see the world. I was a black hat for a very, very long time. So when I look, walk into a room, the first thing I see is okay, there are cameras, where's the the exit strategies? You know, if you tell me that this is an NFC chip that can interact with a mobile device, maybe you're going to use it for your digital business card, I'm going to look at that same device and see how can I use this in a way that would suit my purposes?</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So let's talk about some of those methods, then some of those ways in which this technology could potentially be used to target businesses. You've spoken already about some of the offensive applications of the magnets you have, for example, but what about some of the, for example, the NFC and RFID chips?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Sure. NFC, you know, like I said, it's pretty much a standard protocol on most modern mobile devices and tablets. The abilities through NFC can be anything from transferring, beaming a file, it could you can use it to set up a Wi-Fi network, you can use it to redirect. I mean, we've seen all kinds of different possibilities. So the way that I've redirected those, I released three different attacks at RSA two years ago. The first one was called Flesh Hook. Flesh Hook is a redirect. Yeah, I made the exploits. I got to name them. That's one of the benefits. So essentially, what that one was, is I would I've set up a BeEF server. And you know, for any of the newbies out there that don't remember the good old days of BeEF, BeEF is the browser extension exploit framework. This is the website that, you know, we've all heard the rumours of the minute you log into this website, the bad guys are in your system. Yeah, that's BeEF. So it's a little bit of a social engineering play. You know, I'd walk up Hey, Adam, man, check this out, dude. Let me see your phone. I found this amazing new video on YouTube. I want to show you. As soon as I can get the device in my hand, if you have NFC turned on, the large flexNExT implant that's in the top of my right hand will actually have enough distance on the antenna that it'll actually read through the actual meat of my hand. I can hold the phone in the correct orientation. It will pop up a redirector where I'm going to just send you to a video, but the minute your browser hits that website, the Java code in the HTML page is actually going to hook the browser and then I have access to the entire BeEF suite. So I can do on device spear phishing attacks, I can geolocate your device, access the cameras, I can use DNS enumeration if you're on a local network or a corporate network, I can do domain identity, subdomain identification and enumeration. Anything that I could even think of. The other one was called leprosy. Again, my attack, I named it. Leprosy doesn't really work as well against iOS devices. But when it comes to Android, once again, you know, this one is a little bit easier. Adam, oh my god, man. You know, I'm over here in the UK with you, you know, my phone died. My wife, I was just on the phone with my wife. She told me something happened to my grandson, man, can I borrow your phone for just a second? You know, of course, you know, you know, yeah, here, dude, call your wife. And again, the URL that's been programmed into the NFC chip, points to a web location where I've got an infected APK that was created with MSF Venom or, you know, a Cobalt Strike beacon. At this point, you know, it's Oh, my God, you know, let's be honest, who remembers my who remembers phone numbers anymore? What's my wife's phone? What's the country code for the United States? Plus one. Okay. So I can go through this big rigmarole of trying to remember a phone number, when actually what I'm doing is installing that APK. And as soon as I'm done, it's like, oh, shit, I can't remember the phone number man here, I'm gonna just go plug my phone in. But at this point, I have a reverse TCP connection back to the device, I can set up persistence, I can get a shell. I mean, at that point, it's whatever I want. And the third one was called handshake. You know, they're all you know, biologically related names. What can I say? And, you know, at that one, you know, I can use a Proxmark, any type of card skimmer I want, get your badge information, write it down onto one of my chips. And if we're in one of those single point access situations, I'm in your privileged locations on prem. And once again, the problem is there's zero indications of compromised to any one of these different attacks.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>I think judging by mine and Adam's reactions after the first question we came in with, and we're just like grinning like Cheshire cats, right? I think we can speak for the both of us saying we're so excited just to hear about this kind of thing, because it's not something we hear about a lot. So with that in mind, then, how many black hats like your former self, are using this in the wild or starting to think about using it in terms of real world attacks?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Okay, this is one of the hardest questions to answer in regards to doing conversations like this. I can tell you this with 100. There, there are some facts that I can give you with 100% certainty. Within the United States, one of the biggest distributors for microchip implants is a company called DangerousThings.com. Within Europe, there is a company called KSEC, K-S-E-C. So I am, I spoke with the CEO of Dangerous Things, a gentleman by the name of Amal. And from him, I was able to gain the fact that Dangerous Things has sold close to about 300,000 implants. I was actually back in y'all's neck of the woods last weekend up in Newcastle, where I actually got to meet Kai from KSEC. And between the two of us we basically came up with an estimation of between four hundred and six hundred thousand implants have been shipped. How many of those implants were actually, have actually made their way inside of a human body? We don't know, but I can tell you this much. I know that I'm using it. I know of quite a few people who are on red teams that are using this technology. We have not found any indications from any type of incidents that have actually happened in the wild where implants were shown to be the root cause, but at the same time, how would you be able to determine that, you know, and therein lies the problem. We may have, I mean, we've seen, you know, breach reports where NFC or RFID were included in the evaluation in terms of cause of breach, but without actually getting access to an individual to find out if they were actually augmented, it could have been a card, it could have been an implant, we don't know. Because, as I said before, there's really no way to determine any type of augmented human with current technology.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>And if yourself and, you know, a significant amount of other red teamers are using this technology and are interested in this technology, it's a fairly safe bet that black and grey hat actors are also interested in it and are deploying it in the wild, you know, it's not, it's not that much of a logical leap.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>No, and that's the way I see it. If once I actually brought this to the out at RSA, I knew this was going to open the door and somebody who is going to read this and there's going to be some black or grey hat somewhere that goes, Hey, this is a new vector. And due to the you know, the privacy laws and everything else, this becomes a much safer road to try and travel if you're going to try and do offensive type activities.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So let's talk about some of the practicalities of this, then, cause this is a very kind of new, very emerging field. Have you experienced any challenges with biohacking and with your implants, you know, other than getting through airport security, which I can imagine is just a barrel of laughs.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Okay, well, you brought it up - the airport is the number one question that I get. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>I'm not surprised. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>You want, would you like me to tell you how I walk, how I get through an airport? </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Absolutely. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>I put one, the left foot in front of the right and then I repeat. That's it.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>No. Does it, do none of them come up on the scanners?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>All right, let's talk about the two different types of metal detectors for two seconds. We have the magnetometer which is just kind of the archway you walk through. There is not enough combined metal in all of my implants to actually trigger a magnetometer. I'm going to carbon date myself here; before my my career in IT, you know, almost 30 years ago, I used to do the job of the TSA before there was a TSA and airport, airport security was still privatised. And don't quote me on this, but I if I remember correctly, the magnetometers would not trigger unless you had a combined metallic weight of at least a .22 calibre bullet. So I mean, if you think about it, when you walk through a metal detector, if you have like a necklace on with a gold charm, it doesn't go off, if you have earrings in, it won't go off. Now, I'm not saying that they couldn't change the sensitivity of the magnetometers to where they would detect it. But they would get so many false positives, trying to check people into an airport that it would be an unusable control. Same with the metal detectors. When you think about my implants, most of them are actually silicone, you know, with the exception of the copper antennas on the larger flexible main membrane implants or the bio magnet, which is a iron core wrapped in titanium, but that's less smaller than the size of a pea. So even if I'm doing you know, the X ray metal detector, doesn't show up, I can walk straight through, the magnetometer will not trigger. So that to me kind of says something about what we're dealing with in terms of airport security. But, you know, we can do a different talk on that one another day.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>That's quite a scary prospects in some ways, particularly if you're trying to defend against these types of attacks.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Yeah, I mean, thankfully, at least at this point, there's not a lot in aeroplanes that are relying on RFID or NFC, you know, but if I can get that pegleg you know, where I actually have a full Linux system, then yeah, that is something that could potentially interact with the Wi-Fi entertainment system on the plane, I mean, it opens a whole lot of different vectors at that point.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>But even beyond air travel, if airport security - which is, I would argue, among the most stringent kind of security, you know, scanning in terms of concealed objects and devices - If it can get past airport gate security, then security in and out of a building or or complex doesn't really stand a chance for detecting this kind of stuff, does it?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Not even, not even a little bit. You know, one one thing that I, just cause you guys are are a lot of fun, and I think you guys will get a kick out of this. I think everybody is familiar with the drug smelling dogs that are used by the authorities. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yes. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, one of the, they actually have a new type of canine that is being released to help military and law enforcement. And they're actually technology sniffing dogs. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>No. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Yes, you can look them up. So these are not used in the same way that narcotic sniffing canines are in terms of they don't use them to be able to get an arrest. They don't bring them up and smell somebody and go, okay, yeah, we've got you, we're going to take you away. They're used more in the post arrest investigation point. They're used a lot with human trafficking, child predators, things like that; people that would actually store illegal data on hard drives, in technology. So if someone gets arrested, they'll get a search warrant, they run the dog around the house looking for hard drives, thumb drives, you know, anywhere that they may have, you know, tried to store illegal and illegal things. I found out that one of the law enforcement agencies that is close to me here in Texas, actually recently got one of these drugs, these key technology smelling dogs. So after, you know, sending an email to the police department going, No, I am not crazy. Yes, I have implants. And here's here's my CV. So you can see I'm a real person, and I'm not messing with you. I'm interested in information about this dog. And after they researched me, they're like, okay, apparently cyborgs are a real thing. They became really open to, you know, having conversations, and I've actually been invited to go up to the Dallas Police Department. And we're going to see if Remi, the technology dog, is able to sniff any of the implants that I have. Because that would actually be probably one of the first ways to try and detect somebody of augmented nature. And the one point that I wanted to point out, and since you guys are definitely geeks, and take that as a hardcore compliment, if you think back to the Terminator movies, where, you know, wherever the resistance was right at the entrances, they always had the guys with the dogs, because they could smell the technology. And I just start to wonder is this going to be a situation where life imitates art or art imitates life? I don't know which, but I'm really excited to get up there. Due to my travel schedule, it's been a little difficult, but I'm hoping to be up there sometime towards the middle of November. And you know, maybe I'll drop you a line and let you guys know how it turns out.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yeah, absolutely. I'm going to ask the obvious question, how can dogs smell technology? How can anyone smell technology?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Okay. Just like the they've taught the dogs to be able to detect specific narcotics, you know, heroin, cocaine, marijuana, things like that. They actually have taught them to key in on specific components that are used in the creation of technology. The name is triphenylphosphine oxide. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Oh, wow. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>So they found one very, very specific element that is used in the creation and manufacture of technology circuit boards, hard drives, and they basically train these dogs to hit on that one specific compound. I don't know if they'd be able to smell it through the skin. I don't know. But I still think it's going to be one hell of an interesting experiment.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Hmm. Yeah, definitely. And you get to hang out with more dogs as well. So that's a win win, really, and especially in my eyes. So in terms of getting this tech into the mainstream then, because obviously, I'm just from hearing you for the past half hour, I'm super excited about it, and I'm probably not going to be alone. So say further down the line that this kind of stuff does reach consumers, the everyday consumer that is, what are the limitations you can imagine a potential regulator seeing, you know, for example, can can realistically we actually have Internet facing machine augmentations of the kind like your like your peg leg, or is that is that a hacking risk waiting to happen?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Um, well, I mean, let's be honest, you know, we can talk about QR codes and they are hacking risks waiting, just waiting to happen, and we see those on buses and trains, and taxi cabs. I don't think honestly, the imposed threat of any technology is going to stop someone from using it if there is the potential for a monetary gain. So to answer your original question, there is a lot of implants going out right now that I see is going to probably help break that stigma barrier. One of them, like I said, is the Walletmor chip that I have in my right hand, it's an actual credit card. So I can do tap to pay. I think, right now, the idea of implants is still, like you said, it's very, very fringe. And you everybody looks at me like I'm some kind of a terminator half the time. I mean, my friends shut their Bluetooth and their Wi-Fi off, the minute I walk into a room. All I want to do is just look at him when I leave and go, I'd be back. But another one that I see that's really made an impact is there's the ability, if you drive a specific model Tesla, you can get an implant and you can programme your valet key onto an implant. And you can basically just jump in your Tesla and you can drive. I think as we see a lot more of these types of implants and technologies that people can actually find a legitimate day to day use for is going to help with the concept of adoption and understanding and acceptance. Right now, there's like I said, 400,000 to 600,000 potential augmented humans out there. I see it moving beyond just the microchip concept, especially with a lot of the advancements we're seeing around graphene batteries. The big issue when it comes to any type of implant is outside of anything that's considered biomedical, there's no internal power for anything yet. And even when it comes to the pegleg, that I'm planning on putting in myself, it uses an indirect power receiver to actually power the device, but there's no battery in it. Because to charge something generates heat. So I think we're right at the precipice of you know, a whole new set of things that could be potentially coming out. I did a keynote in Newcastle over the weekend, and the title was Resistance is futile, we're already Borg. And in that talk, I just brought up some of the stuff that's actually already out there that people may not even be aware of. We've got spinal implants that are, you know, returning motility, to paralysed people, we have ocular implants that are working on giving sight to the blind, we're able to use DNA as a storage medium, and one gramme of DNA could potentially hold over seven terabytes worth of data with a retention period of over 100 years. So we are right on the cusp of so many different technological breakthroughs that cross that human technology barrier, that I think that you know, in terms of what we're going to see in the relatively near future is going to really be up to the order in which these discoveries are made.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So speaking of future technology, and just going back to the kind of Tesla use case you mentioned a little earlier, just as a brief digression. What do you think is the kind of feasibility of projects like Neuralink and other brain computer interfaces?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Oh, you brought up Neuralink, if everybody's familiar with Neuralink, but nobody's familiar with the other company. I'm very, very interested in BCI. Brain computer interfaces, especially for disabled and locked in individuals, I think it's going to be crucial. I just watched an amazing documentary on my way back from Newcastle. Dr. Phil Kennedy, the name of the documentary was called Father of the cyborgs. Dr. Phil Kennedy was actually one of the he's a neurosurgeon. And he actually was the first individual to implant brain computer interfaces into paralysed people. You know, so everybody wants to talk about Neuralink, but they don't want to talk about all the other ones. Another really big player in the BCI field is Synchron. And they're already in human trials. So I think that the idea of BCI is definitely something that's going to happen. But at the same time, all of these new technologies they do will have, you know, an underlying firmware. You know, and one of the things that I'm trying to look at in regards to this, the melding of technology and humanity is as security professionals, we already know there are going to be attack vectors there and we need to be talking about those now. You know, the attacks we see today, the vectors may have changed, but at the core, every single attack today is the same attack that it's been for the last 20 years. I mean, they're looking for credentials, I'm looking for data, I'm trying to exfiltrate things, or I'm going to ransom you, you know, the end game is going to be the same; how we get there may be different. And if we think about all this new advancements in technology, and just that crossover, what happens when ransomware starts affecting Bluetooth or internet enabled bio implants, you know, what happens if I'm, my pacemaker gets a ransomware, then it's an a real ransom at that point. You know, and, you know, we keep running towards the technology and trying to, you know, make ourselves more than human, which is absolutely the core of, you know, the trans human movement. But one thing that I've said all along, and I even started the conversation with you guys today is, it needs to be done safely. And when we look at everything that's coming up, honestly, in my opinion, the end game is still identity, you know, and being able to maintain our individual identity as we become something potentially more than human. And as such, I think our identities, our personal information, you know, identity is going to become the new security. Because once the lines between an individual and the tech stacks that they're interfacing with, you know, gets either faded or removed completely, the only thing left is the individual and the individual identity of the person that's making those interactions.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So just to round things off, then looking at the long term, what kind of potential benefits might be out there for technologists or IT professionals, you know, outside of red teams and perhaps even security, who want to explore biohacking as the practice itself matures?</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Well, again, you know, that's like, in my opinion, that's like asking someone how, how do you want to utilise a laptop or a mobile device? I mean, these microchips were never designed to be used necessarily as offensive tools. But if you look at things like Mimikatz, which is every hacker's favourite LDAP tool, it was, it's originally designed as a an LDAP auditing tool. Any tool this, regardless of what its intended purpose was, can be reused and misconfigured and used as a weapon. So I guess I, you know, not to try and blow off your question. But I guess it depends on really, what are they trying to do? You know, it could be something, I mean, I have no doubt that maybe we're going to start seeing the ability to do OTP. If you're not familiar with it, there's an amazing ecosystem out there. It's called the VivoKey. And this is an implant, the VivoKey architecture will actually allow for one time, you know, MFA OTP, where you're actually going to validate via an implant with an app on your phone, you know, so that's a potential security advancement moving forward, it could be something as simple as using your, your chip, almost kind of like a Fido chip, where you're going to scan your implant to access your computer, again, I would still want to password in there, don't like single points of failure as from a security perspective, you know, maybe you're gonna put your, your badge for work on your chip, and you're just not going to, you know, that way you can badge in. Not everything around implants, or implanted technology is a black art, for the lack of a better term, you know, they can be used just to make people's lives a little simpler. But one of the quotes that I love to use in pretty much every single time I talk is in from my personal experience, things that make life easier, rarely make them safer. So we have to, we are the security professionals, we're the ones that you know, have to warn the masses, we're the ones that have to take care of our employees. So it's up to us to understand what these kinds of threats are, and build that layered security approach and that defence in depth, so that these types of people, people such as myself, are left sitting at the door going well, I managed to hit the badge reader, but I still don't know the key, you know, our data, our physical locations, privilege is privilege, I don't care if it's physical, I don't care if it's digital, you know, and we are the ones that have been empowered by our companies to be the gatekeepers in the security for these types of things. And we need to do our job and be aware that people like me exist and build a strategy around that knowledge to be able to stop people like me.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Well, while we could spend all day digging into the intricacies of biohacking, sadly I'm afraid that's all we've got time for this week. </p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>Aww.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>I know, I could spend the rest of the afternoon talking about this. But our thanks once again to cyberArk's Len Noe for joining us.</p><h3 class="article-body__section" id="section-len"><span>Len </span></h3><p>It was absolutely my pleasure, guys. I really enjoyed talking to you. Maybe we can do it again sometime. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yeah, absolutely.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Sounds great. You can find links to all of the topics we've spoken about today in the show notes and even more on our website at ITpro.co.uk.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>You can also follow us on social media as well as subscribe to our daily newsletter.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Don't forget to subscribe to the IT Pro Podcast wherever you find your podcasts. And if you're enjoying the show, leave us a rating and a review.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>We'll be back next week with more insight for the world of IT. And until then, goodbye.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Bye.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: Meet the cyborg hacker ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The technological arsenal available to cyber criminals is already enough to give any security professional nightmares, but there’s another emerging threat on the horizon that may keep them up at night: bio-augmented hackers. Implantable chips and other modifications are growing in capability and sophistication, and there are a variety of creative ways that attackers can use them to carry out both physical and device-based attacks - </p><p>This is made all the more concerning by the fact that these implants are all but impossible to detect. This week, we’re joined by CyberArk technical evangelist, white hat hacker and self-described transhumanist Len Noe to find out what kind of augmentations cyber criminals currently have access to, how can they be used in intrusions, and why the industry needs to start preparing for their implementation now - as well as some of the positive uses that this technology can be put to.</p><iframe frameborder="0" height="350px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=51343108&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><h2 id="highlights">Highlights</h2><p>“Would you like me to tell you how I get through an airport? I put the left foot in front of the right and then I repeat. That's it… There is not enough combined metal in all of my implants to actually trigger a magnetometer… even if I'm doing the X-ray metal detector, [it] doesn't show up, I can walk straight through, the magnetometer will not trigger.” </p><p>“I know that I'm using it. I know of quite a few people who are on red teams that are using this technology. We have not found any indications from any type of incidents that have actually happened in the wild where implants were shown to be the root cause, but at the same time, how would you be able to determine that - and therein lies the problem.” </p><p>“From… an actual implementation perspective, there is currently no way to actually detect an augmented human with this type of technology inside the body. And that becomes a very large problem for security professionals. And the only way that I can really give as a way to try and combat this is a true defence in depth, and a layered security approach.” </p><p><a href="https://www.itpro.com/security/hacking/369133/podcast-transcript-meet-the-cyborg-hacker" data-original-url="https://www.itpro.com/security/hacking/369133/podcast-transcript-meet-the-cyborg-hacker"><em>Read the full transcript here.</em></a></p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/hacking/356480/the-it-pro-podcast-the-secret-life-of-hackers" data-original-url="https://www.itpro.com/security/hacking/356480/the-it-pro-podcast-the-secret-life-of-hackers">The IT Pro Podcast: The secret life of hackers </a></li><li><a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">Stories from the front line: The secrets of the Red Team revealed </a></li><li><a href="https://www.itpro.com/technology/32336/trade-unions-congress-fearful-of-implanting-workers-with-tracking-chips" data-original-url="https://www.itpro.com/technology/32336/trade-unions-congress-fearful-of-implanting-workers-with-tracking-chips">Trade Unions Congress fearful of implanting workers with tracking chips </a></li><li><a href="https://www.itpro.com/enterprise-security/32641/should-employees-be-microchipped" data-original-url="https://www.itpro.com/enterprise-security/32641/should-employees-be-microchipped">Should employees be microchipped? </a></li><li><a href="https://www.itpro.com/technology/357528/what-is-neuralink" data-original-url="https://www.itpro.com/technology/357528/what-is-neuralink">What is Neuralink? </a></li><li><a href="https://www.itpro.com/business/business-strategy" data-original-url="https://www.itpro.com/strategy/28678/arm-fights-paralysis-with-brain-implant-chips">ARM fights paralysis with brain implant chips </a></li><li><a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">What is penetration testing? </a></li><li><a href="https://www.itpro.com/technology/357241/should-human-augmentation-technology-be-regulated" data-original-url="https://www.itpro.com/technology/357241/should-human-augmentation-technology-be-regulated">Should human augmentation technology be regulated? </a></li><li><a href="https://www.itpro.com/technology/augmented-reality-ar/357294/it-pro-2020-augmenting-the-future" data-original-url="https://www.itpro.com/technology/augmented-reality-ar/357294/it-pro-2020-augmenting-the-future">IT Pro 20/20: The future of augmentation </a></li><li><a href="https://www.itpro.com/technology/358869/the-it-pro-podcast-can-technology-make-us-more-than-human" data-original-url="https://www.itpro.com/technology/358869/the-it-pro-podcast-can-technology-make-us-more-than-human">The IT Pro Podcast: Can technology make us more than human? </a></li><li><a href="https://www.itpro.com/security/privacy/359444/the-it-pro-podcast-should-companies-spy-on-their-employees" data-original-url="https://www.itpro.com/security/privacy/359444/the-it-pro-podcast-should-companies-spy-on-their-employees">The IT Pro Podcast: Should companies spy on their employees? </a></li><li><a href="https://www.youtube.com/watch?v=MrqeaJAVeCI&ab_channel=SecurityBSidesSanFrancisco">BSidesSF 2022 - Biohacker: The Invisible Threat (Len Noe) - YouTube</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1227190226694104600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/369132/the-it-pro-podcast-meet-the-cyborg-hacker</link>
                                                                            <description>
                            <![CDATA[ Resistance is futile - offensive biotech implants are already here ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sHqqiJKcvTj48dfZkrwUvF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/F9XLqHX4GgHqvgUS3jYT3C-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Sep 2022 06:30:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/F9XLqHX4GgHqvgUS3jYT3C-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast: Meet the cyborg hacker]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast: Meet the cyborg hacker]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast: Meet the cyborg hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/F9XLqHX4GgHqvgUS3jYT3C-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The technological arsenal available to cyber criminals is already enough to give any security professional nightmares, but there’s another emerging threat on the horizon that may keep them up at night: bio-augmented hackers. Implantable chips and other modifications are growing in capability and sophistication, and there are a variety of creative ways that attackers can use them to carry out both physical and device-based attacks - </p><p>This is made all the more concerning by the fact that these implants are all but impossible to detect. This week, we’re joined by CyberArk technical evangelist, white hat hacker and self-described transhumanist Len Noe to find out what kind of augmentations cyber criminals currently have access to, how can they be used in intrusions, and why the industry needs to start preparing for their implementation now - as well as some of the positive uses that this technology can be put to.</p><iframe frameborder="0" height="350px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=51343108&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><h2 id="highlights">Highlights</h2><p>“Would you like me to tell you how I get through an airport? I put the left foot in front of the right and then I repeat. That's it… There is not enough combined metal in all of my implants to actually trigger a magnetometer… even if I'm doing the X-ray metal detector, [it] doesn't show up, I can walk straight through, the magnetometer will not trigger.” </p><p>“I know that I'm using it. I know of quite a few people who are on red teams that are using this technology. We have not found any indications from any type of incidents that have actually happened in the wild where implants were shown to be the root cause, but at the same time, how would you be able to determine that - and therein lies the problem.” </p><p>“From… an actual implementation perspective, there is currently no way to actually detect an augmented human with this type of technology inside the body. And that becomes a very large problem for security professionals. And the only way that I can really give as a way to try and combat this is a true defence in depth, and a layered security approach.” </p><p><a href="https://www.itpro.com/security/hacking/369133/podcast-transcript-meet-the-cyborg-hacker" data-original-url="https://www.itpro.com/security/hacking/369133/podcast-transcript-meet-the-cyborg-hacker"><em>Read the full transcript here.</em></a></p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/hacking/356480/the-it-pro-podcast-the-secret-life-of-hackers" data-original-url="https://www.itpro.com/security/hacking/356480/the-it-pro-podcast-the-secret-life-of-hackers">The IT Pro Podcast: The secret life of hackers </a></li><li><a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">Stories from the front line: The secrets of the Red Team revealed </a></li><li><a href="https://www.itpro.com/technology/32336/trade-unions-congress-fearful-of-implanting-workers-with-tracking-chips" data-original-url="https://www.itpro.com/technology/32336/trade-unions-congress-fearful-of-implanting-workers-with-tracking-chips">Trade Unions Congress fearful of implanting workers with tracking chips </a></li><li><a href="https://www.itpro.com/enterprise-security/32641/should-employees-be-microchipped" data-original-url="https://www.itpro.com/enterprise-security/32641/should-employees-be-microchipped">Should employees be microchipped? </a></li><li><a href="https://www.itpro.com/technology/357528/what-is-neuralink" data-original-url="https://www.itpro.com/technology/357528/what-is-neuralink">What is Neuralink? </a></li><li><a href="https://www.itpro.com/business/business-strategy" data-original-url="https://www.itpro.com/strategy/28678/arm-fights-paralysis-with-brain-implant-chips">ARM fights paralysis with brain implant chips </a></li><li><a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">What is penetration testing? </a></li><li><a href="https://www.itpro.com/technology/357241/should-human-augmentation-technology-be-regulated" data-original-url="https://www.itpro.com/technology/357241/should-human-augmentation-technology-be-regulated">Should human augmentation technology be regulated? </a></li><li><a href="https://www.itpro.com/technology/augmented-reality-ar/357294/it-pro-2020-augmenting-the-future" data-original-url="https://www.itpro.com/technology/augmented-reality-ar/357294/it-pro-2020-augmenting-the-future">IT Pro 20/20: The future of augmentation </a></li><li><a href="https://www.itpro.com/technology/358869/the-it-pro-podcast-can-technology-make-us-more-than-human" data-original-url="https://www.itpro.com/technology/358869/the-it-pro-podcast-can-technology-make-us-more-than-human">The IT Pro Podcast: Can technology make us more than human? </a></li><li><a href="https://www.itpro.com/security/privacy/359444/the-it-pro-podcast-should-companies-spy-on-their-employees" data-original-url="https://www.itpro.com/security/privacy/359444/the-it-pro-podcast-should-companies-spy-on-their-employees">The IT Pro Podcast: Should companies spy on their employees? </a></li><li><a href="https://www.youtube.com/watch?v=MrqeaJAVeCI&ab_channel=SecurityBSidesSanFrancisco">BSidesSF 2022 - Biohacker: The Invisible Threat (Len Noe) - YouTube</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1227190226694104600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SpaceX bug bounty offers up to $25,000 per Starlink exploit ]]></title>
                                                                                                <dc:content><![CDATA[ <p>SpaceX is offering between $100 and $25,000 in bounties to hackers who report exploits to the company through their website.</p><p>The spacecraft manufacturer has set up a <a href="https://bugcrowd.com/spacex">dedicated page</a> on crowdsourced <a href="https://www.itpro.com/security/zero-day-exploit/362258/google-doubles-bug-bounty-linux-kubernetes-exploits" data-original-url="https://www.itpro.com/security/zero-day-exploit/362258/google-doubles-bug-bounty-linux-kubernetes-exploits">bug bounty</a> platform Bugcrowd, giving would-be <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hats</a> a centralised method for reporting un-patched SpaceX and Starlink exploits.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="R2jbpb4nBynt6hb5iyJKaD" name="R2jbpb4nBynt6hb5iyJKaD.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/R2jbpb4nBynt6hb5iyJKaD.jpg" mos="https://cdn.mos.cms.futurecdn.net/R2jbpb4nBynt6hb5iyJKaD.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Introducing IBM Security QRadar XDR</strong></p><p class="fancy-box__body-text">A comprehensive open solution in a crowded and confusing space</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368459/introducing-ibm-security-qradar-xdr" data-original-url="/security/cyber-security/368459/introducing-ibm-security-qradar-xdr">FREE DOWNLOAD</a></p></div></div><p>Hackers who submit reports on network vulnerabilities can expect up to $10,000, while on a “case-by-case” basis those who discover and report vulnerabilities with Starlink dishes, satellites or other such hardware can receive up to $25,000.</p><p>According to its <a href="https://www.itpro.com/security/bugs/359827/cisa-launches-security-bug-reporting-program" data-original-url="https://www.itpro.com/security/bugs/359827/cisa-launches-security-bug-reporting-program">Bugcrowd</a> page, SpaceX has so far rewarded 41 vulnerability reports, at an average of $972 each. A more comprehensive list of prices per type of vulnerability discovered can be found on the page, but SpaceX specifically forbids physical tampering with its infrastructure or that of Starlink’s, as well as testing that could directly impact its services.</p><p>In a <a href="https://api.starlink.com/public-files/StarlinkWelcomesSecurityResearchersBringOnTheBugs.pdf">document</a> shared by SpaceX titled ‘Starlink welcomes security researchers (bring on the bugs), the company outlines its position on bug bounties.</p><p>“We allow responsible security researchers to do their own testing, and we provide monetary rewards when they find and report vulnerabilities,” states the document.</p><p>“We recognize and appreciate the support of the broader security community in making Starlink better and more secure. We encourage researchers to test Starlink for security issues in a non-destructive way and to report their findings through our bug bounty program.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime" data-original-url="/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime">Ethical hackers handed lifeline in controversial US cyber crime review</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/368793/darpa-recruits-spacex-intel-amazon-satellite-network" data-original-url="/infrastructure/network-internet/368793/darpa-recruits-spacex-intel-amazon-satellite-network">DARPA recruits SpaceX, Intel and Amazon for major satellite network project</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/368813/zoom-patches-privilege-escalation-flaw-for-macos-users" data-original-url="/security/368813/zoom-patches-privilege-escalation-flaw-for-macos-users">Zoom patches privilege escalation flaw for macOS users</a></p></div></div><p>SpaceX further states that it considers vulnerability research within its bug bounty policies to be exempt from Digital Millennium Copyright Act (DMCA) claims, legal action as a result of <a href="https://www.itpro.com/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime" data-original-url="https://www.itpro.com/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime">Computer Fraud and Abuse Act (CFAA)</a> violation, and SpaceX terms and conditions that would interfere with research.</p><p>Bug bounties are a popular form of publicly-sourced testing for companies, that offer white hat hackers <a href="https://www.itpro.com/security/367436/microsoft-announces-lucrative-new-bug-bounty-awards-for-m365-products-and-services" data-original-url="https://www.itpro.com/security/367436/microsoft-announces-lucrative-new-bug-bounty-awards-for-m365-products-and-services">lucrative rewards</a> and permission to attempt to hack some of the most challenging commercial security systems, in return for information on any vulnerabilities that they discover.</p><p>In June, an employee working for the vulnerability coordination platform HackerOne was <a href="https://www.itpro.com/security/368417/hackerone-employee-fired-for-using-position-to-steal-bug-bounties" data-original-url="https://www.itpro.com/security/368417/hackerone-employee-fired-for-using-position-to-steal-bug-bounties">found to have been stealing and re-submitting bug bounties</a> for personal profit and was subsequently fired.</p><p>The Starlink constellation, which aims to provide satellite broadband access to customers worldwide, is rapidly growing. With over 2,500 satellites currently in orbit and an end goal of 12,000 having been approved by the FCC, it is a frontrunner in the growing race for satellite internet dominance, which has already <a href="https://www.itpro.com/infrastructure/network-internet/368492/dish-refutes-spacex-claims-sharing-12ghz-kill-starlink" data-original-url="https://www.itpro.com/infrastructure/network-internet/368492/dish-refutes-spacex-claims-sharing-12ghz-kill-starlink">spawned disagreements</a> as well as interest from agencies such as <a href="https://www.itpro.com/infrastructure/network-internet/368793/darpa-recruits-spacex-intel-amazon-satellite-network" data-original-url="https://www.itpro.com/infrastructure/network-internet/368793/darpa-recruits-spacex-intel-amazon-satellite-network">DARPA</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/368818/spacex-bug-bounty-offers-up-to-25000-per-starlink-exploit</link>
                                                                            <description>
                            <![CDATA[ The spacecraft manufacturer has offered white hats immunity to exploit a wide range of Starlink systems, with a dedicated report page ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kcZcBG9HRWB1E3RwPokuqX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7GkXcP3EpizVUKqUkMfu4b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Aug 2022 15:52:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7GkXcP3EpizVUKqUkMfu4b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close up of the Starlink logo, a stylised black &amp;#039;X&amp;#039; with the word starlink beneath on a white background, with other such logos in the background but blurry]]></media:description>                                                            <media:text><![CDATA[Close up of the Starlink logo, a stylised black &amp;#039;X&amp;#039; with the word starlink beneath on a white background, with other such logos in the background but blurry]]></media:text>
                                <media:title type="plain"><![CDATA[Close up of the Starlink logo, a stylised black &amp;#039;X&amp;#039; with the word starlink beneath on a white background, with other such logos in the background but blurry]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7GkXcP3EpizVUKqUkMfu4b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>SpaceX is offering between $100 and $25,000 in bounties to hackers who report exploits to the company through their website.</p><p>The spacecraft manufacturer has set up a <a href="https://bugcrowd.com/spacex">dedicated page</a> on crowdsourced <a href="https://www.itpro.com/security/zero-day-exploit/362258/google-doubles-bug-bounty-linux-kubernetes-exploits" data-original-url="https://www.itpro.com/security/zero-day-exploit/362258/google-doubles-bug-bounty-linux-kubernetes-exploits">bug bounty</a> platform Bugcrowd, giving would-be <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hats</a> a centralised method for reporting un-patched SpaceX and Starlink exploits.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="R2jbpb4nBynt6hb5iyJKaD" name="R2jbpb4nBynt6hb5iyJKaD.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/R2jbpb4nBynt6hb5iyJKaD.jpg" mos="https://cdn.mos.cms.futurecdn.net/R2jbpb4nBynt6hb5iyJKaD.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Introducing IBM Security QRadar XDR</strong></p><p class="fancy-box__body-text">A comprehensive open solution in a crowded and confusing space</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368459/introducing-ibm-security-qradar-xdr" data-original-url="/security/cyber-security/368459/introducing-ibm-security-qradar-xdr">FREE DOWNLOAD</a></p></div></div><p>Hackers who submit reports on network vulnerabilities can expect up to $10,000, while on a “case-by-case” basis those who discover and report vulnerabilities with Starlink dishes, satellites or other such hardware can receive up to $25,000.</p><p>According to its <a href="https://www.itpro.com/security/bugs/359827/cisa-launches-security-bug-reporting-program" data-original-url="https://www.itpro.com/security/bugs/359827/cisa-launches-security-bug-reporting-program">Bugcrowd</a> page, SpaceX has so far rewarded 41 vulnerability reports, at an average of $972 each. A more comprehensive list of prices per type of vulnerability discovered can be found on the page, but SpaceX specifically forbids physical tampering with its infrastructure or that of Starlink’s, as well as testing that could directly impact its services.</p><p>In a <a href="https://api.starlink.com/public-files/StarlinkWelcomesSecurityResearchersBringOnTheBugs.pdf">document</a> shared by SpaceX titled ‘Starlink welcomes security researchers (bring on the bugs), the company outlines its position on bug bounties.</p><p>“We allow responsible security researchers to do their own testing, and we provide monetary rewards when they find and report vulnerabilities,” states the document.</p><p>“We recognize and appreciate the support of the broader security community in making Starlink better and more secure. We encourage researchers to test Starlink for security issues in a non-destructive way and to report their findings through our bug bounty program.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime" data-original-url="/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime">Ethical hackers handed lifeline in controversial US cyber crime review</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/368793/darpa-recruits-spacex-intel-amazon-satellite-network" data-original-url="/infrastructure/network-internet/368793/darpa-recruits-spacex-intel-amazon-satellite-network">DARPA recruits SpaceX, Intel and Amazon for major satellite network project</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/368813/zoom-patches-privilege-escalation-flaw-for-macos-users" data-original-url="/security/368813/zoom-patches-privilege-escalation-flaw-for-macos-users">Zoom patches privilege escalation flaw for macOS users</a></p></div></div><p>SpaceX further states that it considers vulnerability research within its bug bounty policies to be exempt from Digital Millennium Copyright Act (DMCA) claims, legal action as a result of <a href="https://www.itpro.com/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime" data-original-url="https://www.itpro.com/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime">Computer Fraud and Abuse Act (CFAA)</a> violation, and SpaceX terms and conditions that would interfere with research.</p><p>Bug bounties are a popular form of publicly-sourced testing for companies, that offer white hat hackers <a href="https://www.itpro.com/security/367436/microsoft-announces-lucrative-new-bug-bounty-awards-for-m365-products-and-services" data-original-url="https://www.itpro.com/security/367436/microsoft-announces-lucrative-new-bug-bounty-awards-for-m365-products-and-services">lucrative rewards</a> and permission to attempt to hack some of the most challenging commercial security systems, in return for information on any vulnerabilities that they discover.</p><p>In June, an employee working for the vulnerability coordination platform HackerOne was <a href="https://www.itpro.com/security/368417/hackerone-employee-fired-for-using-position-to-steal-bug-bounties" data-original-url="https://www.itpro.com/security/368417/hackerone-employee-fired-for-using-position-to-steal-bug-bounties">found to have been stealing and re-submitting bug bounties</a> for personal profit and was subsequently fired.</p><p>The Starlink constellation, which aims to provide satellite broadband access to customers worldwide, is rapidly growing. With over 2,500 satellites currently in orbit and an end goal of 12,000 having been approved by the FCC, it is a frontrunner in the growing race for satellite internet dominance, which has already <a href="https://www.itpro.com/infrastructure/network-internet/368492/dish-refutes-spacex-claims-sharing-12ghz-kill-starlink" data-original-url="https://www.itpro.com/infrastructure/network-internet/368492/dish-refutes-spacex-claims-sharing-12ghz-kill-starlink">spawned disagreements</a> as well as interest from agencies such as <a href="https://www.itpro.com/infrastructure/network-internet/368793/darpa-recruits-spacex-intel-amazon-satellite-network" data-original-url="https://www.itpro.com/infrastructure/network-internet/368793/darpa-recruits-spacex-intel-amazon-satellite-network">DARPA</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nomad happy to forgive hackers if they return 90% of $190 million that was stolen ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The crypto bridge Nomad Bridge is offering hackers a 10% bounty after the company was hit by a cyber attack earlier this week in which it lost $190 million.</p><p>Nomad Bridge will consider any party who returns at least 90% of the total funds stolen to be an <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">ethical or white hat hacker</a>, it revealed today. The organisation will, therefore, drop any intent to pursue legal action against the perpetrators, who they'll deem to have conducted the <a href="https://www.itpro.com/security/hacking/357971/how-do-hackers-choose-their-targets" target="_blank" data-original-url="https://www.itpro.com/security/hacking/357971/how-do-hackers-choose-their-targets">hacking operation</a> on reasonable grounds.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/368730/auditors-blame-4-million-cryptocurrency-heist-on-leaky-logging-tech" data-original-url="/security/hacking/368730/auditors-blame-4-million-cryptocurrency-heist-on-leaky-logging-tech">Auditors blame massive $4 million cryptocurrency heist on leaky logging technology</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/368706/nomad-crypto-bridge-drained-of-200m-through-chaotic-exploit" data-original-url="/security/hacking/368706/nomad-crypto-bridge-drained-of-200m-through-chaotic-exploit">Nomad crypto bridge drained of $190 million through “chaotic” exploit</a></p></div></div><p>The company added it’s continuing to work with its community, law enforcement, and <a href="https://www.itpro.com/security/28031/what-is-blockchain" target="_blank" data-original-url="https://www.itpro.com/security/28031/what-is-blockchain">blockchain</a> analysis firms to ensure all funds are returned.</p><p>Nomad said that although it won’t pursue legal action against to-be determined white hat hackers, it'll identify them to any third parties who may be considering legal action. It's also working closely with law enforcement and will advocate for no criminal charges when the so-called ethical hackers return the funds.</p><p>They need to be returned in <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining" target="_blank" data-original-url="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">Ethereum</a> or ERC-20 to the official Nomad recovery wallet address, which is being run along with Anchorage Digital, a nationally regulated custodian bank. </p><p>“Given the unprecedented number of decentralised parties involved, coordinating amongst everyone was a complex process,” said the company. “We wanted to make sure we put the bounty out in the right way, so we took some additional time to make sure we considered the complexities due to the nature of the hack.”</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1555045760588140544"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1555045760588140544"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Some <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hats</a> have already returned money to the crypto bridge. Paladin Blockchain Security and Rugdoc.io returned funds worth $1 million to the recovery wallet, stated Nomad. A total of $11.2 million was also returned by five white hats including darkfi-eth, anime.eth, and returner-of-beans.eth. The total returned seems to be around $17 million.</p><p>Cross-chain token bridge Nomad was <a href="https://www.itpro.com/security/hacking/368706/nomad-crypto-bridge-drained-of-200m-through-chaotic-exploit" target="_blank" data-original-url="https://www.itpro.com/security/hacking/368706/nomad-crypto-bridge-drained-of-200m-through-chaotic-exploit">hit with an exploit earlier this week</a> which saw attackers drain it of nearly $200 million. Following a routing upgrade on the platform, messages were allowed to be spoofed which meant that attackers could abuse this to copy and paste transactions. This quickly drained the bridge in a “frenzied free-for-all” said the Paradigm researcher known as samczsun.</p><p>At the time, the company thanked many of its white hat friends who acted proactively and were safeguarding some of the funds. It instructed them to continue to hold them until it provided further instructions through Twitter.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/368746/nomad-happy-to-forgive-hackers-if-they-return-stolen-funds</link>
                                                                            <description>
                            <![CDATA[ The crypto bridge is offering 'white hat hackers' a 10% bounty following the attack earlier this week ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uxHeQsCbRsCMLgEx7cQtNm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xH65SKaC9StGBUq7g6tS57-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Aug 2022 11:31:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xH65SKaC9StGBUq7g6tS57-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hacker against a red background]]></media:description>                                                            <media:text><![CDATA[A hacker against a red background]]></media:text>
                                <media:title type="plain"><![CDATA[A hacker against a red background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xH65SKaC9StGBUq7g6tS57-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The crypto bridge Nomad Bridge is offering hackers a 10% bounty after the company was hit by a cyber attack earlier this week in which it lost $190 million.</p><p>Nomad Bridge will consider any party who returns at least 90% of the total funds stolen to be an <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">ethical or white hat hacker</a>, it revealed today. The organisation will, therefore, drop any intent to pursue legal action against the perpetrators, who they'll deem to have conducted the <a href="https://www.itpro.com/security/hacking/357971/how-do-hackers-choose-their-targets" target="_blank" data-original-url="https://www.itpro.com/security/hacking/357971/how-do-hackers-choose-their-targets">hacking operation</a> on reasonable grounds.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/368730/auditors-blame-4-million-cryptocurrency-heist-on-leaky-logging-tech" data-original-url="/security/hacking/368730/auditors-blame-4-million-cryptocurrency-heist-on-leaky-logging-tech">Auditors blame massive $4 million cryptocurrency heist on leaky logging technology</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/368706/nomad-crypto-bridge-drained-of-200m-through-chaotic-exploit" data-original-url="/security/hacking/368706/nomad-crypto-bridge-drained-of-200m-through-chaotic-exploit">Nomad crypto bridge drained of $190 million through “chaotic” exploit</a></p></div></div><p>The company added it’s continuing to work with its community, law enforcement, and <a href="https://www.itpro.com/security/28031/what-is-blockchain" target="_blank" data-original-url="https://www.itpro.com/security/28031/what-is-blockchain">blockchain</a> analysis firms to ensure all funds are returned.</p><p>Nomad said that although it won’t pursue legal action against to-be determined white hat hackers, it'll identify them to any third parties who may be considering legal action. It's also working closely with law enforcement and will advocate for no criminal charges when the so-called ethical hackers return the funds.</p><p>They need to be returned in <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining" target="_blank" data-original-url="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">Ethereum</a> or ERC-20 to the official Nomad recovery wallet address, which is being run along with Anchorage Digital, a nationally regulated custodian bank. </p><p>“Given the unprecedented number of decentralised parties involved, coordinating amongst everyone was a complex process,” said the company. “We wanted to make sure we put the bounty out in the right way, so we took some additional time to make sure we considered the complexities due to the nature of the hack.”</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1555045760588140544"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1555045760588140544"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Some <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hats</a> have already returned money to the crypto bridge. Paladin Blockchain Security and Rugdoc.io returned funds worth $1 million to the recovery wallet, stated Nomad. A total of $11.2 million was also returned by five white hats including darkfi-eth, anime.eth, and returner-of-beans.eth. The total returned seems to be around $17 million.</p><p>Cross-chain token bridge Nomad was <a href="https://www.itpro.com/security/hacking/368706/nomad-crypto-bridge-drained-of-200m-through-chaotic-exploit" target="_blank" data-original-url="https://www.itpro.com/security/hacking/368706/nomad-crypto-bridge-drained-of-200m-through-chaotic-exploit">hit with an exploit earlier this week</a> which saw attackers drain it of nearly $200 million. Following a routing upgrade on the platform, messages were allowed to be spoofed which meant that attackers could abuse this to copy and paste transactions. This quickly drained the bridge in a “frenzied free-for-all” said the Paradigm researcher known as samczsun.</p><p>At the time, the company thanked many of its white hat friends who acted proactively and were safeguarding some of the funds. It instructed them to continue to hold them until it provided further instructions through Twitter.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ HackerOne employee fired for using position to steal bug bounties ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Vulnerability coordination platform HackerOne has announced the firing of an employee found to have used their position to access the vulnerability data of customers, and to sell duplicate data back to them for monetary gain.</p><p>HackerOne provides a platform through which <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hat</a> hackers can anonymously submit <a href="https://www.itpro.com/security/hacking/363344/vulnerability-hunters-naturally-inquisitive" data-original-url="https://www.itpro.com/security/hacking/363344/vulnerability-hunters-naturally-inquisitive">vulnerability reports</a> on companies and also facilitates the secure transfer of bounties in return for the information. The company describes itself as the “global leader” in attack resistance management (ARM).</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="d25pnmHteqMFEXehyV5g2n" name="d25pnmHteqMFEXehyV5g2n.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/d25pnmHteqMFEXehyV5g2n.png" mos="https://cdn.mos.cms.futurecdn.net/d25pnmHteqMFEXehyV5g2n.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Securing endpoints amid new threats</strong></p><p class="fancy-box__body-text">Ensuring employees have the flexibility and security to work remotely</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/367650/securing-endpoints-amid-new-threats" data-original-url="/technology/367650/securing-endpoints-amid-new-threats">FREE DOWNLOAD</a></p></div></div><p>It was discovered this week that an employee had improperly accessed HackerOne systems between April 4 and June 23, stealing user-submitted vulnerability data to pass the information along to the affected customers themselves and receive the bounty.</p><p>Concerns were raised by a customer on June 22, when a submitter of vulnerability data used threatening language and provided information with remarkable similarity to a disclosure they had previously received through HackerOne.</p><p>Relying on a community of over a million hackers to submit reports can lead to ‘bug collisions’ or duplicates, where two or more hackers can discover the same vulnerability around the same time as each other. In this instance, however, the company states that it was provided with evidence that cast doubt on simple coincidence being behind this crossover of information.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30203/what-is-hacktivism" data-original-url="/hacking/30203/what-is-hacktivism">What is hacktivism?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/363344/vulnerability-hunters-naturally-inquisitive" data-original-url="/security/hacking/363344/vulnerability-hunters-naturally-inquisitive">Vulnerability hunters are cut from a different cloth – they’re naturally inquisitive</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/368397/cisa-tells-businesses-abandon-legacy-microsoft-exchange-authentication" data-original-url="/security/368397/cisa-tells-businesses-abandon-legacy-microsoft-exchange-authentication">Businesses urged to abandon Microsoft Exchange legacy authentication earlier than planned</a></p></div></div><p>24 hours after the customer tip, HackerOne had identified an employee suspected of being behind the incident and removed their system access. This was possible because only one employee’s access log showed that they had viewed all the disclosures that further customers had identified as being re-submitted by the threat actor.</p><p>Following an interview, their employment was terminated, and criminal referral has not yet been ruled out by the company. </p><p>In a <a href="https://hackerone.com/reports/1622449">report</a>, HackerOne chief information security officer Chris Evans and chief technology officer Alex Rice described the actions as a “serious incident.”</p><p>“Insider threats are one of the most insidious in cybersecurity, and we stand ready to do everything in our power to reduce the likelihood of such incidents in the future.”</p><p>The company states that they have made all customers that they know interacted with the threat actor aware of the incident, but further stressed that any customer who was contacted by user ‘rzlr’ should contact them directly at support-incident-06-22@hackerone.com.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/368417/hackerone-employee-fired-for-using-position-to-steal-bug-bounties</link>
                                                                            <description>
                            <![CDATA[ The threat actor was identified by their duplicate data, which they were trying to pass off as their own for financial gain ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fE1UQQXXTbS7Bn2QrxS66h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gkK5cyPQiHCTuPaDrkc6MU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Jul 2022 11:24:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gkK5cyPQiHCTuPaDrkc6MU-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand holding a magnifying glass reveals a red lock, unlocked among several blue locked locks]]></media:description>                                                            <media:text><![CDATA[A hand holding a magnifying glass reveals a red lock, unlocked among several blue locked locks]]></media:text>
                                <media:title type="plain"><![CDATA[A hand holding a magnifying glass reveals a red lock, unlocked among several blue locked locks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gkK5cyPQiHCTuPaDrkc6MU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Vulnerability coordination platform HackerOne has announced the firing of an employee found to have used their position to access the vulnerability data of customers, and to sell duplicate data back to them for monetary gain.</p><p>HackerOne provides a platform through which <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hat</a> hackers can anonymously submit <a href="https://www.itpro.com/security/hacking/363344/vulnerability-hunters-naturally-inquisitive" data-original-url="https://www.itpro.com/security/hacking/363344/vulnerability-hunters-naturally-inquisitive">vulnerability reports</a> on companies and also facilitates the secure transfer of bounties in return for the information. The company describes itself as the “global leader” in attack resistance management (ARM).</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="d25pnmHteqMFEXehyV5g2n" name="d25pnmHteqMFEXehyV5g2n.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/d25pnmHteqMFEXehyV5g2n.png" mos="https://cdn.mos.cms.futurecdn.net/d25pnmHteqMFEXehyV5g2n.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Securing endpoints amid new threats</strong></p><p class="fancy-box__body-text">Ensuring employees have the flexibility and security to work remotely</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/367650/securing-endpoints-amid-new-threats" data-original-url="/technology/367650/securing-endpoints-amid-new-threats">FREE DOWNLOAD</a></p></div></div><p>It was discovered this week that an employee had improperly accessed HackerOne systems between April 4 and June 23, stealing user-submitted vulnerability data to pass the information along to the affected customers themselves and receive the bounty.</p><p>Concerns were raised by a customer on June 22, when a submitter of vulnerability data used threatening language and provided information with remarkable similarity to a disclosure they had previously received through HackerOne.</p><p>Relying on a community of over a million hackers to submit reports can lead to ‘bug collisions’ or duplicates, where two or more hackers can discover the same vulnerability around the same time as each other. In this instance, however, the company states that it was provided with evidence that cast doubt on simple coincidence being behind this crossover of information.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30203/what-is-hacktivism" data-original-url="/hacking/30203/what-is-hacktivism">What is hacktivism?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/363344/vulnerability-hunters-naturally-inquisitive" data-original-url="/security/hacking/363344/vulnerability-hunters-naturally-inquisitive">Vulnerability hunters are cut from a different cloth – they’re naturally inquisitive</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/368397/cisa-tells-businesses-abandon-legacy-microsoft-exchange-authentication" data-original-url="/security/368397/cisa-tells-businesses-abandon-legacy-microsoft-exchange-authentication">Businesses urged to abandon Microsoft Exchange legacy authentication earlier than planned</a></p></div></div><p>24 hours after the customer tip, HackerOne had identified an employee suspected of being behind the incident and removed their system access. This was possible because only one employee’s access log showed that they had viewed all the disclosures that further customers had identified as being re-submitted by the threat actor.</p><p>Following an interview, their employment was terminated, and criminal referral has not yet been ruled out by the company. </p><p>In a <a href="https://hackerone.com/reports/1622449">report</a>, HackerOne chief information security officer Chris Evans and chief technology officer Alex Rice described the actions as a “serious incident.”</p><p>“Insider threats are one of the most insidious in cybersecurity, and we stand ready to do everything in our power to reduce the likelihood of such incidents in the future.”</p><p>The company states that they have made all customers that they know interacted with the threat actor aware of the incident, but further stressed that any customer who was contacted by user ‘rzlr’ should contact them directly at support-incident-06-22@hackerone.com.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ethical hackers handed lifeline in controversial US cyber crime review ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The US Department of Justice (DoJ) has announced that it will no longer prosecute ethical hackers under its anti-cyber crime law, the Computer Fraud and Abuse Act (CFAA).</p><p>The landmark change comes after a policy revision, stipulating that cyber security research conducted in “good faith” should not be prosecutable, came into force on Thursday.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" data-original-url="/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">80% of cyber professionals say the Computer Misuse Act is working against them</a></p></div></div><p>There is no concrete guidance on what type of activity falling under the umbrella of ‘cyber security research’ is protected or unprotected under the new policy revision, but security researchers acting in a way that intentionally avoids harm will not be charged under the CFAA.</p><p>Cyber security researchers have previously been fearful of reporting <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">security vulnerabilities</a> in the past out of fear of being charged under the Act, but the US is now adopting a fresh perspective, saying vulnerabilities that are discovered responsibly benefit “the common good”.</p><p>“Computer security research is a key driver of improved cybersecurity,” said Lisa O. Monaco, deputy attorney general. “The department has never been interested in prosecuting good-faith computer security research as a crime, and today’s announcement promotes cyber security by providing clarity for good-faith security researchers who root out vulnerabilities for the common good.”</p><p>The majority of security researchers (60%) <a href="https://www.bugcrowd.com/resources/webinars/hackers-dont-wear-black-hoodies-they-wear-capes">speaking to Bugcrowd in 2020</a> said they had not reported security vulnerabilities they found in the past due to fear of being prosecuted under the CFAA. </p><p>The law has also threatened other areas of cyber security such as legitimate <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a>. Security professionals working for Coalfire in 2019, for example, were handed criminal charges for breaking into Iowa’s Dallas County courthouse after being contracted by the state of Iowa.</p><p>The charges were ultimately dropped but the CFAA, which was drafted in 1986, well before the <a href="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3" data-original-url="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3">modern internet</a>, has always threatened ethical security research.</p><p>The UK’s equivalent legislation, the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act</a> (CMA), has been criticised in the past for also not legally accepting <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hacking</a> as a benefit to society and industry.</p><p>Drafted in 1990 but currently under review, the CMA has been labelled an outdated piece of legislation and like the CFAA up until this week, it too outlaws good-faith ethical hacking.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7aXsyZevCE4BJaQcNzp4zm" name="7aXsyZevCE4BJaQcNzp4zm.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/7aXsyZevCE4BJaQcNzp4zm.png" mos="https://cdn.mos.cms.futurecdn.net/7aXsyZevCE4BJaQcNzp4zm.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The state of email security 2022</strong></p><p class="fancy-box__body-text">Confronting the new wave of cyber attacks</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/367501/the-state-of-email-security-2022" data-original-url="/security/cyber-security/367501/the-state-of-email-security-2022">FREE DOWNLOAD</a></p></div></div><p>A recent <a href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" data-original-url="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">report</a> from the CyberUp campaign, in partnership with techUK, showed that 80% of legitimate cyber security researchers have worried about being punished under the CMA while defending cyber attacks.</p><p>Ethical hacking’s protection from the CFAA received a boost last year in a significant ruling in the Van Buren vs United States case.</p><p>In it, the US Supreme Court ruled that a law enforcement officer, bribed by an outside individual, did not break any laws under the CFAA in accessing information from a computer for unsanctioned reasons.</p><p>Although Van Buren was authorised to access a police database, he was not authorised to hand over confidential information to an outside party in exchange for money, but the ruling meant he could not be prosecuted under the CFAA, leading onlookers to believe this could lead to positive implications for ethical hackers.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/6GrNyc1WAgk" allowfullscreen></iframe></div></div><p>The latest policy revision to the CFAA has been greeted warmly by the cyber security community. Brian Higgins, security specialist at Comparitech, told <em>IT Pro</em> that “this is definitely a step in the right direction by the US authorities”.</p><p>“It’s unreasonable to place such disproportionate restrictions on a vital community of professionals, the majority of whom operate to high standards of ethics and integrity,” he said.</p><p>“Taking the gloves off, even to this extent, will allow a better understanding of the threats we face and the best way to defend against them. This proactive development in the United States will undoubtedly attract a lot of scrutiny from the international community, the majority of whom will be seeking to follow suit in some fashion.”</p><p>The DoJ <a href="https://www.justice.gov/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act">said</a> that individuals claiming to be conducting security research “is not a free pass for those acting in bad faith”. It used an example of <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware" data-original-url="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">extorting other people</a> after discovering a vulnerability, all in the name of research, which would not be protected under the policy revision.</p><p>“Hacking itself, using its current common definition rather than the original, isn't inherently good or evil. Using it for profit and abuse is evil,” said Sam Curry, chief security officer at Cybereason to <em>IT Pro</em>. “Breaking the law is evil. But using it to improve security is a vital function without which we really can't resist the darker kind. In the world of cyber, this is great news for white hats and gives a ray of hope to some grey hats too.”</p><p>Although greeted warmly by many, other corners of the industry have criticised the DoJ for not making more allowances in its policy review.</p><p>Not setting a clear line as to what constitutes an offence in the process of ethical hacking, and what doesn’t, is the main point of contention for the Electronic Frontier Foundation (EFF), which said that it would be better if there was a technological restriction defendants would have to defeat in order to be charged under the CFAA.</p><p>“Instead of this clear line, the new policy explicitly names scenarios in which written policies may give rise to a criminal CFAA charge, such as when an employee violates a contract that puts certain files off limits in all situations, or when an outsider receives a cease-and-desist letter informing them that their access is now unauthorised,” it <a href="https://www.eff.org/deeplinks/2022/05/dojs-new-cfaa-policy-good-start-does-not-go-far-enough-protect-security">said</a>.</p><p>The EFF also criticised the DoJ for saying that security research should be conducted “solely” in good faith, and it excludes “a lot of how research happens in the real world”.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime</link>
                                                                            <description>
                            <![CDATA[ The DoJ's latest ruling is a boon to "good-faith security research" but some argue that white hats are still not protected ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6vM2oAtd4Fb2pTaXDSuvKJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N22ik5y6rm5mskzYejFrF7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 May 2022 11:49:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N22ik5y6rm5mskzYejFrF7-1280-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphical mockup of a piece of software being tested for vulnerabilities]]></media:description>                                                            <media:text><![CDATA[Graphical mockup of a piece of software being tested for vulnerabilities]]></media:text>
                                <media:title type="plain"><![CDATA[Graphical mockup of a piece of software being tested for vulnerabilities]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N22ik5y6rm5mskzYejFrF7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Department of Justice (DoJ) has announced that it will no longer prosecute ethical hackers under its anti-cyber crime law, the Computer Fraud and Abuse Act (CFAA).</p><p>The landmark change comes after a policy revision, stipulating that cyber security research conducted in “good faith” should not be prosecutable, came into force on Thursday.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" data-original-url="/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">80% of cyber professionals say the Computer Misuse Act is working against them</a></p></div></div><p>There is no concrete guidance on what type of activity falling under the umbrella of ‘cyber security research’ is protected or unprotected under the new policy revision, but security researchers acting in a way that intentionally avoids harm will not be charged under the CFAA.</p><p>Cyber security researchers have previously been fearful of reporting <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">security vulnerabilities</a> in the past out of fear of being charged under the Act, but the US is now adopting a fresh perspective, saying vulnerabilities that are discovered responsibly benefit “the common good”.</p><p>“Computer security research is a key driver of improved cybersecurity,” said Lisa O. Monaco, deputy attorney general. “The department has never been interested in prosecuting good-faith computer security research as a crime, and today’s announcement promotes cyber security by providing clarity for good-faith security researchers who root out vulnerabilities for the common good.”</p><p>The majority of security researchers (60%) <a href="https://www.bugcrowd.com/resources/webinars/hackers-dont-wear-black-hoodies-they-wear-capes">speaking to Bugcrowd in 2020</a> said they had not reported security vulnerabilities they found in the past due to fear of being prosecuted under the CFAA. </p><p>The law has also threatened other areas of cyber security such as legitimate <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a>. Security professionals working for Coalfire in 2019, for example, were handed criminal charges for breaking into Iowa’s Dallas County courthouse after being contracted by the state of Iowa.</p><p>The charges were ultimately dropped but the CFAA, which was drafted in 1986, well before the <a href="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3" data-original-url="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3">modern internet</a>, has always threatened ethical security research.</p><p>The UK’s equivalent legislation, the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act</a> (CMA), has been criticised in the past for also not legally accepting <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hacking</a> as a benefit to society and industry.</p><p>Drafted in 1990 but currently under review, the CMA has been labelled an outdated piece of legislation and like the CFAA up until this week, it too outlaws good-faith ethical hacking.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7aXsyZevCE4BJaQcNzp4zm" name="7aXsyZevCE4BJaQcNzp4zm.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/7aXsyZevCE4BJaQcNzp4zm.png" mos="https://cdn.mos.cms.futurecdn.net/7aXsyZevCE4BJaQcNzp4zm.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The state of email security 2022</strong></p><p class="fancy-box__body-text">Confronting the new wave of cyber attacks</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/367501/the-state-of-email-security-2022" data-original-url="/security/cyber-security/367501/the-state-of-email-security-2022">FREE DOWNLOAD</a></p></div></div><p>A recent <a href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" data-original-url="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">report</a> from the CyberUp campaign, in partnership with techUK, showed that 80% of legitimate cyber security researchers have worried about being punished under the CMA while defending cyber attacks.</p><p>Ethical hacking’s protection from the CFAA received a boost last year in a significant ruling in the Van Buren vs United States case.</p><p>In it, the US Supreme Court ruled that a law enforcement officer, bribed by an outside individual, did not break any laws under the CFAA in accessing information from a computer for unsanctioned reasons.</p><p>Although Van Buren was authorised to access a police database, he was not authorised to hand over confidential information to an outside party in exchange for money, but the ruling meant he could not be prosecuted under the CFAA, leading onlookers to believe this could lead to positive implications for ethical hackers.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/6GrNyc1WAgk" allowfullscreen></iframe></div></div><p>The latest policy revision to the CFAA has been greeted warmly by the cyber security community. Brian Higgins, security specialist at Comparitech, told <em>IT Pro</em> that “this is definitely a step in the right direction by the US authorities”.</p><p>“It’s unreasonable to place such disproportionate restrictions on a vital community of professionals, the majority of whom operate to high standards of ethics and integrity,” he said.</p><p>“Taking the gloves off, even to this extent, will allow a better understanding of the threats we face and the best way to defend against them. This proactive development in the United States will undoubtedly attract a lot of scrutiny from the international community, the majority of whom will be seeking to follow suit in some fashion.”</p><p>The DoJ <a href="https://www.justice.gov/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act">said</a> that individuals claiming to be conducting security research “is not a free pass for those acting in bad faith”. It used an example of <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware" data-original-url="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">extorting other people</a> after discovering a vulnerability, all in the name of research, which would not be protected under the policy revision.</p><p>“Hacking itself, using its current common definition rather than the original, isn't inherently good or evil. Using it for profit and abuse is evil,” said Sam Curry, chief security officer at Cybereason to <em>IT Pro</em>. “Breaking the law is evil. But using it to improve security is a vital function without which we really can't resist the darker kind. In the world of cyber, this is great news for white hats and gives a ray of hope to some grey hats too.”</p><p>Although greeted warmly by many, other corners of the industry have criticised the DoJ for not making more allowances in its policy review.</p><p>Not setting a clear line as to what constitutes an offence in the process of ethical hacking, and what doesn’t, is the main point of contention for the Electronic Frontier Foundation (EFF), which said that it would be better if there was a technological restriction defendants would have to defeat in order to be charged under the CFAA.</p><p>“Instead of this clear line, the new policy explicitly names scenarios in which written policies may give rise to a criminal CFAA charge, such as when an employee violates a contract that puts certain files off limits in all situations, or when an outsider receives a cease-and-desist letter informing them that their access is now unauthorised,” it <a href="https://www.eff.org/deeplinks/2022/05/dojs-new-cfaa-policy-good-start-does-not-go-far-enough-protect-security">said</a>.</p><p>The EFF also criticised the DoJ for saying that security research should be conducted “solely” in good faith, and it excludes “a lot of how research happens in the real world”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Certified ethical hacker and IT manager steals $575,000 in cryptocurrency from elderly person ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A certified ethical hacker and practising IT manager has been charged with several offences after stealing a large sum of cryptocurrency from an elderly person.</p><p>Aaron Daniel Motta allegedly stole more than $575,000 (£411,900) from an elderly victim by stealing a Trezor hardware wallet used to store cryptocurrency offline. The type of cryptocurrency was not disclosed in the police reports.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/360701/it-pro-panel-do-we-still-need-certifications" data-original-url="/business-strategy/careers-training/360701/it-pro-panel-do-we-still-need-certifications">IT Pro Panel: Do we still need certifications?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">Stories from the front line: The secrets of the Red Team revealed</a></p></div></div><p>Clearwater Police in Florida said Motta transferred the sum into multiple wallets he owned after the victim hired Motta to install a security system in their home.</p><p>Motta faces felony charges of grand theft and offences against computer users, according to an arrest affidavit, <a href="https://www.tampabay.com/news/breaking-news/2022/04/09/pinellas-park-man-stole-nearly-600000-in-cryptocurrency-police-say/?utm_source=fark"><em>Tampa Bay Times</em></a> reported.</p><p>According to a LinkedIn profile in Motta’s name, the accused is a specialist in <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a>, <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a>, <a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">offensive security</a>, and IT.</p><p>The 27-year-old is currently self-employed, an owner at Motta Management & Mitigation Services, and recently left two positions - security technician and network technician - at different companies. Motta is also an active participant in <a href="https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities" data-original-url="https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities">Apple’s bug bounty program</a>.</p><p>According to the profile, Motta also holds a degree in cyber/electronic operations and warfare from St. Petersburg College and is a Certified <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">Ethical Hacker</a> through Cisco Networking Academy - a course that is not currently available through Cisco’s learning platform.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mG92862tEkcmYjwLpumZzk" name="mG92862tEkcmYjwLpumZzk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/mG92862tEkcmYjwLpumZzk.jpg" mos="https://cdn.mos.cms.futurecdn.net/mG92862tEkcmYjwLpumZzk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How a platform approach to security monitoring initiatives adds value</strong></p><p class="fancy-box__body-text">Integration, orchestration, analytics, automation, and the need for speed</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/367042/how-a-platform-approach-to-security-monitoring-initiatives-adds-value" data-original-url="/security/367042/how-a-platform-approach-to-security-monitoring-initiatives-adds-value">FREE DOWNLOAD</a></p></div></div><p>Motta claims to hold other cyber security and networking <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" data-original-url="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training">certifications</a> too. He achieved three CompTIA certifications in 2019: Cybersecurity Analyst (CySA+), Network+, and A+. His profile also shows he achieved the Cisco Certified Network Associate Cyber Ops (CCNA) certification in 2018.</p><p>Motta was taken to Pinellas County Jail on Friday 8 April and was released in the early hours of Saturday morning after paying a $60,000 bail, reports suggested.</p><p>The victim is currently unnamed and many details have yet to be released, but police said they are aged 65 years or older.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/367398/certified-ethical-hacker-and-it-manager-steals-575000-in-cryptocurrency</link>
                                                                            <description>
                            <![CDATA[ The practising IT manager stole the huge sum from an elderly person after being hired to fit a home security system ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">p1pPvVUDxf1DH5aGiewA7m</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZzdJSZhjvG3kZFpodAqtjF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 Apr 2022 11:18:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZzdJSZhjvG3kZFpodAqtjF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ethical hacker silhouette walking through a keyhole, symbolising physical security and penetration testing]]></media:description>                                                            <media:text><![CDATA[Ethical hacker silhouette walking through a keyhole, symbolising physical security and penetration testing]]></media:text>
                                <media:title type="plain"><![CDATA[Ethical hacker silhouette walking through a keyhole, symbolising physical security and penetration testing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZzdJSZhjvG3kZFpodAqtjF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A certified ethical hacker and practising IT manager has been charged with several offences after stealing a large sum of cryptocurrency from an elderly person.</p><p>Aaron Daniel Motta allegedly stole more than $575,000 (£411,900) from an elderly victim by stealing a Trezor hardware wallet used to store cryptocurrency offline. The type of cryptocurrency was not disclosed in the police reports.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/360701/it-pro-panel-do-we-still-need-certifications" data-original-url="/business-strategy/careers-training/360701/it-pro-panel-do-we-still-need-certifications">IT Pro Panel: Do we still need certifications?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">Stories from the front line: The secrets of the Red Team revealed</a></p></div></div><p>Clearwater Police in Florida said Motta transferred the sum into multiple wallets he owned after the victim hired Motta to install a security system in their home.</p><p>Motta faces felony charges of grand theft and offences against computer users, according to an arrest affidavit, <a href="https://www.tampabay.com/news/breaking-news/2022/04/09/pinellas-park-man-stole-nearly-600000-in-cryptocurrency-police-say/?utm_source=fark"><em>Tampa Bay Times</em></a> reported.</p><p>According to a LinkedIn profile in Motta’s name, the accused is a specialist in <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a>, <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a>, <a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">offensive security</a>, and IT.</p><p>The 27-year-old is currently self-employed, an owner at Motta Management & Mitigation Services, and recently left two positions - security technician and network technician - at different companies. Motta is also an active participant in <a href="https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities" data-original-url="https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities">Apple’s bug bounty program</a>.</p><p>According to the profile, Motta also holds a degree in cyber/electronic operations and warfare from St. Petersburg College and is a Certified <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">Ethical Hacker</a> through Cisco Networking Academy - a course that is not currently available through Cisco’s learning platform.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mG92862tEkcmYjwLpumZzk" name="mG92862tEkcmYjwLpumZzk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/mG92862tEkcmYjwLpumZzk.jpg" mos="https://cdn.mos.cms.futurecdn.net/mG92862tEkcmYjwLpumZzk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How a platform approach to security monitoring initiatives adds value</strong></p><p class="fancy-box__body-text">Integration, orchestration, analytics, automation, and the need for speed</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/367042/how-a-platform-approach-to-security-monitoring-initiatives-adds-value" data-original-url="/security/367042/how-a-platform-approach-to-security-monitoring-initiatives-adds-value">FREE DOWNLOAD</a></p></div></div><p>Motta claims to hold other cyber security and networking <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" data-original-url="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training">certifications</a> too. He achieved three CompTIA certifications in 2019: Cybersecurity Analyst (CySA+), Network+, and A+. His profile also shows he achieved the Cisco Certified Network Associate Cyber Ops (CCNA) certification in 2018.</p><p>Motta was taken to Pinellas County Jail on Friday 8 April and was released in the early hours of Saturday morning after paying a $60,000 bail, reports suggested.</p><p>The victim is currently unnamed and many details have yet to be released, but police said they are aged 65 years or older.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ukrainian ethical hackers targeted by Russian malware attacks ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cyber criminals are preying on ethical hackers supporting the IT Army of Ukraine by deceiving them into downloading information-stealing malware.</p><p>Opportunistic cyber criminals are posing as genuine representatives of the IT Army of Ukraine and pretending to provide them with tools to deliver <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">distributed denial of service attacks</a> (DDoS) that ultimately turn out to be <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, according to researchers at Cisco Talos.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war" data-original-url="/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war">How Telegram became Ukraine's biggest digital ally in the war</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/363893/conti-ransomware-data-leaked-ukranian-researcher" data-original-url="/security/ransomware/363893/conti-ransomware-data-leaked-ukranian-researcher">Conti ransomware gang data leaked by Ukrainian cyber researcher</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" data-original-url="/security/28026/what-is-a-ddos-attack">What is a DDoS attack?</a></p></div></div><p>The <a href="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war" data-original-url="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war">IT Army of Ukraine</a> is a group that mobilise via the Telegram platform and was originally assembled at the start of the conflict by a Ukrainian Minister to recruit as many supporters as possible to fight Russia in cyber space.</p><p>The group currently has more than 300,000 members and posts daily ‘hit lists’ - lists of target .ru URLs for tech-savvy supporters of Ukraine to knock offline. Recent targets include Russian electronic signature services and importers of technology for the Russian military.</p><p>Criminals are targeting these <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hackers</a> using Telegram channels that are seemingly related to the real IT Army of Ukraine group, but are not genuine.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hUYRp7SYdVvhXHDNYtaq2h" name="" alt="Screenshot of deceptive malware message in a Telegram group" src="https://cdn.mos.cms.futurecdn.net/hUYRp7SYdVvhXHDNYtaq2h.jpg" mos="https://cdn.mos.cms.futurecdn.net/hUYRp7SYdVvhXHDNYtaq2h.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Cisco Talos)</span></figcaption></figure><p>Cisco Talos researchers saw cases of adverts for inauthentic versions of genuine DDoS tools, such as the real Disbalancer Liberator tool, which when clicked infect the user's system with information-stealing malware that harvests credentials and <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining" data-original-url="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency</a> information.</p><p>The information stealer gleans information from browsers such as Chrome and Firefox, and scans other locations on the file system for key information before relaying it back to a Russian IP address.</p><p>“This is an example of one of the many ways opportunistic cybercriminals are attempting to take advantage of the Russian invasion by exploiting sympathisers on both sides of the conflict,” the researchers said.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/-h_a9Ld9awE" allowfullscreen></iframe></div></div><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PXq3FiGTPiHsCNT9ycYeag" name="PXq3FiGTPiHsCNT9ycYeag.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/PXq3FiGTPiHsCNT9ycYeag.png" mos="https://cdn.mos.cms.futurecdn.net/PXq3FiGTPiHsCNT9ycYeag.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Edge to cloud security: A new WAN and security edge</strong></p><p class="fancy-box__body-text">A practical guide to adopting a secure access service edge (SASE) architecture</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/365573/edge-to-cloud-security-a-new-wan-and-security-edge" data-original-url="/security/365573/edge-to-cloud-security-a-new-wan-and-security-edge">FREE DOWNLOAD</a></p></div></div><p>“Such activity could take the form of themed email lures on news topics or donation solicitations, malicious links purporting to host relief funds or refugee support sites, malware masquerading as security defensive or offensive tools, and more. Users must carefully inspect suspicious emails before opening them and validate software or other files before downloading them.”</p><p>Cisco Talos said evidence suggests the threat actors behind the campaign have been distributing infostealers since “at least November 2021” but have now pivoted to targeting <a href="https://www.itpro.com/hacking/30203/what-is-hacktivism" data-original-url="https://www.itpro.com/hacking/30203/what-is-hacktivism">hacktivists</a> siding with Ukraine.</p><p>It also said it expects the information-stealing activity to continue and diversify as the global interest in the conflict creates a potentially massive pool of targets for threat actors to prey on.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ethical-hacking/366727/russia-targets-ukraine-ethical-hackers-with-malware</link>
                                                                            <description>
                            <![CDATA[ Cisco Talos researchers say the IT Army of Ukraine's Telegram channel is being hit with malicious links ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hZu3PSRNu6UPZ1mJwW3NTD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tkKB3q5gtsyADQHcoXjLSa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Mar 2022 13:38:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tkKB3q5gtsyADQHcoXjLSa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Russian hacking on a laptop mockup with code sprawling over the screen]]></media:description>                                                            <media:text><![CDATA[Russian hacking on a laptop mockup with code sprawling over the screen]]></media:text>
                                <media:title type="plain"><![CDATA[Russian hacking on a laptop mockup with code sprawling over the screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tkKB3q5gtsyADQHcoXjLSa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals are preying on ethical hackers supporting the IT Army of Ukraine by deceiving them into downloading information-stealing malware.</p><p>Opportunistic cyber criminals are posing as genuine representatives of the IT Army of Ukraine and pretending to provide them with tools to deliver <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">distributed denial of service attacks</a> (DDoS) that ultimately turn out to be <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, according to researchers at Cisco Talos.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war" data-original-url="/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war">How Telegram became Ukraine's biggest digital ally in the war</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/363893/conti-ransomware-data-leaked-ukranian-researcher" data-original-url="/security/ransomware/363893/conti-ransomware-data-leaked-ukranian-researcher">Conti ransomware gang data leaked by Ukrainian cyber researcher</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" data-original-url="/security/28026/what-is-a-ddos-attack">What is a DDoS attack?</a></p></div></div><p>The <a href="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war" data-original-url="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war">IT Army of Ukraine</a> is a group that mobilise via the Telegram platform and was originally assembled at the start of the conflict by a Ukrainian Minister to recruit as many supporters as possible to fight Russia in cyber space.</p><p>The group currently has more than 300,000 members and posts daily ‘hit lists’ - lists of target .ru URLs for tech-savvy supporters of Ukraine to knock offline. Recent targets include Russian electronic signature services and importers of technology for the Russian military.</p><p>Criminals are targeting these <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hackers</a> using Telegram channels that are seemingly related to the real IT Army of Ukraine group, but are not genuine.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hUYRp7SYdVvhXHDNYtaq2h" name="" alt="Screenshot of deceptive malware message in a Telegram group" src="https://cdn.mos.cms.futurecdn.net/hUYRp7SYdVvhXHDNYtaq2h.jpg" mos="https://cdn.mos.cms.futurecdn.net/hUYRp7SYdVvhXHDNYtaq2h.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Cisco Talos)</span></figcaption></figure><p>Cisco Talos researchers saw cases of adverts for inauthentic versions of genuine DDoS tools, such as the real Disbalancer Liberator tool, which when clicked infect the user's system with information-stealing malware that harvests credentials and <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining" data-original-url="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency</a> information.</p><p>The information stealer gleans information from browsers such as Chrome and Firefox, and scans other locations on the file system for key information before relaying it back to a Russian IP address.</p><p>“This is an example of one of the many ways opportunistic cybercriminals are attempting to take advantage of the Russian invasion by exploiting sympathisers on both sides of the conflict,” the researchers said.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/-h_a9Ld9awE" allowfullscreen></iframe></div></div><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PXq3FiGTPiHsCNT9ycYeag" name="PXq3FiGTPiHsCNT9ycYeag.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/PXq3FiGTPiHsCNT9ycYeag.png" mos="https://cdn.mos.cms.futurecdn.net/PXq3FiGTPiHsCNT9ycYeag.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Edge to cloud security: A new WAN and security edge</strong></p><p class="fancy-box__body-text">A practical guide to adopting a secure access service edge (SASE) architecture</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/365573/edge-to-cloud-security-a-new-wan-and-security-edge" data-original-url="/security/365573/edge-to-cloud-security-a-new-wan-and-security-edge">FREE DOWNLOAD</a></p></div></div><p>“Such activity could take the form of themed email lures on news topics or donation solicitations, malicious links purporting to host relief funds or refugee support sites, malware masquerading as security defensive or offensive tools, and more. Users must carefully inspect suspicious emails before opening them and validate software or other files before downloading them.”</p><p>Cisco Talos said evidence suggests the threat actors behind the campaign have been distributing infostealers since “at least November 2021” but have now pivoted to targeting <a href="https://www.itpro.com/hacking/30203/what-is-hacktivism" data-original-url="https://www.itpro.com/hacking/30203/what-is-hacktivism">hacktivists</a> siding with Ukraine.</p><p>It also said it expects the information-stealing activity to continue and diversify as the global interest in the conflict creates a potentially massive pool of targets for threat actors to prey on.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anonymous hijacks Russian broadcasts with footage of Ukraine war ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Anonymous hacking group executed another major cyber attack in response to Russia’s invasion of Ukraine this weekend, claiming it hijacked Russian broadcasters and showed war footage from inside <a href="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war" data-original-url="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war">Ukraine</a>.</p><p>The hacking collective <a href="https://twitter.com/YourAnonNews/status/1500613013510008836">announced</a> the attack late Sunday evening, saying it was able to manipulate broadcasts on TV channels such as Russia 24, Channel One, and Moscow 24, in addition to streaming services Wink and Ivi.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war" data-original-url="/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war">How Telegram became Ukraine's biggest digital ally in the war</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/364045/mwc-ukrainian-protesters-call-for-russian-tech-boycott" data-original-url="/security/cyber-warfare/364045/mwc-ukrainian-protesters-call-for-russian-tech-boycott">MWC 2022: Ukrainian protesters call for Russian tech boycott</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/364526/anonymous-hack-russian-space-research-institute" data-original-url="/security/hacking/364526/anonymous-hack-russian-space-research-institute">Anonymous hacks website of Russian Space Research Institute</a></p></div></div><p>Anonymous’ Twitter account made the announcement, and also shared footage that appears to show the hijacked broadcasts appearing on televisions in Russia. </p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1500613013510008836 "><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1500613013510008836 "></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>It’s unclear if Anonymous hacked the broadcasters in question or were able to manipulate the broadcasts by other means, such as interrupting smart TV streams.</p><p>“We are #Anonymous. We are involved in the biggest Anonymous op ever seen,” the group <a href="https://twitter.com/YourAnonNews/status/1500644456680378378">tweeted</a> Monday morning. “That being said, we are worried that some governments will indeed see us as a threat and create some scenario to make us look bad (false flag). We only want peace, not war.</p><p>“We abhor violence. We are anti-war. We are against police brutality. We have raised our fists in the air to stand against aggressors time and time again. We would never choose to hurt anyone physically. Understand this and know this if any government says otherwise.”</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1497678663046905863"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1497678663046905863"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Anonymous also <a href="https://twitter.com/YourAnonNews/status/1500169119219466251">took credit</a> for taking down Russia’s Federal Security Service (FSB) on Saturday too, posting a screenshot of its website not being able to connect. </p><p>The hack aimed to show the reality of the war to the people of Russia after the country’s regime effectively <a href="https://www.reuters.com/world/uk/bbc-halts-reporting-russia-after-new-law-passes-2022-03-04">outlawed independent journalism</a> last week, imposing a maximum jail sentence of 15 years for spreading what it calls ‘misinformation’, and has made numerous attempts to spread falsehoods about the country’s intentions with its efforts. </p><p>Videos supposedly showing a Russian prisoner of war, circulating online in recent days, have shown the <a href="https://twitter.com/hackingbutlegal/status/1500465032966062082">soldiers were misled about the situation in Ukraine</a>. The government allegedly told its troops that Ukraine was being occupied by a fascist, Nazi-like regime and they were being sent to help the situation, not cause it.</p><p>Access to outside information is slowly closing for Russia’s citizens as the country aims to control the narrative of the war.</p><p>The Kremlin <a href="https://www.theguardian.com/world/2022/mar/04/russia-completely-blocks-access-to-facebook-and-twitter">blocked access to Facebook and Twitter</a> recently after it said the sites were blocking Russian state-backed media. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6u4bhND7qJARukeDS8iBvC" name="6u4bhND7qJARukeDS8iBvC.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/6u4bhND7qJARukeDS8iBvC.png" mos="https://cdn.mos.cms.futurecdn.net/6u4bhND7qJARukeDS8iBvC.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Moving forward in a work from anywhere world</strong></p><p class="fancy-box__body-text">A gorilla guide</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/remote-access/362252/moving-forward-in-a-work-from-anywhere-world" data-original-url="/mobile/remote-access/362252/moving-forward-in-a-work-from-anywhere-world">FREE DOWNLOAD</a></p></div></div><p>Legitimate news sources like <em>BBC News</em> have been restricted too, though people in Russia are still able to access such websites via the <a href="https://www.itpro.com/security/identity-theft/356578/a-simple-guide-to-the-dark-web" data-original-url="https://www.itpro.com/security/identity-theft/356578/a-simple-guide-to-the-dark-web">TOR browser</a> and onion mirrors. </p><p>Reporters from British news organisations have been forced to cease their coverage of the war as a result of the Kremlin’s ‘fake news’ law. In addition to a hostile legal environment for journalists, <em>Sky News</em> reporters also reported <a href="https://news.sky.com/story/sky-news-teams-harrowing-account-of-their-violent-ambush-in-ukraine-this-week-12557585">being shot at by Russian forces</a> despite them making it clear they were from the press.</p><p>Journalists sustained gunshot wounds as a result of the ambush, an act that is considered a war crime under international law.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/365021/anonymous-hack-russian-state-broadcasts</link>
                                                                            <description>
                            <![CDATA[ The hacking group said it managed to manipulate the broadcasts of three major Russian state-backed media organisations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xACXJjqJJJFdU9ZbY9kHL5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6JWu5tPs6NR2CXDxtPqvCE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Mar 2022 10:43:34 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6JWu5tPs6NR2CXDxtPqvCE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person wearing a Guy Fawkes mask as a symbol of the Anonymous hacking collective]]></media:description>                                                            <media:text><![CDATA[A person wearing a Guy Fawkes mask as a symbol of the Anonymous hacking collective]]></media:text>
                                <media:title type="plain"><![CDATA[A person wearing a Guy Fawkes mask as a symbol of the Anonymous hacking collective]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6JWu5tPs6NR2CXDxtPqvCE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Anonymous hacking group executed another major cyber attack in response to Russia’s invasion of Ukraine this weekend, claiming it hijacked Russian broadcasters and showed war footage from inside <a href="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war" data-original-url="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war">Ukraine</a>.</p><p>The hacking collective <a href="https://twitter.com/YourAnonNews/status/1500613013510008836">announced</a> the attack late Sunday evening, saying it was able to manipulate broadcasts on TV channels such as Russia 24, Channel One, and Moscow 24, in addition to streaming services Wink and Ivi.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war" data-original-url="/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war">How Telegram became Ukraine's biggest digital ally in the war</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/364045/mwc-ukrainian-protesters-call-for-russian-tech-boycott" data-original-url="/security/cyber-warfare/364045/mwc-ukrainian-protesters-call-for-russian-tech-boycott">MWC 2022: Ukrainian protesters call for Russian tech boycott</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/364526/anonymous-hack-russian-space-research-institute" data-original-url="/security/hacking/364526/anonymous-hack-russian-space-research-institute">Anonymous hacks website of Russian Space Research Institute</a></p></div></div><p>Anonymous’ Twitter account made the announcement, and also shared footage that appears to show the hijacked broadcasts appearing on televisions in Russia. </p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1500613013510008836 "><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1500613013510008836 "></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>It’s unclear if Anonymous hacked the broadcasters in question or were able to manipulate the broadcasts by other means, such as interrupting smart TV streams.</p><p>“We are #Anonymous. We are involved in the biggest Anonymous op ever seen,” the group <a href="https://twitter.com/YourAnonNews/status/1500644456680378378">tweeted</a> Monday morning. “That being said, we are worried that some governments will indeed see us as a threat and create some scenario to make us look bad (false flag). We only want peace, not war.</p><p>“We abhor violence. We are anti-war. We are against police brutality. We have raised our fists in the air to stand against aggressors time and time again. We would never choose to hurt anyone physically. Understand this and know this if any government says otherwise.”</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1497678663046905863"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1497678663046905863"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Anonymous also <a href="https://twitter.com/YourAnonNews/status/1500169119219466251">took credit</a> for taking down Russia’s Federal Security Service (FSB) on Saturday too, posting a screenshot of its website not being able to connect. </p><p>The hack aimed to show the reality of the war to the people of Russia after the country’s regime effectively <a href="https://www.reuters.com/world/uk/bbc-halts-reporting-russia-after-new-law-passes-2022-03-04">outlawed independent journalism</a> last week, imposing a maximum jail sentence of 15 years for spreading what it calls ‘misinformation’, and has made numerous attempts to spread falsehoods about the country’s intentions with its efforts. </p><p>Videos supposedly showing a Russian prisoner of war, circulating online in recent days, have shown the <a href="https://twitter.com/hackingbutlegal/status/1500465032966062082">soldiers were misled about the situation in Ukraine</a>. The government allegedly told its troops that Ukraine was being occupied by a fascist, Nazi-like regime and they were being sent to help the situation, not cause it.</p><p>Access to outside information is slowly closing for Russia’s citizens as the country aims to control the narrative of the war.</p><p>The Kremlin <a href="https://www.theguardian.com/world/2022/mar/04/russia-completely-blocks-access-to-facebook-and-twitter">blocked access to Facebook and Twitter</a> recently after it said the sites were blocking Russian state-backed media. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6u4bhND7qJARukeDS8iBvC" name="6u4bhND7qJARukeDS8iBvC.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/6u4bhND7qJARukeDS8iBvC.png" mos="https://cdn.mos.cms.futurecdn.net/6u4bhND7qJARukeDS8iBvC.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Moving forward in a work from anywhere world</strong></p><p class="fancy-box__body-text">A gorilla guide</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/remote-access/362252/moving-forward-in-a-work-from-anywhere-world" data-original-url="/mobile/remote-access/362252/moving-forward-in-a-work-from-anywhere-world">FREE DOWNLOAD</a></p></div></div><p>Legitimate news sources like <em>BBC News</em> have been restricted too, though people in Russia are still able to access such websites via the <a href="https://www.itpro.com/security/identity-theft/356578/a-simple-guide-to-the-dark-web" data-original-url="https://www.itpro.com/security/identity-theft/356578/a-simple-guide-to-the-dark-web">TOR browser</a> and onion mirrors. </p><p>Reporters from British news organisations have been forced to cease their coverage of the war as a result of the Kremlin’s ‘fake news’ law. In addition to a hostile legal environment for journalists, <em>Sky News</em> reporters also reported <a href="https://news.sky.com/story/sky-news-teams-harrowing-account-of-their-violent-ambush-in-ukraine-this-week-12557585">being shot at by Russian forces</a> despite them making it clear they were from the press.</p><p>Journalists sustained gunshot wounds as a result of the ambush, an act that is considered a war crime under international law.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Vulnerability hunters are cut from a different cloth – they’re naturally inquisitive ]]></title>
                                                                                                <dc:content><![CDATA[ <p>When you’ve been around the information security business for as long as I have (more than 30 years now) it’s not surprising to get a lot of emails from desperate people looking for help. Sadly, I simply can’t respond to most of them, or I wouldn’t have time to do my job. </p><p>Some don’t deserve my guilt for not replying. I’m talking about those who seem to think I’ll either hand out step-by-step instructions for <a href="https://www.itpro.com/security/hacking/358536/social-media-firms-clamp-down-on-stolen-accounts" data-original-url="https://www.itpro.com/security/hacking/358536/social-media-firms-clamp-down-on-stolen-accounts">accessing someone else’s social media account</a> or simply do a job because they’ve said “please”. The reasoning behind these requests is most often transparently bogus: “I’ve been locked out of my account and Twitter support won’t help me, my partner is critically ill and I need access to their email for [insert spurious reason here], my partner has been cheating on me and I need proof”. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29328/your-essential-guide-to-internet-security" data-original-url="/security/29328/your-essential-guide-to-internet-security">Your essential guide to internet security</a></p></div></div><p><a href="https://www.itpro.com/security/29328/your-essential-guide-to-internet-security" data-original-url="https://www.itpro.com/security/29328/your-essential-guide-to-internet-security">Wannabe hackers</a> are the bane of my working life, truth be told; unless, that is, they want to become a hacker, an <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hacker</a> or vulnerability hunter, Odd, then, that I tend to receive very few of these genuine requests for guidance. The ones I do will be pointed in the general direction of great resources that can help them to help themselves. <a href="https://www.itpro.com/security/26608/hacking-at-10-how-to-get-your-child-interested-in-it" data-original-url="https://www.itpro.com/security/26608/hacking-at-10-how-to-get-your-child-interested-in-it">Teaching yourself to hack</a> may seem a bit of a stretch, but you’d be surprised how commonplace this is.</p><p>I’m self-taught, not least as there were no accessible educational routes into the game back when I started out. The latest annual report from Bugcrowd, a crowdsourced <a href="https://www.itpro.com/security/zero-day-exploit/362258/google-doubles-bug-bounty-linux-kubernetes-exploits" data-original-url="https://www.itpro.com/security/zero-day-exploit/362258/google-doubles-bug-bounty-linux-kubernetes-exploits">bug bounty</a> and vulnerability disclosure platform, revealed a staggering 79% of the hackers using the platform were self-taught. I’ll let that sink in for a bit. </p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/1ojGcpJHLKOEausXT9cuVa"></iframe><p>These days there are more traditional educational pathways to becoming an <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">information security professional</a> than you can shake a stick at. If you did shake that stick, I daresay a <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" data-original-url="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training">ream of certifications</a> would fall out of the learning tree as well. Vulnerability hunters, the kind of hackers who love tracking down security problems in hardware, software and services, however, tend to be cut from a different cloth. They’re naturally inquisitive, always interested in learning more, and the successful ones have an inert ability to approach problems from a left-field perspective. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GmEy94iCPBFPs9V6HWFekm" name="GmEy94iCPBFPs9V6HWFekm.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" mos="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The best defence against ransomware</strong></p><p class="fancy-box__body-text">How ransomware is evolving and how to defend against it</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361095/the-best-defence-against-ransomware" data-original-url="/security/ransomware/361095/the-best-defence-against-ransomware">FREE DOWNLOAD</a></p></div></div><p>With this in mind, it’s no surprise the Bugcrowd report found one in five of their hackers <a href="https://www.itpro.com/business-strategy/careers-training/356168/how-the-autistic-population-could-solve-the-tech" data-original-url="https://www.itpro.com/business-strategy/careers-training/356168/how-the-autistic-population-could-solve-the-tech">identified as neurodivergent</a>. Obviously, a coding background – be that as a “hobbyist” programmer or someone who has been through the system and come out the other end with some qualifications – is a bonus for anyone beginning on the hacker journey. On the assumption you’re at least <a href="https://www.itpro.com/national-cyber-security-centre-ncsc/31903/ncsc-challenges-business-leaders-to-learn-the-basics-of" data-original-url="https://www.itpro.com/national-cyber-security-centre-ncsc/31903/ncsc-challenges-business-leaders-to-learn-the-basics-of">code-literate to some degree</a>, though, where do you actually start? This is something I gave a fair bit of thought to recently and, with the help of hacker friends, information security professionals and, indeed, I’ve come up with a learning-to-hack resource list.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">A month in the life of a social engineer – part one</a></p></div></div><p>Before I get onto the list itself, it bears mentioning that “hacking” is a very broad church with multifarious specialisms. It’s possible to decide in advance that you want to find vulnerabilities in applications, devices, web-based services, cars and so on. A grounding in the basics, however, knowing the essentials of hacking methodology, should be a given across all of these. Start to learn first, specialise later.</p><p>Bug bounty and vulnerability hunting platforms themselves will often be a good place to start. <a href="https://github.com/bugcrowd/bugcrowd_university">Bugcrowd University</a> is one highly recommended resource. It’s free to use, open-source, and has multiple content modules with slides, videos and labs, covering everything from introductions to tooling through to recon and discovery. It goes further than this, though, in that it extends out to other online learning resources on bug hunting methodology, data-driven web hacking, social engineering and so on.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/LuqAVA1jiPI" allowfullscreen></iframe></div></div><p>Doing is better than reading, at least for me. It’s how I started my hacking journey decades ago, although largely driven by a lack of reading material (with the exception of the excellent <em>Hacker’s Handbook</em> series). Anyway, with a practical learning experience in mind, it’s hard to ignore the likes of the gamified learning resource that is <a href="http://tryhackme.com">Try Hack Me</a> or the browser-based and highly interactive <a href="http://academy.hackthebox.com">Hack The Box Academy</a>. Both cater for varying skill levels, and you can’t fail but learn if you embrace them. </p><p>Talking of practicalities, the right tooling is one of the most important parts of your hacking armoury and Burp Suite is right up there. The <a href="http://portswigger.net/web-security">PortSwigger Web Security Academy</a> is free and from the people who created Burp Suite. It features interactive labs, with the author of The Web Application Hacker’s Handbook leading the team of experts here.</p><p>A number of my hacking acquaintances, including some with successful careers in the bug bounty world, recommend scouring the web, conference presentations, info security Twitter, for walkthroughs and explanations of <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">proof-of-concept (PoC) exploits</a>. These can be a highly informative way of understanding how the theoretical stuff works in practice once you’ve got far enough along the learning curve. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">What's behind the explosion in zero-day exploits?</a></p></div></div><p>Bug bounty platform HackerOne, for example, has a community feed called <a href="http://hackerone.com/hacktivity">Hacktivity</a> that showcases the latest hacking activity and enables users to search through the various reports for the ones they’re interested in. There’s even a Hacktivity Con, now in its second year, where hackers of all skill levels can learn from each other.</p><p>This is far from an exhaustive collection of hacking resources for the beginner, but it should be enough to provide food for thought as well as, somewhere among these options, a place to start that suits your personality. </p><p>There are some ‘don’t’ to be aware of, and they are very important ones so take heed. Don’t go using any of the readily available search tools that will find open hosts and give you immediate root access and so on. You can practise using Kali (an advanced penetration testing Linux distribution) or whatever on your own stuff, but be absolutely sure that it’s only your own stuff and that you don’t stray into opaque territory when it comes to networks used. Hacking any ‘live’ target is a no-no, a big legal no-no, that could see you landing in very hot water indeed. </p><p>You’ll find there are plenty of targets to practise on and stay within the law if you use those practical, gamified, learning resources. My personal recommendation is to stick to those resources if you want to be 101% sure you’re on the right side of the law.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/363344/vulnerability-hunters-naturally-inquisitive</link>
                                                                            <description>
                            <![CDATA[ So, you want to be a hacker? We share the best advice and resources for getting started ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ipg7AFC5TuhaAStgEp9hqw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qU6bvC48443qckkHxmMnZK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Mar 2022 08:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qU6bvC48443qckkHxmMnZK-1280-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic of a hacker walking through a digital corridor]]></media:description>                                                            <media:text><![CDATA[Graphic of a hacker walking through a digital corridor]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic of a hacker walking through a digital corridor]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qU6bvC48443qckkHxmMnZK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When you’ve been around the information security business for as long as I have (more than 30 years now) it’s not surprising to get a lot of emails from desperate people looking for help. Sadly, I simply can’t respond to most of them, or I wouldn’t have time to do my job. </p><p>Some don’t deserve my guilt for not replying. I’m talking about those who seem to think I’ll either hand out step-by-step instructions for <a href="https://www.itpro.com/security/hacking/358536/social-media-firms-clamp-down-on-stolen-accounts" data-original-url="https://www.itpro.com/security/hacking/358536/social-media-firms-clamp-down-on-stolen-accounts">accessing someone else’s social media account</a> or simply do a job because they’ve said “please”. The reasoning behind these requests is most often transparently bogus: “I’ve been locked out of my account and Twitter support won’t help me, my partner is critically ill and I need access to their email for [insert spurious reason here], my partner has been cheating on me and I need proof”. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29328/your-essential-guide-to-internet-security" data-original-url="/security/29328/your-essential-guide-to-internet-security">Your essential guide to internet security</a></p></div></div><p><a href="https://www.itpro.com/security/29328/your-essential-guide-to-internet-security" data-original-url="https://www.itpro.com/security/29328/your-essential-guide-to-internet-security">Wannabe hackers</a> are the bane of my working life, truth be told; unless, that is, they want to become a hacker, an <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hacker</a> or vulnerability hunter, Odd, then, that I tend to receive very few of these genuine requests for guidance. The ones I do will be pointed in the general direction of great resources that can help them to help themselves. <a href="https://www.itpro.com/security/26608/hacking-at-10-how-to-get-your-child-interested-in-it" data-original-url="https://www.itpro.com/security/26608/hacking-at-10-how-to-get-your-child-interested-in-it">Teaching yourself to hack</a> may seem a bit of a stretch, but you’d be surprised how commonplace this is.</p><p>I’m self-taught, not least as there were no accessible educational routes into the game back when I started out. The latest annual report from Bugcrowd, a crowdsourced <a href="https://www.itpro.com/security/zero-day-exploit/362258/google-doubles-bug-bounty-linux-kubernetes-exploits" data-original-url="https://www.itpro.com/security/zero-day-exploit/362258/google-doubles-bug-bounty-linux-kubernetes-exploits">bug bounty</a> and vulnerability disclosure platform, revealed a staggering 79% of the hackers using the platform were self-taught. I’ll let that sink in for a bit. </p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/1ojGcpJHLKOEausXT9cuVa"></iframe><p>These days there are more traditional educational pathways to becoming an <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">information security professional</a> than you can shake a stick at. If you did shake that stick, I daresay a <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" data-original-url="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training">ream of certifications</a> would fall out of the learning tree as well. Vulnerability hunters, the kind of hackers who love tracking down security problems in hardware, software and services, however, tend to be cut from a different cloth. They’re naturally inquisitive, always interested in learning more, and the successful ones have an inert ability to approach problems from a left-field perspective. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GmEy94iCPBFPs9V6HWFekm" name="GmEy94iCPBFPs9V6HWFekm.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" mos="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The best defence against ransomware</strong></p><p class="fancy-box__body-text">How ransomware is evolving and how to defend against it</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361095/the-best-defence-against-ransomware" data-original-url="/security/ransomware/361095/the-best-defence-against-ransomware">FREE DOWNLOAD</a></p></div></div><p>With this in mind, it’s no surprise the Bugcrowd report found one in five of their hackers <a href="https://www.itpro.com/business-strategy/careers-training/356168/how-the-autistic-population-could-solve-the-tech" data-original-url="https://www.itpro.com/business-strategy/careers-training/356168/how-the-autistic-population-could-solve-the-tech">identified as neurodivergent</a>. Obviously, a coding background – be that as a “hobbyist” programmer or someone who has been through the system and come out the other end with some qualifications – is a bonus for anyone beginning on the hacker journey. On the assumption you’re at least <a href="https://www.itpro.com/national-cyber-security-centre-ncsc/31903/ncsc-challenges-business-leaders-to-learn-the-basics-of" data-original-url="https://www.itpro.com/national-cyber-security-centre-ncsc/31903/ncsc-challenges-business-leaders-to-learn-the-basics-of">code-literate to some degree</a>, though, where do you actually start? This is something I gave a fair bit of thought to recently and, with the help of hacker friends, information security professionals and, indeed, I’ve come up with a learning-to-hack resource list.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">A month in the life of a social engineer – part one</a></p></div></div><p>Before I get onto the list itself, it bears mentioning that “hacking” is a very broad church with multifarious specialisms. It’s possible to decide in advance that you want to find vulnerabilities in applications, devices, web-based services, cars and so on. A grounding in the basics, however, knowing the essentials of hacking methodology, should be a given across all of these. Start to learn first, specialise later.</p><p>Bug bounty and vulnerability hunting platforms themselves will often be a good place to start. <a href="https://github.com/bugcrowd/bugcrowd_university">Bugcrowd University</a> is one highly recommended resource. It’s free to use, open-source, and has multiple content modules with slides, videos and labs, covering everything from introductions to tooling through to recon and discovery. It goes further than this, though, in that it extends out to other online learning resources on bug hunting methodology, data-driven web hacking, social engineering and so on.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/LuqAVA1jiPI" allowfullscreen></iframe></div></div><p>Doing is better than reading, at least for me. It’s how I started my hacking journey decades ago, although largely driven by a lack of reading material (with the exception of the excellent <em>Hacker’s Handbook</em> series). Anyway, with a practical learning experience in mind, it’s hard to ignore the likes of the gamified learning resource that is <a href="http://tryhackme.com">Try Hack Me</a> or the browser-based and highly interactive <a href="http://academy.hackthebox.com">Hack The Box Academy</a>. Both cater for varying skill levels, and you can’t fail but learn if you embrace them. </p><p>Talking of practicalities, the right tooling is one of the most important parts of your hacking armoury and Burp Suite is right up there. The <a href="http://portswigger.net/web-security">PortSwigger Web Security Academy</a> is free and from the people who created Burp Suite. It features interactive labs, with the author of The Web Application Hacker’s Handbook leading the team of experts here.</p><p>A number of my hacking acquaintances, including some with successful careers in the bug bounty world, recommend scouring the web, conference presentations, info security Twitter, for walkthroughs and explanations of <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">proof-of-concept (PoC) exploits</a>. These can be a highly informative way of understanding how the theoretical stuff works in practice once you’ve got far enough along the learning curve. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">What's behind the explosion in zero-day exploits?</a></p></div></div><p>Bug bounty platform HackerOne, for example, has a community feed called <a href="http://hackerone.com/hacktivity">Hacktivity</a> that showcases the latest hacking activity and enables users to search through the various reports for the ones they’re interested in. There’s even a Hacktivity Con, now in its second year, where hackers of all skill levels can learn from each other.</p><p>This is far from an exhaustive collection of hacking resources for the beginner, but it should be enough to provide food for thought as well as, somewhere among these options, a place to start that suits your personality. </p><p>There are some ‘don’t’ to be aware of, and they are very important ones so take heed. Don’t go using any of the readily available search tools that will find open hosts and give you immediate root access and so on. You can practise using Kali (an advanced penetration testing Linux distribution) or whatever on your own stuff, but be absolutely sure that it’s only your own stuff and that you don’t stray into opaque territory when it comes to networks used. Hacking any ‘live’ target is a no-no, a big legal no-no, that could see you landing in very hot water indeed. </p><p>You’ll find there are plenty of targets to practise on and stay within the law if you use those practical, gamified, learning resources. My personal recommendation is to stick to those resources if you want to be 101% sure you’re on the right side of the law.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Belarusian hacktivists target railway in bid to halt Russian military ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Belarusian hacktivists claim to have infected the country's rail network with ransomware in a bid to stop the Russian military from mobilising around Ukraine.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30203/what-is-hacktivism" data-original-url="/hacking/30203/what-is-hacktivism">What is hacktivism?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/361959/us-gov-warning-russia-cyber-threat-critical-infrastructure" data-original-url="/security/cyber-warfare/361959/us-gov-warning-russia-cyber-threat-critical-infrastructure">US gov issues fresh warning over Russian threat to critical infrastructure</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/32717/what-can-an-ethical-hacker-do-for-my-business" data-original-url="/hacking/32717/what-can-an-ethical-hacker-do-for-my-business">What can an ethical hacker do for my business?</a></p></div></div><p>The Cyber Partisan hacktivists claim to have encrypted "the bulk of the servers, databases, and workstations" belonging to the Belarusian Railways, and destroyed their backups, according to posts on <a href="https://t.me/cpartisans/631">Telegram</a> and <a href="https://twitter.com/cpartisans/status/1485618881557315588">Twitter</a>.</p><p>Cyber Partisan is demanding the release of 50 political prisoners who are in need of medical assistance and assurances that Russian troops will stop mobilising on Belarusian soil - a country that shares a border with Ukraine and whose leader has a close relationship with Vladimir Putin.</p><p>"BelZhD, at the command of the terrorist Lukashenko, these days allows the occupying troops to enter our land," the Telegram message read. "As part of the 'Peklo' cyber campaign, we encrypted the bulk of the servers, <a href="https://www.itpro.com/data-insights/databases/358688/five-database-problems-and-how-to-solve-them" data-original-url="https://www.itpro.com/data-insights/databases/358688/five-database-problems-and-how-to-solve-them">databases</a>, and <a href="https://www.itpro.com/hardware/355998/the-best-professional-workstations-for-any-budget" data-original-url="https://www.itpro.com/hardware/355998/the-best-professional-workstations-for-any-budget">workstations</a> of the BelZhD in order to slow down and disrupt the operation of the road. The backups have been destroyed.</p><p>"Dozens of databases have been cyberattacked, including AS-Sledd, AS-USOGDP, SAP, AC-Pred, pass.rw.by, uprava, IRC, etc. Automation and security systems were deliberately NOT affected by a cyber attack in order to avoid emergency situations."</p><p>In the online posts, the group echoed the message shared by Belarusian rail workers <a href="https://t.me/belzhd_live/1257">on Friday</a> that more than 33 Russian military trains containing equipment and soldiers would be entering Belarus. The message was also corroborated by reports from other <a href="https://www.washingtonpost.com/world/2022/01/24/ukraine-eu-us-embassy-russia">news outlets</a>.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1485618881557315588"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1485618881557315588"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Belarusian Railways published a <a href="https://www.rw.by/corporate/press_center/news_of_passengers/2022/01/vnimaniyu-passazhirov_24012022">statement on Monday</a> confirming that it was experiencing difficulties and that some services were unavailable, though no mention of compromised systems, databases, or servers was mentioned - nor was <a href="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022" data-original-url="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022">ransomware</a>.</p><p>"For technical reasons, services for issuing electronic travel documents are temporarily unavailable," it said. "To arrange travel and return electronic travel documents, please contact the ticket office.</p><p>"Currently, work is underway to restore the performance of the systems. Belarusian Railways apologises for the inconvenience caused."</p><p>At the time of writing, <em>IT Pro</em> can confirm online ticket sales are still impacted and are unavailable, with customers greeted with the following message.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sGAmfE7DqzvGRiV3DfTZ58" name="" alt="Screenshot of the message appearing on Belarusian Railways website when trying book tickets online" src="https://cdn.mos.cms.futurecdn.net/sGAmfE7DqzvGRiV3DfTZ58.jpg" mos="https://cdn.mos.cms.futurecdn.net/sGAmfE7DqzvGRiV3DfTZ58.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: IT Pro)</span></figcaption></figure><h3 class="article-body__section" id="section-tensions-in-the-region"><span>Tensions in the region</span></h3><p>Russia has seized Ukrainian territory in the past and in recent months has stepped up its calls against Ukraine joining European institutions, with a particular focus on Nato. Ukrainians have been preparing for a possible invasion by Russia for months, with many in the region fearful of a war looming.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Ee76YV7F7sxSYqNgUctp5T" name="Ee76YV7F7sxSYqNgUctp5T.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/Ee76YV7F7sxSYqNgUctp5T.png" mos="https://cdn.mos.cms.futurecdn.net/Ee76YV7F7sxSYqNgUctp5T.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Seven leading machine learning use cases</strong></p><p class="fancy-box__body-text">Seven ways machine learning solves business problems</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/machine-learning/361108/seven-leading-machine-learning-use-cases" data-original-url="/technology/machine-learning/361108/seven-leading-machine-learning-use-cases">FREE DOWNLOAD</a></p></div></div><p>In recent weeks, both the US and UK have withdrawn significant numbers of embassy staff and their families out of the region, which may indicate that the two allies believe an invasion is likely. </p><p>Today, the US has placed <a href="https://www.bbc.co.uk/news/world-europe-60118193">8,500 of its soldiers on alert</a> amid mounting tensions of Russian troops mobilising at the Ukrainian border. Western powers are showing unanimous unity on the matter, saying they will step in with "swift" and "unprecedented" actions if Russia was to invade Ukraine.</p><p>The news follows <a href="https://www.itpro.com/security/cyber-warfare/361959/us-gov-warning-russia-cyber-threat-critical-infrastructure" data-original-url="https://www.itpro.com/security/cyber-warfare/361959/us-gov-warning-russia-cyber-threat-critical-infrastructure">days of unsuccessful negotiations</a> between President Biden and President Putin in Geneva - failed talks that also prompted the FBI, NSA, DHS, and CISA to issue an alert to cyber security professionals that a Russian-linked cyber attack may be launched on critical infrastructure in relation to the worldwide tensions.</p><p>"The cybersecurity industry has gotten used to tossing around the idea of ‘nation-state’ adversaries, but I think we’ve yet to see cyber attacks used in concert with a full-fledged military campaign," said Tim Erlin, VP of strategy at Tripwire to <em>IT Pro</em>. "DHS’s warning sets that expectation that something has changed in the threat profile, and that organisations should be prepared for a change in the types of attacks they see."</p><h3 class="article-body__section" id="section-brief-overview-of-hacktivism"><span>Brief overview of hacktivism</span></h3><p>It's thought the alleged ransomware attack on Belarusian Railways is one of the first times ransomware has been used in <a href="https://www.itpro.com/hacking/30203/what-is-hacktivism" data-original-url="https://www.itpro.com/hacking/30203/what-is-hacktivism">hacktivism</a> but the practice of campaigning by hitting systems offline is well documented.</p><p>There were a number of high-profile hacktivist 'attacks' in 2021 alone, with right-wing social media platform <a href="https://www.usatoday.com/story/tech/news/2021/01/11/parler-hack-platform-archived-hackers-capitol-riots/6629772002">Parler</a>, and <a href="https://www.bloomberg.com/news/articles/2021-03-09/hackers-expose-tesla-jails-in-breach-of-150-000-security-cams">Verkada's surveillance cameras</a> among the victims targeted by hackers. The Adalat Ali hacking group also <a href="https://www.thetimes.co.uk/article/hackers-post-video-shot-in-iran-s-notorious-evin-prison-wdnk6f3l9">exposed the beatings and mistreatment of prisoners</a> in Iran's Evin prison in August 2021 out of protest against the abject living conditions.</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/1ojGcpJHLKOEausXT9cuVa"></iframe><p>Anonymous, LulzSec, and WikiLeaks are among some of the most well-known hacktivist groups in the world.</p><p>Hacktivism is a controversial practice with some seeing it as an effective means of campaigning while others believe the level of civil disobedience, and often the damage such attacks cause, goes beyond the acceptable level of resistance exhibited in more traditional forms of protest.</p><p>The US sees hacktivism as a significant threat and are categorised similarly, <a href="https://www.reuters.com/article/us-cyber-hacktivism-focus-idUSKBN2BH3HJ">in the eyes of the law</a>, to terrorist groups and transnational criminal organisations.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/362059/belarusian-hacktivists-railway-ransomware-halt-russian-military</link>
                                                                            <description>
                            <![CDATA[ The incident is thought to be one of the first times ransomware has been used in hacktivism ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">etiP2Gz2S96H1r8rtLUiU4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xH65SKaC9StGBUq7g6tS57-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Jan 2022 10:55:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xH65SKaC9StGBUq7g6tS57-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hacker against a red background]]></media:description>                                                            <media:text><![CDATA[A hacker against a red background]]></media:text>
                                <media:title type="plain"><![CDATA[A hacker against a red background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xH65SKaC9StGBUq7g6tS57-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Belarusian hacktivists claim to have infected the country's rail network with ransomware in a bid to stop the Russian military from mobilising around Ukraine.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30203/what-is-hacktivism" data-original-url="/hacking/30203/what-is-hacktivism">What is hacktivism?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/361959/us-gov-warning-russia-cyber-threat-critical-infrastructure" data-original-url="/security/cyber-warfare/361959/us-gov-warning-russia-cyber-threat-critical-infrastructure">US gov issues fresh warning over Russian threat to critical infrastructure</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/32717/what-can-an-ethical-hacker-do-for-my-business" data-original-url="/hacking/32717/what-can-an-ethical-hacker-do-for-my-business">What can an ethical hacker do for my business?</a></p></div></div><p>The Cyber Partisan hacktivists claim to have encrypted "the bulk of the servers, databases, and workstations" belonging to the Belarusian Railways, and destroyed their backups, according to posts on <a href="https://t.me/cpartisans/631">Telegram</a> and <a href="https://twitter.com/cpartisans/status/1485618881557315588">Twitter</a>.</p><p>Cyber Partisan is demanding the release of 50 political prisoners who are in need of medical assistance and assurances that Russian troops will stop mobilising on Belarusian soil - a country that shares a border with Ukraine and whose leader has a close relationship with Vladimir Putin.</p><p>"BelZhD, at the command of the terrorist Lukashenko, these days allows the occupying troops to enter our land," the Telegram message read. "As part of the 'Peklo' cyber campaign, we encrypted the bulk of the servers, <a href="https://www.itpro.com/data-insights/databases/358688/five-database-problems-and-how-to-solve-them" data-original-url="https://www.itpro.com/data-insights/databases/358688/five-database-problems-and-how-to-solve-them">databases</a>, and <a href="https://www.itpro.com/hardware/355998/the-best-professional-workstations-for-any-budget" data-original-url="https://www.itpro.com/hardware/355998/the-best-professional-workstations-for-any-budget">workstations</a> of the BelZhD in order to slow down and disrupt the operation of the road. The backups have been destroyed.</p><p>"Dozens of databases have been cyberattacked, including AS-Sledd, AS-USOGDP, SAP, AC-Pred, pass.rw.by, uprava, IRC, etc. Automation and security systems were deliberately NOT affected by a cyber attack in order to avoid emergency situations."</p><p>In the online posts, the group echoed the message shared by Belarusian rail workers <a href="https://t.me/belzhd_live/1257">on Friday</a> that more than 33 Russian military trains containing equipment and soldiers would be entering Belarus. The message was also corroborated by reports from other <a href="https://www.washingtonpost.com/world/2022/01/24/ukraine-eu-us-embassy-russia">news outlets</a>.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1485618881557315588"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1485618881557315588"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Belarusian Railways published a <a href="https://www.rw.by/corporate/press_center/news_of_passengers/2022/01/vnimaniyu-passazhirov_24012022">statement on Monday</a> confirming that it was experiencing difficulties and that some services were unavailable, though no mention of compromised systems, databases, or servers was mentioned - nor was <a href="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022" data-original-url="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022">ransomware</a>.</p><p>"For technical reasons, services for issuing electronic travel documents are temporarily unavailable," it said. "To arrange travel and return electronic travel documents, please contact the ticket office.</p><p>"Currently, work is underway to restore the performance of the systems. Belarusian Railways apologises for the inconvenience caused."</p><p>At the time of writing, <em>IT Pro</em> can confirm online ticket sales are still impacted and are unavailable, with customers greeted with the following message.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sGAmfE7DqzvGRiV3DfTZ58" name="" alt="Screenshot of the message appearing on Belarusian Railways website when trying book tickets online" src="https://cdn.mos.cms.futurecdn.net/sGAmfE7DqzvGRiV3DfTZ58.jpg" mos="https://cdn.mos.cms.futurecdn.net/sGAmfE7DqzvGRiV3DfTZ58.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: IT Pro)</span></figcaption></figure><h3 class="article-body__section" id="section-tensions-in-the-region"><span>Tensions in the region</span></h3><p>Russia has seized Ukrainian territory in the past and in recent months has stepped up its calls against Ukraine joining European institutions, with a particular focus on Nato. Ukrainians have been preparing for a possible invasion by Russia for months, with many in the region fearful of a war looming.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Ee76YV7F7sxSYqNgUctp5T" name="Ee76YV7F7sxSYqNgUctp5T.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/Ee76YV7F7sxSYqNgUctp5T.png" mos="https://cdn.mos.cms.futurecdn.net/Ee76YV7F7sxSYqNgUctp5T.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Seven leading machine learning use cases</strong></p><p class="fancy-box__body-text">Seven ways machine learning solves business problems</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/machine-learning/361108/seven-leading-machine-learning-use-cases" data-original-url="/technology/machine-learning/361108/seven-leading-machine-learning-use-cases">FREE DOWNLOAD</a></p></div></div><p>In recent weeks, both the US and UK have withdrawn significant numbers of embassy staff and their families out of the region, which may indicate that the two allies believe an invasion is likely. </p><p>Today, the US has placed <a href="https://www.bbc.co.uk/news/world-europe-60118193">8,500 of its soldiers on alert</a> amid mounting tensions of Russian troops mobilising at the Ukrainian border. Western powers are showing unanimous unity on the matter, saying they will step in with "swift" and "unprecedented" actions if Russia was to invade Ukraine.</p><p>The news follows <a href="https://www.itpro.com/security/cyber-warfare/361959/us-gov-warning-russia-cyber-threat-critical-infrastructure" data-original-url="https://www.itpro.com/security/cyber-warfare/361959/us-gov-warning-russia-cyber-threat-critical-infrastructure">days of unsuccessful negotiations</a> between President Biden and President Putin in Geneva - failed talks that also prompted the FBI, NSA, DHS, and CISA to issue an alert to cyber security professionals that a Russian-linked cyber attack may be launched on critical infrastructure in relation to the worldwide tensions.</p><p>"The cybersecurity industry has gotten used to tossing around the idea of ‘nation-state’ adversaries, but I think we’ve yet to see cyber attacks used in concert with a full-fledged military campaign," said Tim Erlin, VP of strategy at Tripwire to <em>IT Pro</em>. "DHS’s warning sets that expectation that something has changed in the threat profile, and that organisations should be prepared for a change in the types of attacks they see."</p><h3 class="article-body__section" id="section-brief-overview-of-hacktivism"><span>Brief overview of hacktivism</span></h3><p>It's thought the alleged ransomware attack on Belarusian Railways is one of the first times ransomware has been used in <a href="https://www.itpro.com/hacking/30203/what-is-hacktivism" data-original-url="https://www.itpro.com/hacking/30203/what-is-hacktivism">hacktivism</a> but the practice of campaigning by hitting systems offline is well documented.</p><p>There were a number of high-profile hacktivist 'attacks' in 2021 alone, with right-wing social media platform <a href="https://www.usatoday.com/story/tech/news/2021/01/11/parler-hack-platform-archived-hackers-capitol-riots/6629772002">Parler</a>, and <a href="https://www.bloomberg.com/news/articles/2021-03-09/hackers-expose-tesla-jails-in-breach-of-150-000-security-cams">Verkada's surveillance cameras</a> among the victims targeted by hackers. The Adalat Ali hacking group also <a href="https://www.thetimes.co.uk/article/hackers-post-video-shot-in-iran-s-notorious-evin-prison-wdnk6f3l9">exposed the beatings and mistreatment of prisoners</a> in Iran's Evin prison in August 2021 out of protest against the abject living conditions.</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/1ojGcpJHLKOEausXT9cuVa"></iframe><p>Anonymous, LulzSec, and WikiLeaks are among some of the most well-known hacktivist groups in the world.</p><p>Hacktivism is a controversial practice with some seeing it as an effective means of campaigning while others believe the level of civil disobedience, and often the damage such attacks cause, goes beyond the acceptable level of resistance exhibited in more traditional forms of protest.</p><p>The US sees hacktivism as a significant threat and are categorised similarly, <a href="https://www.reuters.com/article/us-cyber-hacktivism-focus-idUSKBN2BH3HJ">in the eyes of the law</a>, to terrorist groups and transnational criminal organisations.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Poly Network offers up $500k bug bounty reward to its own hacker ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Poly Network has offered its own hacker a $500,000 bug bounty reward for finding the vulnerability which allowed them to orchestrate what is now considered to be <a href="https://www.itpro.com/technology/cryptocurrencies/360545/poly-network-hack-600-million-cryptocurrency-ether" data-original-url="https://www.itpro.com/technology/cryptocurrencies/360545/poly-network-hack-600-million-cryptocurrency-ether">the largest cryptocurrency heist to date</a>.</p><p>The <a href="https://www.itpro.com/security/28031/what-is-blockchain" data-original-url="https://www.itpro.com/security/28031/what-is-blockchain">blockchain</a> platform reportedly offered up the prize after the hacker returned the remainder of the $610 million (£440 million) worth of Ether, Binance, and USDC tokens, stolen in a hack on the platform on Wednesday.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/cryptocurrencies/360551/poly-network-hacker-returns-342-million-of-stolen-assets" data-original-url="/technology/cryptocurrencies/360551/poly-network-hacker-returns-342-million-of-stolen-assets">Poly Network hacker returns $342 million of stolen assets</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ethical-hacking/360394/google-launches-new-bug-bounty-platform" data-original-url="/security/ethical-hacking/360394/google-launches-new-bug-bounty-platform">Google launches new bug bounty platform</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months" data-original-url="/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months">Microsoft awarded $13.6 million in bug bounties over the last 12 months</a></p></div></div><p>This is according to a Q&A published by the hacker and <a href="https://twitter.com/tomrobin/status/1425487745166753794">shared online</a> by Tom Robinson, the co-founder of the London-based blockchain analytics and compliance company Elliptic. Robinson had found the messages “embedded in ethereum transactions sent from the account controlled by the hacker”.</p><p>In a note meant for the hacker, Poly Network is quoted as saying: “We appreciate you sharing your experience and we believe your action constitutes <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hat behaviour</a>”.</p><p>“We plan to offer you a $500,000 bug bounty after you complete the refund fully,” the company told the hacker, before adding that they won’t face any legal repercussions for the heist, describing it as “very helpful”.</p><p>The hacker stated that they hadn’t responded to Poly Network’s bug bounty offer, yet added that all the stolen assets will be sent back.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="h388diQyR5igVUgsxxNYqd" name="h388diQyR5igVUgsxxNYqd.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd.jpg" mos="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>IT Pro 20/20: Does cyber security's public image need a makeover?</strong></p><p class="fancy-box__body-text">Issue 18 of IT Pro 20/20 looks at recent efforts to retire the 'hacker' stereotype, and how the threat landscape has changed over the past 20 years</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover" data-original-url="/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover">FREE DOWNLOAD</a></p></div></div><p>Elliptic analysts had previously speculated that the decision to return the assets could have been motivated by their traceability: the hacker could be “pursued by the authorities” due to leaving “numerous digital breadcrumbs on the blockchain for law enforcement to follow, aided by blockchain analytics tools”.</p><p>On Thursday evening, Poly Network <a href="https://twitter.com/PolyNetwork2/status/1425870262067548163">stated</a> that “all the remaining assets on Ethereum (except for the frozen USDT) had been transferred to the multisig[nature] wallet controlled by Mr. White Hat and Poly Network”.</p><p>“The repayment process has not yet been completed. To ensure the safe recovery of user assets, we hope to maintain communication with Mr. White Hat and convey accurate information to the public,” it said, before adding that “any unfounded allegations and speculation may damage the extremely important process of asset recovery”.</p><p>The identity of the hacker continues to be unknown. However, in their Q&A, they had hinted that they do not come from an English-speaking country and had been engaged in hacking from a young age. They also described themselves as a “high profile hacker in the real world” working in the “<a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> industry”.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ethical-hacking/360573/poly-network-hacker-offered-500000-bug-bounty</link>
                                                                            <description>
                            <![CDATA[ The reward has been offered following the successful return of $610 million in stolen tokens ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wKSBSXt2Hv4WMPNwEswS9e</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6V6nqMwFpfZtWAn4yd4ZT9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Aug 2021 11:51:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6V6nqMwFpfZtWAn4yd4ZT9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Poly Network logo seen on a mobile phone and a computer screen]]></media:description>                                                            <media:text><![CDATA[Poly Network logo seen on a mobile phone and a computer screen]]></media:text>
                                <media:title type="plain"><![CDATA[Poly Network logo seen on a mobile phone and a computer screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6V6nqMwFpfZtWAn4yd4ZT9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Poly Network has offered its own hacker a $500,000 bug bounty reward for finding the vulnerability which allowed them to orchestrate what is now considered to be <a href="https://www.itpro.com/technology/cryptocurrencies/360545/poly-network-hack-600-million-cryptocurrency-ether" data-original-url="https://www.itpro.com/technology/cryptocurrencies/360545/poly-network-hack-600-million-cryptocurrency-ether">the largest cryptocurrency heist to date</a>.</p><p>The <a href="https://www.itpro.com/security/28031/what-is-blockchain" data-original-url="https://www.itpro.com/security/28031/what-is-blockchain">blockchain</a> platform reportedly offered up the prize after the hacker returned the remainder of the $610 million (£440 million) worth of Ether, Binance, and USDC tokens, stolen in a hack on the platform on Wednesday.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/cryptocurrencies/360551/poly-network-hacker-returns-342-million-of-stolen-assets" data-original-url="/technology/cryptocurrencies/360551/poly-network-hacker-returns-342-million-of-stolen-assets">Poly Network hacker returns $342 million of stolen assets</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ethical-hacking/360394/google-launches-new-bug-bounty-platform" data-original-url="/security/ethical-hacking/360394/google-launches-new-bug-bounty-platform">Google launches new bug bounty platform</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months" data-original-url="/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months">Microsoft awarded $13.6 million in bug bounties over the last 12 months</a></p></div></div><p>This is according to a Q&A published by the hacker and <a href="https://twitter.com/tomrobin/status/1425487745166753794">shared online</a> by Tom Robinson, the co-founder of the London-based blockchain analytics and compliance company Elliptic. Robinson had found the messages “embedded in ethereum transactions sent from the account controlled by the hacker”.</p><p>In a note meant for the hacker, Poly Network is quoted as saying: “We appreciate you sharing your experience and we believe your action constitutes <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hat behaviour</a>”.</p><p>“We plan to offer you a $500,000 bug bounty after you complete the refund fully,” the company told the hacker, before adding that they won’t face any legal repercussions for the heist, describing it as “very helpful”.</p><p>The hacker stated that they hadn’t responded to Poly Network’s bug bounty offer, yet added that all the stolen assets will be sent back.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="h388diQyR5igVUgsxxNYqd" name="h388diQyR5igVUgsxxNYqd.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd.jpg" mos="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>IT Pro 20/20: Does cyber security's public image need a makeover?</strong></p><p class="fancy-box__body-text">Issue 18 of IT Pro 20/20 looks at recent efforts to retire the 'hacker' stereotype, and how the threat landscape has changed over the past 20 years</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover" data-original-url="/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover">FREE DOWNLOAD</a></p></div></div><p>Elliptic analysts had previously speculated that the decision to return the assets could have been motivated by their traceability: the hacker could be “pursued by the authorities” due to leaving “numerous digital breadcrumbs on the blockchain for law enforcement to follow, aided by blockchain analytics tools”.</p><p>On Thursday evening, Poly Network <a href="https://twitter.com/PolyNetwork2/status/1425870262067548163">stated</a> that “all the remaining assets on Ethereum (except for the frozen USDT) had been transferred to the multisig[nature] wallet controlled by Mr. White Hat and Poly Network”.</p><p>“The repayment process has not yet been completed. To ensure the safe recovery of user assets, we hope to maintain communication with Mr. White Hat and convey accurate information to the public,” it said, before adding that “any unfounded allegations and speculation may damage the extremely important process of asset recovery”.</p><p>The identity of the hacker continues to be unknown. However, in their Q&A, they had hinted that they do not come from an English-speaking country and had been engaged in hacking from a young age. They also described themselves as a “high profile hacker in the real world” working in the “<a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> industry”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Poly Network hacker returns $342 million of stolen assets ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The hacker behind what is considered to be the biggest <a href="https://www.itpro.com/technology/cryptocurrencies" data-original-url="https://www.itpro.com/technology/cryptocurrencies">cryptocurrency</a> heist in history has now returned $342 million (£247 million) worth of stolen assets.</p><p>This is according to Poly Network, a <a href="https://www.itpro.com/security/28031/what-is-blockchain" data-original-url="https://www.itpro.com/security/28031/what-is-blockchain">blockchain</a> platform that <a href="https://www.itpro.com/technology/cryptocurrencies/360545/poly-network-hack-600-million-cryptocurrency-ether" data-original-url="https://www.itpro.com/technology/cryptocurrencies/360545/poly-network-hack-600-million-cryptocurrency-ether">fell victim to the virtual robbery on Tuesday</a>, having lost $610 million (£440 million) worth of Ether, Binance, and USDC tokens.</p><p>The company made the announcement on its Twitter page, that as of 8pm UTC (9pm BST) on Thursday, it had been reunited with $256 million worth of BSC, $4.6 million Ethereum, and $85 million Polygon – more than half of the total stolen assets.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/blockchain/32679/coinbase-halts-trading-of-ethereum-classic-after-attack" data-original-url="/blockchain/32679/coinbase-halts-trading-of-ethereum-classic-after-attack">Coinbase halts trading of Ethereum Classic after attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/32717/what-can-an-ethical-hacker-do-for-my-business" data-original-url="/hacking/32717/what-can-an-ethical-hacker-do-for-my-business">What can an ethical hacker do for my business?</a></p></div></div><p>“The remaining is $268M on Ethereum,” Poly Networks <a href="https://twitter.com/PolyNetwork2/status/1425733950614360064">stated</a>.</p><p>The hacker behind the heist started returning the stolen cryptocurrency tokens on Wednesday afternoon following an open letter published by the company, urging the hackers to “establish communication”. It also asked <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining" data-original-url="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">miners</a> of affected blockchain and crypto exchanges to "blacklist tokens” associated with the hacker’s wallet.</p><p>Meanwhile, the hacker decided to explain their reasoning behind the heist by publishing a three-page Q&A which was found embedded in the Ethereum transactions sent to Poly Networks by the hacker.</p><p>In the Q&A, which was <a href="https://twitter.com/tomrobin/status/1425487745166753794">shared by Elliptic chief scientist & co-founder Tom Robinson</a>, the hacker stated that they hack “for fun” and that they are “not very interested in money”. They added that the stolen assets would be returned in due time in order to preserve their identity:</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="h388diQyR5igVUgsxxNYqd" name="h388diQyR5igVUgsxxNYqd.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd.jpg" mos="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>IT Pro 20/20: Does cyber security's public image need a makeover?</strong></p><p class="fancy-box__body-text">Issue 18 of IT Pro 20/20 looks at recent efforts to retire the 'hacker' stereotype, and how the threat landscape has changed over the past 20 years</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover" data-original-url="/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover">FREE DOWNLOAD</a></p></div></div><p>“I understood the risk of exposing myself even if I don’t do evil,” they said, before adding that they “prefer to stay in the dark and save the world”.</p><p>They also alluded to the fact that they might be a <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">white hat hacker</a>, saying that they chose to steal the assets in order to make the public aware of the bug found in Poly Network’s system and prevent the platform from patching it “secretly without any notification”.</p><p>However, according to London-based blockchain analytics and compliance company Elliptic, the hacker is unlikely to escape the consequences of their actions:</p><p>“Whatever the motivation for the hack, these events have demonstrated how difficult it is [to] profit from theft or any other illicit activity using cryptoassets. The transparency of the blockchains allowed crowd-sourced, real-time collaboration between protocol developers, stablecoin issuers, blockchain analytics companies and the wider community, to ensure the hacker would not be able to disappear with the stolen assets,” its analysis <a href="https://www.elliptic.co/blog/the-poly-network-hack-600-million-in-crypto-stolen-and-returned-in-24-hours">stated</a>.</p><p>“Despite the return of the funds, the hacker might well still find themselves being pursued by the authorities. Their activities have left numerous digital breadcrumbs on the blockchain for law enforcement to follow, aided by blockchain analytics tools.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/cryptocurrencies/360551/poly-network-hacker-returns-342-million-of-stolen-assets</link>
                                                                            <description>
                            <![CDATA[ Hacker states that they are “not very interested in money” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ngKCzyKVELEQezvhU2RRB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D5SqEJvUh8pV83LKehBQSU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Aug 2021 09:47:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D5SqEJvUh8pV83LKehBQSU-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Darkened image of a hacker wearing a hoodie using computing equipment]]></media:description>                                                            <media:text><![CDATA[Darkened image of a hacker wearing a hoodie using computing equipment]]></media:text>
                                <media:title type="plain"><![CDATA[Darkened image of a hacker wearing a hoodie using computing equipment]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D5SqEJvUh8pV83LKehBQSU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The hacker behind what is considered to be the biggest <a href="https://www.itpro.com/technology/cryptocurrencies" data-original-url="https://www.itpro.com/technology/cryptocurrencies">cryptocurrency</a> heist in history has now returned $342 million (£247 million) worth of stolen assets.</p><p>This is according to Poly Network, a <a href="https://www.itpro.com/security/28031/what-is-blockchain" data-original-url="https://www.itpro.com/security/28031/what-is-blockchain">blockchain</a> platform that <a href="https://www.itpro.com/technology/cryptocurrencies/360545/poly-network-hack-600-million-cryptocurrency-ether" data-original-url="https://www.itpro.com/technology/cryptocurrencies/360545/poly-network-hack-600-million-cryptocurrency-ether">fell victim to the virtual robbery on Tuesday</a>, having lost $610 million (£440 million) worth of Ether, Binance, and USDC tokens.</p><p>The company made the announcement on its Twitter page, that as of 8pm UTC (9pm BST) on Thursday, it had been reunited with $256 million worth of BSC, $4.6 million Ethereum, and $85 million Polygon – more than half of the total stolen assets.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/blockchain/32679/coinbase-halts-trading-of-ethereum-classic-after-attack" data-original-url="/blockchain/32679/coinbase-halts-trading-of-ethereum-classic-after-attack">Coinbase halts trading of Ethereum Classic after attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/32717/what-can-an-ethical-hacker-do-for-my-business" data-original-url="/hacking/32717/what-can-an-ethical-hacker-do-for-my-business">What can an ethical hacker do for my business?</a></p></div></div><p>“The remaining is $268M on Ethereum,” Poly Networks <a href="https://twitter.com/PolyNetwork2/status/1425733950614360064">stated</a>.</p><p>The hacker behind the heist started returning the stolen cryptocurrency tokens on Wednesday afternoon following an open letter published by the company, urging the hackers to “establish communication”. It also asked <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining" data-original-url="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">miners</a> of affected blockchain and crypto exchanges to "blacklist tokens” associated with the hacker’s wallet.</p><p>Meanwhile, the hacker decided to explain their reasoning behind the heist by publishing a three-page Q&A which was found embedded in the Ethereum transactions sent to Poly Networks by the hacker.</p><p>In the Q&A, which was <a href="https://twitter.com/tomrobin/status/1425487745166753794">shared by Elliptic chief scientist & co-founder Tom Robinson</a>, the hacker stated that they hack “for fun” and that they are “not very interested in money”. They added that the stolen assets would be returned in due time in order to preserve their identity:</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="h388diQyR5igVUgsxxNYqd" name="h388diQyR5igVUgsxxNYqd.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd.jpg" mos="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>IT Pro 20/20: Does cyber security's public image need a makeover?</strong></p><p class="fancy-box__body-text">Issue 18 of IT Pro 20/20 looks at recent efforts to retire the 'hacker' stereotype, and how the threat landscape has changed over the past 20 years</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover" data-original-url="/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover">FREE DOWNLOAD</a></p></div></div><p>“I understood the risk of exposing myself even if I don’t do evil,” they said, before adding that they “prefer to stay in the dark and save the world”.</p><p>They also alluded to the fact that they might be a <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">white hat hacker</a>, saying that they chose to steal the assets in order to make the public aware of the bug found in Poly Network’s system and prevent the platform from patching it “secretly without any notification”.</p><p>However, according to London-based blockchain analytics and compliance company Elliptic, the hacker is unlikely to escape the consequences of their actions:</p><p>“Whatever the motivation for the hack, these events have demonstrated how difficult it is [to] profit from theft or any other illicit activity using cryptoassets. The transparency of the blockchains allowed crowd-sourced, real-time collaboration between protocol developers, stablecoin issuers, blockchain analytics companies and the wider community, to ensure the hacker would not be able to disappear with the stolen assets,” its analysis <a href="https://www.elliptic.co/blog/the-poly-network-hack-600-million-in-crypto-stolen-and-returned-in-24-hours">stated</a>.</p><p>“Despite the return of the funds, the hacker might well still find themselves being pursued by the authorities. Their activities have left numerous digital breadcrumbs on the blockchain for law enforcement to follow, aided by blockchain analytics tools.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Does cyber security’s public image need a makeover? ]]></title>
                                                                                                <dc:content><![CDATA[ <p><strong><em>This article originally appeared in the June edition of IT Pro 20/20, <a href="https://www.itpro.com/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover" rel="noopener" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover">available here</a>. To sign up to receive each new issue in your inbox, <a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">click here</a>.</em></strong></p><p>Bryan McAninch grew up with very few computers around him. He was poor, but remembers always having something to tinker with. He also had a supportive grandfather – a secondary school science and maths teacher. One Saturday morning in 1984 McAninch’s grandfather sat him down, aged eight, in front of an Apple IIe in the school lab with a ‘choose your own adventure’ programming book.</p><p>“I was hooked like a fish,” McAninch says. “From then on I was in technology. I got into phone phreaking. I got into what we would consider an 80s ‘true’ hacking scene.”</p><p>McAninch developed an interest in Linux systems, which led him to networking and eventually network security. He’s worked in penetration testing, incident response, and cloud security. Hacking has become more than a job for McAninch.</p><p>“It's not a fashion statement or a movie character,” he says. “It's an identity. And it's something that's really deeply rooted in my own personal character.”</p><h3 class="article-body__section" id="section-the-vilification-of-hackers"><span>The vilification of hackers</span></h3><p>A year before McAninch started coding, film company MGM released <em>WarGames</em>. The film tells the fictional story of a young hacker who, by accident, infiltrates a North American Aerospace Defense Command (NORAD) computer and initiates a World War Three-type situation.</p><p>Three years later, in 1986, US President Ronald Regan’s administration introduced the <a href="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges" data-original-url="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges">Computer Fraud and Abuse Act (CFAA)</a>, which was followed in the UK by the introduction of <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">the Computer Misuse Act (CMA) in 1990</a>. Both pieces of legislation limited hackers’ legal authority to penetrate computer systems. It was this legislation, according to McAninch, that marked the beginning of the world’s vilification of hackers.</p><p>Alyssa Miller, business information security officer at S&P Global Ratings, thinks the public’s overall impression of hackers has become distorted.</p><p>“Hacking isn’t just cyber criminal activity,” she says. “If you look back at the history of hacking, it comes back to innovators who take technology, tear it apart, figure out how it works, and then improve upon it. Unfortunately, because of things that have happened over the last 30 years or so, the cyber criminals get all of the media attention.”</p><p>Media organisations often use the word ‘hacker’ to refer to cyber criminals (<em>IT Pro</em> is, admittedly, also guilty of this). This frustrates many white hats who would prefer to be separated from the criminal side of the industry. Miller believes positive intentions are intrinsic to the role of a hacker and that we should avoid calling anyone else a hacker at all.</p><p>“All the work that's happening out there from people like me, Bryan (McAninch), and all the others in this community, kind of gets lost,” explains Miller, “and we become part of this almost clandestine community that people don't really understand and are often afraid of.”</p><p>This misunderstanding affects more than hackers’ identities. A spokesperson for the UK’s National Cyber Security Centre (NCSC) tells <em>IT Pro</em> it may contribute to the industry skills gap.</p><p>“We are aware that stereotyping can sometimes hold people back from applying for cyber-security job roles,” the spokesperson says. “However, there is a lot of work being done by both Government and industry to address diversity and the cyber-skills gap.”</p><p>Despite these warm words, after 30 years of vilification, McAninch decided it was time to do something.</p><h3 class="article-body__section" id="section-the-start-of-hacking-is-not-a-crime"><span>The start of Hacking is NOT a Crime</span></h3><p>McAninch was attracted to other subcultures in his youth, so alongside computers he also spent a lot of time skateboarding. With no money to build a ramp or rail in his backyard, like many others, he relied on public stairs and embankments to perform tricks on.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MhoDQHbDgtzbg6RyMTEvAn" name="MhoDQHbDgtzbg6RyMTEvAn.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/MhoDQHbDgtzbg6RyMTEvAn.jpg" mos="https://cdn.mos.cms.futurecdn.net/MhoDQHbDgtzbg6RyMTEvAn.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Aberdeen Report: How a platform approach to security monitoring initiatives adds value</strong></p><p class="fancy-box__body-text">Integration, orchestration, analytics, automation, and the need for speed</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/360172/aberdeen-report-how-a-platform-approach-to-security-monitoring-initiatives-adds" data-original-url="/security/360172/aberdeen-report-how-a-platform-approach-to-security-monitoring-initiatives-adds">FREE DOWNLOAD</a></p></div></div><p>The police would harass him and his friends in an attempt to stop them and, after a while, stickers bearing the words ‘Skateboarding is NOT a Crime’ appeared. It was the skateboarding community’s response to rules it felt were unfair.</p><p>Decades later McAninch was chatting to Dustin Dykes, founder of the Dallas Hackers Association, at a local meetup. Both were frustrated with the media’s mischaracterisation of the hacker identity. McAninch had an epiphany.</p><p>He made a small graphic with the words ‘Hacking is NOT a Crime’, uploaded it to Sticker Mule, and printed 500 copies of the sticker. It was summer 2018 and security conference Def Con 26 was about to happen, so he handed them out to attendees. They were so popular he took 5,000 to the following year’s event. Since then, Hacking is Not a Crime, or HINAC as it has come to be known, has expanded at a rapid pace. It had 1,500 Twitter followers in August last year. Now it has 15,300.</p><p>The movement has grown from a simple stickering campaign to lectures and community outreach. Its international network of 109 advocates across six continents and 21 countries now includes Argentina, China and Pakistan.</p><h3 class="article-body__section" id="section-more-than-words"><span>More than words</span></h3><p>HINAC has come to represent a movement with a much wider scope than the reductionist language often used in the media. It’s about changing the entire public’s perception of hacking and the cyber-security community. McAninch believes that, through this, governments can be convinced to improve legislation like the CFAA and the CMA that create unnecessary barriers for security professionals.</p><p>Miller says her CIO once received an email from a hacker when she was working in financial technology. The hacker was disclosing a vulnerability in the company’s online bill payment site, and the CIO’s first reaction was to call lawyers – Miller had to talk him out of it. It’s this type of treatment, which the likes of HINAC say is the result of a distorted public image, that bug-bounty hunters and researchers alike want to change. In fact, 80% of cyber-security professionals in the UK are <a href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" data-original-url="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">worried about breaking the law because of the CMA</a>.</p><p>McAninch says: “We're advocating global legal reform for security researchers so we can provide them some assurance that when they disclose any sort of privacy or security vulnerabilities, they're not going to receive some sort of legal retaliation.</p><p>“As we become more dependent on technology, so too is our security and privacy. So if there's no one out there proactively trying to identify these privacy and security vulnerabilities, the true bad guys are going to do it.”</p><p>There is hope for white hats like McAninch and Miller; in the UK, home secretary Priti Patel has announced a formal review of the CMA, for example. But it will take time for the industry to adjust its language and, as with all things, action must follow.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ethical-hacking/360431/does-cyber-securitys-public-image-need-a-makeover</link>
                                                                            <description>
                            <![CDATA[ A growing number of ethical hackers want the media to change the way it talks about the industry ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oPXQnJdgz1NeDksnXHQvFU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QsFy3psCVCAnojY8jkxPdN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 30 Jul 2021 10:25:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ethical Hacking]]></category>
                                                                                                                    <dc:creator><![CDATA[ Charlie Metcalfe ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QsFy3psCVCAnojY8jkxPdN-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cartoon of a hacker wearing a black hoodie, with crosses on its eyes and blue flames surrounding it]]></media:description>                                                            <media:text><![CDATA[A cartoon of a hacker wearing a black hoodie, with crosses on its eyes and blue flames surrounding it]]></media:text>
                                <media:title type="plain"><![CDATA[A cartoon of a hacker wearing a black hoodie, with crosses on its eyes and blue flames surrounding it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QsFy3psCVCAnojY8jkxPdN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong><em>This article originally appeared in the June edition of IT Pro 20/20, <a href="https://www.itpro.com/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover" rel="noopener" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover">available here</a>. To sign up to receive each new issue in your inbox, <a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">click here</a>.</em></strong></p><p>Bryan McAninch grew up with very few computers around him. He was poor, but remembers always having something to tinker with. He also had a supportive grandfather – a secondary school science and maths teacher. One Saturday morning in 1984 McAninch’s grandfather sat him down, aged eight, in front of an Apple IIe in the school lab with a ‘choose your own adventure’ programming book.</p><p>“I was hooked like a fish,” McAninch says. “From then on I was in technology. I got into phone phreaking. I got into what we would consider an 80s ‘true’ hacking scene.”</p><p>McAninch developed an interest in Linux systems, which led him to networking and eventually network security. He’s worked in penetration testing, incident response, and cloud security. Hacking has become more than a job for McAninch.</p><p>“It's not a fashion statement or a movie character,” he says. “It's an identity. And it's something that's really deeply rooted in my own personal character.”</p><h3 class="article-body__section" id="section-the-vilification-of-hackers"><span>The vilification of hackers</span></h3><p>A year before McAninch started coding, film company MGM released <em>WarGames</em>. The film tells the fictional story of a young hacker who, by accident, infiltrates a North American Aerospace Defense Command (NORAD) computer and initiates a World War Three-type situation.</p><p>Three years later, in 1986, US President Ronald Regan’s administration introduced the <a href="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges" data-original-url="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges">Computer Fraud and Abuse Act (CFAA)</a>, which was followed in the UK by the introduction of <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">the Computer Misuse Act (CMA) in 1990</a>. Both pieces of legislation limited hackers’ legal authority to penetrate computer systems. It was this legislation, according to McAninch, that marked the beginning of the world’s vilification of hackers.</p><p>Alyssa Miller, business information security officer at S&P Global Ratings, thinks the public’s overall impression of hackers has become distorted.</p><p>“Hacking isn’t just cyber criminal activity,” she says. “If you look back at the history of hacking, it comes back to innovators who take technology, tear it apart, figure out how it works, and then improve upon it. Unfortunately, because of things that have happened over the last 30 years or so, the cyber criminals get all of the media attention.”</p><p>Media organisations often use the word ‘hacker’ to refer to cyber criminals (<em>IT Pro</em> is, admittedly, also guilty of this). This frustrates many white hats who would prefer to be separated from the criminal side of the industry. Miller believes positive intentions are intrinsic to the role of a hacker and that we should avoid calling anyone else a hacker at all.</p><p>“All the work that's happening out there from people like me, Bryan (McAninch), and all the others in this community, kind of gets lost,” explains Miller, “and we become part of this almost clandestine community that people don't really understand and are often afraid of.”</p><p>This misunderstanding affects more than hackers’ identities. A spokesperson for the UK’s National Cyber Security Centre (NCSC) tells <em>IT Pro</em> it may contribute to the industry skills gap.</p><p>“We are aware that stereotyping can sometimes hold people back from applying for cyber-security job roles,” the spokesperson says. “However, there is a lot of work being done by both Government and industry to address diversity and the cyber-skills gap.”</p><p>Despite these warm words, after 30 years of vilification, McAninch decided it was time to do something.</p><h3 class="article-body__section" id="section-the-start-of-hacking-is-not-a-crime"><span>The start of Hacking is NOT a Crime</span></h3><p>McAninch was attracted to other subcultures in his youth, so alongside computers he also spent a lot of time skateboarding. With no money to build a ramp or rail in his backyard, like many others, he relied on public stairs and embankments to perform tricks on.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MhoDQHbDgtzbg6RyMTEvAn" name="MhoDQHbDgtzbg6RyMTEvAn.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/MhoDQHbDgtzbg6RyMTEvAn.jpg" mos="https://cdn.mos.cms.futurecdn.net/MhoDQHbDgtzbg6RyMTEvAn.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Aberdeen Report: How a platform approach to security monitoring initiatives adds value</strong></p><p class="fancy-box__body-text">Integration, orchestration, analytics, automation, and the need for speed</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/360172/aberdeen-report-how-a-platform-approach-to-security-monitoring-initiatives-adds" data-original-url="/security/360172/aberdeen-report-how-a-platform-approach-to-security-monitoring-initiatives-adds">FREE DOWNLOAD</a></p></div></div><p>The police would harass him and his friends in an attempt to stop them and, after a while, stickers bearing the words ‘Skateboarding is NOT a Crime’ appeared. It was the skateboarding community’s response to rules it felt were unfair.</p><p>Decades later McAninch was chatting to Dustin Dykes, founder of the Dallas Hackers Association, at a local meetup. Both were frustrated with the media’s mischaracterisation of the hacker identity. McAninch had an epiphany.</p><p>He made a small graphic with the words ‘Hacking is NOT a Crime’, uploaded it to Sticker Mule, and printed 500 copies of the sticker. It was summer 2018 and security conference Def Con 26 was about to happen, so he handed them out to attendees. They were so popular he took 5,000 to the following year’s event. Since then, Hacking is Not a Crime, or HINAC as it has come to be known, has expanded at a rapid pace. It had 1,500 Twitter followers in August last year. Now it has 15,300.</p><p>The movement has grown from a simple stickering campaign to lectures and community outreach. Its international network of 109 advocates across six continents and 21 countries now includes Argentina, China and Pakistan.</p><h3 class="article-body__section" id="section-more-than-words"><span>More than words</span></h3><p>HINAC has come to represent a movement with a much wider scope than the reductionist language often used in the media. It’s about changing the entire public’s perception of hacking and the cyber-security community. McAninch believes that, through this, governments can be convinced to improve legislation like the CFAA and the CMA that create unnecessary barriers for security professionals.</p><p>Miller says her CIO once received an email from a hacker when she was working in financial technology. The hacker was disclosing a vulnerability in the company’s online bill payment site, and the CIO’s first reaction was to call lawyers – Miller had to talk him out of it. It’s this type of treatment, which the likes of HINAC say is the result of a distorted public image, that bug-bounty hunters and researchers alike want to change. In fact, 80% of cyber-security professionals in the UK are <a href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" data-original-url="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">worried about breaking the law because of the CMA</a>.</p><p>McAninch says: “We're advocating global legal reform for security researchers so we can provide them some assurance that when they disclose any sort of privacy or security vulnerabilities, they're not going to receive some sort of legal retaliation.</p><p>“As we become more dependent on technology, so too is our security and privacy. So if there's no one out there proactively trying to identify these privacy and security vulnerabilities, the true bad guys are going to do it.”</p><p>There is hope for white hats like McAninch and Miller; in the UK, home secretary Priti Patel has announced a formal review of the CMA, for example. But it will take time for the industry to adjust its language and, as with all things, action must follow.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google launches new bug bounty platform ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Google has announced the launch of a new bug bounty platform that will make it easier for <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">vulnerability hunters</a> to submit issues.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months" data-original-url="/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months">Microsoft awarded $13.6 million in bug bounties over the last 12 months</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year" data-original-url="/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year">GitHub bug bounty payouts surpass $1.5 million</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/360310/google-cloud-rolls-out-new-security-capabilities-following-surge-in" data-original-url="/cloud/cloud-security/360310/google-cloud-rolls-out-new-security-capabilities-following-surge-in">Google Cloud beefs up security following surge in ransomware attacks</a></p></div></div><p>Available under bughunters.google.com, the platform brings together all of the tech giant’s vulnerability reward programmes (VRP) – Google, Android, Abuse, <a href="https://www.itpro.com/software/operating-systems/360341/google-coding-typo-effectively-bricks-chrome-os-devices" data-original-url="https://www.itpro.com/software/operating-systems/360341/google-coding-typo-effectively-bricks-chrome-os-devices">Chrome</a>, and Play – with hunters able to submit issues using a single intake form.</p><p>Moreover, the new platform will provide more opportunities for interaction with other hunters through gamification, including awards and badges for certain bug-reporting achievements. </p><p>Google has also improved its VRP leaderboards, which will now be “more functional and aesthetically pleasing”, as well as show the best hunters per country, making it easier to use the results to boost a CV when applying for a job in tech.</p><p>The new platform also provides greater emphasis on research and education, making it easier for hunters to publish their bug reports in order to share their knowledge. Hunters will also be able to improve their skills through the newly-launched <a href="http://goo.gle/bhu">Bug Hunter University</a>, which includes courses on how to submit a successful vulnerability report.</p><p>Research papers on the security of open source will be <a href="https://bughunters.google.com/about/rules/5122527111938048">eligible for a reward</a>, just like open source software <a href="http://goo.gle/patchz">patch submissions</a>, while hunters improving security in open source programmes will be eligible to <a href="http://goo.gle/subsidiz">apply for a grant</a> to better secure their own projects.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gGRwbS6T2JYCbdQmJ8xJri" name="gGRwbS6T2JYCbdQmJ8xJri.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri.png" mos="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to increase cyber resilience within your organisation</strong></p><p class="fancy-box__body-text">Cyber resilience for dummies</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359468/how-to-increase-cyber-resilience-within-your-organisation" data-original-url="/security/cyber-security/359468/how-to-increase-cyber-resilience-within-your-organisation">FREE DOWNLOAD</a></p></div></div><p>Commenting on the announcement, Google VRP technical programme manager, Jan Keller, <a href="https://security.googleblog.com/2021/07/a-new-chapter-for-googles-vulnerability.html">said</a> that when Google launched its “very first VRP” over a decade ago, no one knew “how many valid vulnerabilities – if any – would be submitted on the first day”.</p><p>“Everyone on the team put in their estimate, with predictions ranging from zero to 20. In the end, we actually received more than 25 reports, taking all of us by surprise,” he added.</p><p>Three years later, the programme was expanded to include <a href="https://www.itpro.com/security/software-vulnerability/20766/google-launches-open-source-bug-bounty-programme" data-original-url="https://www.itpro.com/security/software-vulnerability/20766/google-launches-open-source-bug-bounty-programme">open source</a> as well as <a href="https://www.itpro.com/security/21057/google-extends-open-source-bug-bounty-programme-android-and-apache" data-original-url="https://www.itpro.com/security/21057/google-extends-open-source-bug-bounty-programme-android-and-apache">Google Android and Apache</a>.</p><p>“Since its inception, the VRP programme has not only grown significantly in terms of report volume, but the team of security engineers behind it has also expanded – including almost 20 bug hunters who reported vulnerabilities to us and ended up joining the Google VRP team. That is why we are thrilled to bring you this new platform, continue to grow our community of bug hunters and support the skill development of up-and-coming vulnerability researchers,” said Keller.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ethical-hacking/360394/google-launches-new-bug-bounty-platform</link>
                                                                            <description>
                            <![CDATA[ Vulnerability hunters will be able to improve their skills through the newly launched Bug Hunter University ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qHzmz8RHKtVbAHk9g2n5KG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rzbbePFwKtpa9HpTeo4kz9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 28 Jul 2021 11:25:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rzbbePFwKtpa9HpTeo4kz9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close up Google logo with the security lock icon isolated on black background]]></media:description>                                                            <media:text><![CDATA[Close up Google logo with the security lock icon isolated on black background]]></media:text>
                                <media:title type="plain"><![CDATA[Close up Google logo with the security lock icon isolated on black background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rzbbePFwKtpa9HpTeo4kz9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has announced the launch of a new bug bounty platform that will make it easier for <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">vulnerability hunters</a> to submit issues.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months" data-original-url="/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months">Microsoft awarded $13.6 million in bug bounties over the last 12 months</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year" data-original-url="/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year">GitHub bug bounty payouts surpass $1.5 million</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/360310/google-cloud-rolls-out-new-security-capabilities-following-surge-in" data-original-url="/cloud/cloud-security/360310/google-cloud-rolls-out-new-security-capabilities-following-surge-in">Google Cloud beefs up security following surge in ransomware attacks</a></p></div></div><p>Available under bughunters.google.com, the platform brings together all of the tech giant’s vulnerability reward programmes (VRP) – Google, Android, Abuse, <a href="https://www.itpro.com/software/operating-systems/360341/google-coding-typo-effectively-bricks-chrome-os-devices" data-original-url="https://www.itpro.com/software/operating-systems/360341/google-coding-typo-effectively-bricks-chrome-os-devices">Chrome</a>, and Play – with hunters able to submit issues using a single intake form.</p><p>Moreover, the new platform will provide more opportunities for interaction with other hunters through gamification, including awards and badges for certain bug-reporting achievements. </p><p>Google has also improved its VRP leaderboards, which will now be “more functional and aesthetically pleasing”, as well as show the best hunters per country, making it easier to use the results to boost a CV when applying for a job in tech.</p><p>The new platform also provides greater emphasis on research and education, making it easier for hunters to publish their bug reports in order to share their knowledge. Hunters will also be able to improve their skills through the newly-launched <a href="http://goo.gle/bhu">Bug Hunter University</a>, which includes courses on how to submit a successful vulnerability report.</p><p>Research papers on the security of open source will be <a href="https://bughunters.google.com/about/rules/5122527111938048">eligible for a reward</a>, just like open source software <a href="http://goo.gle/patchz">patch submissions</a>, while hunters improving security in open source programmes will be eligible to <a href="http://goo.gle/subsidiz">apply for a grant</a> to better secure their own projects.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gGRwbS6T2JYCbdQmJ8xJri" name="gGRwbS6T2JYCbdQmJ8xJri.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri.png" mos="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to increase cyber resilience within your organisation</strong></p><p class="fancy-box__body-text">Cyber resilience for dummies</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359468/how-to-increase-cyber-resilience-within-your-organisation" data-original-url="/security/cyber-security/359468/how-to-increase-cyber-resilience-within-your-organisation">FREE DOWNLOAD</a></p></div></div><p>Commenting on the announcement, Google VRP technical programme manager, Jan Keller, <a href="https://security.googleblog.com/2021/07/a-new-chapter-for-googles-vulnerability.html">said</a> that when Google launched its “very first VRP” over a decade ago, no one knew “how many valid vulnerabilities – if any – would be submitted on the first day”.</p><p>“Everyone on the team put in their estimate, with predictions ranging from zero to 20. In the end, we actually received more than 25 reports, taking all of us by surprise,” he added.</p><p>Three years later, the programme was expanded to include <a href="https://www.itpro.com/security/software-vulnerability/20766/google-launches-open-source-bug-bounty-programme" data-original-url="https://www.itpro.com/security/software-vulnerability/20766/google-launches-open-source-bug-bounty-programme">open source</a> as well as <a href="https://www.itpro.com/security/21057/google-extends-open-source-bug-bounty-programme-android-and-apache" data-original-url="https://www.itpro.com/security/21057/google-extends-open-source-bug-bounty-programme-android-and-apache">Google Android and Apache</a>.</p><p>“Since its inception, the VRP programme has not only grown significantly in terms of report volume, but the team of security engineers behind it has also expanded – including almost 20 bug hunters who reported vulnerabilities to us and ended up joining the Google VRP team. That is why we are thrilled to bring you this new platform, continue to grow our community of bug hunters and support the skill development of up-and-coming vulnerability researchers,” said Keller.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft awarded $13.6 million in bug bounties over the last 12 months ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Microsoft has said it awarded over $13.6 million (£9.87 million) in rewards to <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> researchers participating in its public bug bounty programmes over the last 12 months.</p><p>Between 1 July 2020 and 30 June 2021, over 340 security researchers from across 58 countries participated in the tech giant’s 17 software bug hunts, reporting a total of 1,261 valid vulnerabilities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/5g/360028/48-of-enterprise-5g-operators-lack-the-tools-or-knowledge-to-fix-security-bugs" data-original-url="/mobile/5g/360028/48-of-enterprise-5g-operators-lack-the-tools-or-knowledge-to-fix-security-bugs">Half of enterprise 5G operators lack the tools to fix security bugs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/360027/microsoft-fixes-windows-11-upgrade-bug" data-original-url="/operating-systems/microsoft-windows/360027/microsoft-fixes-windows-11-upgrade-bug">Microsoft fixes Windows 11 upgrade bug</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year" data-original-url="/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year">GitHub bug bounty payouts surpass $1.5 million</a></p></div></div><p>The number of participating researchers grew by at least a dozen since the same period last year, when Microsoft awarded <a href="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year" data-original-url="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year">$13.7 million to 327 security researchers</a>. Since then, the tech giant has added two more bug bounty programmes, including <a href="https://www.itpro.com/security/bugs/359024/microsoft-launches-bug-bounty-programme-for-teams" data-original-url="https://www.itpro.com/security/bugs/359024/microsoft-launches-bug-bounty-programme-for-teams">one for its Teams desktop client</a> with potential rewards of up to $30,000, and saw the number of vulnerability reports increase by 35.</p><p>However, despite the reward amount tripling between 2019 and 2020, 2021 saw a slight decrease, of around $100,000.</p><p>Over the last 12 months, the highest number of bug reports were submitted from security researchers based in China, the US, Israel, and India. Although the average reward was over $10,000 (£7,260), the largest payout – $200,000 (£145,000) – was awarded for a vulnerability reported in Microsoft’s OS virtualisation technology, Hyper-V, under the <a href="https://www.microsoft.com/en-us/msrc/bounty-hyper-v?rtc=1">Hyper-V Bounty Programme</a>.</p><p>Microsoft Security Response Center members Jarek Stanley, Lynn Miyashita, and Madeline Eckert thanked “everyone who shared their research with Microsoft this year and for their partnership in securing millions of customers”, in a statement on the company’s <a href="https://msrc-blog.microsoft.com/2021/07/08/microsoft-bug-bounty-programs-year-in-review-13-6m-in-rewards">blog</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ffna7TmpqYrgTZpXMRi9u6" name="ffna7TmpqYrgTZpXMRi9u6.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ffna7TmpqYrgTZpXMRi9u6.jpg" mos="https://cdn.mos.cms.futurecdn.net/ffna7TmpqYrgTZpXMRi9u6.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Forrester Wave: Top security analytics platforms</strong></p><p class="fancy-box__body-text">The 11 providers that matter most and how they stack up</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360171/the-forrester-wave-top-security-analytics-platforms" data-original-url="/security/cyber-security/360171/the-forrester-wave-top-security-analytics-platforms">FREE DOWNLOAD</a></p></div></div><p>“We’re constantly evaluating the threat landscape to evolve our programmes and listening to feedback from researchers to help make it easier to share their research. This year, we introduced new challenges and scenarios to award research focused on the highest impact to customer security.</p><p>"These focus areas helped us not only discover and fix risks to customer privacy and security, but also offer researchers top awards for their high-impact work,” they said, adding that the Microsoft Security Response Center will share “more bounty programme updates and improvements in the coming year”.</p><p>The title of the Most Valuable Security Researcher 2021 is to be announced in August.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months</link>
                                                                            <description>
                            <![CDATA[ Over 340 security researchers from 58 countries reported a total of 1,261 valid vulnerabilities between 2020-2021 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5dq9gR2Z2HngSWVZ57RdHy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/a6UYCVj2xe9xHmoYCjcSBe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Jul 2021 10:54:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/a6UYCVj2xe9xHmoYCjcSBe-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft sign-in page on screen]]></media:description>                                                            <media:text><![CDATA[Microsoft sign-in page on screen]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft sign-in page on screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/a6UYCVj2xe9xHmoYCjcSBe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has said it awarded over $13.6 million (£9.87 million) in rewards to <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> researchers participating in its public bug bounty programmes over the last 12 months.</p><p>Between 1 July 2020 and 30 June 2021, over 340 security researchers from across 58 countries participated in the tech giant’s 17 software bug hunts, reporting a total of 1,261 valid vulnerabilities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/5g/360028/48-of-enterprise-5g-operators-lack-the-tools-or-knowledge-to-fix-security-bugs" data-original-url="/mobile/5g/360028/48-of-enterprise-5g-operators-lack-the-tools-or-knowledge-to-fix-security-bugs">Half of enterprise 5G operators lack the tools to fix security bugs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/360027/microsoft-fixes-windows-11-upgrade-bug" data-original-url="/operating-systems/microsoft-windows/360027/microsoft-fixes-windows-11-upgrade-bug">Microsoft fixes Windows 11 upgrade bug</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year" data-original-url="/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year">GitHub bug bounty payouts surpass $1.5 million</a></p></div></div><p>The number of participating researchers grew by at least a dozen since the same period last year, when Microsoft awarded <a href="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year" data-original-url="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year">$13.7 million to 327 security researchers</a>. Since then, the tech giant has added two more bug bounty programmes, including <a href="https://www.itpro.com/security/bugs/359024/microsoft-launches-bug-bounty-programme-for-teams" data-original-url="https://www.itpro.com/security/bugs/359024/microsoft-launches-bug-bounty-programme-for-teams">one for its Teams desktop client</a> with potential rewards of up to $30,000, and saw the number of vulnerability reports increase by 35.</p><p>However, despite the reward amount tripling between 2019 and 2020, 2021 saw a slight decrease, of around $100,000.</p><p>Over the last 12 months, the highest number of bug reports were submitted from security researchers based in China, the US, Israel, and India. Although the average reward was over $10,000 (£7,260), the largest payout – $200,000 (£145,000) – was awarded for a vulnerability reported in Microsoft’s OS virtualisation technology, Hyper-V, under the <a href="https://www.microsoft.com/en-us/msrc/bounty-hyper-v?rtc=1">Hyper-V Bounty Programme</a>.</p><p>Microsoft Security Response Center members Jarek Stanley, Lynn Miyashita, and Madeline Eckert thanked “everyone who shared their research with Microsoft this year and for their partnership in securing millions of customers”, in a statement on the company’s <a href="https://msrc-blog.microsoft.com/2021/07/08/microsoft-bug-bounty-programs-year-in-review-13-6m-in-rewards">blog</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ffna7TmpqYrgTZpXMRi9u6" name="ffna7TmpqYrgTZpXMRi9u6.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ffna7TmpqYrgTZpXMRi9u6.jpg" mos="https://cdn.mos.cms.futurecdn.net/ffna7TmpqYrgTZpXMRi9u6.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Forrester Wave: Top security analytics platforms</strong></p><p class="fancy-box__body-text">The 11 providers that matter most and how they stack up</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360171/the-forrester-wave-top-security-analytics-platforms" data-original-url="/security/cyber-security/360171/the-forrester-wave-top-security-analytics-platforms">FREE DOWNLOAD</a></p></div></div><p>“We’re constantly evaluating the threat landscape to evolve our programmes and listening to feedback from researchers to help make it easier to share their research. This year, we introduced new challenges and scenarios to award research focused on the highest impact to customer security.</p><p>"These focus areas helped us not only discover and fix risks to customer privacy and security, but also offer researchers top awards for their high-impact work,” they said, adding that the Microsoft Security Response Center will share “more bounty programme updates and improvements in the coming year”.</p><p>The title of the Most Valuable Security Researcher 2021 is to be announced in August.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IT Pro 20/20: Does cyber security's public image need a makeover? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Welcome to issue 18 of IT Pro 20/20, distilling the most important themes of the previous month into an easy-to-read package.</p><p>In this cyber-security-themed issue, we highlight some of the most pressing challenges facing the industry. Our lead feature looks at the role of white hat hackers across the industry, the challenges they have faced in proving their value to companies, and whether media depictions of the traditional ‘hacker’ are creating unhelpful stereotypes.</p><p>We also look at the evolution of the security threat landscape from the 1990s until now, as well as consider whether the sudden appearance of social conscience among hackers may spell the end of the ransomware industry as we know it.</p><p>Also in this issue, you’ll find an overview of the most exciting features coming with Windows 11, as well as a look at the motivations fuelling the war against end-to-end encryption.</p><div ><table><tbody><tr><td  ><a href="https://dennistrk.cvtr.io/click?lid=29069pid=3&sid=">DOWNLOAD ISSUE 18 OF IT PRO 20/20 HERE</a></td></tr></tbody></table></div><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3r4BUHLFm5JGD8kAssAhHa" name="" alt="IT Pro 20/20 Issue 18: Does cyber security's public image need a makeover?" src="https://cdn.mos.cms.futurecdn.net/3r4BUHLFm5JGD8kAssAhHa.jpg" mos="https://cdn.mos.cms.futurecdn.net/3r4BUHLFm5JGD8kAssAhHa.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The next IT Pro 20/20 will be available on 30 July – previous issues can be found here. If you would like to receive each issue in your inbox as they release, you can <a href="https://www.itpro.com/magazine-signup" rel="noopener" target="_blank" data-original-url="https://www.itpro.com/magazine-signup">subscribe to our mailing list here</a>.</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/undefined?locale=1&p=false&wp=dennistrk.cvtr.io%2Fclick%3Flid%3D29069pid%3D3%26sid%3D"></iframe> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover</link>
                                                                            <description>
                            <![CDATA[ Issue 18 of IT Pro 20/20 looks at recent efforts to retire the 'hacker' stereotype, and how the threat landscape has changed over the past 20 years ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dtiXYdEodZWsfueDgo12E6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Jun 2021 13:46:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IT Pro 20/20 Issue 18: Does cyber security&amp;#039;s public image need a makeover?]]></media:description>                                                            <media:text><![CDATA[IT Pro 20/20 Issue 18: Does cyber security&amp;#039;s public image need a makeover?]]></media:text>
                                <media:title type="plain"><![CDATA[IT Pro 20/20 Issue 18: Does cyber security&amp;#039;s public image need a makeover?]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Welcome to issue 18 of IT Pro 20/20, distilling the most important themes of the previous month into an easy-to-read package.</p><p>In this cyber-security-themed issue, we highlight some of the most pressing challenges facing the industry. Our lead feature looks at the role of white hat hackers across the industry, the challenges they have faced in proving their value to companies, and whether media depictions of the traditional ‘hacker’ are creating unhelpful stereotypes.</p><p>We also look at the evolution of the security threat landscape from the 1990s until now, as well as consider whether the sudden appearance of social conscience among hackers may spell the end of the ransomware industry as we know it.</p><p>Also in this issue, you’ll find an overview of the most exciting features coming with Windows 11, as well as a look at the motivations fuelling the war against end-to-end encryption.</p><div ><table><tbody><tr><td  ><a href="https://dennistrk.cvtr.io/click?lid=29069pid=3&sid=">DOWNLOAD ISSUE 18 OF IT PRO 20/20 HERE</a></td></tr></tbody></table></div><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3r4BUHLFm5JGD8kAssAhHa" name="" alt="IT Pro 20/20 Issue 18: Does cyber security's public image need a makeover?" src="https://cdn.mos.cms.futurecdn.net/3r4BUHLFm5JGD8kAssAhHa.jpg" mos="https://cdn.mos.cms.futurecdn.net/3r4BUHLFm5JGD8kAssAhHa.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The next IT Pro 20/20 will be available on 30 July – previous issues can be found here. If you would like to receive each issue in your inbox as they release, you can <a href="https://www.itpro.com/magazine-signup" rel="noopener" target="_blank" data-original-url="https://www.itpro.com/magazine-signup">subscribe to our mailing list here</a>.</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/undefined?locale=1&p=false&wp=dennistrk.cvtr.io%2Fclick%3Flid%3D29069pid%3D3%26sid%3D"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: Why is it so hard to convict hackers? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Hacking, ransomware attacks and other forms of cybercrime have become a fact of life in the modern age, but while the rates of these attacks have drastically increased, the ability of law enforcement to bring the perpetrators to justice seems to be lagging behind somewhat. Even when suspects are caught, it's rare for cases to result in convictions.</p><p>There are a number of factors that contribute to this, including the sophistication of modern anonymisation tools, police resource constraints and jurisdictional difficulties. In this week's episode, we're joined by Jake Moore, ESET cyber security specialist and former digital forensic investigator, to discuss why this is such a problem, and how police can work with the security industry to help solve it. </p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=45148356&theme=light&playlist=false&playlist-continuous=false&autoplay=false&live-autoplay=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><h2 id="footnotes-2">Footnotes</h2><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1385104733254393856"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1385104733254393856"></a></p></blockquote></figure><div class="see-more__filter"></div></div><ul><li><a href="https://dennis-publishing-hvmg.brand.live/c/Inside-the-mind-of-a-forensic-investigator">IT Pro Live: Inside the mind of a forensic investigator</a></li><li><a href="https://www.itpro.com/639379/updated-lulzsec-leader-betrays-clan-as-arrests-made" data-original-url="https://www.itpro.com/639379/updated-lulzsec-leader-betrays-clan-as-arrests-made">LulzSec leader betrays clan as arrests made</a></li><li><a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a></li><li><a href="https://www.itpro.com/security/hacking/356480/the-it-pro-podcast-the-secret-life-of-hackers" data-original-url="https://www.itpro.com/security/hacking/356480/the-it-pro-podcast-the-secret-life-of-hackers">The IT Pro Podcast: The secret life of hackers</a></li><li><a href="https://www.itpro.com/security/359618/the-evolution-of-security" data-original-url="https://www.itpro.com/security/359618/the-evolution-of-security">The evolution of security</a></li><li><a href="https://www.itpro.com/data-insights/analytics/355268/funding-cuts-lead-to-dodgy-digital-forensics" data-original-url="https://www.itpro.com/data-insights/analytics/355268/funding-cuts-lead-to-dodgy-digital-forensics">Funding cuts lead to dodgy digital forensics</a></li><li><a href="https://www.itpro.com/it-governance/30886/cloud-act-ends-microsofts-us-data-privacy-dispute" data-original-url="https://www.itpro.com/it-governance/30886/cloud-act-ends-microsofts-us-data-privacy-dispute">CLOUD Act ends Microsoft's US data privacy dispute</a></li><li><a href="https://www.itpro.com/intellectual-property/26615/the-pirate-bay-returns-to-its-org-domain" data-original-url="https://www.itpro.com/intellectual-property/26615/the-pirate-bay-returns-to-its-org-domain">The Pirate Bay returns to its .org domain</a></li><li><a href="https://www.itpro.com/policy-legislation/data-protection/354650/open-rights-group-calls-for-government-to-protect-data" data-original-url="https://www.itpro.com/policy-legislation/data-protection/354650/open-rights-group-calls-for-government-to-protect-data">Open Rights Group calls for government to protect data post-Brexit</a></li><li><a href="https://www.itpro.com/penetration-testing/34392/pen-testers-arrested-after-breaking-into-courthouse-that-hired-them" data-original-url="https://www.itpro.com/penetration-testing/34392/pen-testers-arrested-after-breaking-into-courthouse-that-hired-them">Pen testers arrested after breaking into courthouse that hired them</a></li><li><a href="https://www.itpro.com/security/32975/british-hacker-lauri-love-invokes-victorian-law-in-bid-to-get-back-seized-computers" data-original-url="https://www.itpro.com/security/32975/british-hacker-lauri-love-invokes-victorian-law-in-bid-to-get-back-seized-computers">British 'hacker' Lauri Love invokes Victorian law in bid to get back seized computers</a></li><li><a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a></li><li><a href="https://www.itpro.com/security/359443/googles-about-to-push-everyone-into-two-factor-authentication" data-original-url="https://www.itpro.com/security/359443/googles-about-to-push-everyone-into-two-factor-authentication">Google's about to push everyone into two-factor authentication</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://podcasts.apple.com/gb/podcast/the-itpro-podcast/id1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-security/359759/the-it-pro-podcast-why-is-it-so-hard-to-convict-hackers</link>
                                                                            <description>
                            <![CDATA[ Catching cyber criminals is hard enough - but putting them behind bars is even more challenging ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i6DnXGCT9wvGySMTib8b6f</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yiWQ8hUL5Qf6rak8Gg8vJT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Jun 2021 10:10:56 +0000</pubDate>                                                                                                                                <updated>Fri, 04 Jun 2021 06:30:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yiWQ8hUL5Qf6rak8Gg8vJT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast: Why is it so hard to convict hackers?]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast: Why is it so hard to convict hackers?]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast: Why is it so hard to convict hackers?]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yiWQ8hUL5Qf6rak8Gg8vJT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hacking, ransomware attacks and other forms of cybercrime have become a fact of life in the modern age, but while the rates of these attacks have drastically increased, the ability of law enforcement to bring the perpetrators to justice seems to be lagging behind somewhat. Even when suspects are caught, it's rare for cases to result in convictions.</p><p>There are a number of factors that contribute to this, including the sophistication of modern anonymisation tools, police resource constraints and jurisdictional difficulties. In this week's episode, we're joined by Jake Moore, ESET cyber security specialist and former digital forensic investigator, to discuss why this is such a problem, and how police can work with the security industry to help solve it. </p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=45148356&theme=light&playlist=false&playlist-continuous=false&autoplay=false&live-autoplay=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><h2 id="footnotes-2">Footnotes</h2><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1385104733254393856"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1385104733254393856"></a></p></blockquote></figure><div class="see-more__filter"></div></div><ul><li><a href="https://dennis-publishing-hvmg.brand.live/c/Inside-the-mind-of-a-forensic-investigator">IT Pro Live: Inside the mind of a forensic investigator</a></li><li><a href="https://www.itpro.com/639379/updated-lulzsec-leader-betrays-clan-as-arrests-made" data-original-url="https://www.itpro.com/639379/updated-lulzsec-leader-betrays-clan-as-arrests-made">LulzSec leader betrays clan as arrests made</a></li><li><a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a></li><li><a href="https://www.itpro.com/security/hacking/356480/the-it-pro-podcast-the-secret-life-of-hackers" data-original-url="https://www.itpro.com/security/hacking/356480/the-it-pro-podcast-the-secret-life-of-hackers">The IT Pro Podcast: The secret life of hackers</a></li><li><a href="https://www.itpro.com/security/359618/the-evolution-of-security" data-original-url="https://www.itpro.com/security/359618/the-evolution-of-security">The evolution of security</a></li><li><a href="https://www.itpro.com/data-insights/analytics/355268/funding-cuts-lead-to-dodgy-digital-forensics" data-original-url="https://www.itpro.com/data-insights/analytics/355268/funding-cuts-lead-to-dodgy-digital-forensics">Funding cuts lead to dodgy digital forensics</a></li><li><a href="https://www.itpro.com/it-governance/30886/cloud-act-ends-microsofts-us-data-privacy-dispute" data-original-url="https://www.itpro.com/it-governance/30886/cloud-act-ends-microsofts-us-data-privacy-dispute">CLOUD Act ends Microsoft's US data privacy dispute</a></li><li><a href="https://www.itpro.com/intellectual-property/26615/the-pirate-bay-returns-to-its-org-domain" data-original-url="https://www.itpro.com/intellectual-property/26615/the-pirate-bay-returns-to-its-org-domain">The Pirate Bay returns to its .org domain</a></li><li><a href="https://www.itpro.com/policy-legislation/data-protection/354650/open-rights-group-calls-for-government-to-protect-data" data-original-url="https://www.itpro.com/policy-legislation/data-protection/354650/open-rights-group-calls-for-government-to-protect-data">Open Rights Group calls for government to protect data post-Brexit</a></li><li><a href="https://www.itpro.com/penetration-testing/34392/pen-testers-arrested-after-breaking-into-courthouse-that-hired-them" data-original-url="https://www.itpro.com/penetration-testing/34392/pen-testers-arrested-after-breaking-into-courthouse-that-hired-them">Pen testers arrested after breaking into courthouse that hired them</a></li><li><a href="https://www.itpro.com/security/32975/british-hacker-lauri-love-invokes-victorian-law-in-bid-to-get-back-seized-computers" data-original-url="https://www.itpro.com/security/32975/british-hacker-lauri-love-invokes-victorian-law-in-bid-to-get-back-seized-computers">British 'hacker' Lauri Love invokes Victorian law in bid to get back seized computers</a></li><li><a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">What is the Computer Misuse Act?</a></li><li><a href="https://www.itpro.com/security/359443/googles-about-to-push-everyone-into-two-factor-authentication" data-original-url="https://www.itpro.com/security/359443/googles-about-to-push-everyone-into-two-factor-authentication">Google's about to push everyone into two-factor authentication</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://podcasts.apple.com/gb/podcast/the-itpro-podcast/id1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple's AirTag tracker has already been hacked ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Apple’s AirTag has only been out for around a week, but it’s already been hacked.</p><p>A German <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> researcher cracked the AirTag’s microcontroller, the tiny integrated circuit that controls the device. </p><p>The AirTag, a small locator that retails for $29, can help you find your car keys or anything else it’s attached to. Normally, when you use your phone to find an AirTag, your phone opens in the “Find My” website at found.apple.com to initiate the “Lost Mode” process. However, the researcher found he could redirect the microcontroller to his personal website instead.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/359464/australia-watchdog-takes-unusual-step-in-seeking-to-appear-in" data-original-url="/business/policy-legislation/359464/australia-watchdog-takes-unusual-step-in-seeking-to-appear-in">ACCC takes “unusual” step of seeking to assist in Epic vs Apple lawsuit</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/359438/weekly-threat-roundup-dell-apple-qualcomm" data-original-url="/security/vulnerability/359438/weekly-threat-roundup-dell-apple-qualcomm">Weekly threat roundup: Dell, Apple, Qualcomm</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/359407/apple-patches-ios-macos-webkit-flaws" data-original-url="/security/zero-day-exploit/359407/apple-patches-ios-macos-webkit-flaws">Apple patches exploited iOS and macOS WebKit flaws</a></p></div></div><p>Security researcher Thomas Roth, who goes by the name Stack Smashing, posted a video of the process to <a href="https://twitter.com/ghidraninja/status/1391165711448518658" target="_blank">Twitter</a>, and wrote: “After hours of trying (and bricking 2 AirTags) I managed to break into the microcontroller of the AirTag."</p><p>This means hackers could potentially direct hacked AirTags to <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> or malware sites, and it remains to be seen whether Apple will implement some mechanism to block this sort of attack.</p><p>Although this sounds alarming, the tech review website <em><a href="https://www.slashgear.com/apple-airtag-can-be-hacked-but-its-not-as-bad-as-it-sounds-09672053">SlashGear</a></em> cautions that even if a hacker can reprogram an AirTag, “the process and the end result might not yet be worth the worry.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TgYwXSHV6efgCB2UrGXGXc" name="TgYwXSHV6efgCB2UrGXGXc.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TgYwXSHV6efgCB2UrGXGXc.png" mos="https://cdn.mos.cms.futurecdn.net/TgYwXSHV6efgCB2UrGXGXc.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Prevent fraud and phishing attacks with DMARC</strong></p><p class="fancy-box__body-text">How to use domain-based message authentication, reporting, and conformance for email security</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359475/prevent-fraud-and-phishing-attacks-with-dmarc" data-original-url="/security/cyber-security/359475/prevent-fraud-and-phishing-attacks-with-dmarc">FREE DOWNLOAD</a></p></div></div><p>“The security researcher hasn’t disclosed yet the process but he admits bricking at least two AirTags to get there,” SlashGear noted. “Unless the tracker’s firmware can be modified remotely over the air, the only way you’ll get a hacked AirTag would be if you acquired it through other parties.”</p><p>As always, there are proactive ways to avoid falling victim to phishing and malware campaigns like this. When you navigate to a site, always verify the URL looks exactly as you expect. Many times, these spoofed sites will have one character off or a different domain extension. </p><p>If you see anything suspicious in the link, close the browser, open a fresh browser and navigate to your target site by typing it manually into the URL bar.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/359480/security-researcher-has-already-hacked-the-new-apple-airtag</link>
                                                                            <description>
                            <![CDATA[ An IT security researcher redirected the device’s finding feature to his own website ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oKEc7squEjd2hzLFZXmaVM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/st9yDTqti6UwRqBTR2jiUk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 May 2021 16:45:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mike Brassfield ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/st9yDTqti6UwRqBTR2jiUk-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[White Apple AirTag with a smiling emoji on it]]></media:description>                                                            <media:text><![CDATA[White Apple AirTag with a smiling emoji on it]]></media:text>
                                <media:title type="plain"><![CDATA[White Apple AirTag with a smiling emoji on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/st9yDTqti6UwRqBTR2jiUk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple’s AirTag has only been out for around a week, but it’s already been hacked.</p><p>A German <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> researcher cracked the AirTag’s microcontroller, the tiny integrated circuit that controls the device. </p><p>The AirTag, a small locator that retails for $29, can help you find your car keys or anything else it’s attached to. Normally, when you use your phone to find an AirTag, your phone opens in the “Find My” website at found.apple.com to initiate the “Lost Mode” process. However, the researcher found he could redirect the microcontroller to his personal website instead.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/359464/australia-watchdog-takes-unusual-step-in-seeking-to-appear-in" data-original-url="/business/policy-legislation/359464/australia-watchdog-takes-unusual-step-in-seeking-to-appear-in">ACCC takes “unusual” step of seeking to assist in Epic vs Apple lawsuit</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/359438/weekly-threat-roundup-dell-apple-qualcomm" data-original-url="/security/vulnerability/359438/weekly-threat-roundup-dell-apple-qualcomm">Weekly threat roundup: Dell, Apple, Qualcomm</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/359407/apple-patches-ios-macos-webkit-flaws" data-original-url="/security/zero-day-exploit/359407/apple-patches-ios-macos-webkit-flaws">Apple patches exploited iOS and macOS WebKit flaws</a></p></div></div><p>Security researcher Thomas Roth, who goes by the name Stack Smashing, posted a video of the process to <a href="https://twitter.com/ghidraninja/status/1391165711448518658" target="_blank">Twitter</a>, and wrote: “After hours of trying (and bricking 2 AirTags) I managed to break into the microcontroller of the AirTag."</p><p>This means hackers could potentially direct hacked AirTags to <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> or malware sites, and it remains to be seen whether Apple will implement some mechanism to block this sort of attack.</p><p>Although this sounds alarming, the tech review website <em><a href="https://www.slashgear.com/apple-airtag-can-be-hacked-but-its-not-as-bad-as-it-sounds-09672053">SlashGear</a></em> cautions that even if a hacker can reprogram an AirTag, “the process and the end result might not yet be worth the worry.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TgYwXSHV6efgCB2UrGXGXc" name="TgYwXSHV6efgCB2UrGXGXc.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TgYwXSHV6efgCB2UrGXGXc.png" mos="https://cdn.mos.cms.futurecdn.net/TgYwXSHV6efgCB2UrGXGXc.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Prevent fraud and phishing attacks with DMARC</strong></p><p class="fancy-box__body-text">How to use domain-based message authentication, reporting, and conformance for email security</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359475/prevent-fraud-and-phishing-attacks-with-dmarc" data-original-url="/security/cyber-security/359475/prevent-fraud-and-phishing-attacks-with-dmarc">FREE DOWNLOAD</a></p></div></div><p>“The security researcher hasn’t disclosed yet the process but he admits bricking at least two AirTags to get there,” SlashGear noted. “Unless the tracker’s firmware can be modified remotely over the air, the only way you’ll get a hacked AirTag would be if you acquired it through other parties.”</p><p>As always, there are proactive ways to avoid falling victim to phishing and malware campaigns like this. When you navigate to a site, always verify the URL looks exactly as you expect. Many times, these spoofed sites will have one character off or a different domain extension. </p><p>If you see anything suspicious in the link, close the browser, open a fresh browser and navigate to your target site by typing it manually into the URL bar.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Defense Dept. expands vulnerability disclosure program to all publicly accessible defense systems ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The US Department of Defense (DoD) has expanded its Vulnerability Disclosure Program (VDP) to include all publicly accessible DoD websites and systems.</p><p>The <a href="https://www.dc3.mil/Organizations/Vulnerability-Disclosure/Vulnerability-Disclosure-Program-VDP">VDP</a> is run by the Department of Defense Cyber Crime Center (DC3) to enable security researchers to report vulnerabilities on the DoD Information Network (DoDIN) to improve network defense.</p><p>The expansion announced today allows for research and reporting of vulnerabilities related to all DOD publicly accessible networks, frequency-based communication, internet of things (IoT), and industrial control systems, according to Brett Goldstein, the director of the Defense Digital Service. Originally, the program was limited to DoD public-facing websites and applications.</p><p>"This expansion is a testament to transforming the government's approach to security and leapfrogging the current state of technology within DOD," he said.</p><p>Before the program’s launch, researchers had no way of reporting bugs they found in publicly accessible DoD systems. </p><p>“Because of this, many vulnerabilities went unreported," said Goldstein. "The DOD Vulnerability Policy launched in 2016 because we demonstrated the efficacy of working with the hacker community and even hiring hackers to find and fix vulnerabilities in systems."</p><p>Since the launch of the Vulnerability Disclosure Program, security researchers have submitted over 29,000 vulnerability reports. Officials said that over 70% of them were determined to be valid.</p><p>Experts believe the expansion will lead to a massive increase in the number of bugs reported to them.</p><p>"The department has always maintained the perspective that DOD websites were only the beginning as they account for a fraction of our overall attack surface," said DOD Cyber Crime Center director Kristopher Johnson.</p><p>In April, <a href="https://twitter.com/DC3Forensics/status/1379046874242498563">the DoD Cyber Crime Center unveiled</a> a 12-month Defense Industrial Base Vulnerability Disclosure Program (<a href="https://hackerone.com/dib-vdp-pilot/?type=team">DIB-VDP</a>) pilot to enable security researchers to report flaws in DoD contractor partner’s information systems, web properties, and other identified scoped assets. The 12-month program aspires to employ the lessons learned from existing reports made through the Pentagon’s Vulnerability Disclosure Program.</p><p>“The expansion of vulnerability research to participating DoD contractor networks replicates the DoD’s’ success by making participating DoD contractor networks available for vulnerability research,” said the DoD's Cyber Crime Center on its HackerOne webpage. “No technology is perfect, but DC3 believes that working with skilled security researchers across the globe is crucial to identifying their weaknesses.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ethical-hacking/359430/department-of-defense-expands-vulnerability-disclosure-program-to</link>
                                                                            <description>
                            <![CDATA[ This move allows greater research and reporting of bugs to Pentagon ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">e1CVsHSw7nVHbKQAdtM8iT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dLQZ4pyPjPZAxUhBSTsYJn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 May 2021 18:20:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dLQZ4pyPjPZAxUhBSTsYJn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[depatment of defenve buiding]]></media:description>                                                            <media:text><![CDATA[depatment of defenve buiding]]></media:text>
                                <media:title type="plain"><![CDATA[depatment of defenve buiding]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dLQZ4pyPjPZAxUhBSTsYJn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Department of Defense (DoD) has expanded its Vulnerability Disclosure Program (VDP) to include all publicly accessible DoD websites and systems.</p><p>The <a href="https://www.dc3.mil/Organizations/Vulnerability-Disclosure/Vulnerability-Disclosure-Program-VDP">VDP</a> is run by the Department of Defense Cyber Crime Center (DC3) to enable security researchers to report vulnerabilities on the DoD Information Network (DoDIN) to improve network defense.</p><p>The expansion announced today allows for research and reporting of vulnerabilities related to all DOD publicly accessible networks, frequency-based communication, internet of things (IoT), and industrial control systems, according to Brett Goldstein, the director of the Defense Digital Service. Originally, the program was limited to DoD public-facing websites and applications.</p><p>"This expansion is a testament to transforming the government's approach to security and leapfrogging the current state of technology within DOD," he said.</p><p>Before the program’s launch, researchers had no way of reporting bugs they found in publicly accessible DoD systems. </p><p>“Because of this, many vulnerabilities went unreported," said Goldstein. "The DOD Vulnerability Policy launched in 2016 because we demonstrated the efficacy of working with the hacker community and even hiring hackers to find and fix vulnerabilities in systems."</p><p>Since the launch of the Vulnerability Disclosure Program, security researchers have submitted over 29,000 vulnerability reports. Officials said that over 70% of them were determined to be valid.</p><p>Experts believe the expansion will lead to a massive increase in the number of bugs reported to them.</p><p>"The department has always maintained the perspective that DOD websites were only the beginning as they account for a fraction of our overall attack surface," said DOD Cyber Crime Center director Kristopher Johnson.</p><p>In April, <a href="https://twitter.com/DC3Forensics/status/1379046874242498563">the DoD Cyber Crime Center unveiled</a> a 12-month Defense Industrial Base Vulnerability Disclosure Program (<a href="https://hackerone.com/dib-vdp-pilot/?type=team">DIB-VDP</a>) pilot to enable security researchers to report flaws in DoD contractor partner’s information systems, web properties, and other identified scoped assets. The 12-month program aspires to employ the lessons learned from existing reports made through the Pentagon’s Vulnerability Disclosure Program.</p><p>“The expansion of vulnerability research to participating DoD contractor networks replicates the DoD’s’ success by making participating DoD contractor networks available for vulnerability research,” said the DoD's Cyber Crime Center on its HackerOne webpage. “No technology is perfect, but DC3 believes that working with skilled security researchers across the globe is crucial to identifying their weaknesses.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security researchers take control of a Tesla via drone ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Last week at an IT <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> conference, a pair of <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> researchers demonstrated how they could unlock and open a Tesla’s doors using only a drone outfitted with a Wi-Fi dongle.</p><p>They were originally going to demonstrate this at last year’s Pwn2Own hacking competition, but that contest got canceled due to the COVID-19 pandemic. So, they presented it at this year’s CanSecWest conference instead.</p><p>You can view the German cyber security experts’ presentation via <a href="https://www.youtube.com/watch?v=krSj81thN0w">a 40-minute-long YouTube video</a>. If you want to skip to the action, you can head directly to the 36-minute mark to see them unlock the Tesla.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/automation/359253/two-men-die-in-tesla-car-said-to-be-in-autopilot" data-original-url="/business-strategy/automation/359253/two-men-die-in-tesla-car-said-to-be-in-autopilot">Texas police issue warrant for Tesla crash data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/cryptocurrencies/358938/teslas-bitcoin-investment-equivalent-to-carbon-footprint-of-18m" data-original-url="/technology/cryptocurrencies/358938/teslas-bitcoin-investment-equivalent-to-carbon-footprint-of-18m">Tesla's bitcoin investment 'equivalent to carbon footprint of 1.8m cars', bank claims</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358840/cloudflare-and-tesla-among-victims-of-security-camera-hack" data-original-url="/security/hacking/358840/cloudflare-and-tesla-among-victims-of-security-camera-hack">Hackers breach security cameras at Cloudflare, Tesla and more</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/356909/tesla-was-the-target-of-serious-ransomware-attack" data-original-url="/security/ransomware/356909/tesla-was-the-target-of-serious-ransomware-attack">Tesla was the target of "serious" ransomware attack</a></p></div></div><p>The hack shouldn’t be possible today, the researchers explained, because the security flaw they exploited got fixed with a software update last October after they informed Tesla about it. However, the researchers said other automakers might have the same vulnerability in their operating systems.</p><p>In their presentation, the researchers said they exploited vulnerabilities in ConnMan, an open source software component produced by Inte that functions as an internet connection manager for embedded devices. </p><p>The researchers discovered they could exploit this flaw to take control of a Tesla’s infotainment system. From there, they could do anything a driver could do by pressing the buttons on the car’s console, including unlocking the doors and trunk, changing seat positions, playing music, and controlling the air conditioning.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bRgjxZYos5Bjth4n8XKXvf" name="bRgjxZYos5Bjth4n8XKXvf.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/bRgjxZYos5Bjth4n8XKXvf.jpg" mos="https://cdn.mos.cms.futurecdn.net/bRgjxZYos5Bjth4n8XKXvf.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The definitive guide to IT security</strong></p><p class="fancy-box__body-text">Protecting your MSP and your customers</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/359166/the-definitive-guide-to-it-security" data-original-url="/business-operations/managed-service-provider-msp/359166/the-definitive-guide-to-it-security">FREE DOWNLOAD</a></p></div></div><p>However, they couldn’t start or drive the car.</p><p>In the video, they use a drone equipped with a Wi-Fi dongle to remotely hack into a Tesla Model X’s infotainment system. They said this technique worked on Tesla S, 3, X, and Y models from up to 300 feet away.</p><p>The really concerning part is that other automakers besides Tesla use ConnMan software. An improved version of ConnMan came out in February, the researchers said, but it’s not clear how many automakers are using it.</p><p>Of course, this isn’t the first time hackers or cyber security researchers have targeted Tesla or its vehicles. In March, hackers <a href="https://www.itpro.com/security/hacking/358840/cloudflare-and-tesla-among-victims-of-security-camera-hack" data-original-url="https://www.itpro.com/security/hacking/358840/cloudflare-and-tesla-among-victims-of-security-camera-hack">breached more than 150,000 security cameras</a> at Tesla and internet security provider Cloudflare. Last year, McAfee researchers <a href="https://www.itpro.com/security/cyber-security/354827/mcafee-researchers-trick-tesla-autopilot-with-a-strip-of-tape" data-original-url="https://www.itpro.com/security/cyber-security/354827/mcafee-researchers-trick-tesla-autopilot-with-a-strip-of-tape">used a two-inch strip of tape</a> to trick Tesla autopilot systems into accelerating their vehicles 50 mph above the speed limit. Finally, in 2018, security researchers discovered <a href="https://www.itpro.com/cyber-security/31898/tesla-keyfob-vulnerable-to-spoofing-attacks" data-original-url="https://www.itpro.com/cyber-security/31898/tesla-keyfob-vulnerable-to-spoofing-attacks">Tesla keyfobs were vulnerable to spoofing attacks</a> that would allow attackers to steal a Tesla simply by walking past the owner and cloning their key.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ethical-hacking/359429/security-researchers-take-control-of-a-tesla-via-drone</link>
                                                                            <description>
                            <![CDATA[ Cyber security researchers found a way to unlock the car doors with a Wi-Fi dongle ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q7JiLRBE8scdni2rkySK78</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tJTvydREGqgeBHpdMdUvHn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 May 2021 18:04:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mike Brassfield ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tJTvydREGqgeBHpdMdUvHn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Tesla factory]]></media:description>                                                            <media:text><![CDATA[Tesla factory]]></media:text>
                                <media:title type="plain"><![CDATA[Tesla factory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tJTvydREGqgeBHpdMdUvHn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Last week at an IT <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> conference, a pair of <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> researchers demonstrated how they could unlock and open a Tesla’s doors using only a drone outfitted with a Wi-Fi dongle.</p><p>They were originally going to demonstrate this at last year’s Pwn2Own hacking competition, but that contest got canceled due to the COVID-19 pandemic. So, they presented it at this year’s CanSecWest conference instead.</p><p>You can view the German cyber security experts’ presentation via <a href="https://www.youtube.com/watch?v=krSj81thN0w">a 40-minute-long YouTube video</a>. If you want to skip to the action, you can head directly to the 36-minute mark to see them unlock the Tesla.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/automation/359253/two-men-die-in-tesla-car-said-to-be-in-autopilot" data-original-url="/business-strategy/automation/359253/two-men-die-in-tesla-car-said-to-be-in-autopilot">Texas police issue warrant for Tesla crash data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/cryptocurrencies/358938/teslas-bitcoin-investment-equivalent-to-carbon-footprint-of-18m" data-original-url="/technology/cryptocurrencies/358938/teslas-bitcoin-investment-equivalent-to-carbon-footprint-of-18m">Tesla's bitcoin investment 'equivalent to carbon footprint of 1.8m cars', bank claims</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358840/cloudflare-and-tesla-among-victims-of-security-camera-hack" data-original-url="/security/hacking/358840/cloudflare-and-tesla-among-victims-of-security-camera-hack">Hackers breach security cameras at Cloudflare, Tesla and more</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/356909/tesla-was-the-target-of-serious-ransomware-attack" data-original-url="/security/ransomware/356909/tesla-was-the-target-of-serious-ransomware-attack">Tesla was the target of "serious" ransomware attack</a></p></div></div><p>The hack shouldn’t be possible today, the researchers explained, because the security flaw they exploited got fixed with a software update last October after they informed Tesla about it. However, the researchers said other automakers might have the same vulnerability in their operating systems.</p><p>In their presentation, the researchers said they exploited vulnerabilities in ConnMan, an open source software component produced by Inte that functions as an internet connection manager for embedded devices. </p><p>The researchers discovered they could exploit this flaw to take control of a Tesla’s infotainment system. From there, they could do anything a driver could do by pressing the buttons on the car’s console, including unlocking the doors and trunk, changing seat positions, playing music, and controlling the air conditioning.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bRgjxZYos5Bjth4n8XKXvf" name="bRgjxZYos5Bjth4n8XKXvf.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/bRgjxZYos5Bjth4n8XKXvf.jpg" mos="https://cdn.mos.cms.futurecdn.net/bRgjxZYos5Bjth4n8XKXvf.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The definitive guide to IT security</strong></p><p class="fancy-box__body-text">Protecting your MSP and your customers</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/359166/the-definitive-guide-to-it-security" data-original-url="/business-operations/managed-service-provider-msp/359166/the-definitive-guide-to-it-security">FREE DOWNLOAD</a></p></div></div><p>However, they couldn’t start or drive the car.</p><p>In the video, they use a drone equipped with a Wi-Fi dongle to remotely hack into a Tesla Model X’s infotainment system. They said this technique worked on Tesla S, 3, X, and Y models from up to 300 feet away.</p><p>The really concerning part is that other automakers besides Tesla use ConnMan software. An improved version of ConnMan came out in February, the researchers said, but it’s not clear how many automakers are using it.</p><p>Of course, this isn’t the first time hackers or cyber security researchers have targeted Tesla or its vehicles. In March, hackers <a href="https://www.itpro.com/security/hacking/358840/cloudflare-and-tesla-among-victims-of-security-camera-hack" data-original-url="https://www.itpro.com/security/hacking/358840/cloudflare-and-tesla-among-victims-of-security-camera-hack">breached more than 150,000 security cameras</a> at Tesla and internet security provider Cloudflare. Last year, McAfee researchers <a href="https://www.itpro.com/security/cyber-security/354827/mcafee-researchers-trick-tesla-autopilot-with-a-strip-of-tape" data-original-url="https://www.itpro.com/security/cyber-security/354827/mcafee-researchers-trick-tesla-autopilot-with-a-strip-of-tape">used a two-inch strip of tape</a> to trick Tesla autopilot systems into accelerating their vehicles 50 mph above the speed limit. Finally, in 2018, security researchers discovered <a href="https://www.itpro.com/cyber-security/31898/tesla-keyfob-vulnerable-to-spoofing-attacks" data-original-url="https://www.itpro.com/cyber-security/31898/tesla-keyfob-vulnerable-to-spoofing-attacks">Tesla keyfobs were vulnerable to spoofing attacks</a> that would allow attackers to steal a Tesla simply by walking past the owner and cloning their key.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Widely-used cyber crime forums targeted in hacking spree ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Four widely-used hacking forums operating on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web" target="_blank" data-original-url="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a> have been compromised in a series of cyber attacks, with unknown attackers seizing the personal data of members while also siphoning away cash.</p><p>Over the past few weeks, attackers have stolen user databases from these forums, which have included email addresses and hashed passwords, according to security researcher <a href="https://krebsonsecurity.com/2021/03/three-top-russian-cybercrime-forums-hacked" target="_blank">Brian Krebs</a>. The incidents have left members of these sites worried that subsequent leaks could reveal their real-world identities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/32117/what-is-the-dark-web" data-original-url="/security/32117/what-is-the-dark-web">What is the dark web?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358048/dark-web-markets-consolidate-as-competition-takes-its-toll" data-original-url="/security/hacking/358048/dark-web-markets-consolidate-as-competition-takes-its-toll">Dark web markets consolidate as competition takes its toll</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/358297/worlds-largest-dark-web-marketplace-taken-offline" data-original-url="/security/cyber-crime/358297/worlds-largest-dark-web-marketplace-taken-offline">World’s largest dark web marketplace taken offline</a></p></div></div><p>The most recent hack, affecting an invite-only cyber crime forum known as Maza, took place this week, with <a href="https://intel471.com/blog/mazafaka-hacked-cybercrime-forums-exploit-crdclub-verified" target="_blank">security firm Intel 471</a> revealing that its users were redirected to a breach notification page upon signing in. This was posted alongside a 35-page PDF file allegedly containing a portion of forum user data, comprising more than 3,000 rows of usernames, partially obfuscated password hashes, email addresses, and other contact details.</p><p>The Maza hack follows attacks against Verified in January, Crdclub in February, and Exploit last week - all well-known dark web forums. This is in addition to a recent fifth attack against Hydra, a dark web marketplace known for the trade of illegal drugs and other criminal services, according to <a href="https://daily.afisha.ru/news/47522-v-set-slili-dannye-predpolagaemyh-razrabotchikov-gidry-ploschadki-po-prodazhe-narkotikov-v-darknete" target="_blank">reports from Russian media</a>.</p><p>“The incidents show that even perpetrators of cybercrime aren’t immune from experiencing the fallout that comes with personally identifiable information being made public,” Intel 471 said in a blog post.</p><p>“Various cybercrime forums are alive with chatter following the breaches, with nefarious actors wondering if their real-world identities will be discovered thanks to the leaked data.”</p><p>Some forum members have speculated these are the efforts of government agencies, although Intel 471 has cast doubt on the theory due to the public nature of these attacks. Krebs also reported that members across these forums have questioned whether the wider strategy is to sow distrust across the community, with cyber criminals now fixated on which platform would be compromised next.</p><p>The security company added that while the perpetrators haven’t identified themselves, they have <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" target="_blank" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">indirectly given researchers an advantage</a>. All information unearthed from these breaches will help in the fight against cyber crime, Intel 471 said, due to the added visibility it gives security teams who are tracking forum members.</p><p>Following the initial attack on the Verified forum, hackers then claimed on another site, Raid Forums, that they had taken Verified’s entire database of registered users and associated information, such as private messages, hashed passwords, and posts. The attackers also managed to steal $150,000 (approximately £108,700) worth of cryptocurrency from Verified’s <a href="https://www.itpro.com/strategy/28296/what-is-bitcoin" target="_blank" data-original-url="https://www.itpro.com/strategy/28296/what-is-bitcoin">Bitcoin wallet</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dtLyta9kj3q48mKrCtkyRM" name="dtLyta9kj3q48mKrCtkyRM.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/dtLyta9kj3q48mKrCtkyRM.png" mos="https://cdn.mos.cms.futurecdn.net/dtLyta9kj3q48mKrCtkyRM.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Online safety: A leader's responsibilities</strong></p><p class="fancy-box__body-text">Sample our exclusive Business Briefing content</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/358718/online-safety-a-leaders-responsibilities" data-original-url="/business/business-strategy/358718/online-safety-a-leaders-responsibilities">FREE DOWNLOAD</a></p></div></div><p>Crdclub’s administrator, a month later, announced the forum had sustained an attack in which their own account was compromised. The attacker was able to lure members into using a money transfer service that was supposedly vouched for by administrators, which led to an unknown amount of money being diverted away from the site.</p><p>Last week’s attack against Exploit saw a <a href="https://www.itpro.com/server-storage/30246/what-is-a-proxy-server" target="_blank" data-original-url="https://www.itpro.com/server-storage/30246/what-is-a-proxy-server">proxy server</a> used to protect against <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">distributed denial of service (DDoS)</a> attacks compromised by an unknown third-party. The forum’s administrator said that a monitoring service had detected <a href="https://www.itpro.com/security/cyber-security/355232/do-you-have-visibility-of-all-your-machine-identities" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/355232/do-you-have-visibility-of-all-your-machine-identities">secure shell (SSH)</a> access to the server, and had attempted to capture network traffic.</p><p>Intel 471 has said its researchers will continue to monitor widely-used cyber crime forums to assess how these incidents have affected members of the hacking community.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/358789/widely-used-cyber-crime-forums-targeted-in-hacking-spree</link>
                                                                            <description>
                            <![CDATA[ Security researchers say hacker-on-hacker campaigns indirectly help the good guys ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">n7rWss48EfqvgD67VMiJvU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wDQfXhNPUxQ6TfnH5UYHo3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Mar 2021 11:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wDQfXhNPUxQ6TfnH5UYHo3-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Shutterstock]]></media:description>                                                            <media:text><![CDATA[A person on a laptop to depict hacking]]></media:text>
                                <media:title type="plain"><![CDATA[A person on a laptop to depict hacking]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wDQfXhNPUxQ6TfnH5UYHo3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Four widely-used hacking forums operating on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web" target="_blank" data-original-url="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a> have been compromised in a series of cyber attacks, with unknown attackers seizing the personal data of members while also siphoning away cash.</p><p>Over the past few weeks, attackers have stolen user databases from these forums, which have included email addresses and hashed passwords, according to security researcher <a href="https://krebsonsecurity.com/2021/03/three-top-russian-cybercrime-forums-hacked" target="_blank">Brian Krebs</a>. The incidents have left members of these sites worried that subsequent leaks could reveal their real-world identities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/32117/what-is-the-dark-web" data-original-url="/security/32117/what-is-the-dark-web">What is the dark web?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358048/dark-web-markets-consolidate-as-competition-takes-its-toll" data-original-url="/security/hacking/358048/dark-web-markets-consolidate-as-competition-takes-its-toll">Dark web markets consolidate as competition takes its toll</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/358297/worlds-largest-dark-web-marketplace-taken-offline" data-original-url="/security/cyber-crime/358297/worlds-largest-dark-web-marketplace-taken-offline">World’s largest dark web marketplace taken offline</a></p></div></div><p>The most recent hack, affecting an invite-only cyber crime forum known as Maza, took place this week, with <a href="https://intel471.com/blog/mazafaka-hacked-cybercrime-forums-exploit-crdclub-verified" target="_blank">security firm Intel 471</a> revealing that its users were redirected to a breach notification page upon signing in. This was posted alongside a 35-page PDF file allegedly containing a portion of forum user data, comprising more than 3,000 rows of usernames, partially obfuscated password hashes, email addresses, and other contact details.</p><p>The Maza hack follows attacks against Verified in January, Crdclub in February, and Exploit last week - all well-known dark web forums. This is in addition to a recent fifth attack against Hydra, a dark web marketplace known for the trade of illegal drugs and other criminal services, according to <a href="https://daily.afisha.ru/news/47522-v-set-slili-dannye-predpolagaemyh-razrabotchikov-gidry-ploschadki-po-prodazhe-narkotikov-v-darknete" target="_blank">reports from Russian media</a>.</p><p>“The incidents show that even perpetrators of cybercrime aren’t immune from experiencing the fallout that comes with personally identifiable information being made public,” Intel 471 said in a blog post.</p><p>“Various cybercrime forums are alive with chatter following the breaches, with nefarious actors wondering if their real-world identities will be discovered thanks to the leaked data.”</p><p>Some forum members have speculated these are the efforts of government agencies, although Intel 471 has cast doubt on the theory due to the public nature of these attacks. Krebs also reported that members across these forums have questioned whether the wider strategy is to sow distrust across the community, with cyber criminals now fixated on which platform would be compromised next.</p><p>The security company added that while the perpetrators haven’t identified themselves, they have <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" target="_blank" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">indirectly given researchers an advantage</a>. All information unearthed from these breaches will help in the fight against cyber crime, Intel 471 said, due to the added visibility it gives security teams who are tracking forum members.</p><p>Following the initial attack on the Verified forum, hackers then claimed on another site, Raid Forums, that they had taken Verified’s entire database of registered users and associated information, such as private messages, hashed passwords, and posts. The attackers also managed to steal $150,000 (approximately £108,700) worth of cryptocurrency from Verified’s <a href="https://www.itpro.com/strategy/28296/what-is-bitcoin" target="_blank" data-original-url="https://www.itpro.com/strategy/28296/what-is-bitcoin">Bitcoin wallet</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dtLyta9kj3q48mKrCtkyRM" name="dtLyta9kj3q48mKrCtkyRM.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/dtLyta9kj3q48mKrCtkyRM.png" mos="https://cdn.mos.cms.futurecdn.net/dtLyta9kj3q48mKrCtkyRM.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Online safety: A leader's responsibilities</strong></p><p class="fancy-box__body-text">Sample our exclusive Business Briefing content</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/358718/online-safety-a-leaders-responsibilities" data-original-url="/business/business-strategy/358718/online-safety-a-leaders-responsibilities">FREE DOWNLOAD</a></p></div></div><p>Crdclub’s administrator, a month later, announced the forum had sustained an attack in which their own account was compromised. The attacker was able to lure members into using a money transfer service that was supposedly vouched for by administrators, which led to an unknown amount of money being diverted away from the site.</p><p>Last week’s attack against Exploit saw a <a href="https://www.itpro.com/server-storage/30246/what-is-a-proxy-server" target="_blank" data-original-url="https://www.itpro.com/server-storage/30246/what-is-a-proxy-server">proxy server</a> used to protect against <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">distributed denial of service (DDoS)</a> attacks compromised by an unknown third-party. The forum’s administrator said that a monitoring service had detected <a href="https://www.itpro.com/security/cyber-security/355232/do-you-have-visibility-of-all-your-machine-identities" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/355232/do-you-have-visibility-of-all-your-machine-identities">secure shell (SSH)</a> access to the server, and had attempted to capture network traffic.</p><p>Intel 471 has said its researchers will continue to monitor widely-used cyber crime forums to assess how these incidents have affected members of the hacking community.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MoD launches bug bounty programme ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Ministry of Defence (MoD) has introduced its own bug bounty programme through which <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hat hackers</a> can disclose vulnerabilities to the UK government department without fear of prosecution.</p><p>Partnering up with HackerOne, the MoD has published a <a href="https://hackerone.com/ef81a495-9cb5-49bb-88ec-430fc4cffb90/embedded_submissions/new">submission form</a> that security researchers can use to report any bugs or flaws with systems or platforms managed by the UK’s defence authorities. Unlike bug bounty programmes commonly run by private companies, however, there is no monetary reward available for disclosure.</p><p>Researchers who find a <a href="https://www.itpro.com/security/vulnerability/356709/why-vulnerability-management-is-crucial-right-now" target="_blank" data-original-url="https://www.itpro.com/security/vulnerability/356709/why-vulnerability-management-is-crucial-right-now">security vulnerability</a> relating to an MoD system must include details of the website IP or page where the vulnerability can be observed, a brief description of its nature, and steps to reproduce. These should be a benign and non-destructive proof-of-concept and works to ensure the report can be triaged quickly and with accuracy.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">The top 12 password-cracking techniques used by hackers <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/357836/uk-government-unveils-national-cyber-force" data-original-url="/security/cyber-security/357836/uk-government-unveils-national-cyber-force">UK gov finally unveils its new National Cyber Force</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/357724/dwp-data-breach-exposed-6000-ni-numbers" data-original-url="/security/data-breaches/357724/dwp-data-breach-exposed-6000-ni-numbers">DWP exposed 6,000 people’s data online for two years</a></p></div></div><p>“If you believe you have found a vulnerability on any MOD system, you can report using the Hacker One: submit a vulnerability report,” the MoD said. “We recommend reading this disclosure policy fully before you report any vulnerabilities. This helps ensure that you understand the policy, and act in compliance with it.</p><p>“This policy is designed to be compatible with common vulnerability disclosure good practice. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause the MOD or partner organisations to be in breach of any legal obligations.”</p><p>After you submit a report, the MoD will respond within five working days and will aim to triage the report within ten working days. A representative will keep you informed on its progress throughout the process via HackerOne if you’ve registered for an account.</p><p>After the ten-day process has elapsed, the priority for remediation will be assessed based on the impact, severity and exploit complexity. Some flaws may take time to address if they are not deemed a priority, and researchers are welcome to enquire on the status of their reports. However, the MoD stressed they should only check in once every fortnight at a maximum.</p><p>The MoD will then report back when the <a href="https://www.itpro.com/tag/vulnerability" target="_blank" data-original-url="https://www.itpro.com/security/vulnerability/354391/getting-started-with-vulnerability-mitigation">vulnerability is fixed</a>, with researchers invited to confirm the solution fixes the problem adequate. Future public disclosure arrangements will then be subject to co-ordination between researchers and the MoD.</p><p>Researchers seeking to report a vulnerability must abide by a set of strict protocols, however. They must not, for example, break any law, access unnecessary of significant amounts of data, modify data in MoD systems, disrupt any systems, use high-intensity invasive of destructive scanning tool, or attempt any form of <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">denial of service</a>. </p><p>Also out of bounds is <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" target="_blank" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">social engineering</a> or <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> exercises, demanding financial compensation to disclose vulnerabilities, submitting reports detailing non-exploitable flaws, or submitting reports detailing TLS configuration weaknesses. </p><p>The MoD claims its policy is compatible with common industry-wide vulnerability disclosure practices, and that it does not give white hat hackers or security researchers permission to act in any way that’s inconsistent with the law.</p><p>The government department will not, however, seek prosecution of any researcher who reports vulnerabilities on MoD services or systems where they’ve acted in good faith and in accordance with the disclosure policy.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/358083/mod-launches-bug-bounty-programme</link>
                                                                            <description>
                            <![CDATA[ Researchers are encouraged to report any flaws they find on MoD systems, but they must not engage in social engineering or phishing attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gjDn1E3uRZj8PDj9RB5hTg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2QVtGsQqwJmbv96BVLpaAJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Dec 2020 12:40:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2QVtGsQqwJmbv96BVLpaAJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of a cyber criminal using several computers in a dark room ]]></media:description>                                                            <media:text><![CDATA[Image of a cyber criminal using several computers in a dark room ]]></media:text>
                                <media:title type="plain"><![CDATA[Image of a cyber criminal using several computers in a dark room ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2QVtGsQqwJmbv96BVLpaAJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Ministry of Defence (MoD) has introduced its own bug bounty programme through which <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hat hackers</a> can disclose vulnerabilities to the UK government department without fear of prosecution.</p><p>Partnering up with HackerOne, the MoD has published a <a href="https://hackerone.com/ef81a495-9cb5-49bb-88ec-430fc4cffb90/embedded_submissions/new">submission form</a> that security researchers can use to report any bugs or flaws with systems or platforms managed by the UK’s defence authorities. Unlike bug bounty programmes commonly run by private companies, however, there is no monetary reward available for disclosure.</p><p>Researchers who find a <a href="https://www.itpro.com/security/vulnerability/356709/why-vulnerability-management-is-crucial-right-now" target="_blank" data-original-url="https://www.itpro.com/security/vulnerability/356709/why-vulnerability-management-is-crucial-right-now">security vulnerability</a> relating to an MoD system must include details of the website IP or page where the vulnerability can be observed, a brief description of its nature, and steps to reproduce. These should be a benign and non-destructive proof-of-concept and works to ensure the report can be triaged quickly and with accuracy.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">The top 12 password-cracking techniques used by hackers <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/357836/uk-government-unveils-national-cyber-force" data-original-url="/security/cyber-security/357836/uk-government-unveils-national-cyber-force">UK gov finally unveils its new National Cyber Force</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/357724/dwp-data-breach-exposed-6000-ni-numbers" data-original-url="/security/data-breaches/357724/dwp-data-breach-exposed-6000-ni-numbers">DWP exposed 6,000 people’s data online for two years</a></p></div></div><p>“If you believe you have found a vulnerability on any MOD system, you can report using the Hacker One: submit a vulnerability report,” the MoD said. “We recommend reading this disclosure policy fully before you report any vulnerabilities. This helps ensure that you understand the policy, and act in compliance with it.</p><p>“This policy is designed to be compatible with common vulnerability disclosure good practice. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause the MOD or partner organisations to be in breach of any legal obligations.”</p><p>After you submit a report, the MoD will respond within five working days and will aim to triage the report within ten working days. A representative will keep you informed on its progress throughout the process via HackerOne if you’ve registered for an account.</p><p>After the ten-day process has elapsed, the priority for remediation will be assessed based on the impact, severity and exploit complexity. Some flaws may take time to address if they are not deemed a priority, and researchers are welcome to enquire on the status of their reports. However, the MoD stressed they should only check in once every fortnight at a maximum.</p><p>The MoD will then report back when the <a href="https://www.itpro.com/tag/vulnerability" target="_blank" data-original-url="https://www.itpro.com/security/vulnerability/354391/getting-started-with-vulnerability-mitigation">vulnerability is fixed</a>, with researchers invited to confirm the solution fixes the problem adequate. Future public disclosure arrangements will then be subject to co-ordination between researchers and the MoD.</p><p>Researchers seeking to report a vulnerability must abide by a set of strict protocols, however. They must not, for example, break any law, access unnecessary of significant amounts of data, modify data in MoD systems, disrupt any systems, use high-intensity invasive of destructive scanning tool, or attempt any form of <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">denial of service</a>. </p><p>Also out of bounds is <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" target="_blank" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">social engineering</a> or <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> exercises, demanding financial compensation to disclose vulnerabilities, submitting reports detailing non-exploitable flaws, or submitting reports detailing TLS configuration weaknesses. </p><p>The MoD claims its policy is compatible with common industry-wide vulnerability disclosure practices, and that it does not give white hat hackers or security researchers permission to act in any way that’s inconsistent with the law.</p><p>The government department will not, however, seek prosecution of any researcher who reports vulnerabilities on MoD services or systems where they’ve acted in good faith and in accordance with the disclosure policy.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple pays ethical hackers $288k for finding 55 vulnerabilities ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Apple has paid a group of <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hackers</a> $288,500 (£222,813) for finding and disclosing critical vulnerabilities in its network, some of which could have provided access to company infrastructure and iCloud data.</p><p>Since 6 July of this year, Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes have worked together as a part of Apple’s bug bounty programme. The team managed to discover a total of 55 vulnerabilities, 11 of which were of critical severity, 29 of high severity, 13 of medium severity, and two of low severity.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/32717/what-can-an-ethical-hacker-do-for-my-business" data-original-url="/hacking/32717/what-can-an-ethical-hacker-do-for-my-business">What can an ethical hacker do for my business?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year" data-original-url="/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year">Microsoft tripled bug bounty payouts to $13.7m last year</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud-security/34663/cloud-storage-how-secure-are-dropbox-onedrive-google-drive-and-icloud" data-original-url="/cloud-security/34663/cloud-storage-how-secure-are-dropbox-onedrive-google-drive-and-icloud">Cloud storage: How secure are Dropbox, OneDrive, Google Drive, and iCloud?</a></p></div></div><p>The 11 most critical bugs made it possible for the group to access Apple’s <a href="https://www.itpro.com/infrastructure" data-original-url="https://www.itpro.com/infrastructure">infrastructure</a> and use it to potentially steal confidential information such as private emails and <a href="https://www.itpro.com/tag/icloud" data-original-url="https://www.itpro.com/search/icloud">iCloud</a> data.</p><p>Sam Curry said that the team “found a variety of vulnerabilities in core portions of [Apple’s] infrastructure that would've allowed an attacker to fully compromise both customer and employee applications, launch a worm capable of automatically taking over a victim's iCloud account" and "fully compromise an industrial control warehouse <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> used by Apple", as detailed in a blog covering three months of research.</p><p>He added that exploits may have also allowed hackers to "take over the sessions of Apple employees with the capability of accessing management tools and sensitive resources".</p><p>The 11 vulnerabilities found to be critical were as follows:</p><ul><li>Remote Code Execution via Authorization and Authentication Bypass</li><li>Authentication Bypass via Misconfigured Permissions allows Global Administrator Access</li><li>Command Injection via Unsanitized Filename Argument</li><li>Remote Code Execution via Leaked Secret and Exposed Administrator Tool</li><li>Memory Leak leads to Employee and User Account Compromise allowing access to various internal applications</li><li>Vertica SQL Injection via Unsanitized Input Parameter</li><li>Wormable Stored XSS allows Attacker to Fully Compromise Victim iCloud Account</li><li>Wormable Stored XSS allows Attacker to Fully Compromise Victim iCloud Account</li><li>Full Response SSRF allows Attacker to Read Internal Source Code and Access Protected Resources</li><li>Blind XSS allows Attacker to Access Internal Support Portal for Customer and Employee Issue Tracking</li><li>Server-Side PhantomJS Execution allows attacker to Access Internal Resources and Retrieve AWS IAM Keys</li></ul><p>According to Curry, the “vast majority” of the 55 vulnerabilities have already been fixed.</p><p>“They were typically remediated within 1-2 business days (with some being fixed in as little as 4-6 hours),” he added.</p><p>Apple has so far paid the team a total of $288,500 for discovering the vulnerabilities, yet they could be awarded another quarter of a million dollars when the tech giant processes the entirety of their report.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities</link>
                                                                            <description>
                            <![CDATA[ If exploited the bugs would have provided access to Apple's infrastructure and sensitive user data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wncpZeTzjvY2uJG4rm6uEN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gg9aXpt82myN8kj48ADaBV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Oct 2020 10:37:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gg9aXpt82myN8kj48ADaBV-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Apple logo stuck onto a glass building]]></media:description>                                                            <media:text><![CDATA[The Apple logo stuck onto a glass building]]></media:text>
                                <media:title type="plain"><![CDATA[The Apple logo stuck onto a glass building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gg9aXpt82myN8kj48ADaBV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has paid a group of <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hackers</a> $288,500 (£222,813) for finding and disclosing critical vulnerabilities in its network, some of which could have provided access to company infrastructure and iCloud data.</p><p>Since 6 July of this year, Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes have worked together as a part of Apple’s bug bounty programme. The team managed to discover a total of 55 vulnerabilities, 11 of which were of critical severity, 29 of high severity, 13 of medium severity, and two of low severity.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/32717/what-can-an-ethical-hacker-do-for-my-business" data-original-url="/hacking/32717/what-can-an-ethical-hacker-do-for-my-business">What can an ethical hacker do for my business?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year" data-original-url="/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year">Microsoft tripled bug bounty payouts to $13.7m last year</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud-security/34663/cloud-storage-how-secure-are-dropbox-onedrive-google-drive-and-icloud" data-original-url="/cloud-security/34663/cloud-storage-how-secure-are-dropbox-onedrive-google-drive-and-icloud">Cloud storage: How secure are Dropbox, OneDrive, Google Drive, and iCloud?</a></p></div></div><p>The 11 most critical bugs made it possible for the group to access Apple’s <a href="https://www.itpro.com/infrastructure" data-original-url="https://www.itpro.com/infrastructure">infrastructure</a> and use it to potentially steal confidential information such as private emails and <a href="https://www.itpro.com/tag/icloud" data-original-url="https://www.itpro.com/search/icloud">iCloud</a> data.</p><p>Sam Curry said that the team “found a variety of vulnerabilities in core portions of [Apple’s] infrastructure that would've allowed an attacker to fully compromise both customer and employee applications, launch a worm capable of automatically taking over a victim's iCloud account" and "fully compromise an industrial control warehouse <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> used by Apple", as detailed in a blog covering three months of research.</p><p>He added that exploits may have also allowed hackers to "take over the sessions of Apple employees with the capability of accessing management tools and sensitive resources".</p><p>The 11 vulnerabilities found to be critical were as follows:</p><ul><li>Remote Code Execution via Authorization and Authentication Bypass</li><li>Authentication Bypass via Misconfigured Permissions allows Global Administrator Access</li><li>Command Injection via Unsanitized Filename Argument</li><li>Remote Code Execution via Leaked Secret and Exposed Administrator Tool</li><li>Memory Leak leads to Employee and User Account Compromise allowing access to various internal applications</li><li>Vertica SQL Injection via Unsanitized Input Parameter</li><li>Wormable Stored XSS allows Attacker to Fully Compromise Victim iCloud Account</li><li>Wormable Stored XSS allows Attacker to Fully Compromise Victim iCloud Account</li><li>Full Response SSRF allows Attacker to Read Internal Source Code and Access Protected Resources</li><li>Blind XSS allows Attacker to Access Internal Support Portal for Customer and Employee Issue Tracking</li><li>Server-Side PhantomJS Execution allows attacker to Access Internal Resources and Retrieve AWS IAM Keys</li></ul><p>According to Curry, the “vast majority” of the 55 vulnerabilities have already been fixed.</p><p>“They were typically remediated within 1-2 business days (with some being fixed in as little as 4-6 hours),” he added.</p><p>Apple has so far paid the team a total of $288,500 for discovering the vulnerabilities, yet they could be awarded another quarter of a million dollars when the tech giant processes the entirety of their report.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GitLab patches API flaw that exposed private group data ]]></title>
                                                                                                <dc:content><![CDATA[ <p>An <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hacker</a> has been awarded $3,000 (£2,300) for disclosing a security vulnerability that could have lead to the exposure of private GitLab groups.</p><p>Solutions architect Riccardo Padovani first encountered the vulnerability in November 2019. He promptly informed GitLab to the fact that private projects which were formerly public could have been accessed by other parties through vulnerable search APIs.</p><p>Although the issue was disclosed almost a year ago, the report was only <a href="https://hackerone.com/reports/748375">made public</a> on 6 October.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/355793/gitlab-phishes-its-remote-employees-and-1-in-5-fell-for-it" data-original-url="/security/phishing/355793/gitlab-phishes-its-remote-employees-and-1-in-5-fell-for-it">GitLab phished its employees and 20% handed over credentials</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/development/32887/what-is-continuous-integration" data-original-url="/development/32887/what-is-continuous-integration">What is continuous integration?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/32717/what-can-an-ethical-hacker-do-for-my-business" data-original-url="/hacking/32717/what-can-an-ethical-hacker-do-for-my-business">What can an ethical hacker do for my business?</a></p></div></div><p>As explained by Padavani on the bug bounty platform HackerOne: "Alice creates the public group 'Example', and a public project named 'Example-project' inside the group. In the readme of the project, Alice writes 'Example'. Now, Alice creates a private group called 'private', and transfers all the 'Example' group to the 'private' group.</p><p>'If Bob (totally unrelated to Alice) searches for 'Example' instance-wide, he will not find anything [... but if he] uses APIs, he will receive the results back with the information that should be private,” he wrote, adding that the issue only arises when entire groups are transferred, as opposed to single projects.</p><p>GitLab <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> security expert Jeremy Matos verified this finding and escalated the issue to GitLab’s engineering team. The <a href="https://www.itpro.com/devops/28097/what-is-devops" target="_blank" data-original-url="https://www.itpro.com/devops/28097/what-is-devops">DevOps</a> tool patched the vulnerability in GitLab version 12.5.4 and awarded Padavani with $3,000 for disclosing it.</p><p>Bug bounty hunting, which is a form of ethical hacking that focuses on finding and disclosing <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> issues, is becoming an increasingly popular source of income for security experts.</p><p>In August, it was reported that <a href="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year" data-original-url="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year">Microsoft paid out $13.7 million</a> (roughly £10.5 million) across 15 bounty programmes during the previous 12 months, more than three times the amount paid out to researchers in the same period during 2018/19. The company rewarded 327 researchers for identifying bugs and flaws in Microsoft software, with 1,226 eligible vulnerability reports being filed during the period. The biggest single reward was $200,000.</p><p>CREST chairman Ian Glover <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">previously told <em>IT Pro</em></a><em> </em>that "the demand for high-quality individuals working for professional companies far outstrips supply."</p><p>"The UK is seen as one of the leaders in this area and the opportunity to work on international projects is increasing every day,” he said, adding that a registered level professional would expect to earn in the region of £55,000 and a team leader could be looking at more than £90,000.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/357348/gitlab-search-api-flaw-exposed</link>
                                                                            <description>
                            <![CDATA[ GitLab private projects that were formerly public could have been accessed through search APIs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jB4UppQkyeCjbckN8mCB53</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vYQidYuUdSSKxGSthkR8Lj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 Oct 2020 09:43:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vYQidYuUdSSKxGSthkR8Lj-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Gitlab logo visible on display screen]]></media:description>                                                            <media:text><![CDATA[Gitlab logo visible on display screen]]></media:text>
                                <media:title type="plain"><![CDATA[Gitlab logo visible on display screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vYQidYuUdSSKxGSthkR8Lj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hacker</a> has been awarded $3,000 (£2,300) for disclosing a security vulnerability that could have lead to the exposure of private GitLab groups.</p><p>Solutions architect Riccardo Padovani first encountered the vulnerability in November 2019. He promptly informed GitLab to the fact that private projects which were formerly public could have been accessed by other parties through vulnerable search APIs.</p><p>Although the issue was disclosed almost a year ago, the report was only <a href="https://hackerone.com/reports/748375">made public</a> on 6 October.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/355793/gitlab-phishes-its-remote-employees-and-1-in-5-fell-for-it" data-original-url="/security/phishing/355793/gitlab-phishes-its-remote-employees-and-1-in-5-fell-for-it">GitLab phished its employees and 20% handed over credentials</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/development/32887/what-is-continuous-integration" data-original-url="/development/32887/what-is-continuous-integration">What is continuous integration?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/32717/what-can-an-ethical-hacker-do-for-my-business" data-original-url="/hacking/32717/what-can-an-ethical-hacker-do-for-my-business">What can an ethical hacker do for my business?</a></p></div></div><p>As explained by Padavani on the bug bounty platform HackerOne: "Alice creates the public group 'Example', and a public project named 'Example-project' inside the group. In the readme of the project, Alice writes 'Example'. Now, Alice creates a private group called 'private', and transfers all the 'Example' group to the 'private' group.</p><p>'If Bob (totally unrelated to Alice) searches for 'Example' instance-wide, he will not find anything [... but if he] uses APIs, he will receive the results back with the information that should be private,” he wrote, adding that the issue only arises when entire groups are transferred, as opposed to single projects.</p><p>GitLab <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> security expert Jeremy Matos verified this finding and escalated the issue to GitLab’s engineering team. The <a href="https://www.itpro.com/devops/28097/what-is-devops" target="_blank" data-original-url="https://www.itpro.com/devops/28097/what-is-devops">DevOps</a> tool patched the vulnerability in GitLab version 12.5.4 and awarded Padavani with $3,000 for disclosing it.</p><p>Bug bounty hunting, which is a form of ethical hacking that focuses on finding and disclosing <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> issues, is becoming an increasingly popular source of income for security experts.</p><p>In August, it was reported that <a href="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year" data-original-url="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year">Microsoft paid out $13.7 million</a> (roughly £10.5 million) across 15 bounty programmes during the previous 12 months, more than three times the amount paid out to researchers in the same period during 2018/19. The company rewarded 327 researchers for identifying bugs and flaws in Microsoft software, with 1,226 eligible vulnerability reports being filed during the period. The biggest single reward was $200,000.</p><p>CREST chairman Ian Glover <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">previously told <em>IT Pro</em></a><em> </em>that "the demand for high-quality individuals working for professional companies far outstrips supply."</p><p>"The UK is seen as one of the leaders in this area and the opportunity to work on international projects is increasing every day,” he said, adding that a registered level professional would expect to earn in the region of £55,000 and a team leader could be looking at more than £90,000.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: The secret life of hackers ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Hacking is one of the glitzier parts of IT, and Hollywood frequently bombards us with images of black-clad hackers hunched malevolently over glowing screens. Sadly, real-world hacking isn’t quite as glamorous as it’s often made out to be - but that doesn’t mean it’s not a fascinating and lively career.</p><p>In this week’s episode, we sit down with professional pen-tester and Cyberis director Gemma Moore to find out what the life of a hacker for hire is really like, the common security holes that intruders exploit, and why laziness is a hacker’s greatest weapon.</p><p>Elsewhere, we discuss the Twitterpocalypse which saw verified users barred from tweeting, and the landmark decision by the government to remove Huawei from the UK’s 5G networks, as well as what it could mean for UK businesses.</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/1ojGcpJHLKOEausXT9cuVa"></iframe><h2 id="footnotes-3">Footnotes</h2><h3 class="article-body__section" id="section-news"><span>News</span></h3><p><strong>Twitter</strong></p><ul><li><a href="https://www.itpro.com/security/data-breaches/356472/twitter-targeted-by-social-engineering-attack-as-hackers-launch" data-original-url="https://www.itpro.com/security/data-breaches/356472/twitter-targeted-by-social-engineering-attack-as-hackers-launch">Obama, Biden and Musk Twitter accounts hacked in Bitcoin scam</a></li><li><a href="https://www.itpro.com/645481/twitter-hack-exposes-250000-user-details" data-original-url="https://www.itpro.com/645481/twitter-hack-exposes-250000-user-details">Twitter hack exposes 250,000 user details (2013)</a></li></ul><p><strong>Huawei</strong></p><ul><li><a href="https://www.itpro.com/mobile/5g/356451/what-does-the-huawei-ban-mean-for-uk-businesses" data-original-url="https://www.itpro.com/mobile/5g/356451/what-does-the-huawei-ban-mean-for-uk-businesses">Why the Huawei ban could be disastrous for UK businesses</a></li><li><a href="https://www.itpro.com/mobile/mobile-phones/356335/the-man-has-ruined-my-huawei-p40" data-original-url="https://www.itpro.com/mobile/mobile-phones/356335/the-man-has-ruined-my-huawei-p40">The Man has ruined my Huawei P40</a></li><li><a href="https://www.itpro.com/infrastructure/network-internet/356299/us-officially-designates-huawei-and-zte-as-national-security" data-original-url="https://www.itpro.com/infrastructure/network-internet/356299/us-officially-designates-huawei-and-zte-as-national-security">US officially designates Huawei and ZTE as national security threats</a></li><li><a href="https://www.itpro.com/business-operations/supply-chain-management-scm/355646/can-tech-survive-without-china" data-original-url="https://www.itpro.com/business-operations/supply-chain-management-scm/355646/can-tech-survive-without-china">Can tech survive without China?</a></li><li><a href="https://www.itpro.com/mobile/5g/354727/deutsche-telekom-tells-nokia-to-shape-up-with-huawei-ban-looming" data-original-url="https://www.itpro.com/mobile/5g/354727/deutsche-telekom-tells-nokia-to-shape-up-with-huawei-ban-looming">Deutsche Telekom tells Nokia to shape up with Huawei ban looming</a></li><li><a href="https://www.itpro.com/mobile/5g/355594/ericsson-to-raise-its-global-5g-subscriptions-forecast-due-to-coronavirus-outbreak" data-original-url="https://www.itpro.com/mobile/5g/355594/ericsson-to-raise-its-global-5g-subscriptions-forecast-due-to-coronavirus-outbreak">Ericsson increases 5G forecast as data demand surges</a></li><li><a href="https://www.itpro.com/mobile/5g/355458/gigabit-5g-jumpstart-uk-economy" data-original-url="https://www.itpro.com/mobile/5g/355458/gigabit-5g-jumpstart-uk-economy">Gigabit broadband and 5G could jumpstart the UK economy, report claims</a></li><li><a href="https://www.itpro.com/mobile/5g/356479/can-the-uk-develop-a-5g-giant-to-take-on-huawei" data-original-url="https://www.itpro.com/mobile/5g/356479/can-the-uk-develop-a-5g-giant-to-take-on-huawei">Can the UK develop a 5G giant to take on Huawei?</a></li></ul><h3 class="article-body__section" id="section-in-depth"><span>In-depth</span></h3><ul><li><a href="https://www.itpro.com/security/penetration-testing/354693/ethics-of-red-team-security-testing-questioned-in-new-report" data-original-url="https://www.itpro.com/security/penetration-testing/354693/ethics-of-red-team-security-testing-questioned-in-new-report">Ethics of red team security testing questioned in new report</a></li><li><a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">Stories from the front line: The secrets of the Red Team revealed</a></li><li><a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">What is phishing?</a></li><li><a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">10 quick tips to identifying phishing emails</a></li><li><a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">IT pros air their opinions on phishing employees</a></li><li><a href="https://www.itpro.com/business-strategy/34735/the-it-pro-podcast-how-do-we-fix-security" data-original-url="https://www.itpro.com/business-strategy/34735/the-it-pro-podcast-how-do-we-fix-security">The IT Pro Podcast: How do we fix security?</a></li><li><a href="https://www.itpro.com/software/355126/hp-announces-new-security-solutions" data-original-url="https://www.itpro.com/software/355126/hp-announces-new-security-solutions">HP announces lockdown-friendly security products</a></li><li><a href="https://www.itpro.com/business-strategy/flexible-working/355696/most-uk-workers-dont-want-to-return-to-the-office" data-original-url="https://www.itpro.com/business-strategy/flexible-working/355696/most-uk-workers-dont-want-to-return-to-the-office">Most UK workers don't want to return to the office</a></li><li><a href="https://dennis-publishing-hvmg.brand.live/c/What-hackers-don-t-want-you-to-know">What hackers don’t want you to know</a></li><li><a href="https://www.itpro.com/business-strategy/business-continuity/356221/why-business-resilience-matters-in-times-of-crisis-and" data-original-url="https://www.itpro.com/business-strategy/business-continuity/356221/why-business-resilience-matters-in-times-of-crisis-and">Why business resilience matters in times of crisis (and beyond)</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/356480/the-it-pro-podcast-the-secret-life-of-hackers</link>
                                                                            <description>
                            <![CDATA[ What it’s really like to be a professional penetration tester ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uRoAtgR6n8ctWXgTgnkPBY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gM9p5jwgA7zxw4LQMUgCy3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2020 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gM9p5jwgA7zxw4LQMUgCy3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast: The secret life of hackers]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast: The secret life of hackers]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast: The secret life of hackers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gM9p5jwgA7zxw4LQMUgCy3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hacking is one of the glitzier parts of IT, and Hollywood frequently bombards us with images of black-clad hackers hunched malevolently over glowing screens. Sadly, real-world hacking isn’t quite as glamorous as it’s often made out to be - but that doesn’t mean it’s not a fascinating and lively career.</p><p>In this week’s episode, we sit down with professional pen-tester and Cyberis director Gemma Moore to find out what the life of a hacker for hire is really like, the common security holes that intruders exploit, and why laziness is a hacker’s greatest weapon.</p><p>Elsewhere, we discuss the Twitterpocalypse which saw verified users barred from tweeting, and the landmark decision by the government to remove Huawei from the UK’s 5G networks, as well as what it could mean for UK businesses.</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/1ojGcpJHLKOEausXT9cuVa"></iframe><h2 id="footnotes-3">Footnotes</h2><h3 class="article-body__section" id="section-news"><span>News</span></h3><p><strong>Twitter</strong></p><ul><li><a href="https://www.itpro.com/security/data-breaches/356472/twitter-targeted-by-social-engineering-attack-as-hackers-launch" data-original-url="https://www.itpro.com/security/data-breaches/356472/twitter-targeted-by-social-engineering-attack-as-hackers-launch">Obama, Biden and Musk Twitter accounts hacked in Bitcoin scam</a></li><li><a href="https://www.itpro.com/645481/twitter-hack-exposes-250000-user-details" data-original-url="https://www.itpro.com/645481/twitter-hack-exposes-250000-user-details">Twitter hack exposes 250,000 user details (2013)</a></li></ul><p><strong>Huawei</strong></p><ul><li><a href="https://www.itpro.com/mobile/5g/356451/what-does-the-huawei-ban-mean-for-uk-businesses" data-original-url="https://www.itpro.com/mobile/5g/356451/what-does-the-huawei-ban-mean-for-uk-businesses">Why the Huawei ban could be disastrous for UK businesses</a></li><li><a href="https://www.itpro.com/mobile/mobile-phones/356335/the-man-has-ruined-my-huawei-p40" data-original-url="https://www.itpro.com/mobile/mobile-phones/356335/the-man-has-ruined-my-huawei-p40">The Man has ruined my Huawei P40</a></li><li><a href="https://www.itpro.com/infrastructure/network-internet/356299/us-officially-designates-huawei-and-zte-as-national-security" data-original-url="https://www.itpro.com/infrastructure/network-internet/356299/us-officially-designates-huawei-and-zte-as-national-security">US officially designates Huawei and ZTE as national security threats</a></li><li><a href="https://www.itpro.com/business-operations/supply-chain-management-scm/355646/can-tech-survive-without-china" data-original-url="https://www.itpro.com/business-operations/supply-chain-management-scm/355646/can-tech-survive-without-china">Can tech survive without China?</a></li><li><a href="https://www.itpro.com/mobile/5g/354727/deutsche-telekom-tells-nokia-to-shape-up-with-huawei-ban-looming" data-original-url="https://www.itpro.com/mobile/5g/354727/deutsche-telekom-tells-nokia-to-shape-up-with-huawei-ban-looming">Deutsche Telekom tells Nokia to shape up with Huawei ban looming</a></li><li><a href="https://www.itpro.com/mobile/5g/355594/ericsson-to-raise-its-global-5g-subscriptions-forecast-due-to-coronavirus-outbreak" data-original-url="https://www.itpro.com/mobile/5g/355594/ericsson-to-raise-its-global-5g-subscriptions-forecast-due-to-coronavirus-outbreak">Ericsson increases 5G forecast as data demand surges</a></li><li><a href="https://www.itpro.com/mobile/5g/355458/gigabit-5g-jumpstart-uk-economy" data-original-url="https://www.itpro.com/mobile/5g/355458/gigabit-5g-jumpstart-uk-economy">Gigabit broadband and 5G could jumpstart the UK economy, report claims</a></li><li><a href="https://www.itpro.com/mobile/5g/356479/can-the-uk-develop-a-5g-giant-to-take-on-huawei" data-original-url="https://www.itpro.com/mobile/5g/356479/can-the-uk-develop-a-5g-giant-to-take-on-huawei">Can the UK develop a 5G giant to take on Huawei?</a></li></ul><h3 class="article-body__section" id="section-in-depth"><span>In-depth</span></h3><ul><li><a href="https://www.itpro.com/security/penetration-testing/354693/ethics-of-red-team-security-testing-questioned-in-new-report" data-original-url="https://www.itpro.com/security/penetration-testing/354693/ethics-of-red-team-security-testing-questioned-in-new-report">Ethics of red team security testing questioned in new report</a></li><li><a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">Stories from the front line: The secrets of the Red Team revealed</a></li><li><a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">What is phishing?</a></li><li><a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">10 quick tips to identifying phishing emails</a></li><li><a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">IT pros air their opinions on phishing employees</a></li><li><a href="https://www.itpro.com/business-strategy/34735/the-it-pro-podcast-how-do-we-fix-security" data-original-url="https://www.itpro.com/business-strategy/34735/the-it-pro-podcast-how-do-we-fix-security">The IT Pro Podcast: How do we fix security?</a></li><li><a href="https://www.itpro.com/software/355126/hp-announces-new-security-solutions" data-original-url="https://www.itpro.com/software/355126/hp-announces-new-security-solutions">HP announces lockdown-friendly security products</a></li><li><a href="https://www.itpro.com/business-strategy/flexible-working/355696/most-uk-workers-dont-want-to-return-to-the-office" data-original-url="https://www.itpro.com/business-strategy/flexible-working/355696/most-uk-workers-dont-want-to-return-to-the-office">Most UK workers don't want to return to the office</a></li><li><a href="https://dennis-publishing-hvmg.brand.live/c/What-hackers-don-t-want-you-to-know">What hackers don’t want you to know</a></li><li><a href="https://www.itpro.com/business-strategy/business-continuity/356221/why-business-resilience-matters-in-times-of-crisis-and" data-original-url="https://www.itpro.com/business-strategy/business-continuity/356221/why-business-resilience-matters-in-times-of-crisis-and">Why business resilience matters in times of crisis (and beyond)</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Mobile banking apps are exposing user data to attackers ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Positive Technologies has found that 14 banking apps available on iOS and Android were affected by vulnerabilities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/102800/criminals-aim-at-mobile-phone-banking" data-original-url="/102800/criminals-aim-at-mobile-phone-banking">Criminals aim at mobile phone banking</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/102596/russian-gang-defrauds-bank-customers-with-trojan" data-original-url="/102596/russian-gang-defrauds-bank-customers-with-trojan">Russian gang defrauds bank customers with trojan</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/95278/hsbc-banks-on-success-of-new-mobile-offering" data-original-url="/95278/hsbc-banks-on-success-of-new-mobile-offering">HSBC banks on success of new mobile offering</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/620950/so-youve-been-hacked-now-what" data-original-url="/620950/so-youve-been-hacked-now-what">So you've been hacked, now what?</a></p></div></div><p>In 2019, Positive Technologies assessed the security level of a number of banking apps and found vulnerabilities in each one. Per the report, each vulnerability could be traced to faults in the application code, client-server interaction and the implementation of security mechanisms.</p><p>On the user-side, Positive Technologies found 13 out of 14 applications unwittingly gave attackers access to user data. For more than a third of the banking apps tests, vulnerabilities could be exploited without administrator rights. Further, 76% of these vulnerabilities could be exploited without the attacker having physical access to the account holder’s device.</p><p>On the server-side, researchers found servers contained 54% of all vulnerabilities identified in the study. According to Positive Technologies, each mobile bank had an average of 23 server-side vulnerabilities. Plus, at five out of seven banks, hackers were able to steal user credentials and at one-third of banks, users’ card information is at risk of being stolen.</p><p>Though these statistics are staggering enough, the FBI <a href="https://www.ic3.gov/media/2020/200610.aspx">recently revealed</a> a 50% increase in attacks against mobile banking apps since the beginning of 2020. In its announcement, the FBI said it expects threat actors to attempt to exploit mobile banking customers by using a variety of techniques, such as app-based banking Trojans and even fake banking apps. </p><p>To protect themselves, users should use <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication</a> along with a strong password.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ethical-hacking/356252/poorly-secured-banking-apps-lead-to-cyber-threats</link>
                                                                            <description>
                            <![CDATA[ Positive Technologies’ study finds 13 out of 14 banking apps gave attackers access to user data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kH9jok7VvU47LBLRfTn8wA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wtBXVyUScqZXJ7JKHTm3GS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2020 19:14:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sarah Brennan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wtBXVyUScqZXJ7JKHTm3GS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Banking written in red surrounded by coding]]></media:description>                                                            <media:text><![CDATA[Banking written in red surrounded by coding]]></media:text>
                                <media:title type="plain"><![CDATA[Banking written in red surrounded by coding]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wtBXVyUScqZXJ7JKHTm3GS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Positive Technologies has found that 14 banking apps available on iOS and Android were affected by vulnerabilities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/102800/criminals-aim-at-mobile-phone-banking" data-original-url="/102800/criminals-aim-at-mobile-phone-banking">Criminals aim at mobile phone banking</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/102596/russian-gang-defrauds-bank-customers-with-trojan" data-original-url="/102596/russian-gang-defrauds-bank-customers-with-trojan">Russian gang defrauds bank customers with trojan</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/95278/hsbc-banks-on-success-of-new-mobile-offering" data-original-url="/95278/hsbc-banks-on-success-of-new-mobile-offering">HSBC banks on success of new mobile offering</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/620950/so-youve-been-hacked-now-what" data-original-url="/620950/so-youve-been-hacked-now-what">So you've been hacked, now what?</a></p></div></div><p>In 2019, Positive Technologies assessed the security level of a number of banking apps and found vulnerabilities in each one. Per the report, each vulnerability could be traced to faults in the application code, client-server interaction and the implementation of security mechanisms.</p><p>On the user-side, Positive Technologies found 13 out of 14 applications unwittingly gave attackers access to user data. For more than a third of the banking apps tests, vulnerabilities could be exploited without administrator rights. Further, 76% of these vulnerabilities could be exploited without the attacker having physical access to the account holder’s device.</p><p>On the server-side, researchers found servers contained 54% of all vulnerabilities identified in the study. According to Positive Technologies, each mobile bank had an average of 23 server-side vulnerabilities. Plus, at five out of seven banks, hackers were able to steal user credentials and at one-third of banks, users’ card information is at risk of being stolen.</p><p>Though these statistics are staggering enough, the FBI <a href="https://www.ic3.gov/media/2020/200610.aspx">recently revealed</a> a 50% increase in attacks against mobile banking apps since the beginning of 2020. In its announcement, the FBI said it expects threat actors to attempt to exploit mobile banking customers by using a variety of techniques, such as app-based banking Trojans and even fake banking apps. </p><p>To protect themselves, users should use <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication</a> along with a strong password.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Developer scores $100,000 bounty from Apple for exposing a critical vulnerability ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Apple <a href="https://www.notebookcheck.net/Apple-pays-US-100-000-bounty-to-developer-for-finding-critical-login-vulnerability.467528.0.html">awarded $100,000</a> to Bhavuk Jain for identifying a security vulnerability in the <a href="https://www.itpro.com/mobile/33765/sign-in-with-apple-launched-at-wwdc-2019" data-original-url="https://www.itpro.com/mobile/33765/sign-in-with-apple-launched-at-wwdc-2019">"Sign in with Apple"</a> feature found on some websites and third-party applications. Hackers could use the bug to take control of a user's account.</p><p>Apple's servers use a JSON Web Token, which can contain the user’s Apple ID email address, to verify a user account during the “Sign in with Apple” process.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/26532/white-hat-hackers-access-full-database-of-pornhub-members" data-original-url="/security/26532/white-hat-hackers-access-full-database-of-pornhub-members">White hat hackers access full database of Pornhub members</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/29793/the-white-hat-brigade" data-original-url="/security/innovation-at-work/29793/the-white-hat-brigade">The white hat brigade</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/33955/white-hat-gets-firework-hack-restored-on-youtube" data-original-url="/hacking/33955/white-hat-gets-firework-hack-restored-on-youtube">White hat gets firework hack restored on YouTube</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a></p></div></div><p>Jain discovered he could request a JSON Web Token for a real Apple account, and the signature would be verified each time. With an email address connected to an Apple ID, a hacker could to get a validated token and access the account. </p><p>Apple reviewed server logs during the patching process and determined the flaw had not been exploited. Accounts using <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication</a> are less likely to be vulnerable to this bug.</p><p>This type of hacking-for-pay is relatively common today. Apple and other tech companies use <a href="https://www.itpro.com/security/27056/apple-finally-introduces-bug-bounty-programme" data-original-url="https://www.itpro.com/security/27056/apple-finally-introduces-bug-bounty-programme">bounty programs</a> to encourage <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white-hat</a> hackers to uncover vulnerabilities in their software.</p><p>This allows companies to patch flaws before they are made public for a fraction of the cost of fixing hacks post-mortem. Companies pay the most substantial bounties for exposing serious vulnerabilities.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ethical-hacking/355860/developer-scores-100000-bounty-from-apple-for-exposing-a-critical</link>
                                                                            <description>
                            <![CDATA[ Apple ID bug would allow hackers to take control of a user’s account ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">juosdn4SgArnF7TDM26U6H</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/v4j367nsp96PK3hjm8MxGk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Jun 2020 18:07:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Gargaro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/v4j367nsp96PK3hjm8MxGk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Fake ladybug on a circuit board]]></media:description>                                                            <media:text><![CDATA[Fake ladybug on a circuit board]]></media:text>
                                <media:title type="plain"><![CDATA[Fake ladybug on a circuit board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/v4j367nsp96PK3hjm8MxGk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple <a href="https://www.notebookcheck.net/Apple-pays-US-100-000-bounty-to-developer-for-finding-critical-login-vulnerability.467528.0.html">awarded $100,000</a> to Bhavuk Jain for identifying a security vulnerability in the <a href="https://www.itpro.com/mobile/33765/sign-in-with-apple-launched-at-wwdc-2019" data-original-url="https://www.itpro.com/mobile/33765/sign-in-with-apple-launched-at-wwdc-2019">"Sign in with Apple"</a> feature found on some websites and third-party applications. Hackers could use the bug to take control of a user's account.</p><p>Apple's servers use a JSON Web Token, which can contain the user’s Apple ID email address, to verify a user account during the “Sign in with Apple” process.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/26532/white-hat-hackers-access-full-database-of-pornhub-members" data-original-url="/security/26532/white-hat-hackers-access-full-database-of-pornhub-members">White hat hackers access full database of Pornhub members</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/29793/the-white-hat-brigade" data-original-url="/security/innovation-at-work/29793/the-white-hat-brigade">The white hat brigade</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/33955/white-hat-gets-firework-hack-restored-on-youtube" data-original-url="/hacking/33955/white-hat-gets-firework-hack-restored-on-youtube">White hat gets firework hack restored on YouTube</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a></p></div></div><p>Jain discovered he could request a JSON Web Token for a real Apple account, and the signature would be verified each time. With an email address connected to an Apple ID, a hacker could to get a validated token and access the account. </p><p>Apple reviewed server logs during the patching process and determined the flaw had not been exploited. Accounts using <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication</a> are less likely to be vulnerable to this bug.</p><p>This type of hacking-for-pay is relatively common today. Apple and other tech companies use <a href="https://www.itpro.com/security/27056/apple-finally-introduces-bug-bounty-programme" data-original-url="https://www.itpro.com/security/27056/apple-finally-introduces-bug-bounty-programme">bounty programs</a> to encourage <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white-hat</a> hackers to uncover vulnerabilities in their software.</p><p>This allows companies to patch flaws before they are made public for a fraction of the cost of fixing hacks post-mortem. Companies pay the most substantial bounties for exposing serious vulnerabilities.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US Air Force launches $50,000 satellite hacking challenge ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The US Air Force is offering $50,000 to help shore up its satellite cyber security as part of an online challenge called <a href="https://www.hackasat.com" target="_blank">Hack-A-Sat</a>.</p><p>The event, which kicks off on 22 May with a final round set for August, has been developed in partnership with the US Defense Digital Service, the digital arm of the Department of Defense.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/355109/who-partners-with-big-tech-for-mega-covid-19-hackathon" data-original-url="/software/development/355109/who-partners-with-big-tech-for-mega-covid-19-hackathon">WHO collaborates with Big Tech for mega COVID-19 hackathon</a></p></div></div><p>Due to the outbreak of COVID-19, the <a href="https://www.itpro.com/software/development/355109/who-partners-with-big-tech-for-mega-covid-19-hackathon" target="_blank" data-original-url="https://www.itpro.com/software/development/355109/who-partners-with-big-tech-for-mega-covid-19-hackathon">hackathon</a> has been moved entirely online and aims to help improve <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> safeguards ahead of the Pentagon's rollout of a satellite constellation network later this year.</p><p>The Hack-A-Sat challenge is open to hackers around the world and will begin with a 48-hour 'Capture the Flag' first-round. Participants will be given a set of challenges in one of several categories on a Jeopardy-style board. The first team to solve a challenge has the ability to unlock the next challenge in any given category, with each solved challenge resulting in the competitor retrieving a 'flag'. 'Redemption' of this flag by another team results in points being awarded to the challenger. </p><p>The final will be contested from 7 to 9 August where the top three constants will have the chance to attempt to hack a virtualized satellite and win $50,000, with $30,000 awarded to second and $20,000 for third.</p><p>"The democratization of space has opened up a new frontier for exploration and innovation," the Hack-A-Sat website reads. "But with this opportunity, new cyber security vulnerabilities are also being created. One human can design, build and launch a satellite, adhering to very few standards and security protocols. So how can we achieve safe, reliable and trustworthy operations to truly realize the promise of space? ...by hacking a satellite."</p><p>The event takes place at the virtual Aerospace Village at DEFCON, which will also host workshops for satellite hacking and avionics.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ethical-hacking/355663/us-air-force-launches-online-satellite-hacking-comp</link>
                                                                            <description>
                            <![CDATA[ Hack-a-Sat challenge will kick off on 22 May and is open to ethical hackers worldwide ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c5HXL4viAbkc1pjXVn6FHR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6VmBsDoDVnfVTCHmTtvzwn-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 May 2020 11:18:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ethical Hacking]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/6VmBsDoDVnfVTCHmTtvzwn-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Hack-A-Sat logo]]></media:description>                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6VmBsDoDVnfVTCHmTtvzwn-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Air Force is offering $50,000 to help shore up its satellite cyber security as part of an online challenge called <a href="https://www.hackasat.com" target="_blank">Hack-A-Sat</a>.</p><p>The event, which kicks off on 22 May with a final round set for August, has been developed in partnership with the US Defense Digital Service, the digital arm of the Department of Defense.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/355109/who-partners-with-big-tech-for-mega-covid-19-hackathon" data-original-url="/software/development/355109/who-partners-with-big-tech-for-mega-covid-19-hackathon">WHO collaborates with Big Tech for mega COVID-19 hackathon</a></p></div></div><p>Due to the outbreak of COVID-19, the <a href="https://www.itpro.com/software/development/355109/who-partners-with-big-tech-for-mega-covid-19-hackathon" target="_blank" data-original-url="https://www.itpro.com/software/development/355109/who-partners-with-big-tech-for-mega-covid-19-hackathon">hackathon</a> has been moved entirely online and aims to help improve <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> safeguards ahead of the Pentagon's rollout of a satellite constellation network later this year.</p><p>The Hack-A-Sat challenge is open to hackers around the world and will begin with a 48-hour 'Capture the Flag' first-round. Participants will be given a set of challenges in one of several categories on a Jeopardy-style board. The first team to solve a challenge has the ability to unlock the next challenge in any given category, with each solved challenge resulting in the competitor retrieving a 'flag'. 'Redemption' of this flag by another team results in points being awarded to the challenger. </p><p>The final will be contested from 7 to 9 August where the top three constants will have the chance to attempt to hack a virtualized satellite and win $50,000, with $30,000 awarded to second and $20,000 for third.</p><p>"The democratization of space has opened up a new frontier for exploration and innovation," the Hack-A-Sat website reads. "But with this opportunity, new cyber security vulnerabilities are also being created. One human can design, build and launch a satellite, adhering to very few standards and security protocols. So how can we achieve safe, reliable and trustworthy operations to truly realize the promise of space? ...by hacking a satellite."</p><p>The event takes place at the virtual Aerospace Village at DEFCON, which will also host workshops for satellite hacking and avionics.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Journalist Glenn Greenwald charged with cyber crimes in Brazil ]]></title>
                                                                                                <dc:content><![CDATA[ <p>American journalist Glenn Greenwald has been arrested in Brazil and accused of <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">hacking</a> into the mobile phones of public officials following an investigation.</p><p>The reporter gained notoriety for his prominent role in publishing classified material that former <a href="https://www.itpro.com/security/34436/us-sues-edward-snowden-over-his-memoir" data-original-url="https://www.itpro.com/security/34436/us-sues-edward-snowden-over-his-memoir">National Security Agency (NSA) analyst Edward Snowden</a> obtained from the US government agency in 2013.</p><p>Through his publication, <em>the Intercept Brasil</em>, Greenwald published articles based on information obtained from the leaked messages of public officials within the right-wing Brazilian government. </p><p>The articles accused key members of Brazil’s justice system, and the Jair Bolsonaro-led government, of engaging in corruption.</p><p>Brazil’s public prosecutors have responded in kind by charging Greenwald with cyber crimes and for being part of a criminal organisation that allegedly hacked into these individuals’ devices, according to <em>the</em> <a href="https://www.nytimes.com/2020/01/21/world/americas/glenn-greenwald-brazil-cybercrimes.html"><em>New York Times</em></a>.</p><p>The 95-page criminal complaint alleges that the reporter had gone beyond simply publishing information that was passed to him, but played a “clear role in facilitating the commission of a crime”. Greenwald is said to have encouraged the hackers to delete archives that have already been shared in order to cover their tracks, authorities claim.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/public-sector/20109/prism-nsa-allegedly-spying-eu-politicians" data-original-url="/public-sector/20109/prism-nsa-allegedly-spying-eu-politicians">PRISM: NSA allegedly spying on EU politicians</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/23900/edward-snowden-claims-iphones-have-built-in-spyware" data-original-url="/mobile/23900/edward-snowden-claims-iphones-have-built-in-spyware">Edward Snowden claims iPhones have built-in spyware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow" data-original-url="/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow">Chinese hackers used 'stolen' NSA tools a year before they were leaked by the Shadow Brokers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/microsoft-windows/33142/privacy-watchdog-calls-for-windows-10-to-stop-uploading-encryption-keys-to" data-original-url="/microsoft-windows/33142/privacy-watchdog-calls-for-windows-10-to-stop-uploading-encryption-keys-to">Privacy watchdog calls for Windows 10 to stop uploading encryption keys to Microsoft</a></p></div></div><p>The Electronic Frontier Foundation, an organisation committed to <a href="https://www.itpro.com/security/20566/electronic-frontier-foundation-forces-nsa-reveal-surveillance-documents" data-original-url="https://www.itpro.com/security/20566/electronic-frontier-foundation-forces-nsa-reveal-surveillance-documents">campaigning for digital rights</a>, has blasted the Brazilian government for charging the reporter under its computer crime laws.</p><p>“EFF has long warned that cybersecurity laws in the Americas have been written and interpreted so broadly as to invite misuse,” <a href="https://www.eff.org/deeplinks/2020/01/brazils-attempt-prosecute-glenn-greenwald-computer-crimes-threatens-democracy">the organisation said in a statement</a>. “Computer crime laws should never be used to criminalize legitimate journalistic practice. Prosecutors must not apply them without considering the chilling effects on the free press, and the risk of politicized prosecutions.</p><p>“It is a threat to democracy when authorities use cybercrime laws to punish their critics, as the Brazilian government has done here with Glenn Greenwald, and it discourages journalists from using technology to best serve the public.”</p><p>President Bolsonaro, himself, commented in July 2019 that he would <a href="https://oglobo.globo.com/brasil/talvez-pegue-uma-cana-aqui-no-brasil-afirma-bolsonaro-sobre-glenn-greenwald-23837301">relish seeing the journalist spend time in prison</a> after he had published articles damaging his presidency. Greenwald, at the time, raised concerns that the authorities may respond by arresting and charging him.</p><p>This led to the country’s Supreme Court justice to issue an order preventing federal police from investigating the journalist’s activities with regards to the leaked information.</p><p>The prosecutors who charged Greenwald, however, said they had found audio messages that implicated the reporter in criminal activity.</p><p>Greenwald himself has denied the charges, and suggested <a href="https://twitter.com/ggreenwald/status/1219692225401163780/photo/1">in a statement</a> that the country’s Federal Police examined the same evidence and explicitly stated that he had not committed any of the crimes he’s been charged with. Edward Snowden, moreover, has branded these charges as “unbelievable, unsupported, and indefensible”.</p><p><em><a href="https://commons.wikimedia.org/wiki/File:Glenn_Greenwald.JP" target="_blank">Photo</a> by Robert O'Neill / CC BY 2.0</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-crime/354604/journalist-glenn-greenwald-charged-with-cyber-crimes-in-brazil</link>
                                                                            <description>
                            <![CDATA[ The Snowden-era investigative journalist has been accused of playing a key role in hacking into public officials' mobile phones ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">soGLKofzTLirTxmBEw9eSD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LUifViTqsXYp5Qe6njSguB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jan 2020 15:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LUifViTqsXYp5Qe6njSguB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LUifViTqsXYp5Qe6njSguB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>American journalist Glenn Greenwald has been arrested in Brazil and accused of <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">hacking</a> into the mobile phones of public officials following an investigation.</p><p>The reporter gained notoriety for his prominent role in publishing classified material that former <a href="https://www.itpro.com/security/34436/us-sues-edward-snowden-over-his-memoir" data-original-url="https://www.itpro.com/security/34436/us-sues-edward-snowden-over-his-memoir">National Security Agency (NSA) analyst Edward Snowden</a> obtained from the US government agency in 2013.</p><p>Through his publication, <em>the Intercept Brasil</em>, Greenwald published articles based on information obtained from the leaked messages of public officials within the right-wing Brazilian government. </p><p>The articles accused key members of Brazil’s justice system, and the Jair Bolsonaro-led government, of engaging in corruption.</p><p>Brazil’s public prosecutors have responded in kind by charging Greenwald with cyber crimes and for being part of a criminal organisation that allegedly hacked into these individuals’ devices, according to <em>the</em> <a href="https://www.nytimes.com/2020/01/21/world/americas/glenn-greenwald-brazil-cybercrimes.html"><em>New York Times</em></a>.</p><p>The 95-page criminal complaint alleges that the reporter had gone beyond simply publishing information that was passed to him, but played a “clear role in facilitating the commission of a crime”. Greenwald is said to have encouraged the hackers to delete archives that have already been shared in order to cover their tracks, authorities claim.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/public-sector/20109/prism-nsa-allegedly-spying-eu-politicians" data-original-url="/public-sector/20109/prism-nsa-allegedly-spying-eu-politicians">PRISM: NSA allegedly spying on EU politicians</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/23900/edward-snowden-claims-iphones-have-built-in-spyware" data-original-url="/mobile/23900/edward-snowden-claims-iphones-have-built-in-spyware">Edward Snowden claims iPhones have built-in spyware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow" data-original-url="/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow">Chinese hackers used 'stolen' NSA tools a year before they were leaked by the Shadow Brokers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/microsoft-windows/33142/privacy-watchdog-calls-for-windows-10-to-stop-uploading-encryption-keys-to" data-original-url="/microsoft-windows/33142/privacy-watchdog-calls-for-windows-10-to-stop-uploading-encryption-keys-to">Privacy watchdog calls for Windows 10 to stop uploading encryption keys to Microsoft</a></p></div></div><p>The Electronic Frontier Foundation, an organisation committed to <a href="https://www.itpro.com/security/20566/electronic-frontier-foundation-forces-nsa-reveal-surveillance-documents" data-original-url="https://www.itpro.com/security/20566/electronic-frontier-foundation-forces-nsa-reveal-surveillance-documents">campaigning for digital rights</a>, has blasted the Brazilian government for charging the reporter under its computer crime laws.</p><p>“EFF has long warned that cybersecurity laws in the Americas have been written and interpreted so broadly as to invite misuse,” <a href="https://www.eff.org/deeplinks/2020/01/brazils-attempt-prosecute-glenn-greenwald-computer-crimes-threatens-democracy">the organisation said in a statement</a>. “Computer crime laws should never be used to criminalize legitimate journalistic practice. Prosecutors must not apply them without considering the chilling effects on the free press, and the risk of politicized prosecutions.</p><p>“It is a threat to democracy when authorities use cybercrime laws to punish their critics, as the Brazilian government has done here with Glenn Greenwald, and it discourages journalists from using technology to best serve the public.”</p><p>President Bolsonaro, himself, commented in July 2019 that he would <a href="https://oglobo.globo.com/brasil/talvez-pegue-uma-cana-aqui-no-brasil-afirma-bolsonaro-sobre-glenn-greenwald-23837301">relish seeing the journalist spend time in prison</a> after he had published articles damaging his presidency. Greenwald, at the time, raised concerns that the authorities may respond by arresting and charging him.</p><p>This led to the country’s Supreme Court justice to issue an order preventing federal police from investigating the journalist’s activities with regards to the leaked information.</p><p>The prosecutors who charged Greenwald, however, said they had found audio messages that implicated the reporter in criminal activity.</p><p>Greenwald himself has denied the charges, and suggested <a href="https://twitter.com/ggreenwald/status/1219692225401163780/photo/1">in a statement</a> that the country’s Federal Police examined the same evidence and explicitly stated that he had not committed any of the crimes he’s been charged with. Edward Snowden, moreover, has branded these charges as “unbelievable, unsupported, and indefensible”.</p><p><em><a href="https://commons.wikimedia.org/wiki/File:Glenn_Greenwald.JP" target="_blank">Photo</a> by Robert O'Neill / CC BY 2.0</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ HackerOne bug bounty platform breached by its own user ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Provider of bug bounty support to <a href="https://www.itpro.com/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties" target="_blank" data-original-url="https://www.itpro.com/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties">major global organisations</a> HackerOne has paid one of its members for exposing an internal security breach. </p><p>A reward of $20,000 (£15,244) has been given to haxta4ok00, the bug hunter who exposed the mistake committed by a staffer at the company which helps the likes of <a href="https://www.itpro.com/business/policy-legislation/354196/uber-denied-licence-to-operate-in-london" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/354196/uber-denied-licence-to-operate-in-london">Uber</a>, <a href="https://www.itpro.com/security/34708/never-give-humans-the-keys-to-your-kingdom-say-goldman-sachs-security-chiefs" target="_blank" data-original-url="https://www.itpro.com/security/34708/never-give-humans-the-keys-to-your-kingdom-say-goldman-sachs-security-chiefs">Goldman Sachs</a> and the US Department of Defense offer bug bounties of their own.</p><p>The bug hunter was potentially able to view the records and private, undisclosed <a href="https://www.itpro.com/vulnerability/34184/what-s-the-difference-between-a-security-vulnerability-and-a-security-threat" target="_blank" data-original-url="https://www.itpro.com/vulnerability/34184/what-s-the-difference-between-a-security-vulnerability-and-a-security-threat">vulnerabilities</a> of HackerOne's biggest clients due to what the company is calling a "human error".</p><p>A HackerOne security analyst tasked with verifying disclosure reports from bug hunters sent a URL loaded with their session <a href="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law" target="_blank" data-original-url="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law">cookie information</a> which the hunter was able to use to view things on the site only logged-in staffers should be able to.</p><p>Sending URLs between analyst and hunter is a routine process, HackerOne said in a report. </p><p>"When a security analyst fails to reproduce a potentially valid security vulnerability, they go back and forth with the hacker to better understand the report," said HackerOne. "During this dialogue, security analysts may include steps they've taken in their response to the report, including HTTP requests that they made to reproduce. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties" data-original-url="/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties">Microsoft joins forces with HackerOne to boost bug bounties</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards" data-original-url="/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards">Teenage hacker makes $1m from bug bounty rewards</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34708/never-give-humans-the-keys-to-your-kingdom-say-goldman-sachs-security-chiefs" data-original-url="/security/34708/never-give-humans-the-keys-to-your-kingdom-say-goldman-sachs-security-chiefs">Never give humans the keys to your kingdom, say Goldman Sachs security chiefs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28649/why-can-t-software-firms-sort-their-own-security" data-original-url="/security/28649/why-can-t-software-firms-sort-their-own-security">Why can’t software firms sort their own security?</a></p></div></div><p>"In this particular case, parts of a cURL command, copied from a browser console, were not removed before posting it to the report, disclosing the session cookie," it added.</p><p>The company confirmed that the event lasted only a short time and was not carried out with malicious intent. No undisclosed vulnerabilities were stolen, exploited or published as a result of the incident. All copies of potentially sensitive information were deleted.</p><p>"Similar to previously disclosed incidents or weaknesses within BugZilla or Google Issue Tracker, exposure of non-public HackerOne reports presents an immediate danger to not only businesses with hosted programs but also effectively all Internet users," said Craig Young, senior security researcher at Tripwire.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mVM9DUbmvCJhNp5jYeasdf" name="mVM9DUbmvCJhNp5jYeasdf.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/mVM9DUbmvCJhNp5jYeasdf.png" mos="https://cdn.mos.cms.futurecdn.net/mVM9DUbmvCJhNp5jYeasdf.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Why UEM is the key to enterprise IT security</strong></p><p class="fancy-box__body-text">A guide to effective endpoint security</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/354132/why-uem-is-the-key-to-enterprise-it-security" data-original-url="/security/endpoint-security/354132/why-uem-is-the-key-to-enterprise-it-security">FREE DOWNLOAD</a></p></div></div><p>"While I commend HackerOne for their response, this incident is yet another reminder of the distinct risk organisations take by using managed vulnerability reporting services like BugCrowd or HackerOne," he added. "The consolidation of valuable data by such vendors creates a hugely attractive attack target for intelligence agencies (or even criminal actors) to fill their arsenal."</p><p>Something that seemed to concern Jobert Abma, co-founder of HackerOne and the individual responsible for following-up with haxta4ok00, was the observation he made regarding the sheer number of pages the hunter opened while accessing a privileged account.</p><p>"We didn't find it necessary for you to have opened all the reports and pages in order to validate you had access to the account," said Abma. "Would you mind explaining why you did so to us?"</p><p>"I did it to show the impact," said haxta4ok00. "I didn't mean any harm by it. I reported it to you at once.</p><p>"I apologise if I did anything wrong, but it was just a <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hack</a>," the bug hunter added.</p><p>The issue was given a CVSS score of 8.3, which is considered "high", not as severe as the likes of <a href="https://www.itpro.com/security/34802/bluekeep-attack-discovery-has-done-nothing-to-motivate-businesses-into-patching" target="_blank" data-original-url="https://www.itpro.com/security/34802/bluekeep-attack-discovery-has-done-nothing-to-motivate-businesses-into-patching">BlueKeep</a>, for example.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/bugs/354287/hackerone-bug-bounty-platform-breached-by-its-own-user</link>
                                                                            <description>
                            <![CDATA[ The bug bounty specialist paid the hacker responsible a cool $20,000 for their efforts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eX5G43mZHbYhshH8tUFMi2</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JcULBUeCjTeXK6wU56j3e4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Dec 2019 08:37:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JcULBUeCjTeXK6wU56j3e4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hacker wearing an anonymous mask with a golden halo above their head]]></media:description>                                                            <media:text><![CDATA[A hacker wearing an anonymous mask with a golden halo above their head]]></media:text>
                                <media:title type="plain"><![CDATA[A hacker wearing an anonymous mask with a golden halo above their head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JcULBUeCjTeXK6wU56j3e4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Provider of bug bounty support to <a href="https://www.itpro.com/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties" target="_blank" data-original-url="https://www.itpro.com/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties">major global organisations</a> HackerOne has paid one of its members for exposing an internal security breach. </p><p>A reward of $20,000 (£15,244) has been given to haxta4ok00, the bug hunter who exposed the mistake committed by a staffer at the company which helps the likes of <a href="https://www.itpro.com/business/policy-legislation/354196/uber-denied-licence-to-operate-in-london" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/354196/uber-denied-licence-to-operate-in-london">Uber</a>, <a href="https://www.itpro.com/security/34708/never-give-humans-the-keys-to-your-kingdom-say-goldman-sachs-security-chiefs" target="_blank" data-original-url="https://www.itpro.com/security/34708/never-give-humans-the-keys-to-your-kingdom-say-goldman-sachs-security-chiefs">Goldman Sachs</a> and the US Department of Defense offer bug bounties of their own.</p><p>The bug hunter was potentially able to view the records and private, undisclosed <a href="https://www.itpro.com/vulnerability/34184/what-s-the-difference-between-a-security-vulnerability-and-a-security-threat" target="_blank" data-original-url="https://www.itpro.com/vulnerability/34184/what-s-the-difference-between-a-security-vulnerability-and-a-security-threat">vulnerabilities</a> of HackerOne's biggest clients due to what the company is calling a "human error".</p><p>A HackerOne security analyst tasked with verifying disclosure reports from bug hunters sent a URL loaded with their session <a href="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law" target="_blank" data-original-url="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law">cookie information</a> which the hunter was able to use to view things on the site only logged-in staffers should be able to.</p><p>Sending URLs between analyst and hunter is a routine process, HackerOne said in a report. </p><p>"When a security analyst fails to reproduce a potentially valid security vulnerability, they go back and forth with the hacker to better understand the report," said HackerOne. "During this dialogue, security analysts may include steps they've taken in their response to the report, including HTTP requests that they made to reproduce. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties" data-original-url="/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties">Microsoft joins forces with HackerOne to boost bug bounties</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards" data-original-url="/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards">Teenage hacker makes $1m from bug bounty rewards</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34708/never-give-humans-the-keys-to-your-kingdom-say-goldman-sachs-security-chiefs" data-original-url="/security/34708/never-give-humans-the-keys-to-your-kingdom-say-goldman-sachs-security-chiefs">Never give humans the keys to your kingdom, say Goldman Sachs security chiefs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28649/why-can-t-software-firms-sort-their-own-security" data-original-url="/security/28649/why-can-t-software-firms-sort-their-own-security">Why can’t software firms sort their own security?</a></p></div></div><p>"In this particular case, parts of a cURL command, copied from a browser console, were not removed before posting it to the report, disclosing the session cookie," it added.</p><p>The company confirmed that the event lasted only a short time and was not carried out with malicious intent. No undisclosed vulnerabilities were stolen, exploited or published as a result of the incident. All copies of potentially sensitive information were deleted.</p><p>"Similar to previously disclosed incidents or weaknesses within BugZilla or Google Issue Tracker, exposure of non-public HackerOne reports presents an immediate danger to not only businesses with hosted programs but also effectively all Internet users," said Craig Young, senior security researcher at Tripwire.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mVM9DUbmvCJhNp5jYeasdf" name="mVM9DUbmvCJhNp5jYeasdf.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/mVM9DUbmvCJhNp5jYeasdf.png" mos="https://cdn.mos.cms.futurecdn.net/mVM9DUbmvCJhNp5jYeasdf.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Why UEM is the key to enterprise IT security</strong></p><p class="fancy-box__body-text">A guide to effective endpoint security</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/354132/why-uem-is-the-key-to-enterprise-it-security" data-original-url="/security/endpoint-security/354132/why-uem-is-the-key-to-enterprise-it-security">FREE DOWNLOAD</a></p></div></div><p>"While I commend HackerOne for their response, this incident is yet another reminder of the distinct risk organisations take by using managed vulnerability reporting services like BugCrowd or HackerOne," he added. "The consolidation of valuable data by such vendors creates a hugely attractive attack target for intelligence agencies (or even criminal actors) to fill their arsenal."</p><p>Something that seemed to concern Jobert Abma, co-founder of HackerOne and the individual responsible for following-up with haxta4ok00, was the observation he made regarding the sheer number of pages the hunter opened while accessing a privileged account.</p><p>"We didn't find it necessary for you to have opened all the reports and pages in order to validate you had access to the account," said Abma. "Would you mind explaining why you did so to us?"</p><p>"I did it to show the impact," said haxta4ok00. "I didn't mean any harm by it. I reported it to you at once.</p><p>"I apologise if I did anything wrong, but it was just a <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hack</a>," the bug hunter added.</p><p>The issue was given a CVSS score of 8.3, which is considered "high", not as severe as the likes of <a href="https://www.itpro.com/security/34802/bluekeep-attack-discovery-has-done-nothing-to-motivate-businesses-into-patching" target="_blank" data-original-url="https://www.itpro.com/security/34802/bluekeep-attack-discovery-has-done-nothing-to-motivate-businesses-into-patching">BlueKeep</a>, for example.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is the Computer Misuse Act? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>It’s important to know what the Computer Misuse Act (CMA) is, as it forms the backbone of law enforcement against hacking in the UK. It’s through this law that UK legislators enforce protections for devices and data and in the UK, like their international counterparts.</p><p>The CMA was first introduced in the UK in 1990 and sought to draw boundaries between lawful and unlawful access to a computer system and its data. The CMA intended to criminalize any unauthorized activity of this nature.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RUqRvKotEcdx7mncP2Vh2G" name="GettyImages-1365148935-cyber-padlocks-yellow.jpg" caption="" alt="A graphic of dozens of locked, gold padlocks on a pale yellow background, lined up in rows and viewed with an isometric view to represent cyber security. To the right of the frame there is one especially large, unlocked padlock. They are set against a pale yellow background." src="https://cdn.mos.cms.futurecdn.net/RUqRvKotEcdx7mncP2Vh2G.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/how-many-security-providers-is-the-right-amount" target="_blank">How many security providers do you really need?</a></p></div></div><p>The UK government has updated the CMA several times in the decades since, to match contemporary cyber threats. A particularly major overhaul was passed in 2015, which aligned the CMA with EU law and with the Serious Crime Act 2015 through added protections for attacks on personal property.</p><p>Some have argued that the CMA is seriously out of date and should be subjected to a more radical overhaul to address growing attacks on the UK and new concerns such as the <a href="https://www.itpro.com/technology/artificial-intelligence/six-generative-ai-cyber-security-threats-and-how-to-mitigate-them"><u>cyber security implications of generative AI</u></a>.</p><h2 class="article-body__section" id="section-computer-misuse-act-summary-and-criticisms"><span>Computer Misuse Act summary and criticisms</span></h2><p>The CMA is used to protect against and prosecute hackers and would-be cyber criminals. In 2022, computer misuse accounted for 14% of total UK crime and the CMA has provisions to cover a broad variety of criminal digital activity.</p><p>One of several laws that protects the devices and data of UK citizens, the CMA sits alongside the <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018"><u>Data Protection Act 2018</u></a> and UK <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a>. It has alsom been joined by government projects such as the <a href="https://www.itpro.com/business/policy-legislation/361849/uk-unveils-ps26-billion-national-cyber-strategy"><u>UK’s National Cyber Strategy</u></a>, which seeks to shore up the UK’s digital skills.</p><section class="article__schema-question"><h3>Why was the Computer Misuse Act introduced?</h3><article class="article__schema-answer"><p>Much of the justification for the CMA lay in the 1988 case of <a href="http://swarb.co.uk/regina-v-gold-and-schifreen-cacd-17-jul-1987"><em>Regina v Gold and Schifreen</em></a><em>,</em> which saw two hackers gain access to a BT data service using stolen engineer credentials obtained through <a href="https://www.itpro.com/security/31723/what-is-shoulder-surfing"><u>shoulder surfing</u></a>.</p><p>Both individuals were found guilty under the Forgery and Counterfeiting Act 1981, but this was subsequently overturned on appeal as they did not commit the hacking for profit, a specification of the 1981 Act. This helped to expose gaps in the law that had to be filled, with legal experts expressing concerns that the case set a precedent for recreational hacking being legal activity. Two years later, the CMA was introduced to parliament.</p></article></section><section class="article__schema-question"><h3>What are the Computer Misuse Act penalties?</h3><article class="article__schema-answer"><p>There are four penalty levels if you are prosecuted under the CMA, applied in proportion to the severity of the Act. They range from potential fines to imprisonment.</p></article></section><p>The first level applies if one gains unauthorized access to a computer without permission, you could face a penalty of up to two years in prison and a £5,000 ($6,254) fine.</p><p>Those who gain access to a computer without permission to steal data or take part in another crime, such as using that data to commit fraud, will be tried under the second penalty level. For this, you face a sentence of up to 10 years in prison and can receive an unlimited fine. The extent of the punishment depends on the severity of the individual case, and the prosecution has to prove they had intent to commit another crime with illicit access, which can be difficult.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uH2UFsZsWQr9xxCirTLXZP" name="More than a number_Your risk score explained_listing.jpg" caption="" alt="The back of two colleagues looking, and pointing at, a dual screen workstation in an office" src="https://cdn.mos.cms.futurecdn.net/uH2UFsZsWQr9xxCirTLXZP.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>More than a number: Your risk score explained</strong></p><p class="fancy-box__body-text"><em>Leverage a company-wide risk index to make a high-level assessment of your organization’s risk</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/risk/370277/more-than-a-number-your-risk-score-explained">DOWNLOAD NOW</a></p></div></div><p>If one modifies the content of a computer or provides the tools for others to alter or destroy them, for example through the sale of <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">ransomware</a>, they could face a prison sentence of up to ten years alongside an unlimited fine.</p><p>The final level relates to those who perform acts that cause or risk causing serious material damage. It carries a maximum prison sentence of 14 years, but if this potential damage is found to threaten human well-being or put national security at risk the sentence could be up to life imprisonment.</p><section class="article__schema-question"><h3>How has the Computer Misuse Act changed?</h3><article class="article__schema-answer"><p>When the CMA was passed in 1990, computers were not yet commonly used and the act was therefore unable to anticipate all the cyber threats of the coming decades. If one had access to a computer back then, it was likely at a place of work and commercial internet access was still years away. Nowadays we access the internet and use devices like <a href="https://www.itpro.com/laptops/23742/best-laptops">laptops</a> and <a href="https://www.itpro.com/tablets/21843/best-business-tablets-2023">tablets</a> every day, with the threat landscape having grown in tandem. </p><p>Legislators have been repeatedly forced to tweak the act to adapt to new online threats. For example, updates to the law added definitions for cyber attack methods that criminals could carry out, as well as considering the preparation required to launch an attack as a malicious action in and of itself.</p></article></section><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/370054/cyber-security-certification-vs-degree" target="_blank">Cyber security certification vs degree: Which is best for your career?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" target="_blank">What is the Data Protection Act 1998?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid" target="_blank">GDPR fines: How high are they, and how can you avoid them?</a></p></div></div><p>The legislation was additionally amended in 2015, thanks to the Serious Crime Act, which included specific passages on computer misuse and introduced three alterations to the original law. Amendments in Section 3ZA defined unauthorized acts causing serious damage as offenses and brought the EU Directive on Attacks against Information Systems into law in the UK. It also sought to clarify the "savings" provision that protects law enforcement from prosecution for acts performed on computers under powers of inspection or examination.</p><p>In a <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/415953/Factsheet_-_Computer_Misuse_-_Act.pdf" target="_blank">fact sheet</a> [PDF], the government stated that the new offense of unauthorized acts causing serious damage "addresses the most serious cyber attacks, for example, those on essential systems controlling power supply, communications, food or fuel distribution". </p><p>This helped to align the CMA with the severe nature of modern cyber crime, with organizations such as the <a href="https://www.itpro.com/tag/national-cyber-security-centre"><u>National Cyber Security Centre (NCSC)</u></a> having warned of <a href="https://www.itpro.com/security/cyber-attacks/ncsc-new-class-of-russian-cyber-attackers-seek-to-destroy-critical-infrastructure"><u>advanced attacks on critical national infrastructure (CNI)</u></a> by Russia-aligned threat actors. The government’s own National Risk Register (NRR) report has also <a href="https://www.itpro.com/security/cyber-attacks/threat-of-cyber-attacks-to-national-security-compared-to-that-of-chemical-weapons"><u>compared cyber threats to chemical weapons</u></a> in terms of severity, particularly those that could affect critical utilities.</p><p>Until this provision, the most serious crime covered by the act was the aforementioned section 3 offense of unauthorized access to impair the operation of a computer, which carries a maximum penalty of 10 years. The government argued that this "did not sufficiently reflect the level of personal and economic harm that a major cyber attack on critical systems could cause". Therefore, conviction under the new offense can result in a more severe prison sentence, of up to 14 years.</p><p>Changes made regarding the EU Directive on Attacks against Information Systems extended extraterritorial jurisdiction, increasing the ease with which cyber criminals using the UK as a base of operations can be prosecuted. It applies even if they are not physically located within the UK, and also allows the police and Crown Prosecution Service (CPS) to pursue and prosecute UK residents for cyber crimes committed overseas.</p><section class="article__schema-question"><h3>What are the Computer Misuse Act's problems?</h3><p>Additions to the CMA have been far from a cure-all, and in many cases have simply complicated the legal landscape through which legitimate computer users must navigate.</p><article class="article__schema-answer"><p>Section 37 of the Police and Justice Act of 2006 is one of many provisions that has faced criticism for its poorly conceived scope, with its sub-section 3a stating that making, supplying, or obtaining any articles for use in a malicious act using a computer is categorized as criminal activity. Under this legislation, owning any hacking software or exploit tools is a crime, even if you are a ‘white hat’ hacker using them for <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">ethical hacking</a>, or for researching security threats.</p><p>A provision relating to protection for law enforcement accessing computers in the act of investigation caused much controversy. The government argued that the changes were made "to remove any ambiguity for the lawful use of powers to investigate crime (for example under Part 3 of the Police Act 1997) and the interaction of those powers with the offenses in the 1990 Act".</p></article></section><p>"The changes do not extend law enforcement agencies&apos; powers but merely clarify the use of existing powers (derived from other enactments, wherever exercised) in the context of the offenses in the 1990 Act," it added.</p><p>However, civil rights groups including Privacy International have argued that the changes are far too broad, and that complete legal exemption for police and spy agencies such as MI5 is excessive and unwarranted. Privacy raised concerns in a case to the European Court of Human Rights along with five other complainants.</p><h2 class="article-body__section" id="section-is-the-computer-misuse-act-fit-for-purpose"><span>Is the Computer Misuse Act fit for purpose?</span></h2><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/6GrNyc1WAgk" allowfullscreen></iframe></div></div><p>Recent years have seen repeated calls to reform or scrap the CMA, with many security researchers and law enforcement professionals citing its ability to cope with the complexities of modern-day computing.</p><p>Some point to the act’s relatively poor record of backing criminal investigations, with around less than 1% of computer hacking offenses investigated in the UK in 2019<a href="https://www.itpro.com/security/hacking/357298/less-than-1-percent-hacking-resulted-in-prosecution-2019"> <u>resulting in prosecution</u></a>. The National Fraud Intelligence Bureau (NFIB) does not link individual computer misuse offenses to their outcomes, which makes analysis of its effectiveness difficult. </p><p>There is also little evidence of the CMA acting as a deterrent to criminals, with the 850,000 offenses of computer misuse <a href="https://www.ons.gov.uk/peoplepopulationandcommunity/crimeandjustice/bulletins/crimeinenglandandwales/yearendingjune2023#computer-misuse" target="_blank"><u>reported</u></a> by the Crime Survey for England and Wales (CSEW) in the year ending June 2023 similar to the 876,000 offenses recorded in the year ending March 2020. Much CMA criticism hinges on the limitations of the act’s definitions and its binary view on hacking.</p><h3 class="article-body__section" id="section-the-definition-of-computer-in-the-act"><span>The definition of 'computer' in the Act</span></h3><p>Perhaps the most obvious criticism is that the act represents a time when ‘computer’ is mainly referred to as a desktop or <a href="https://www.itpro.com/hardware/the-time-has-come-to-say-arrivederci-to-the-all-in-one"><u>all-in-one PC</u></a>. In this regard, it fails to account for much of the innovation of the 21st century, putting it well out of step with the demands of the modern world.</p><p>“The Computer Misuse Act 1990 contains several issues that apply subjectivity when objectivity should be the test,” argues Tim Mackey, principal security strategist at the Synopsys Cybersecurity Research Centre. “The term “computer” isn’t defined and the contemporary definition of “computer” has likely shifted in the intervening thirty years.”</p><p>This lack of clear definition creates a “grey area”, adds Mackey, where prosecutors are forced to apply the act based on subjective interpretation, rather than objective information.</p><p>“This can lead to interesting scenarios that would question whether a <a href="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy"><u>smartphone</u></a>, nanny-cam, <a href="https://www.itpro.com/infrastructure/network-internet/366963/what-is-wi-fi-7">Wi-Fi</a>-connected dishwasher, or CCTV system are in fact computers – despite the reality that each of these devices often runs a general-purpose <a href="https://www.itpro.com/uk/tag/operating-systems"><u>operating system</u></a>, is connected to a network, and runs software at the behest of its user.”</p><h3 class="article-body__section" id="section-failure-to-keep-up-with-novel-cyber-threats"><span>Failure to keep up with novel cyber threats</span></h3><p>Another area of criticism for the CMA is that it has failed to keep up with the developments in cyber crime landscape such as the <a href="https://www.itpro.com/security/cyber-attacks/the-rise-of-identity-based-cyber-attacks-and-how-to-mitigate-them"><u>rise in identity-based attacks</u></a> and <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec"><u>business email compromise (BEC)</u></a>.</p><p>“The types of crime the act was originally designed to fight are actually decreasing – but new threats are emerging seemingly every month,” says Peter Yapp, Partner at law firm Schillings and former deputy director of the UK’s NCSC. “For example, hacking for extortion has nearly doubled over the past year while virus/<a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> reports have dropped. This underlines one of the main shortfalls of the act – the evolution of using computers to commit fraud to the computer becoming the main conduit for fraud.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wE3UT9aDVGm6fZh2yRZMu6" name="wE3UT9aDVGm6fZh2yRZMu6.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/wE3UT9aDVGm6fZh2yRZMu6.jpg" mos="https://cdn.mos.cms.futurecdn.net/wE3UT9aDVGm6fZh2yRZMu6.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>An EDR buyer's guide</strong></p><p class="fancy-box__body-text">How to pick the best endpoint detection and response solution for your business</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368443/an-edr-buyers-guide" data-original-url="/security/cyber-security/368443/an-edr-buyers-guide">FREE DOWNLOAD</a></p></div></div><p>The subjective interpretation of the Act ultimately drives a wedge between the legal system and security researchers, and some have argued that judges often appear to misunderstand the wider issues facing the industry.</p><p>“In essence, the Act isn’t working for <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> practitioners, law enforcement officers, the Crown Prosecution Office and the Courts,” adds Yapp. “Even more worryingly, judges don’t seem to understand the issues. For example, Southwark Crown Court is supposedly a specialist fraud center that deals with the majority of the serious and major fraud cases in England and Wales, but its level of understanding around computer crime isn’t sufficient to facilitate any significant number of successful prosecutions. The police have dedicated many more resources to this area over the past five years, but until every police officer understands cybercrime, we will be playing catch up.”</p><p>Richard Millett, training development manager at Firebrand Training and regular cyber security advisor for police forces across the UK, explains that many cyber crime cases are instead tried under other legislation, such as fraud and theft, not only because of a lack of definitions but also because it allows stricter penalties to be issued.</p><p>“If you look at the tariffs for the various sections under the [Computer Misuse] Act you see that the penalties defined do not match the severity of some of the offenses that have been committed,” says Millett. “It is only when you look at section 3za which covers “causing or creating a risk of serious damage” do you see tariffs of “imprisonment for life”. The financial and economic damage that has been inflicted by some individuals is not reflected in the penalties that have been applied, running into millions in many cases.”</p><h3 class="article-body__section" id="section-how-the-computer-misuse-act-limits-ethical-hacking"><span>How the Computer Misuse Act limits ethical hacking</span></h3><p>The greatest challenge facing cyber security researchers trying to operate within the scope of the act is its failure to distinguish between criminal and ethical hacking.</p><p>As Rob Shooter, managing partner of law firm Fieldfisher explains to <em>ITPro</em>, many in the industry argue that offenses under the CMA are too “broad brush”, leaving cyber security researchers with little legal room to perform ethical hacking against cyber criminals.</p><p>The Act defines non-consensually accessing a computer system as a crime, regardless of the intent or benefits that may come about as a result of the action. Technically, this means that core <a href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs#section-risk-management"><u>cyber security skills</u></a> and research tasks used to analyze potential threats from probing for <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management"><u>vulnerability management</u></a>, file interrogation, or analyzing compromised systems are illegal unless consent has been given by both the victim and perpetrator of the crime.</p><p>“As an example, there are a multitude of US-based companies offering vulnerability scanning services of the extended supply chain, whereas there are few, if any, UK companies offering the same service,” explains Yapp.</p><p>Although this technicality may limit the actions of ethical hacking or may leave some wary about potential prosecution, Yapp adds that he is unaware of any cases involving UK researchers being sanctioned by law enforcement as a direct result of their work.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=54751392&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act</link>
                                                                            <description>
                            <![CDATA[ If your computer systems are attacked, is the Computer Misuse Act effective enough to put those criminals behind bars? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sqK7aDSRcVRg6mxChRgXaQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cFGftVxymDaVkoPEafBXm9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Sep 2019 07:46:00 +0000</pubDate>                                                                                                                                <updated>Thu, 23 Nov 2023 10:57:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is deputy editor at ITPro, and its sibling titles Cloud Pro and ChannelPro. She’s started out with the brands as a staff writer specializing in cloud computing. She went on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cyber security, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialise in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;
&lt;p&gt;In October 2021, she became the sites’ deputy editor and now has a more strategic role, although she is still a specialist in enterprise IT infrastructure and business strategy.&lt;/p&gt;
&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;
&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cFGftVxymDaVkoPEafBXm9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A statue of Lady Justice, a blindfolded woman raising two scales in the air to represent the legal system, set against a blurred background of a laptop with blue light streaming from the monitor, to represent the Computer Misuse Act.]]></media:description>                                                            <media:text><![CDATA[A statue of Lady Justice, a blindfolded woman raising two scales in the air to represent the legal system, set against a blurred background of a laptop with blue light streaming from the monitor, to represent the Computer Misuse Act.]]></media:text>
                                <media:title type="plain"><![CDATA[A statue of Lady Justice, a blindfolded woman raising two scales in the air to represent the legal system, set against a blurred background of a laptop with blue light streaming from the monitor, to represent the Computer Misuse Act.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cFGftVxymDaVkoPEafBXm9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It’s important to know what the Computer Misuse Act (CMA) is, as it forms the backbone of law enforcement against hacking in the UK. It’s through this law that UK legislators enforce protections for devices and data and in the UK, like their international counterparts.</p><p>The CMA was first introduced in the UK in 1990 and sought to draw boundaries between lawful and unlawful access to a computer system and its data. The CMA intended to criminalize any unauthorized activity of this nature.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RUqRvKotEcdx7mncP2Vh2G" name="GettyImages-1365148935-cyber-padlocks-yellow.jpg" caption="" alt="A graphic of dozens of locked, gold padlocks on a pale yellow background, lined up in rows and viewed with an isometric view to represent cyber security. To the right of the frame there is one especially large, unlocked padlock. They are set against a pale yellow background." src="https://cdn.mos.cms.futurecdn.net/RUqRvKotEcdx7mncP2Vh2G.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/how-many-security-providers-is-the-right-amount" target="_blank">How many security providers do you really need?</a></p></div></div><p>The UK government has updated the CMA several times in the decades since, to match contemporary cyber threats. A particularly major overhaul was passed in 2015, which aligned the CMA with EU law and with the Serious Crime Act 2015 through added protections for attacks on personal property.</p><p>Some have argued that the CMA is seriously out of date and should be subjected to a more radical overhaul to address growing attacks on the UK and new concerns such as the <a href="https://www.itpro.com/technology/artificial-intelligence/six-generative-ai-cyber-security-threats-and-how-to-mitigate-them"><u>cyber security implications of generative AI</u></a>.</p><h2 class="article-body__section" id="section-computer-misuse-act-summary-and-criticisms"><span>Computer Misuse Act summary and criticisms</span></h2><p>The CMA is used to protect against and prosecute hackers and would-be cyber criminals. In 2022, computer misuse accounted for 14% of total UK crime and the CMA has provisions to cover a broad variety of criminal digital activity.</p><p>One of several laws that protects the devices and data of UK citizens, the CMA sits alongside the <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018"><u>Data Protection Act 2018</u></a> and UK <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a>. It has alsom been joined by government projects such as the <a href="https://www.itpro.com/business/policy-legislation/361849/uk-unveils-ps26-billion-national-cyber-strategy"><u>UK’s National Cyber Strategy</u></a>, which seeks to shore up the UK’s digital skills.</p><section class="article__schema-question"><h3>Why was the Computer Misuse Act introduced?</h3><article class="article__schema-answer"><p>Much of the justification for the CMA lay in the 1988 case of <a href="http://swarb.co.uk/regina-v-gold-and-schifreen-cacd-17-jul-1987"><em>Regina v Gold and Schifreen</em></a><em>,</em> which saw two hackers gain access to a BT data service using stolen engineer credentials obtained through <a href="https://www.itpro.com/security/31723/what-is-shoulder-surfing"><u>shoulder surfing</u></a>.</p><p>Both individuals were found guilty under the Forgery and Counterfeiting Act 1981, but this was subsequently overturned on appeal as they did not commit the hacking for profit, a specification of the 1981 Act. This helped to expose gaps in the law that had to be filled, with legal experts expressing concerns that the case set a precedent for recreational hacking being legal activity. Two years later, the CMA was introduced to parliament.</p></article></section><section class="article__schema-question"><h3>What are the Computer Misuse Act penalties?</h3><article class="article__schema-answer"><p>There are four penalty levels if you are prosecuted under the CMA, applied in proportion to the severity of the Act. They range from potential fines to imprisonment.</p></article></section><p>The first level applies if one gains unauthorized access to a computer without permission, you could face a penalty of up to two years in prison and a £5,000 ($6,254) fine.</p><p>Those who gain access to a computer without permission to steal data or take part in another crime, such as using that data to commit fraud, will be tried under the second penalty level. For this, you face a sentence of up to 10 years in prison and can receive an unlimited fine. The extent of the punishment depends on the severity of the individual case, and the prosecution has to prove they had intent to commit another crime with illicit access, which can be difficult.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uH2UFsZsWQr9xxCirTLXZP" name="More than a number_Your risk score explained_listing.jpg" caption="" alt="The back of two colleagues looking, and pointing at, a dual screen workstation in an office" src="https://cdn.mos.cms.futurecdn.net/uH2UFsZsWQr9xxCirTLXZP.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>More than a number: Your risk score explained</strong></p><p class="fancy-box__body-text"><em>Leverage a company-wide risk index to make a high-level assessment of your organization’s risk</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/risk/370277/more-than-a-number-your-risk-score-explained">DOWNLOAD NOW</a></p></div></div><p>If one modifies the content of a computer or provides the tools for others to alter or destroy them, for example through the sale of <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">ransomware</a>, they could face a prison sentence of up to ten years alongside an unlimited fine.</p><p>The final level relates to those who perform acts that cause or risk causing serious material damage. It carries a maximum prison sentence of 14 years, but if this potential damage is found to threaten human well-being or put national security at risk the sentence could be up to life imprisonment.</p><section class="article__schema-question"><h3>How has the Computer Misuse Act changed?</h3><article class="article__schema-answer"><p>When the CMA was passed in 1990, computers were not yet commonly used and the act was therefore unable to anticipate all the cyber threats of the coming decades. If one had access to a computer back then, it was likely at a place of work and commercial internet access was still years away. Nowadays we access the internet and use devices like <a href="https://www.itpro.com/laptops/23742/best-laptops">laptops</a> and <a href="https://www.itpro.com/tablets/21843/best-business-tablets-2023">tablets</a> every day, with the threat landscape having grown in tandem. </p><p>Legislators have been repeatedly forced to tweak the act to adapt to new online threats. For example, updates to the law added definitions for cyber attack methods that criminals could carry out, as well as considering the preparation required to launch an attack as a malicious action in and of itself.</p></article></section><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/370054/cyber-security-certification-vs-degree" target="_blank">Cyber security certification vs degree: Which is best for your career?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" target="_blank">What is the Data Protection Act 1998?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid" target="_blank">GDPR fines: How high are they, and how can you avoid them?</a></p></div></div><p>The legislation was additionally amended in 2015, thanks to the Serious Crime Act, which included specific passages on computer misuse and introduced three alterations to the original law. Amendments in Section 3ZA defined unauthorized acts causing serious damage as offenses and brought the EU Directive on Attacks against Information Systems into law in the UK. It also sought to clarify the "savings" provision that protects law enforcement from prosecution for acts performed on computers under powers of inspection or examination.</p><p>In a <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/415953/Factsheet_-_Computer_Misuse_-_Act.pdf" target="_blank">fact sheet</a> [PDF], the government stated that the new offense of unauthorized acts causing serious damage "addresses the most serious cyber attacks, for example, those on essential systems controlling power supply, communications, food or fuel distribution". </p><p>This helped to align the CMA with the severe nature of modern cyber crime, with organizations such as the <a href="https://www.itpro.com/tag/national-cyber-security-centre"><u>National Cyber Security Centre (NCSC)</u></a> having warned of <a href="https://www.itpro.com/security/cyber-attacks/ncsc-new-class-of-russian-cyber-attackers-seek-to-destroy-critical-infrastructure"><u>advanced attacks on critical national infrastructure (CNI)</u></a> by Russia-aligned threat actors. The government’s own National Risk Register (NRR) report has also <a href="https://www.itpro.com/security/cyber-attacks/threat-of-cyber-attacks-to-national-security-compared-to-that-of-chemical-weapons"><u>compared cyber threats to chemical weapons</u></a> in terms of severity, particularly those that could affect critical utilities.</p><p>Until this provision, the most serious crime covered by the act was the aforementioned section 3 offense of unauthorized access to impair the operation of a computer, which carries a maximum penalty of 10 years. The government argued that this "did not sufficiently reflect the level of personal and economic harm that a major cyber attack on critical systems could cause". Therefore, conviction under the new offense can result in a more severe prison sentence, of up to 14 years.</p><p>Changes made regarding the EU Directive on Attacks against Information Systems extended extraterritorial jurisdiction, increasing the ease with which cyber criminals using the UK as a base of operations can be prosecuted. It applies even if they are not physically located within the UK, and also allows the police and Crown Prosecution Service (CPS) to pursue and prosecute UK residents for cyber crimes committed overseas.</p><section class="article__schema-question"><h3>What are the Computer Misuse Act's problems?</h3><p>Additions to the CMA have been far from a cure-all, and in many cases have simply complicated the legal landscape through which legitimate computer users must navigate.</p><article class="article__schema-answer"><p>Section 37 of the Police and Justice Act of 2006 is one of many provisions that has faced criticism for its poorly conceived scope, with its sub-section 3a stating that making, supplying, or obtaining any articles for use in a malicious act using a computer is categorized as criminal activity. Under this legislation, owning any hacking software or exploit tools is a crime, even if you are a ‘white hat’ hacker using them for <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">ethical hacking</a>, or for researching security threats.</p><p>A provision relating to protection for law enforcement accessing computers in the act of investigation caused much controversy. The government argued that the changes were made "to remove any ambiguity for the lawful use of powers to investigate crime (for example under Part 3 of the Police Act 1997) and the interaction of those powers with the offenses in the 1990 Act".</p></article></section><p>"The changes do not extend law enforcement agencies&apos; powers but merely clarify the use of existing powers (derived from other enactments, wherever exercised) in the context of the offenses in the 1990 Act," it added.</p><p>However, civil rights groups including Privacy International have argued that the changes are far too broad, and that complete legal exemption for police and spy agencies such as MI5 is excessive and unwarranted. Privacy raised concerns in a case to the European Court of Human Rights along with five other complainants.</p><h2 class="article-body__section" id="section-is-the-computer-misuse-act-fit-for-purpose"><span>Is the Computer Misuse Act fit for purpose?</span></h2><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/6GrNyc1WAgk" allowfullscreen></iframe></div></div><p>Recent years have seen repeated calls to reform or scrap the CMA, with many security researchers and law enforcement professionals citing its ability to cope with the complexities of modern-day computing.</p><p>Some point to the act’s relatively poor record of backing criminal investigations, with around less than 1% of computer hacking offenses investigated in the UK in 2019<a href="https://www.itpro.com/security/hacking/357298/less-than-1-percent-hacking-resulted-in-prosecution-2019"> <u>resulting in prosecution</u></a>. The National Fraud Intelligence Bureau (NFIB) does not link individual computer misuse offenses to their outcomes, which makes analysis of its effectiveness difficult. </p><p>There is also little evidence of the CMA acting as a deterrent to criminals, with the 850,000 offenses of computer misuse <a href="https://www.ons.gov.uk/peoplepopulationandcommunity/crimeandjustice/bulletins/crimeinenglandandwales/yearendingjune2023#computer-misuse" target="_blank"><u>reported</u></a> by the Crime Survey for England and Wales (CSEW) in the year ending June 2023 similar to the 876,000 offenses recorded in the year ending March 2020. Much CMA criticism hinges on the limitations of the act’s definitions and its binary view on hacking.</p><h3 class="article-body__section" id="section-the-definition-of-computer-in-the-act"><span>The definition of 'computer' in the Act</span></h3><p>Perhaps the most obvious criticism is that the act represents a time when ‘computer’ is mainly referred to as a desktop or <a href="https://www.itpro.com/hardware/the-time-has-come-to-say-arrivederci-to-the-all-in-one"><u>all-in-one PC</u></a>. In this regard, it fails to account for much of the innovation of the 21st century, putting it well out of step with the demands of the modern world.</p><p>“The Computer Misuse Act 1990 contains several issues that apply subjectivity when objectivity should be the test,” argues Tim Mackey, principal security strategist at the Synopsys Cybersecurity Research Centre. “The term “computer” isn’t defined and the contemporary definition of “computer” has likely shifted in the intervening thirty years.”</p><p>This lack of clear definition creates a “grey area”, adds Mackey, where prosecutors are forced to apply the act based on subjective interpretation, rather than objective information.</p><p>“This can lead to interesting scenarios that would question whether a <a href="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy"><u>smartphone</u></a>, nanny-cam, <a href="https://www.itpro.com/infrastructure/network-internet/366963/what-is-wi-fi-7">Wi-Fi</a>-connected dishwasher, or CCTV system are in fact computers – despite the reality that each of these devices often runs a general-purpose <a href="https://www.itpro.com/uk/tag/operating-systems"><u>operating system</u></a>, is connected to a network, and runs software at the behest of its user.”</p><h3 class="article-body__section" id="section-failure-to-keep-up-with-novel-cyber-threats"><span>Failure to keep up with novel cyber threats</span></h3><p>Another area of criticism for the CMA is that it has failed to keep up with the developments in cyber crime landscape such as the <a href="https://www.itpro.com/security/cyber-attacks/the-rise-of-identity-based-cyber-attacks-and-how-to-mitigate-them"><u>rise in identity-based attacks</u></a> and <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec"><u>business email compromise (BEC)</u></a>.</p><p>“The types of crime the act was originally designed to fight are actually decreasing – but new threats are emerging seemingly every month,” says Peter Yapp, Partner at law firm Schillings and former deputy director of the UK’s NCSC. “For example, hacking for extortion has nearly doubled over the past year while virus/<a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> reports have dropped. This underlines one of the main shortfalls of the act – the evolution of using computers to commit fraud to the computer becoming the main conduit for fraud.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wE3UT9aDVGm6fZh2yRZMu6" name="wE3UT9aDVGm6fZh2yRZMu6.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/wE3UT9aDVGm6fZh2yRZMu6.jpg" mos="https://cdn.mos.cms.futurecdn.net/wE3UT9aDVGm6fZh2yRZMu6.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>An EDR buyer's guide</strong></p><p class="fancy-box__body-text">How to pick the best endpoint detection and response solution for your business</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368443/an-edr-buyers-guide" data-original-url="/security/cyber-security/368443/an-edr-buyers-guide">FREE DOWNLOAD</a></p></div></div><p>The subjective interpretation of the Act ultimately drives a wedge between the legal system and security researchers, and some have argued that judges often appear to misunderstand the wider issues facing the industry.</p><p>“In essence, the Act isn’t working for <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> practitioners, law enforcement officers, the Crown Prosecution Office and the Courts,” adds Yapp. “Even more worryingly, judges don’t seem to understand the issues. For example, Southwark Crown Court is supposedly a specialist fraud center that deals with the majority of the serious and major fraud cases in England and Wales, but its level of understanding around computer crime isn’t sufficient to facilitate any significant number of successful prosecutions. The police have dedicated many more resources to this area over the past five years, but until every police officer understands cybercrime, we will be playing catch up.”</p><p>Richard Millett, training development manager at Firebrand Training and regular cyber security advisor for police forces across the UK, explains that many cyber crime cases are instead tried under other legislation, such as fraud and theft, not only because of a lack of definitions but also because it allows stricter penalties to be issued.</p><p>“If you look at the tariffs for the various sections under the [Computer Misuse] Act you see that the penalties defined do not match the severity of some of the offenses that have been committed,” says Millett. “It is only when you look at section 3za which covers “causing or creating a risk of serious damage” do you see tariffs of “imprisonment for life”. The financial and economic damage that has been inflicted by some individuals is not reflected in the penalties that have been applied, running into millions in many cases.”</p><h3 class="article-body__section" id="section-how-the-computer-misuse-act-limits-ethical-hacking"><span>How the Computer Misuse Act limits ethical hacking</span></h3><p>The greatest challenge facing cyber security researchers trying to operate within the scope of the act is its failure to distinguish between criminal and ethical hacking.</p><p>As Rob Shooter, managing partner of law firm Fieldfisher explains to <em>ITPro</em>, many in the industry argue that offenses under the CMA are too “broad brush”, leaving cyber security researchers with little legal room to perform ethical hacking against cyber criminals.</p><p>The Act defines non-consensually accessing a computer system as a crime, regardless of the intent or benefits that may come about as a result of the action. Technically, this means that core <a href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs#section-risk-management"><u>cyber security skills</u></a> and research tasks used to analyze potential threats from probing for <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management"><u>vulnerability management</u></a>, file interrogation, or analyzing compromised systems are illegal unless consent has been given by both the victim and perpetrator of the crime.</p><p>“As an example, there are a multitude of US-based companies offering vulnerability scanning services of the extended supply chain, whereas there are few, if any, UK companies offering the same service,” explains Yapp.</p><p>Although this technicality may limit the actions of ethical hacking or may leave some wary about potential prosecution, Yapp adds that he is unaware of any cases involving UK researchers being sanctioned by law enforcement as a direct result of their work.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=54751392&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How do you become an ethical hacker? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Often depicted as hooded basement-dwellers, faces lit only by blue light, hackers come in all shapes and sizes - and notably wear different coloured hats. The annoying, destruction-wielding hackers are known as black hats whereas those who use their hacking abilities for ethical, productive purposes are known as <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hats</a>.</p><p>Ethical hackers are in short supply in the industry and they serve an important purpose in the overall protection of modern businesses and other organisations. The old saying ‘attack is the best form of defence’ certainly rings true in the cyber security industry, and it’s why ethical hackers are paid handsomely for their services. Their role is to use their hacking abilities and knowledge of systems to find security vulnerabilities in software and infrastructure so they can be patched before criminals can exploit them. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/635041/getting-inside-the-minds-of-ethical-hackers" data-original-url="/635041/getting-inside-the-minds-of-ethical-hackers">Getting inside the minds of ethical hackers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a></p></div></div><p>Their work is invaluable to businesses that handle large quantities of sensitive or personally identifiable information, or those that are subject to tight regulations such as banking and financial services firms. </p><p>White hats can most commonly be found working in-house at businesses or independently, either as contractors or as modern-day bounty hunters - hackers who look for security vulnerabilities in companies that offer bug bounty programmes. There are a number of large companies such as Apple and Microsoft that offer lucrative bug bounties that increase in monetary reward based on how severe the vulnerability is.</p><p>There are a multitude of routes one can take to become an ethical hacker and, as previously mentioned, a number of different ways these hackers can monetise their skill set. The cyber security industry has been intent on attracting new talent to the scene and there is an abundance of resources to get you on your way to becoming a fully-fledged white hat. </p><h2 id="what-is-an-ethical-hacker">What is an ethical hacker?</h2><p>Before delving any deeper, it's important to clear up any misconceptions of what an ethical hacker is, rather than making judgements on what's morally right and wrong.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ebWTwtZnKEPD3hvMervZkk" name="ebWTwtZnKEPD3hvMervZkk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" mos="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The truth about cyber security training</strong></p><p class="fancy-box__body-text">Stop ticking boxes. Start delivering real change.</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361094/the-truth-about-cyber-security-training" data-original-url="/security/cyber-security/361094/the-truth-about-cyber-security-training">FREE DOWNLOAD</a></p></div></div><p>Jeff Schmidt, global head of business continuity, security and governance at BT, describes an ethical hacker as a computer security expert. They must specialise in penetration testing (i.e. working out how easy it is to break into computer systems) and other testing methods to ensure infrastructure is sufficiently secured against potential hacks.</p><p>However, another expert in the field of cyber security, Conrad Constantine, a research team engineer at AlienVault, thinks the description of any role as a "hacker," whether ethical or not, is irrelevant.</p><p>"Nobody says they are going to go see an ethical locksmith or an ethical lawyer do they?" he told <em>IT Pro</em>.</p><p>But what the role is called is simply semantics. It could be we decide to refer to them as a white hat hacker or penetration tester. The important differentiator between an ethical hacker and a criminal hacker is that the former carries out <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> testing with the full consent of the company they are working on behalf of.</p><p>If they did not have permission, the offence would be punishable under the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act</a>.</p><p>Ian Glover, chairman of CREST, prefers the <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration tester</a> label and his definition goes a little further in that it recognises you need to be more than just a techie in order to truly fulfil the role. He believes you need to have consultancy skills as well.</p><p>A penetration tester, he says, has to be able to "communicate the results of the tests at a level tailored to the audience", Glover says, and "provide technical consultancy and recommendations to customers as to how any reported vulnerabilities could be mitigated".</p><h2 id="what-certifications-and-training-do-ethical-hackers-need">What certifications and training do ethical hackers need?</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FuCpWYsutYheGJP5YKKdSU" name="" alt="A group of people seated at desks during a training session" src="https://cdn.mos.cms.futurecdn.net/FuCpWYsutYheGJP5YKKdSU.jpg" mos="https://cdn.mos.cms.futurecdn.net/FuCpWYsutYheGJP5YKKdSU.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>OK, so talking of the necessary skills for the job, what <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" target="_blank" data-original-url="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training">qualifications</a> do you need? Peter Chadha, <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do" data-original-url="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">chief executive</a> and founder of DrPete, reckons that all you need is "a vast amount of technical knowledge of IT systems and <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> and, in particular, how to exploit their vulnerabilities", but acknowledges that there are formal qualifications available.</p><p>"Most commonly the EC-Council Certified Ethical Hacker certification, a self-study or classroom course with a 200 multiple choice question exam at the end," Chadha says, adding: "<a href="https://www.itpro.com/security/20685/gchq-extends-skills-cyber-security-certification-scheme-private-sector" data-original-url="https://www.itpro.com/security/20685/gchq-extends-skills-cyber-security-certification-scheme-private-sector">Communications-Electronics Security Group (CESG)</a> [now part of the National Cyber Security Centre] approval is also required for any penetration test on a company, and this is appointed by a government department."</p><p>This involves the CHECK scheme, where penetration testers prove themselves through practical examination under lab conditions. "There are two levels of approval," Chadha explains. "A penetration test member and a penetration test team lead, and government departments will require at least one team lead working on any project."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HzoyL9nmubvMyv9xsnSFZ5" name="HzoyL9nmubvMyv9xsnSFZ5.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/HzoyL9nmubvMyv9xsnSFZ5.png" mos="https://cdn.mos.cms.futurecdn.net/HzoyL9nmubvMyv9xsnSFZ5.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Security awareness training strategies for account takeover protection</strong></p><p class="fancy-box__body-text">Why you need an inside-the-perimeter strategy for internal threats</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/internet-security/359469/security-awareness-training-strategies-for-account-takeover" data-original-url="/security/internet-security/359469/security-awareness-training-strategies-for-account-takeover">FREE DOWNLOAD</a></p></div></div><p>Phil Robinson, director of Digital Assurance and a Founder Associate Member of the Institute of Information Security Professionals points towards the Tiger Scheme and CREST certifications. "There are entry level testing certifications, for those wishing to be part of a testing team and working under the management of a team leader, and senior testing <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" data-original-url="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training">certifications</a> for more experienced individuals to either work on their own or to lead a team," Robinson told <em>IT Pro</em>.</p><p>"It also helps to have a reasonable general background and experience alongside certifications such as <a href="https://www.itpro.com/business-strategy/careers-training/356572/best-it-degrees-for-landing-the-hottest-tech-jobs" data-original-url="https://www.itpro.com/business-strategy/careers-training/356572/best-it-degrees-for-landing-the-hottest-tech-jobs">a Masters in Information Security</a>," he added.</p><p>As far as the CREST certification is concerned, Ian Glover points out that in order to pass at the lower level a candidate will need "knowledge and skills on a wide range of relevant subjects, and in addition they would normally require two to three years regular and frequent practical experience, equating to about 6,000 hours experience and research." When it comes to the higher level that increases to five years or 10,000 hours.</p><h2 id="can-cyber-criminals-become-ethical-hackers">Can cyber criminals become ethical hackers?</h2><p>But what about if that 'experience and research' was largely garnered on, for want of a better phrase, the dark side? Can, and do, black hat hackers cross the divide and <a href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" data-original-url="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">enter the legit world of the penetration tester</a>?</p><p>Dominique Karg, is the co-founder and brilliantly titled chief hacking officer at AlienVault. He has no problem with poachers turned gamekeeper.</p><p>"I think they're the only ones that can do the job well," he says, adding "I got my ethical hacking job that way. I had to choose between being taught something I already knew at the <a href="https://www.itpro.com/security/hacking/358001/20-universities-targeted-by-shadow-academy-hackers" data-original-url="https://www.itpro.com/security/hacking/358001/20-universities-targeted-by-shadow-academy-hackers">university</a> or getting paid for what I liked to do anyway. The decision was easy."</p><p>Ian Glover agrees that we have to recognise where the industry has come from. "There are individuals within the industry that have crossed from the dark to the light," he says, but warns that the situation is changing very quickly.</p><p>"There is no reason now to have worked on the dark side to enter or progress in the industry," Glover argues, concluding "in fact the high ethical standards that CREST member companies sign up to would make it difficult for them to employ such individuals."</p><p>Marcus Ranum, chief security officer at <a href="https://www.itpro.com/security/34773/tenable-declares-there-are-far-worse-security-threats-to-fear-than-zero-day-exploits" data-original-url="https://www.itpro.com/security/34773/tenable-declares-there-are-far-worse-security-threats-to-fear-than-zero-day-exploits">Tenable Network Security</a>, thinks that a track record as a recreational hacker simply shows errors in judgement and a willingness to put self-interest first. "That's not something that should impress a prospective client," he insists. "After all, if you were acting like a sociopath last month, why should I believe you're not one today?"</p><h2 id="what-kinds-of-ethical-hacker-job-roles-are-available">What kinds of ethical hacker job roles are available?</h2><p>Much like how cyber security as an industry is somewhat of a catch-all term for different sub-fields, the term ‘ethical hacker’ also encompasses many different types of <a href="https://www.itpro.com/business-strategy/careers-training/355028/5-best-entry-level-tech-jobs" data-original-url="https://www.itpro.com/business-strategy/careers-training/355028/5-best-entry-level-tech-jobs">jobs</a>, the most common and perhaps most glamorised being a <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration tester</a>.</p><p>Penetration testers, or pen testers, are hired to probe a business for cyber security weaknesses through both digital and kinetic means. Some penetration testers are hired to assess the physical security of a company’s office building, for example, since this can be an entry point through which hackers could conduct local attacks. Other common job roles are security analysts, information security consultants, and network security specialists.</p><p>There are also opportunities to get involved in corporate <a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">red team</a>-blue team exercises, which involve cyber security staff taking part in <a href="https://www.itpro.com/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you" data-original-url="https://www.itpro.com/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you">virtual war games</a> to hone skills and ensure everyone is prepared to face a real cyber attack when the time comes. Ethical hackers will typically get drafted in to participate on the red team - the offensive team the company’s staff try to keep out of their systems - and these kinds of roles can often pay well too, especially on a contract or consultancy basis.</p><h2 id="what-39-s-the-average-salary-for-an-ethical-hacker">What's the average salary for an ethical hacker?</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WFFZJ9EoCo3pMpB9QwbAXZ" name="" alt="A pile of British pound sterling banknotes" src="https://cdn.mos.cms.futurecdn.net/WFFZJ9EoCo3pMpB9QwbAXZ.jpg" mos="https://cdn.mos.cms.futurecdn.net/WFFZJ9EoCo3pMpB9QwbAXZ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Experts speaking to <em>IT Pro</em> all said that there is <a href="https://www.itpro.com/business-strategy/careers-training/359789/best-paying-tech-jobs" data-original-url="https://www.itpro.com/business-strategy/careers-training/359789/best-paying-tech-jobs">plenty of money to be made</a> as an ethical hacker, with the demand for such talents far outweighing the supply. Newcomers to the job market can expect to make around £25,000, according to Ian Glover, while a registered professional with some experience could be looking at a salary in the region of £55,000. A team leader should be expecting even more; a sum north of £90,000 would be about right in the current market.</p><p>Peter Chadha adds that a penetration tester working as a contractor can easily earn between £400-£500 a day. As for <a href="https://www.itpro.com/business-strategy/careers-training/34591/how-to-make-yourself-irreplaceable-in-tomorrow-s-job-market" data-original-url="https://www.itpro.com/business-strategy/careers-training/34591/how-to-make-yourself-irreplaceable-in-tomorrow-s-job-market">market buoyancy</a>, Glover told <em>IT Pro</em> that "the demand for high-quality individuals working for professional companies far outstrips supply."</p><p>"The UK is seen as one of the leaders in this area and the opportunity to work on international projects is increasing every day."</p><p>John Yeo, director at Trustwave SpiderLabs, put it in a nutshell when he told us that given the recent uptick in mainstream media awareness of the types of malicious compromises that take place on a regular basis, and the reality that now cyber security is much higher on every organisation's executive agenda "in many respects it has never been better".</p><p>Another way to ethically make money from hacking is to take part in bug bounty programmes, which are used by companies like <a href="https://www.itpro.com/security/23979/google-offers-security-flaw-hunters-3000-bounty" data-original-url="https://www.itpro.com/security/23979/google-offers-security-flaw-hunters-3000-bounty">Google</a>, <a href="https://www.itpro.com/security/26694/microsoft-targets-net-core-with-new-bug-bounty-rewards" data-original-url="https://www.itpro.com/security/26694/microsoft-targets-net-core-with-new-bug-bounty-rewards">Microsoft</a>, <a href="https://www.itpro.com/security/26256/uber-launches-bug-bounty-programme-with-10k-prize" data-original-url="https://www.itpro.com/security/26256/uber-launches-bug-bounty-programme-with-10k-prize">Uber</a>, and <a href="https://www.itpro.com/security/26532/white-hat-hackers-access-full-database-of-pornhub-members" data-original-url="https://www.itpro.com/security/26532/white-hat-hackers-access-full-database-of-pornhub-members">even PornHub</a> to encourage hackers to discreetly report flaws instead of exploiting them. However, bug bounty programmes aren’t only reserved for major tech companies. The UK’s Ministry of Defence (MoD) recently introduced <a href="https://www.itpro.com/security/358083/mod-launches-bug-bounty-programme" data-original-url="https://www.itpro.com/security/358083/mod-launches-bug-bounty-programme">its own programme</a> through which white hat hackers can disclose vulnerabilities to the UK government department without fear of prosecution.</p><p>Apple is especially well-known for handsomely rewarding its ethical hackers, having <a href="https://www.itpro.com/security/27056/apple-finally-introduces-bug-bounty-programme" data-original-url="https://www.itpro.com/security/27056/apple-finally-introduces-bug-bounty-programme">launched a bug bounty programme in 2016</a> which pays security experts between $25,000 (£18,000) and $1 million (£720,000) for a disclosed security issue. What's more, the company <a href="https://developer.apple.com/security-bounty/payouts">states</a> that vulnerabilities which “were previously unknown to Apple” could potentially “result in a 50% additional bonus” added to the payout.</p><p>In October 2020, the tech giant paid a team of penetration testers <a href="https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities" data-original-url="https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities">at least $288,500</a> (£222,813) for finding and disclosing critical vulnerabilities in its network. Out of the 55 bugs reported by the team, the 11 most critical ones made it possible to access Apple’s <a href="https://www.itpro.com/infrastructure" data-original-url="https://www.itpro.com/infrastructure">infrastructure</a> and use it to potentially steal confidential information such as private emails and <a href="https://www.itpro.com/tag/icloud" data-original-url="https://www.itpro.com/search/icloud">iCloud</a> data.</p><p>Only a few months prior, <a href="https://www.itpro.com/security/ethical-hacking/355860/developer-scores-100000-bounty-from-apple-for-exposing-a-critical" data-original-url="https://www.itpro.com/security/ethical-hacking/355860/developer-scores-100000-bounty-from-apple-for-exposing-a-critical">developer Bhavuk Jain</a> managed to identify a security vulnerability in the <a href="https://www.itpro.com/mobile/33765/sign-in-with-apple-launched-at-wwdc-2019" data-original-url="https://www.itpro.com/mobile/33765/sign-in-with-apple-launched-at-wwdc-2019">"Sign in with Apple"</a> feature which could have been used to enable hackers to take control of a user's account. For this discovery, the tech giant chose to award Jain with a $100,000 (£72,280) payout.</p><p>So what are you waiting for?</p><h2 id="how-to-apply-for-a-job-as-an-ethical-hacker">How to apply for a job as an ethical hacker </h2><p>Who should you approach if you actually want to get started in the penetration testing field? We ask the experts...</p><ul><li><strong>Ian Glover:</strong> "Anyone interested in a career in the industry should contact CREST who will provide advice and guidance on the <a href="https://www.itpro.com/business-strategy/careers-training/356531/tech-leaders-share-how-to-break-into-the-tech-industry" data-original-url="https://www.itpro.com/business-strategy/careers-training/356531/tech-leaders-share-how-to-break-into-the-tech-industry">best way to enter</a> and then progress in the industry. We are also working with a number of universities to provide internship and work placement opportunities for individuals, with a great deal of success."</li><li><strong>Marcus Ranum:</strong> "Get a job working as an auditor. Penetration testing can be thought of as a 'more aggressive audit' and there's a lot of intellectual overlap in the field."</li><li><strong>Jeff Schmidt:</strong> "The <a href="https://www.itpro.com/625504/cyber-security-challenge-uk-launched" data-original-url="https://www.itpro.com/625504/cyber-security-challenge-uk-launched">Cyber Security Challenge UK</a> is a good starting point to get an understanding of the cyber learning opportunities and careers within the industry."</li><li><strong>Peter Chadha:</strong> "Search for the equivalent of CESG team members and network with them to build connections and knowledge in this area."</li><li><strong>John Yeo:</strong> "Invest the time and effort in going to conferences and get to know the various characters within the industries for which this isn't just a day a job, but enjoy it so much that they're regulars on the conference circuit."</li></ul> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker</link>
                                                                            <description>
                            <![CDATA[ We examine what certifications do you need, what jobs are available and how much you can expect to be paid ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8sfKBHrggppFm6qjTAe767</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZzdJSZhjvG3kZFpodAqtjF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Jul 2019 12:10:00 +0000</pubDate>                                                                                                                                <updated>Fri, 29 Apr 2022 15:27:50 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ connor.jones@futurenet.com (Connor Jones) ]]></author>                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Connor Jones is the News and Analysis Editor at ITPro, CloudPro, and ChannelPro. As the brands’ leader for news, he welcomes pitches on all topics, and he personally still reports breaking news on the topics of cyber security, software, and Big Tech firms.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;He has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs.&lt;/p&gt;
&lt;p&gt;Connor is currently in his third year at ITPro, but has been a journalist for much longer, having written for the likes of Red Bull Esports and UNILAD. He has a master’s degree in Magazine Journalism from one of the UK’s leading journalism departments at the University of Sheffield, as well as an undergraduate degree in English Language from Sheffield Hallam University.&lt;/p&gt;
&lt;p&gt;When he’s not hitting the phones trying to squeeze stories out of sources and press offices, in his free time Connor studies software development, is a keen cook, and enjoys leading an active life through cycling, hiking, racket sports, and weightlifting.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZzdJSZhjvG3kZFpodAqtjF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ethical hacker silhouette walking through a keyhole, symbolising physical security and penetration testing]]></media:description>                                                            <media:text><![CDATA[Ethical hacker silhouette walking through a keyhole, symbolising physical security and penetration testing]]></media:text>
                                <media:title type="plain"><![CDATA[Ethical hacker silhouette walking through a keyhole, symbolising physical security and penetration testing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZzdJSZhjvG3kZFpodAqtjF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Often depicted as hooded basement-dwellers, faces lit only by blue light, hackers come in all shapes and sizes - and notably wear different coloured hats. The annoying, destruction-wielding hackers are known as black hats whereas those who use their hacking abilities for ethical, productive purposes are known as <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hats</a>.</p><p>Ethical hackers are in short supply in the industry and they serve an important purpose in the overall protection of modern businesses and other organisations. The old saying ‘attack is the best form of defence’ certainly rings true in the cyber security industry, and it’s why ethical hackers are paid handsomely for their services. Their role is to use their hacking abilities and knowledge of systems to find security vulnerabilities in software and infrastructure so they can be patched before criminals can exploit them. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/635041/getting-inside-the-minds-of-ethical-hackers" data-original-url="/635041/getting-inside-the-minds-of-ethical-hackers">Getting inside the minds of ethical hackers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a></p></div></div><p>Their work is invaluable to businesses that handle large quantities of sensitive or personally identifiable information, or those that are subject to tight regulations such as banking and financial services firms. </p><p>White hats can most commonly be found working in-house at businesses or independently, either as contractors or as modern-day bounty hunters - hackers who look for security vulnerabilities in companies that offer bug bounty programmes. There are a number of large companies such as Apple and Microsoft that offer lucrative bug bounties that increase in monetary reward based on how severe the vulnerability is.</p><p>There are a multitude of routes one can take to become an ethical hacker and, as previously mentioned, a number of different ways these hackers can monetise their skill set. The cyber security industry has been intent on attracting new talent to the scene and there is an abundance of resources to get you on your way to becoming a fully-fledged white hat. </p><h2 id="what-is-an-ethical-hacker">What is an ethical hacker?</h2><p>Before delving any deeper, it's important to clear up any misconceptions of what an ethical hacker is, rather than making judgements on what's morally right and wrong.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ebWTwtZnKEPD3hvMervZkk" name="ebWTwtZnKEPD3hvMervZkk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" mos="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The truth about cyber security training</strong></p><p class="fancy-box__body-text">Stop ticking boxes. Start delivering real change.</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361094/the-truth-about-cyber-security-training" data-original-url="/security/cyber-security/361094/the-truth-about-cyber-security-training">FREE DOWNLOAD</a></p></div></div><p>Jeff Schmidt, global head of business continuity, security and governance at BT, describes an ethical hacker as a computer security expert. They must specialise in penetration testing (i.e. working out how easy it is to break into computer systems) and other testing methods to ensure infrastructure is sufficiently secured against potential hacks.</p><p>However, another expert in the field of cyber security, Conrad Constantine, a research team engineer at AlienVault, thinks the description of any role as a "hacker," whether ethical or not, is irrelevant.</p><p>"Nobody says they are going to go see an ethical locksmith or an ethical lawyer do they?" he told <em>IT Pro</em>.</p><p>But what the role is called is simply semantics. It could be we decide to refer to them as a white hat hacker or penetration tester. The important differentiator between an ethical hacker and a criminal hacker is that the former carries out <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> testing with the full consent of the company they are working on behalf of.</p><p>If they did not have permission, the offence would be punishable under the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" target="_blank" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act</a>.</p><p>Ian Glover, chairman of CREST, prefers the <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration tester</a> label and his definition goes a little further in that it recognises you need to be more than just a techie in order to truly fulfil the role. He believes you need to have consultancy skills as well.</p><p>A penetration tester, he says, has to be able to "communicate the results of the tests at a level tailored to the audience", Glover says, and "provide technical consultancy and recommendations to customers as to how any reported vulnerabilities could be mitigated".</p><h2 id="what-certifications-and-training-do-ethical-hackers-need">What certifications and training do ethical hackers need?</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FuCpWYsutYheGJP5YKKdSU" name="" alt="A group of people seated at desks during a training session" src="https://cdn.mos.cms.futurecdn.net/FuCpWYsutYheGJP5YKKdSU.jpg" mos="https://cdn.mos.cms.futurecdn.net/FuCpWYsutYheGJP5YKKdSU.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>OK, so talking of the necessary skills for the job, what <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" target="_blank" data-original-url="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training">qualifications</a> do you need? Peter Chadha, <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do" data-original-url="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">chief executive</a> and founder of DrPete, reckons that all you need is "a vast amount of technical knowledge of IT systems and <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> and, in particular, how to exploit their vulnerabilities", but acknowledges that there are formal qualifications available.</p><p>"Most commonly the EC-Council Certified Ethical Hacker certification, a self-study or classroom course with a 200 multiple choice question exam at the end," Chadha says, adding: "<a href="https://www.itpro.com/security/20685/gchq-extends-skills-cyber-security-certification-scheme-private-sector" data-original-url="https://www.itpro.com/security/20685/gchq-extends-skills-cyber-security-certification-scheme-private-sector">Communications-Electronics Security Group (CESG)</a> [now part of the National Cyber Security Centre] approval is also required for any penetration test on a company, and this is appointed by a government department."</p><p>This involves the CHECK scheme, where penetration testers prove themselves through practical examination under lab conditions. "There are two levels of approval," Chadha explains. "A penetration test member and a penetration test team lead, and government departments will require at least one team lead working on any project."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HzoyL9nmubvMyv9xsnSFZ5" name="HzoyL9nmubvMyv9xsnSFZ5.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/HzoyL9nmubvMyv9xsnSFZ5.png" mos="https://cdn.mos.cms.futurecdn.net/HzoyL9nmubvMyv9xsnSFZ5.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Security awareness training strategies for account takeover protection</strong></p><p class="fancy-box__body-text">Why you need an inside-the-perimeter strategy for internal threats</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/internet-security/359469/security-awareness-training-strategies-for-account-takeover" data-original-url="/security/internet-security/359469/security-awareness-training-strategies-for-account-takeover">FREE DOWNLOAD</a></p></div></div><p>Phil Robinson, director of Digital Assurance and a Founder Associate Member of the Institute of Information Security Professionals points towards the Tiger Scheme and CREST certifications. "There are entry level testing certifications, for those wishing to be part of a testing team and working under the management of a team leader, and senior testing <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" data-original-url="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training">certifications</a> for more experienced individuals to either work on their own or to lead a team," Robinson told <em>IT Pro</em>.</p><p>"It also helps to have a reasonable general background and experience alongside certifications such as <a href="https://www.itpro.com/business-strategy/careers-training/356572/best-it-degrees-for-landing-the-hottest-tech-jobs" data-original-url="https://www.itpro.com/business-strategy/careers-training/356572/best-it-degrees-for-landing-the-hottest-tech-jobs">a Masters in Information Security</a>," he added.</p><p>As far as the CREST certification is concerned, Ian Glover points out that in order to pass at the lower level a candidate will need "knowledge and skills on a wide range of relevant subjects, and in addition they would normally require two to three years regular and frequent practical experience, equating to about 6,000 hours experience and research." When it comes to the higher level that increases to five years or 10,000 hours.</p><h2 id="can-cyber-criminals-become-ethical-hackers">Can cyber criminals become ethical hackers?</h2><p>But what about if that 'experience and research' was largely garnered on, for want of a better phrase, the dark side? Can, and do, black hat hackers cross the divide and <a href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" data-original-url="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">enter the legit world of the penetration tester</a>?</p><p>Dominique Karg, is the co-founder and brilliantly titled chief hacking officer at AlienVault. He has no problem with poachers turned gamekeeper.</p><p>"I think they're the only ones that can do the job well," he says, adding "I got my ethical hacking job that way. I had to choose between being taught something I already knew at the <a href="https://www.itpro.com/security/hacking/358001/20-universities-targeted-by-shadow-academy-hackers" data-original-url="https://www.itpro.com/security/hacking/358001/20-universities-targeted-by-shadow-academy-hackers">university</a> or getting paid for what I liked to do anyway. The decision was easy."</p><p>Ian Glover agrees that we have to recognise where the industry has come from. "There are individuals within the industry that have crossed from the dark to the light," he says, but warns that the situation is changing very quickly.</p><p>"There is no reason now to have worked on the dark side to enter or progress in the industry," Glover argues, concluding "in fact the high ethical standards that CREST member companies sign up to would make it difficult for them to employ such individuals."</p><p>Marcus Ranum, chief security officer at <a href="https://www.itpro.com/security/34773/tenable-declares-there-are-far-worse-security-threats-to-fear-than-zero-day-exploits" data-original-url="https://www.itpro.com/security/34773/tenable-declares-there-are-far-worse-security-threats-to-fear-than-zero-day-exploits">Tenable Network Security</a>, thinks that a track record as a recreational hacker simply shows errors in judgement and a willingness to put self-interest first. "That's not something that should impress a prospective client," he insists. "After all, if you were acting like a sociopath last month, why should I believe you're not one today?"</p><h2 id="what-kinds-of-ethical-hacker-job-roles-are-available">What kinds of ethical hacker job roles are available?</h2><p>Much like how cyber security as an industry is somewhat of a catch-all term for different sub-fields, the term ‘ethical hacker’ also encompasses many different types of <a href="https://www.itpro.com/business-strategy/careers-training/355028/5-best-entry-level-tech-jobs" data-original-url="https://www.itpro.com/business-strategy/careers-training/355028/5-best-entry-level-tech-jobs">jobs</a>, the most common and perhaps most glamorised being a <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration tester</a>.</p><p>Penetration testers, or pen testers, are hired to probe a business for cyber security weaknesses through both digital and kinetic means. Some penetration testers are hired to assess the physical security of a company’s office building, for example, since this can be an entry point through which hackers could conduct local attacks. Other common job roles are security analysts, information security consultants, and network security specialists.</p><p>There are also opportunities to get involved in corporate <a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">red team</a>-blue team exercises, which involve cyber security staff taking part in <a href="https://www.itpro.com/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you" data-original-url="https://www.itpro.com/security/33151/ibm-s-cyber-security-crash-course-brings-out-the-very-worst-in-you">virtual war games</a> to hone skills and ensure everyone is prepared to face a real cyber attack when the time comes. Ethical hackers will typically get drafted in to participate on the red team - the offensive team the company’s staff try to keep out of their systems - and these kinds of roles can often pay well too, especially on a contract or consultancy basis.</p><h2 id="what-39-s-the-average-salary-for-an-ethical-hacker">What's the average salary for an ethical hacker?</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WFFZJ9EoCo3pMpB9QwbAXZ" name="" alt="A pile of British pound sterling banknotes" src="https://cdn.mos.cms.futurecdn.net/WFFZJ9EoCo3pMpB9QwbAXZ.jpg" mos="https://cdn.mos.cms.futurecdn.net/WFFZJ9EoCo3pMpB9QwbAXZ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Experts speaking to <em>IT Pro</em> all said that there is <a href="https://www.itpro.com/business-strategy/careers-training/359789/best-paying-tech-jobs" data-original-url="https://www.itpro.com/business-strategy/careers-training/359789/best-paying-tech-jobs">plenty of money to be made</a> as an ethical hacker, with the demand for such talents far outweighing the supply. Newcomers to the job market can expect to make around £25,000, according to Ian Glover, while a registered professional with some experience could be looking at a salary in the region of £55,000. A team leader should be expecting even more; a sum north of £90,000 would be about right in the current market.</p><p>Peter Chadha adds that a penetration tester working as a contractor can easily earn between £400-£500 a day. As for <a href="https://www.itpro.com/business-strategy/careers-training/34591/how-to-make-yourself-irreplaceable-in-tomorrow-s-job-market" data-original-url="https://www.itpro.com/business-strategy/careers-training/34591/how-to-make-yourself-irreplaceable-in-tomorrow-s-job-market">market buoyancy</a>, Glover told <em>IT Pro</em> that "the demand for high-quality individuals working for professional companies far outstrips supply."</p><p>"The UK is seen as one of the leaders in this area and the opportunity to work on international projects is increasing every day."</p><p>John Yeo, director at Trustwave SpiderLabs, put it in a nutshell when he told us that given the recent uptick in mainstream media awareness of the types of malicious compromises that take place on a regular basis, and the reality that now cyber security is much higher on every organisation's executive agenda "in many respects it has never been better".</p><p>Another way to ethically make money from hacking is to take part in bug bounty programmes, which are used by companies like <a href="https://www.itpro.com/security/23979/google-offers-security-flaw-hunters-3000-bounty" data-original-url="https://www.itpro.com/security/23979/google-offers-security-flaw-hunters-3000-bounty">Google</a>, <a href="https://www.itpro.com/security/26694/microsoft-targets-net-core-with-new-bug-bounty-rewards" data-original-url="https://www.itpro.com/security/26694/microsoft-targets-net-core-with-new-bug-bounty-rewards">Microsoft</a>, <a href="https://www.itpro.com/security/26256/uber-launches-bug-bounty-programme-with-10k-prize" data-original-url="https://www.itpro.com/security/26256/uber-launches-bug-bounty-programme-with-10k-prize">Uber</a>, and <a href="https://www.itpro.com/security/26532/white-hat-hackers-access-full-database-of-pornhub-members" data-original-url="https://www.itpro.com/security/26532/white-hat-hackers-access-full-database-of-pornhub-members">even PornHub</a> to encourage hackers to discreetly report flaws instead of exploiting them. However, bug bounty programmes aren’t only reserved for major tech companies. The UK’s Ministry of Defence (MoD) recently introduced <a href="https://www.itpro.com/security/358083/mod-launches-bug-bounty-programme" data-original-url="https://www.itpro.com/security/358083/mod-launches-bug-bounty-programme">its own programme</a> through which white hat hackers can disclose vulnerabilities to the UK government department without fear of prosecution.</p><p>Apple is especially well-known for handsomely rewarding its ethical hackers, having <a href="https://www.itpro.com/security/27056/apple-finally-introduces-bug-bounty-programme" data-original-url="https://www.itpro.com/security/27056/apple-finally-introduces-bug-bounty-programme">launched a bug bounty programme in 2016</a> which pays security experts between $25,000 (£18,000) and $1 million (£720,000) for a disclosed security issue. What's more, the company <a href="https://developer.apple.com/security-bounty/payouts">states</a> that vulnerabilities which “were previously unknown to Apple” could potentially “result in a 50% additional bonus” added to the payout.</p><p>In October 2020, the tech giant paid a team of penetration testers <a href="https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities" data-original-url="https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities">at least $288,500</a> (£222,813) for finding and disclosing critical vulnerabilities in its network. Out of the 55 bugs reported by the team, the 11 most critical ones made it possible to access Apple’s <a href="https://www.itpro.com/infrastructure" data-original-url="https://www.itpro.com/infrastructure">infrastructure</a> and use it to potentially steal confidential information such as private emails and <a href="https://www.itpro.com/tag/icloud" data-original-url="https://www.itpro.com/search/icloud">iCloud</a> data.</p><p>Only a few months prior, <a href="https://www.itpro.com/security/ethical-hacking/355860/developer-scores-100000-bounty-from-apple-for-exposing-a-critical" data-original-url="https://www.itpro.com/security/ethical-hacking/355860/developer-scores-100000-bounty-from-apple-for-exposing-a-critical">developer Bhavuk Jain</a> managed to identify a security vulnerability in the <a href="https://www.itpro.com/mobile/33765/sign-in-with-apple-launched-at-wwdc-2019" data-original-url="https://www.itpro.com/mobile/33765/sign-in-with-apple-launched-at-wwdc-2019">"Sign in with Apple"</a> feature which could have been used to enable hackers to take control of a user's account. For this discovery, the tech giant chose to award Jain with a $100,000 (£72,280) payout.</p><p>So what are you waiting for?</p><h2 id="how-to-apply-for-a-job-as-an-ethical-hacker">How to apply for a job as an ethical hacker </h2><p>Who should you approach if you actually want to get started in the penetration testing field? We ask the experts...</p><ul><li><strong>Ian Glover:</strong> "Anyone interested in a career in the industry should contact CREST who will provide advice and guidance on the <a href="https://www.itpro.com/business-strategy/careers-training/356531/tech-leaders-share-how-to-break-into-the-tech-industry" data-original-url="https://www.itpro.com/business-strategy/careers-training/356531/tech-leaders-share-how-to-break-into-the-tech-industry">best way to enter</a> and then progress in the industry. We are also working with a number of universities to provide internship and work placement opportunities for individuals, with a great deal of success."</li><li><strong>Marcus Ranum:</strong> "Get a job working as an auditor. Penetration testing can be thought of as a 'more aggressive audit' and there's a lot of intellectual overlap in the field."</li><li><strong>Jeff Schmidt:</strong> "The <a href="https://www.itpro.com/625504/cyber-security-challenge-uk-launched" data-original-url="https://www.itpro.com/625504/cyber-security-challenge-uk-launched">Cyber Security Challenge UK</a> is a good starting point to get an understanding of the cyber learning opportunities and careers within the industry."</li><li><strong>Peter Chadha:</strong> "Search for the equivalent of CESG team members and network with them to build connections and knowledge in this area."</li><li><strong>John Yeo:</strong> "Invest the time and effort in going to conferences and get to know the various characters within the industries for which this isn't just a day a job, but enjoy it so much that they're regulars on the conference circuit."</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>